Threat groups N–P
13 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
Naikon
Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region…
NEODYMIUM
NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity…
Nomadic Octopus (DustSquad)
Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic…
OilRig (COBALT GYPSY)
Also tracked asIRN2 · APT34 · Helix Kitten and 7 more
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a…
Orangeworm
Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for…
Patchwork (Hangover Group)
Also tracked asDropping Elephant · Chinastrats · MONSOON and 1 more
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial…
PittyTiger
PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
PLATINUM
PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related…
Play
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical…
POLONIUM (Plaid Rain)
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and…
Poseidon Group
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information…
PROMETHIUM (StrongPity)
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a…
Putter Panda (APT2)
Also tracked asMSUpdater
Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD).
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator