Threat groups Q–S
23 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
Rancor
Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice…
RedCurl
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the…
RedEcho
RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities.…
Rocke
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the…
RTM
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and…
Saint Bear (Storm-0587)
Also tracked asTA471 · UAC-0056 · Lorec53
Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a…
Salt Typhoon
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous…
Sandworm Team (ELECTRUM)
Also tracked asTelebots · IRON VIKING · BlackEnergy (Group) and 6 more
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for…
Scarlet Mimic
Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the…
Scattered Spider (Roasted 0ktapus)
Also tracked asOcto Tempest · Storm-0875 · UNC3944
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship…
Sea Turtle (Teal Kurma)
Also tracked asMarbled Dust · Cosmic Wolf · SILICON
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against…
SideCopy
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at…
Sidewinder (T-APT-04)
Also tracked asRattlesnake
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military,…
Silence (Whisper Spider)
Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their…
Silent Librarian (TA407)
Also tracked asCOBALT DICKENS
Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies…
SilverTerrier
SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher…
Sowbug
Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government…
Star Blizzard (SEABORGIUM)
Also tracked asCallisto Group · TA446 · COLDRIVER
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align…
Stealth Falcon
Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least…
Storm-0501
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has…
Storm-1811
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social…
Strider (ProjectSauron)
Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.
Suckfly
Suckfly is a China-based threat group that has been active since at least 2014.
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator