NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups Q–S

23 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. Rancor

    G0075Espionage9 techniques4 tools & malware

    Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice…

  2. RedCurl

    G103941 techniques

    RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the…

  3. RedEcho

    G1042China5 techniques1 tools & malware

    RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities.…

  4. Rocke

    G0106China36 techniques

    Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the…

  5. RTM

    G0048Russia7 techniques1 tools & malware2 live indicators

    RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and…

  6. Saint Bear (Storm-0587)

    G1031Russia18 techniques2 tools & malware2 live indicators

    Also tracked asTA471 · UAC-0056 · Lorec53

    Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a…

  7. Salt Typhoon

    G1045China14 techniques1 tools & malware

    Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous…

  8. Sandworm Team (ELECTRUM)

    G0034RussiaEspionage79 techniques27 tools & malware68 live indicators

    Also tracked asTelebots · IRON VIKING · BlackEnergy (Group) and 6 more

    Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for…

  9. Scarlet Mimic

    G00291 techniques4 tools & malware1 live indicators

    Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the…

  10. Scattered Spider (Roasted 0ktapus)

    G101564 techniques9 tools & malware1,065 live indicators

    Also tracked asOcto Tempest · Storm-0875 · UNC3944

    Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship…

  11. Sea Turtle (Teal Kurma)

    G104127 techniques1 tools & malware

    Also tracked asMarbled Dust · Cosmic Wolf · SILICON

    Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against…

  12. SideCopy

    G1008Pakistan16 techniques2 tools & malware

    SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at…

  13. Sidewinder (T-APT-04)

    G0121India30 techniques1 tools & malware157 live indicators

    Also tracked asRattlesnake

    Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military,…

  14. Silence (Whisper Spider)

    G009128 techniques3 tools & malware

    Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their…

  15. Silent Librarian (TA407)

    G012213 techniques

    Also tracked asCOBALT DICKENS

    Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies…

  16. SilverTerrier

    G00834 techniques5 tools & malware1,075 live indicators

    SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher…

  17. Sowbug

    G0054Espionage9 techniques2 tools & malware15 live indicators

    Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government…

  18. Star Blizzard (SEABORGIUM)

    G1033Russia20 techniques1 tools & malware4 live indicators

    Also tracked asCallisto Group · TA446 · COLDRIVER

    Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align…

  19. Stealth Falcon

    G0038Espionage16 techniques

    Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least…

  20. Storm-0501

    G105342 techniques8 tools & malware9 live indicators

    Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has…

  21. Storm-1811

    G104631 techniques7 tools & malware413 live indicators

    Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social…

  22. Strider (ProjectSauron)

    G0041ChinaEspionage3 techniques1 tools & malware

    Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.

  23. Suckfly

    G0039China5 techniques1 tools & malware

    Suckfly is a China-based threat group that has been active since at least 2014.

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator