Threat groups T–V
22 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
TA2541
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least…
TA459
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
TA505 (Hive0065)
Also tracked asSpandex Tempest · CHIMBORAZO
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in…
TA551 (GOLD CABIN)
Also tracked asShathak
TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian,…
TA577
TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in…
TA578
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including…
TeamTNT
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and…
TEMP.Veles (XENOTIME)
TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware…
The White Company
The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign…
Threat Group-1314 (TG-1314)
Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.
Threat Group-3390 (Earth Smilodon)
Also tracked asTG-3390 · Emissary Panda · BRONZE UNION and 4 more
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at…
Thrip
Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia.…
ToddyCat
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains…
Tonto Team (Earth Akhlut)
Also tracked asBRONZE HUNTLEY · CactusPete · Karma Panda
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United…
Transparent Tribe (COPPER FIELDSTONE)
Also tracked asAPT36 · Mythic Leopard · ProjectM
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and…
Tropic Trooper (Pirate Panda)
Also tracked asKeyBoy
Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic…
Turla (IRON HUNTER)
Also tracked asGroup 88 · Waterbug · WhiteBear and 5 more
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50…
UNC3886
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication…
Velvet Ant
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network…
VOID MANTICORE (COBALT MYSTIQUE)
Also tracked asHandala Hack · Homeland Justice · Karma and 3 more
VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least…
Volatile Cedar (Lebanese Cedar)
Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating…
Volt Typhoon (BRONZE SILHOUETTE)
Also tracked asVanguard Panda · DEV-0391 · UNC3236 and 3 more
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical…
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator