NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups T–V

22 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. TA2541

    G101828 techniques9 tools & malware788 live indicators

    TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least…

  2. TA459

    G0062China5 techniques4 tools & malware

    TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.

  3. TA505 (Hive0065)

    G009234 techniques16 tools & malware1,683 live indicators

    Also tracked asSpandex Tempest · CHIMBORAZO

    TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in…

  4. TA551 (GOLD CABIN)

    G012714 techniques5 tools & malware2,044 live indicators

    Also tracked asShathak

    TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian,…

  5. TA577

    G10376 techniques3 tools & malware956 live indicators

    TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in…

  6. TA578

    G10384 techniques3 tools & malware915 live indicators

    TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including…

  7. TeamTNT

    G013956 techniques4 tools & malware

    TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and…

  8. TEMP.Veles (XENOTIME)

    G00882 tools & malware

    TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware…

  9. The White Company

    G00897 techniques2 tools & malware502 live indicators

    The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign…

  10. Threat Group-1314 (TG-1314)

    G00284 techniques2 tools & malware

    Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.

  11. Threat Group-3390 (Earth Smilodon)

    G0027ChinaEspionage57 techniques24 tools & malware5 live indicators

    Also tracked asTG-3390 · Emissary Panda · BRONZE UNION and 4 more

    Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at…

  12. Thrip

    G0076Espionage4 techniques3 tools & malware

    Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia.…

  13. ToddyCat

    G102225 techniques9 tools & malware

    ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains…

  14. Tonto Team (Earth Akhlut)

    G0131China15 techniques6 tools & malware

    Also tracked asBRONZE HUNTLEY · CactusPete · Karma Panda

    Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United…

  15. Transparent Tribe (COPPER FIELDSTONE)

    G0134Pakistan14 techniques5 tools & malware327 live indicators

    Also tracked asAPT36 · Mythic Leopard · ProjectM

    Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and…

  16. Tropic Trooper (Pirate Panda)

    G0081China40 techniques6 tools & malware

    Also tracked asKeyBoy

    Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic…

  17. Turla (IRON HUNTER)

    G0010RussiaEspionage68 techniques30 tools & malware7 live indicators

    Also tracked asGroup 88 · Waterbug · WhiteBear and 5 more

    Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50…

  18. UNC3886

    G1048China49 techniques8 tools & malware33 live indicators

    UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication…

  19. Velvet Ant

    G104722 techniques2 tools & malware

    Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network…

  20. VOID MANTICORE (COBALT MYSTIQUE)

    G1055IranEspionage63 techniques

    Also tracked asHandala Hack · Homeland Justice · Karma and 3 more

    VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least…

  21. Volatile Cedar (Lebanese Cedar)

    G01235 techniques2 tools & malware

    Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating…

  22. Volt Typhoon (BRONZE SILHOUETTE)

    G1017China81 techniques17 tools & malware1 live indicators

    Also tracked asVanguard Panda · DEV-0391 · UNC3236 and 3 more

    Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator