NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups W–Z

9 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. Water Galura (GOLD FEATHER)

    G10503 techniques2 tools & malware138 live indicators

    Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of…

  2. Whitefly

    G01079 techniques1 tools & malware

    Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore…

  3. Windigo

    G01247 techniques1 tools & malware15 live indicators

    The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a…

  4. Windshift (Bahamut)

    G011219 techniques1 tools & malware

    Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and…

  5. Winnti Group (Blackfly)

    G0044China6 techniques3 tools & malware

    Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but…

  6. Winter Vivern (TA473)

    G1035Russia27 techniques

    Also tracked asUAC-0114

    Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO…

  7. WIRTE (Ashen Lepus)

    G009026 techniques8 tools & malware770 live indicators

    WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018.…

  8. Wizard Spider (UNC1878)

    G0102Russia64 techniques22 tools & malware1,016 live indicators

    Also tracked asTEMP.MixMaster · Grim Spider · FIN12 and 6 more

    Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016.…

  9. ZIRCONIUM (APT31)

    G0128China29 techniques

    Also tracked asViolet Typhoon

    ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator