Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

Threat Actors

Groups and claims

Adversary groups and their claimed victims, tracked as profiles over time.

626 groups tracked·33,857 claims·Since 2020

Groups publish these on their own leak sites. A claim is not a confirmed breach — treat every entry as an assertion, not a fact.

Ecosystem pulse
Claims per month, all groups
322 groups
2020-01 · 1 · 1 groups2020-02 · 1 · 1 groups2020-03 · 3 · 1 groups2020-04 · 1 · 1 groups2020-06 · 14 · 2 groups2020-07 · 7 · 2 groups2020-08 · 1 · 1 groups2020-09 · 3 · 2 groups2020-10 · 4 · 2 groups2020-11 · 7 · 2 groups2020-12 · 15 · 3 groups2021-01 · 7 · 4 groups2021-02 · 3 · 3 groups2021-03 · 1 · 1 groups2021-04 · 8 · 2 groups2021-05 · 18 · 4 groups2021-06 · 13 · 5 groups2021-07 · 5 · 4 groups2021-08 · 14 · 4 groups2021-09 · 1007 · 27 groups2021-10 · 502 · 19 groups2021-11 · 356 · 18 groups2021-12 · 400 · 31 groups2022-01 · 689 · 25 groups2022-02 · 425 · 19 groups2022-03 · 403 · 19 groups2022-04 · 467 · 18 groups2022-05 · 388 · 14 groups2022-06 · 223 · 13 groups2022-07 · 204 · 12 groups2022-08 · 727 · 33 groups2022-09 · 258 · 26 groups2022-10 · 245 · 22 groups2022-11 · 240 · 26 groups2022-12 · 293 · 23 groups2023-01 · 159 · 20 groups2023-02 · 265 · 19 groups2023-03 · 454 · 26 groups2023-04 · 408 · 29 groups2023-05 · 445 · 27 groups2023-06 · 477 · 33 groups2023-07 · 565 · 37 groups2023-08 · 704 · 33 groups2023-09 · 549 · 40 groups2023-10 · 441 · 37 groups2023-11 · 515 · 34 groups2023-12 · 440 · 40 groups2024-01 · 307 · 41 groups2024-02 · 433 · 37 groups2024-03 · 416 · 35 groups2024-05 · 620 · 47 groups2024-06 · 438 · 42 groups2024-07 · 449 · 49 groups2024-08 · 525 · 45 groups2024-09 · 420 · 44 groups2024-10 · 611 · 51 groups2024-11 · 725 · 50 groups2024-12 · 668 · 54 groups2025-01 · 696 · 49 groups2025-02 · 1004 · 53 groups2025-03 · 809 · 60 groups2025-04 · 672 · 56 groups2025-05 · 502 · 54 groups2025-06 · 520 · 48 groups2025-07 · 622 · 57 groups2025-08 · 551 · 58 groups2025-09 · 654 · 62 groups2025-10 · 1029 · 62 groups2025-11 · 769 · 58 groups2025-12 · 1007 · 62 groups2026-01 · 789 · 60 groups2026-02 · 831 · 59 groups2026-03 · 931 · 62 groups2026-04 · 834 · 67 groups2026-05 · 763 · 59 groups2026-06 · 842 · 65 groups2026-07 · 845 · 63 groups2026-08 · 1200 · 78 groups
2020202120222023202420252026
Ransomware groups322ATT&CK groups176

176 results·Page 2 / 8

G0028
Threat Group-1314
aka Threat Group-1314 · TG-1314

Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.

MITRE ↗
G0029
Scarlet Mimic
aka Scarlet Mimic

Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of the Chinese government.

MITRE ↗
G0030
Lotus Blossom
aka Lotus Blossom · DRAGONFISH · Spring Dragon · RADIUM

Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.

MITRE ↗
G0032
Lazarus Group
aka Lazarus Group · Labyrinth Chollima · HIDDEN COBRA · Guardians of Peace

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pic…

Prev2 / 8Next
MITRE ↗
G0033
Poseidon Group
aka Poseidon Group

Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm.

MITRE ↗
G0034
Sandworm Team
aka Sandworm Team · ELECTRUM · Telebots · IRON VIKING

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. This group has been active since at least 2009.

MITRE ↗
G0035
Dragonfly
aka Dragonfly · TEMP.Isotope · DYMALLOY · Berserk Bear

Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, government entities, companies related to industrial control…

MITRE ↗
G0036
GCMAN
aka GCMAN

GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.

MITRE ↗
G0037
FIN6
aka FIN6 · Magecart Group 6 · ITG08 · Skeleton Spider

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.

MITRE ↗
G0038
Stealth Falcon
aka Stealth Falcon

Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012.

MITRE ↗
G0039
Suckfly
aka Suckfly

Suckfly is a China-based threat group that has been active since at least 2014.

MITRE ↗
G0040
Patchwork
aka Patchwork · Hangover Group · Dropping Elephant · Chinastrats

Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or Indian entity.

MITRE ↗
G0041
Strider
aka Strider · ProjectSauron

Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.

MITRE ↗
G0043
Group5
aka Group5

Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering holes, normally using Syrian and Iranian themes.

MITRE ↗
G0044
Winnti Group
aka Winnti Group · Blackfly

Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting.

MITRE ↗
G0045
menuPass
aka menuPass · Cicada · POTASSIUM · Stone Panda

menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for the Huaying Haitai Scien…

MITRE ↗
G0046
FIN7
aka FIN7 · GOLD NIAGARA · ITG14 · Carbon Spider

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmace…

MITRE ↗
G0047
Gamaredon Group
aka Gamaredon Group · IRON TILDEN · Primitive Bear · ACTINIUM

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013.

MITRE ↗
G0048
RTM
aka RTM

RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name (RTM).

MITRE ↗
G0049
OilRig
aka OilRig · COBALT GYPSY · IRN2 · APT34

OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications.

MITRE ↗
G0050
APT32
aka APT32 · SeaLotus · OceanLotus · APT-C-00

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries lik…

MITRE ↗
G0051
FIN10
aka FIN10

FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations.

MITRE ↗
G0052
CopyKittens
aka CopyKittens

CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany.

MITRE ↗
G0053
FIN5
aka FIN5

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries.

MITRE ↗
G0054
Sowbug
aka Sowbug

Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.

MITRE ↗