Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

Threat Actors

Groups and claims

Adversary groups and their claimed victims, tracked as profiles over time.

626 groups tracked·33,857 claims·Since 2020

Groups publish these on their own leak sites. A claim is not a confirmed breach — treat every entry as an assertion, not a fact.

Ecosystem pulse
Claims per month, all groups
322 groups
2020-01 · 1 · 1 groups2020-02 · 1 · 1 groups2020-03 · 3 · 1 groups2020-04 · 1 · 1 groups2020-06 · 14 · 2 groups2020-07 · 7 · 2 groups2020-08 · 1 · 1 groups2020-09 · 3 · 2 groups2020-10 · 4 · 2 groups2020-11 · 7 · 2 groups2020-12 · 15 · 3 groups2021-01 · 7 · 4 groups2021-02 · 3 · 3 groups2021-03 · 1 · 1 groups2021-04 · 8 · 2 groups2021-05 · 18 · 4 groups2021-06 · 13 · 5 groups2021-07 · 5 · 4 groups2021-08 · 14 · 4 groups2021-09 · 1007 · 27 groups2021-10 · 502 · 19 groups2021-11 · 356 · 18 groups2021-12 · 400 · 31 groups2022-01 · 689 · 25 groups2022-02 · 425 · 19 groups2022-03 · 403 · 19 groups2022-04 · 467 · 18 groups2022-05 · 388 · 14 groups2022-06 · 223 · 13 groups2022-07 · 204 · 12 groups2022-08 · 727 · 33 groups2022-09 · 258 · 26 groups2022-10 · 245 · 22 groups2022-11 · 240 · 26 groups2022-12 · 293 · 23 groups2023-01 · 159 · 20 groups2023-02 · 265 · 19 groups2023-03 · 454 · 26 groups2023-04 · 408 · 29 groups2023-05 · 445 · 27 groups2023-06 · 477 · 33 groups2023-07 · 565 · 37 groups2023-08 · 704 · 33 groups2023-09 · 549 · 40 groups2023-10 · 441 · 37 groups2023-11 · 515 · 34 groups2023-12 · 440 · 40 groups2024-01 · 307 · 41 groups2024-02 · 433 · 37 groups2024-03 · 416 · 35 groups2024-05 · 620 · 47 groups2024-06 · 438 · 42 groups2024-07 · 449 · 49 groups2024-08 · 525 · 45 groups2024-09 · 420 · 44 groups2024-10 · 611 · 51 groups2024-11 · 725 · 50 groups2024-12 · 668 · 54 groups2025-01 · 696 · 49 groups2025-02 · 1004 · 53 groups2025-03 · 809 · 60 groups2025-04 · 672 · 56 groups2025-05 · 502 · 54 groups2025-06 · 520 · 48 groups2025-07 · 622 · 57 groups2025-08 · 551 · 58 groups2025-09 · 654 · 62 groups2025-10 · 1029 · 62 groups2025-11 · 769 · 58 groups2025-12 · 1007 · 62 groups2026-01 · 789 · 60 groups2026-02 · 831 · 59 groups2026-03 · 931 · 62 groups2026-04 · 834 · 67 groups2026-05 · 763 · 59 groups2026-06 · 842 · 65 groups2026-07 · 845 · 63 groups2026-08 · 1200 · 78 groups
2020202120222023202420252026
Ransomware groups322ATT&CK groups176

176 results·Page 5 / 8

G0119
Indrik Spider
aka Indrik Spider · Evil Corp · Manatee Tempest · DEV-0243

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ran…

MITRE ↗
G0120
Evilnum
aka Evilnum

Evilnum is a financially motivated threat group that has been active since at least 2018.

MITRE ↗
G0121
Sidewinder
aka Sidewinder · T-APT-04 · Rattlesnake

Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.

MITRE ↗
G0122
Silent Librarian
aka Silent Librarian · TA407 · COBALT DICKENS

Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013.

Prev5 / 8Next
MITRE ↗
G0123
Volatile Cedar
aka Volatile Cedar · Lebanese Cedar

Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideological interests.

MITRE ↗
G0124
Windigo
aka Windigo

The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet.

MITRE ↗
G0125
HAFNIUM
aka HAFNIUM · Operation Exchange Marauder · Silk Typhoon

HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of industry sectors, including infectious disease researchers, law f…

MITRE ↗
G0126
Higaisa
aka Higaisa

Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China, Japan, Russia, Poland, and other nations.

MITRE ↗
G0127
TA551
aka TA551 · GOLD CABIN · Shathak

TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware distribution campaigns.

MITRE ↗
G0128
ZIRCONIUM
aka ZIRCONIUM · APT31 · Violet Typhoon

ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.

MITRE ↗
G0129
Mustang Panda
aka Mustang Panda · TA416 · RedDelta · BRONZE PRESIDENT

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads.

MITRE ↗
G0130
Ajax Security Team
aka Ajax Security Team · Operation Woolen-Goldfish · AjaxTM · Rocket Kitten

Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense indu…

MITRE ↗
G0131
Tonto Team
aka Tonto Team · Earth Akhlut · BRONZE HUNTLEY · CactusPete

Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009;

MITRE ↗
G0133
Nomadic Octopus
aka Nomadic Octopus · DustSquad

Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014.

MITRE ↗
G0134
Transparent Tribe
aka Transparent Tribe · COPPER FIELDSTONE · APT36 · Mythic Leopard

Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.

MITRE ↗
G0135
BackdoorDiplomacy
aka BackdoorDiplomacy

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.

MITRE ↗
G0136
IndigoZebra
aka IndigoZebra

IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.

MITRE ↗
G0137
Ferocious Kitten
aka Ferocious Kitten

Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.

MITRE ↗
G0138
Andariel
aka Andariel · Silent Chollima · PLUTONIUM · Onyx Sleet

Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South Korean government agencies, military organizations, and a va…

MITRE ↗
G0139
TeamTNT
aka TeamTNT

TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in v…

MITRE ↗
G0140
LazyScripter
aka LazyScripter

LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

MITRE ↗
G0142
Confucius
aka Confucius · Confucius APT

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013.

MITRE ↗
G0143
Aquatic Panda
aka Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government s…

MITRE ↗
G1001
HEXANE
aka HEXANE · Lyceum · Siamesekitten · Spirlin

HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017.

MITRE ↗
G1002
BITTER
aka BITTER · T-APT-17

BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.

MITRE ↗