Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

Threat Actors

Groups and claims

Adversary groups and their claimed victims, tracked as profiles over time.

626 groups tracked·33,857 claims·Since 2020

Groups publish these on their own leak sites. A claim is not a confirmed breach — treat every entry as an assertion, not a fact.

Ecosystem pulse
Claims per month, all groups
322 groups
2020-01 · 1 · 1 groups2020-02 · 1 · 1 groups2020-03 · 3 · 1 groups2020-04 · 1 · 1 groups2020-06 · 14 · 2 groups2020-07 · 7 · 2 groups2020-08 · 1 · 1 groups2020-09 · 3 · 2 groups2020-10 · 4 · 2 groups2020-11 · 7 · 2 groups2020-12 · 15 · 3 groups2021-01 · 7 · 4 groups2021-02 · 3 · 3 groups2021-03 · 1 · 1 groups2021-04 · 8 · 2 groups2021-05 · 18 · 4 groups2021-06 · 13 · 5 groups2021-07 · 5 · 4 groups2021-08 · 14 · 4 groups2021-09 · 1007 · 27 groups2021-10 · 502 · 19 groups2021-11 · 356 · 18 groups2021-12 · 400 · 31 groups2022-01 · 689 · 25 groups2022-02 · 425 · 19 groups2022-03 · 403 · 19 groups2022-04 · 467 · 18 groups2022-05 · 388 · 14 groups2022-06 · 223 · 13 groups2022-07 · 204 · 12 groups2022-08 · 727 · 33 groups2022-09 · 258 · 26 groups2022-10 · 245 · 22 groups2022-11 · 240 · 26 groups2022-12 · 293 · 23 groups2023-01 · 159 · 20 groups2023-02 · 265 · 19 groups2023-03 · 454 · 26 groups2023-04 · 408 · 29 groups2023-05 · 445 · 27 groups2023-06 · 477 · 33 groups2023-07 · 565 · 37 groups2023-08 · 704 · 33 groups2023-09 · 549 · 40 groups2023-10 · 441 · 37 groups2023-11 · 515 · 34 groups2023-12 · 440 · 40 groups2024-01 · 307 · 41 groups2024-02 · 433 · 37 groups2024-03 · 416 · 35 groups2024-05 · 620 · 47 groups2024-06 · 438 · 42 groups2024-07 · 449 · 49 groups2024-08 · 525 · 45 groups2024-09 · 420 · 44 groups2024-10 · 611 · 51 groups2024-11 · 725 · 50 groups2024-12 · 668 · 54 groups2025-01 · 696 · 49 groups2025-02 · 1004 · 53 groups2025-03 · 809 · 60 groups2025-04 · 672 · 56 groups2025-05 · 502 · 54 groups2025-06 · 520 · 48 groups2025-07 · 622 · 57 groups2025-08 · 551 · 58 groups2025-09 · 654 · 62 groups2025-10 · 1029 · 62 groups2025-11 · 769 · 58 groups2025-12 · 1007 · 62 groups2026-01 · 789 · 60 groups2026-02 · 831 · 59 groups2026-03 · 931 · 62 groups2026-04 · 834 · 67 groups2026-05 · 763 · 59 groups2026-06 · 842 · 65 groups2026-07 · 845 · 63 groups2026-08 · 1200 · 78 groups
2020202120222023202420252026
Ransomware groups322ATT&CK groups176

176 results·Page 6 / 8

G1003
Ember Bear
aka Ember Bear · UNC2589 · Bleeding Bear · DEV-0586

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).

MITRE ↗
G1004
LAPSUS$
aka LAPSUS$ · DEV-0537 · Strawberry Tempest

LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware.

claims →MITRE ↗
G1005
POLONIUM
aka POLONIUM · Plaid Rain

POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022.

MITRE ↗
G1006
Earth Lusca
aka Earth Lusca · TAG-22 · Charcoal Typhoon · CHROMIUM

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emi…

Prev6 / 8Next
MITRE ↗
G1007
Aoqin Dragon
aka Aoqin Dragon

Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam.…

MITRE ↗
G1008
SideCopy
aka SideCopy

SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019.

MITRE ↗
G1009
Moses Staff
aka Moses Staff · DEV-0500 · Marigold Sandstorm

Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly stated their motivation in attacking Israeli companies is to cause damage by leaking stolen sensitive data and encry…

claims →MITRE ↗
G1011
EXOTIC LILY
aka EXOTIC LILY

EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol.

MITRE ↗
G1012
CURIUM
aka CURIUM · Crimson Sandstorm · TA456 · Tortoise Shell

CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East.

MITRE ↗
G1013
Metador
aka Metador

Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication companies, internet service providers, and universities in the Middle East and Africa.

MITRE ↗
G1014
LuminousMoth
aka LuminousMoth

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast…

MITRE ↗
G1015
Scattered Spider
aka Scattered Spider · Roasted 0ktapus · Octo Tempest · Storm-0875

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology compani…

MITRE ↗
G1016
FIN13
aka FIN13 · Elephant Beetle

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016.

MITRE ↗
G1017
Volt Typhoon
aka Volt Typhoon · BRONZE SILHOUETTE · Vanguard Panda · DEV-0391

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam.

MITRE ↗
G1018
TA2541
aka TA2541

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017.

MITRE ↗
G1019
MoustachedBouncer
aka MoustachedBouncer

MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.

MITRE ↗
G1020
Mustard Tempest
aka Mustard Tempest · DEV-0206 · TA569 · GOLD PRELUDE

Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the download of additional malware including LockBit, WastedLocker, an…

MITRE ↗
G1021
Cinnamon Tempest
aka Cinnamon Tempest · DEV-0401 · Emperor Dragonfly · BRONZE STARLIGHT

Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code.

MITRE ↗
G1022
ToddyCat
aka ToddyCat

ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.

MITRE ↗
G1023
APT5
aka APT5 · Mulberry Typhoon · MANGANESE · BRONZE FLEETWOOD

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia.

MITRE ↗
G1024
Akira
aka Akira · GOLD SAHARA · PUNK SPIDER · Howling Scorpius

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for initial access, then various publicly-available tools and te…

claims →MITRE ↗
G1026
Malteiro
aka Malteiro

Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model.

MITRE ↗
G1028
APT-C-23
aka APT-C-23 · Mantis · Arid Viper · Desert Falcon

APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile spyware targeting Android and iOS devices since 2017.

MITRE ↗
G1030
Agrius
aka Agrius · Pink Sandstorm · AMERICIUM · Agonizing Serpens

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).

claims →MITRE ↗
G1031
Saint Bear
aka Saint Bear · Storm-0587 · TA471 · UAC-0056

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns.

MITRE ↗