Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

Threat Actors

Groups and claims

Adversary groups and their claimed victims, tracked as profiles over time.

626 groups tracked·33,857 claims·Since 2020

Groups publish these on their own leak sites. A claim is not a confirmed breach — treat every entry as an assertion, not a fact.

Ecosystem pulse
Claims per month, all groups
322 groups
2020-01 · 1 · 1 groups2020-02 · 1 · 1 groups2020-03 · 3 · 1 groups2020-04 · 1 · 1 groups2020-06 · 14 · 2 groups2020-07 · 7 · 2 groups2020-08 · 1 · 1 groups2020-09 · 3 · 2 groups2020-10 · 4 · 2 groups2020-11 · 7 · 2 groups2020-12 · 15 · 3 groups2021-01 · 7 · 4 groups2021-02 · 3 · 3 groups2021-03 · 1 · 1 groups2021-04 · 8 · 2 groups2021-05 · 18 · 4 groups2021-06 · 13 · 5 groups2021-07 · 5 · 4 groups2021-08 · 14 · 4 groups2021-09 · 1007 · 27 groups2021-10 · 502 · 19 groups2021-11 · 356 · 18 groups2021-12 · 400 · 31 groups2022-01 · 689 · 25 groups2022-02 · 425 · 19 groups2022-03 · 403 · 19 groups2022-04 · 467 · 18 groups2022-05 · 388 · 14 groups2022-06 · 223 · 13 groups2022-07 · 204 · 12 groups2022-08 · 727 · 33 groups2022-09 · 258 · 26 groups2022-10 · 245 · 22 groups2022-11 · 240 · 26 groups2022-12 · 293 · 23 groups2023-01 · 159 · 20 groups2023-02 · 265 · 19 groups2023-03 · 454 · 26 groups2023-04 · 408 · 29 groups2023-05 · 445 · 27 groups2023-06 · 477 · 33 groups2023-07 · 565 · 37 groups2023-08 · 704 · 33 groups2023-09 · 549 · 40 groups2023-10 · 441 · 37 groups2023-11 · 515 · 34 groups2023-12 · 440 · 40 groups2024-01 · 307 · 41 groups2024-02 · 433 · 37 groups2024-03 · 416 · 35 groups2024-05 · 620 · 47 groups2024-06 · 438 · 42 groups2024-07 · 449 · 49 groups2024-08 · 525 · 45 groups2024-09 · 420 · 44 groups2024-10 · 611 · 51 groups2024-11 · 725 · 50 groups2024-12 · 668 · 54 groups2025-01 · 696 · 49 groups2025-02 · 1004 · 53 groups2025-03 · 809 · 60 groups2025-04 · 672 · 56 groups2025-05 · 502 · 54 groups2025-06 · 520 · 48 groups2025-07 · 622 · 57 groups2025-08 · 551 · 58 groups2025-09 · 654 · 62 groups2025-10 · 1029 · 62 groups2025-11 · 769 · 58 groups2025-12 · 1007 · 62 groups2026-01 · 789 · 60 groups2026-02 · 831 · 59 groups2026-03 · 931 · 62 groups2026-04 · 834 · 67 groups2026-05 · 763 · 59 groups2026-06 · 842 · 65 groups2026-07 · 845 · 63 groups2026-08 · 1200 · 78 groups
2020202120222023202420252026
Ransomware groups322ATT&CK groups176

176 results·Page 7 / 8

G1032
INC Ransom
aka INC Ransom · GOLD IONIC

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023.

claims →MITRE ↗
G1033
Star Blizzard
aka Star Blizzard · SEABORGIUM · Callisto Group · TA446

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academi…

MITRE ↗
G1034
Daggerfly
aka Daggerfly · Evasive Panda · BRONZE HIGHLAND

Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Africa.

MITRE ↗
G1035
Winter Vivern
aka Winter Vivern · TA473 · UAC-0114

Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US victims.

Prev7 / 8Next
MITRE ↗
G1036
Moonstone Sleet
aka Moonstone Sleet · Storm-1789

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradec…

MITRE ↗
G1037
TA577
aka TA577

TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.

MITRE ↗
G1038
TA578
aka TA578

TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.

MITRE ↗
G1039
RedCurl
aka RedCurl

RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including but not limited to travel agencies, insurance companies, and…

MITRE ↗
G1040
Play
aka Play

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe.

claims →MITRE ↗
G1041
Sea Turtle
aka Sea Turtle · Teal Kurma · Marbled Dust · Cosmic Wolf

Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America.

MITRE ↗
G1042
RedEcho
aka RedEcho

RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities.

MITRE ↗
G1043
BlackByte
aka BlackByte · Hecamede

BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware.

claims →MITRE ↗
G1044
APT42
aka APT42

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.

MITRE ↗
G1045
Salt Typhoon
aka Salt Typhoon

Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).

MITRE ↗
G1046
Storm-1811
aka Storm-1811

Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overloading victim email inboxes with non-malicious spam to prompt…

MITRE ↗
G1047
Velvet Ant
aka Velvet Ant

Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.

MITRE ↗
G1048
UNC3886
aka UNC3886

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions.

MITRE ↗
G1049
AppleJeus
aka AppleJeus · Gleaming Pisces · Citrine Sleet · UNC1720

AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since at least 2018 and is closely aligned in resources with TEMP.…

MITRE ↗
G1050
Water Galura
aka Water Galura · GOLD FEATHER

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums.

MITRE ↗
G1051
Medusa Group
aka Medusa Group

Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation.

MITRE ↗
G1052
Contagious Interview
aka Contagious Interview · DeceptiveDevelopment · Gwisin Gang · Tenacious Pungsan

Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials.

MITRE ↗
G1053
Storm-0501
aka Storm-0501

Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations.

MITRE ↗
G1054
MirrorFace
aka MirrorFace · Earth Kasha

MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps.

MITRE ↗
G1055
VOID MANTICORE
aka VOID MANTICORE · COBALT MYSTIQUE · Handala Hack · Homeland Justice

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations ac…

claims →MITRE ↗
G1056
TeamPCP
aka TeamPCP · PCPCat · ShellForce · DeadCatx3

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software s…

MITRE ↗