Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

Threat Actors

Groups and claims

Adversary groups and their claimed victims, tracked as profiles over time.

626 groups tracked·33,857 claims·Since 2020

Groups publish these on their own leak sites. A claim is not a confirmed breach — treat every entry as an assertion, not a fact.

Ecosystem pulse
Claims per month, all groups
322 groups
2020-01 · 1 · 1 groups2020-02 · 1 · 1 groups2020-03 · 3 · 1 groups2020-04 · 1 · 1 groups2020-06 · 14 · 2 groups2020-07 · 7 · 2 groups2020-08 · 1 · 1 groups2020-09 · 3 · 2 groups2020-10 · 4 · 2 groups2020-11 · 7 · 2 groups2020-12 · 15 · 3 groups2021-01 · 7 · 4 groups2021-02 · 3 · 3 groups2021-03 · 1 · 1 groups2021-04 · 8 · 2 groups2021-05 · 18 · 4 groups2021-06 · 13 · 5 groups2021-07 · 5 · 4 groups2021-08 · 14 · 4 groups2021-09 · 1007 · 27 groups2021-10 · 502 · 19 groups2021-11 · 356 · 18 groups2021-12 · 400 · 31 groups2022-01 · 689 · 25 groups2022-02 · 425 · 19 groups2022-03 · 403 · 19 groups2022-04 · 467 · 18 groups2022-05 · 388 · 14 groups2022-06 · 223 · 13 groups2022-07 · 204 · 12 groups2022-08 · 727 · 33 groups2022-09 · 258 · 26 groups2022-10 · 245 · 22 groups2022-11 · 240 · 26 groups2022-12 · 293 · 23 groups2023-01 · 159 · 20 groups2023-02 · 265 · 19 groups2023-03 · 454 · 26 groups2023-04 · 408 · 29 groups2023-05 · 445 · 27 groups2023-06 · 477 · 33 groups2023-07 · 565 · 37 groups2023-08 · 704 · 33 groups2023-09 · 549 · 40 groups2023-10 · 441 · 37 groups2023-11 · 515 · 34 groups2023-12 · 440 · 40 groups2024-01 · 307 · 41 groups2024-02 · 433 · 37 groups2024-03 · 416 · 35 groups2024-05 · 620 · 47 groups2024-06 · 438 · 42 groups2024-07 · 449 · 49 groups2024-08 · 525 · 45 groups2024-09 · 420 · 44 groups2024-10 · 611 · 51 groups2024-11 · 725 · 50 groups2024-12 · 668 · 54 groups2025-01 · 696 · 49 groups2025-02 · 1004 · 53 groups2025-03 · 809 · 60 groups2025-04 · 672 · 56 groups2025-05 · 502 · 54 groups2025-06 · 520 · 48 groups2025-07 · 622 · 57 groups2025-08 · 551 · 58 groups2025-09 · 654 · 62 groups2025-10 · 1029 · 62 groups2025-11 · 769 · 58 groups2025-12 · 1007 · 62 groups2026-01 · 789 · 60 groups2026-02 · 831 · 59 groups2026-03 · 931 · 62 groups2026-04 · 834 · 67 groups2026-05 · 763 · 59 groups2026-06 · 842 · 65 groups2026-07 · 845 · 63 groups2026-08 · 1200 · 78 groups
2020202120222023202420252026
Ransomware groups322ATT&CK groups176

176 results·Page 1 / 8

G0001
Axiom
aka Axiom · Group 72

Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008.

MITRE ↗
G0002
Moafee
aka Moafee

Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK.

MITRE ↗
G0003
Cleaver
aka Cleaver · Threat Group 2889 · TG-2889

Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889).

MITRE ↗
G0004
Ke3chang
aka Ke3chang · APT15 · Mirage · Vixen Panda

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.

Prev1 / 8Next
MITRE ↗
G0005
APT12
aka APT12 · IXESHE · DynCalc · Numbered Panda

APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.

MITRE ↗
G0006
APT1
aka APT1 · Comment Crew · Comment Group · Comment Panda

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.

MITRE ↗
G0007
APT28
aka APT28 · IRON TWILIGHT · SNAKEMACKEREL · Swallowtail

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004.

MITRE ↗
G0008
Carbanak
aka Carbanak · Anunak

Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that have also used Carbanak malware.

MITRE ↗
G0009
Deep Panda
aka Deep Panda · Shell Crew · WebMasters · KungFu Kittens

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda.

MITRE ↗
G0010
Turla
aka Turla · IRON HUNTER · Group 88 · Waterbug

Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, educa…

MITRE ↗
G0011
PittyTiger
aka PittyTiger

PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.

MITRE ↗
G0012
Darkhotel
aka Darkhotel · DUBNIUM · Zigzag Hail

Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select…

MITRE ↗
G0013
APT30
aka APT30

APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.

MITRE ↗
G0016
APT29
aka APT29 · IRON RITUAL · IRON HEMLOCK · NobleBaron

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks.

MITRE ↗
G0017
DragonOK
aka DragonOK

DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect relationship with the threat group Moafee.

MITRE ↗
G0018
admin@338
aka admin@338

admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as Pois…

MITRE ↗
G0019
Naikon
aka Naikon

Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).

MITRE ↗
G0020
Equation
aka Equation

Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives.

MITRE ↗
G0021
Molerats
aka Molerats · Operation Molerats · Gaza Cybergang

Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.

MITRE ↗
G0022
APT3
aka APT3 · Gothic Panda · Pirpi · UPS Team

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.

MITRE ↗
G0023
APT16
aka APT16

APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.

MITRE ↗
G0024
Putter Panda
aka Putter Panda · APT2 · MSUpdater

Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD).

MITRE ↗
G0025
APT17
aka APT17 · Deputy Dog

APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.

MITRE ↗
G0026
APT18
aka APT18 · TG-0416 · Dynamite Panda · Threat Group-0416

APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.

MITRE ↗
G0027
Threat Group-3390
aka Threat Group-3390 · Earth Smilodon · TG-3390 · Emissary Panda

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufactu…

MITRE ↗