THREAT GROUPS AND HACKER 2026() 2025() 2024()
H APT(180) CYBERCRIME() CLUSTER(2) HACKTIVISTS() MaaS() NATION STATE() RaaS() VISHING(1) | ABECEDNĚ | GROUP LIST | Group Records
| DATE | NAME | INFO | CATEGORY | SUBCATE | GROUP |
|
5.10.26 |
TA419 | Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles | GROUPS | GROUPS | |
|
3.10.26 |
UAT-11587 | China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor | GROUPS | GROUPS | |
|
28.9.26 |
JADEPUFFER | Storm-3168: Agentic-driven cloud attacks using compromised service principals | GROUPS | GROUPS | |
|
24.9.26 |
UNK_CondorFiltration | Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts | GROUPS | CLUSTER | |
|
19.9.26 |
Lemmings | Data posted to a darknet forum by an account named okenit_hackers in October 2025 reveals that Russian actors have potentially upgraded their disinformation methods through the automated creation and management of fake personae. | GROUPS | GROUPS | |
|
19.9.26 |
Sudeep Singh | Tracking nation-state adversaries — hunting their malware, infrastructure and tradecraft across China-, Russia-, Iran-, Pakistan- and North Korea-nexus operations. | GROUPS | GROUPS | |
|
16.9.26 |
Tajin Group’s | Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. | GROUPS | GROUPS | |
|
15.9.26 |
Red Heron | Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit | GROUPS | HACKER | |
| 11.09.26 | Mantax Otax | Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration | GROUP | RANSOM | |
| 31.08.26 | Fire Ant | Fire Ant Evolves: From Hypervisors to Trusted Infrastructure | GROUP | APT | |
| 28.08.26 | BlueDelta | BlueDelta Targets Defense and Diplomacy with HOOKEDGE | GROUP | GROUP | |
| 24.08.26 | UAT-10147 | deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities | GROUP | GROUP | |
| 24.08.26 | UAT-10147 | Chinese-speaking adversary integrates agentic AI into post-compromise operations | GROUP | GROUP | |
| 19.08.26 | Medusa Ransomware | Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. | GROUP | RANSOM | |
| 19.08.26 | MAJINAHANASHI RANSOMWARE | This is the initial intelligence gathering and analysis based on the newly found IOCs of Ransomware and also uncovered new File Servers and Communication Channel of the Group. | GROUP | RANSOM | |
| 19.08.26 | CRPX0 Ransomware | CRPX0 Ransomware Group, releasing samples (which has not yet been public as of now) and uncovering a Scam Service which was running by the same group, | GROUP | RANSOM | |
| 19.08.26 | TENGU RANSOMWARE | This is the initial report of Tengu Ransomware. New Information was last added on 16th March 2026. | GROUP | RANSOM | |
| 19.08.26 | SilkParasite | SilkParasite: Tracking a China-Nexus APT Across Central Asia | GROUP | APT | |
| 14.08.26 | Jewelbug | Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side | GROUP | APT | |
| 12.08.26 | Head Mare | Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants | GROUP | APT | |
| 11.08.26 | DeadLock ransomware | DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | GROUP | RANSOM | |
| 11.08.26 | Gunra Ransomware | Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. | GROUP | RANSOM | |
| 11.08.26 | Gunra Ransomware | The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. | GROUP | RANSOM | |
| 08.08.26 | Pink | New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits | GROUP | GROUP | |
| 08.08.26 | UNC6671 | UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | GROUP | GROUP | |
| 03.08.26 | Larva-24009 | Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor | GROUP | GROUP | |
| 30.07.26 | Toy Ghouls | Toy Ghouls’ new toy: the GenieLocker ransomware | GROUP | RANSOM | |
| 30.07.26 | Toy Ghouls | Toy Ghouls’ new toy: the GenieLocker ransomware | GROUP | GROUP | |
| 30.07.26 | SilverFox Evolves | Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan | GROUP | GROUP | |
| 30.07.26 | TA488 | Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | GROUP | GROUP | |
| 25.07.26 | The Gentlemen RaaS | The Gentlemen RaaS: Origins, OPSEC & OSINT | GROUP | RaaS | |
| 25.07.26 | DEVMAN Ransomware | DEVMAN Ransomware: Analysis of New DragonForce Variant | GROUP | RANSOM | |
| 25.07.26 | Funky Mantis | Funky Mantis operates as a centralized ransomware-as-a-service model. | GROUP | GROUP | |
| 24.07.26 | TAG-195 | TAG-195 Upgrades MaaS Ecosystem with Modular Tools | GROUP | GROUP | |
| 23.07.26 | Chaos RaaS | Unmasking the new Chaos RaaS group attacks | GROUP | GROUP | |
| 21.07.26 | JADEPUFFER | JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models | GROUP | AI | |
| 18.07.26 | SuccessKey | ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey | GROUP | GROUP | |
| 18.07.26 | UAT-11795 | Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. | GROUP | GROUP | |
| 17.07.26 | GoldenEyeDog | Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident | GROUP | GROUP | |
| 12.07.26 | Helix | Helix, a New Name in the Data Extortion Ecosystem? | GROUP | Vishing | |
| 12.07.26 | UNK_MassTraction | One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | GROUP | Cluster | |
| 09.07.26 | Beast Ransomware | The Nature of the Beast Ransomware | GROUP | RANSOM | |
| 09.07.26 | GodDamn Ransomware | GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | GROUP | RANSOM | |
| 07.07.26 | Cavern Manticore | Cavern Manticore: Exposing Iran-Linked Modular C2 Framework | GROUP | GROUP | |
| 02.07.26 | JADEPUFFER | JADEPUFFER: Agentic ransomware for automated database extortion | GROUP | RANSOM | |
| 02.07.26 | ToddyCat | ToddyCat: your hidden email assistant. Part 2 | GROUP | APT | |
| 29.06.26 | Payouts King Ransomware | Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware | GROUP | RANSOM | |
| 29.06.26 | Mustang Panda | Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON | GROUP | APT | |
| 29.06.26 | Gamaredon in 2025 | Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances | GROUP | APT | |
| 21.06.26 | Prinz Eugen ransomware | Prinz Eugen ransomware: a deep dive into a new Go-based encryptor | GROUP | RANSOM | |
| 13.06.26 | Velvet Ant | China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence | GROUP | GROUP | |
| 11.06.26 | OceanLotus | OceanLotus: From external espionage to domestic targeting | GROUP | APT | |
| 08.06.26 | UNC3753 | Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms | GROUP | GROUP | |
| 06.06.26 | TA505 exploits SolarWinds Serv-U | NCC Group’s global Cyber Incident Response Team has observed an increase in Clop ransomware victims in the past weeks. | GROUP | GROUP | |
| 05.06.26 | Cluster OP-512 | ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512 | GROUP | GROUP | |
| 04.06.26 | TA4922 | TA4922: The Suspected Chinese Crime Group is Going Global | GROUP | GROUP | |
| 03.06.26 | UAC-0184 | UAC-0184: From HTA to a Signed Network Stack | GROUP | GROUP | |
| 29.05.26 | GREYVIBE | GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations | GROUP | GROUP | |
| 28.05.26 | JINX-0164 | Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure | GROUP | GROUP | |
| 23.05.26 | Storm-2949 | How Storm-2949 turned a compromised identity into a cloud-wide breach | GROUP | GROUP | |
| 20.05.26 | Disrupting Fox Tempest | Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware | GROUP | RANSOM | |
| 18.05.26 | Fast16 | Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations | GROUP | GROUP | |
| 14.05.26 | UNC1151 | UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign | GROUP | GROUP | |
| 14.05.26 | FrostyNeighbor | FrostyNeighbor: Fresh mischief and digital shenanigans | GROUP | GROUP | |
| 14.05.26 | APT ActivityApril– September 2025 | RUSSIA-ALIGNED APTs RAMP UP ATTACKS AGAINST UKRAINE AND ITS STRATEGIC PARTNERS | GROUP | APT | |
| 13.05.26 | FamousSparrow | FamousSparrow APT Targets Azerbaijani Oil and Gas Industry | GROUP | APT | |
| 06.05.26 | UAT-8302 | UAT-8302 and its box full of malware | GROUP | GROUP | |
| 06.05.26 | MuddyWater | Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware | GROUP | APT | |
| 04.05.26 | Silver Fox | Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India | GROUP | APT | |
| 04.05.26 | South-East Asian Military Entitiesl | On April 29th 2026, watchTowr Labs published research on CVE-2026-41940, a critical authentication bypass in cPanel & WHM.) | GROUP | APT | |
| 01.05.26 | Cordial Spider | CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. | GROUP | GROUP | |
| 01.05.26 | Snarky Spider | SNARKY SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion and cryptocurrency theft since at least October 2025. T | GROUP | GROUP | |
| 01.05.26 | Shadow-Earth-053 | Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia | GROUP | GROUP | |
| 28.04.26 | VECT 2.0 Ransomware | A new ransomware gang calling itself Vect is recruiting affiliates and preparing for further operations. | GROUP | RANSOM | |
| 26.04.26 | Cordial Spider | CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. | GROUP | GROUP | |
| 25.04.26 | UNC6692 | Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, | GROUP | GROUP | |
| 25.04.26 | UAT-4356's | Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). | GROUP | GROUP | |
| 24.04.26 | UNC6692 | GROUP | GROUP | ||
| 23.04.26 | GopherWhisper | GopherWhisper: A burrow full of malware | GROUP | APT | |
| 23.04.26 | Harvester | Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor | GROUP | APT | |
| 22.04.26 | Kyber Ransomware | Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained | GROUP | RANSOM | |
| 22.04.26 | DFIR– The Gentlemen & SystemBC | DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy | GROUP | RANSOM | |
| 22.04.26 | Mustang Panda | Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics | GROUP | APT | |
| 17.04.26 | UAC-0247 | Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247 | GROUP | GROUP | |
| 14.04.26 | APT37 | APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks | GROUP | APT | |
| 12.04.26 | Storm-2755 | Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees | GROUP | GROUP | |
| 10.04.26 | BITTER APT | Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT | GROUP | APT | |
| 08.04.26 | FrostArmada | A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. | GROUP | GROUP | |
| 08.04.26 | Pay2Key | Pay2Key Iranian-Linked Ransomware is Back, Back Again | GROUP | RANSOM | |
| 08.04.26 | Storm-1175 | Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations | GROUP | GROUP | |
| 08.04.26 | PIONEER KITTEN | Who Is PIONEER KITTEN? | GROUP | APT | |
| 08.04.26 | APT28 | APT28 exploit routers to enable DNS hijacking operations | GROUP | APT | |
| 05.04.26 | TA416 | I’d come running back to EU again: TA416 resumes European government espionage campaigns | GROUP | GROUP | |
| 03.04.26 | UAT-10608 | UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications | GROUP | GROUP | |
| 01.04.26 | UNC1069 | North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack | GROUP | GROUP | |
| 27.03.26 | Bearlyfy | Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware | GROUP | GROUP | |
| 14.03.26 | Handala Hack | Handala Hack is an online persona operated by Void Manticore (aka Red Sandstorm, Banished Kitten), an actor affiliated with... | GROUP | GROUP | |
| 14.03.26 | CL-STA-1087 | Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia | GROUP | CLUSTER | |
| 14.03.26 | Storm-2561 | Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft | GROUP | GROUP | |
| 10.03.26 | Sednit | Sednit reloaded: Back in the trenches | GROUP | GROUP | |
| 08.03.26 | Anubis | Anubis: A New Ransomware Threat | GROUP | RANSOM | |
| 08.03.26 | Jasper Sleet | Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations | GROUP | GROUP | |
| 06.03.26 | UAT-9244 | UAT-9244 targets South American telecommunication providers with three new malware implants | GROUP | GROUP | |
| 06.03.26 | Dust Specter | Dust Specter APT Targets Government Officials in Iraq | GROUP | APT | |
| 04.03.26 | Silver Dragon | Silver Dragon Targets Organizations in Southeast Asia and Europe | GROUP | APT | |
| 03.03.26 | SloppyLemming | SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, | GROUP | GROUP | |
| 01.03.26 | COOKIE SPIDER | COOKIE SPIDER (active since at least October 2018) develops and rents Atomic macOS Stealer (AMOS).. | GROUP | GROUP | |
| 01.03.26 | Diesel Vortex | Diesel Vortex: Inside the Russian cybercrime group targeting US & EU freight | GROUP | GROUP | |
| 27.02.26 | APT37 | APT37 Adds New Capabilities for Air-Gapped Networks | GROUP | GROUP | |
| 26.02.26 | Scattered LAPSUS$ Hunters | Cyber Intel Brief: Scattered Lapsus$ Hunters (SLH) Kicks Off Campaign to Recruit Women | GROUP | GROUP | |
| 26.02.26 | UNC2814 | Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign | GROUP | GROUP | |
| 15.02.26 | Storm-2603 | Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware | GROUP | GROUP | |
| 14.02.26 | UAT-9921 | New threat actor, UAT-9921, leverages VoidLink framework in campaigns | GROUP | GROUP | |
| 11.02.26 | UNC1069 | UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering | GROUP | GROUP | |
| 10.02.26 | UNC3886 | Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector | GROUP | GROUP | |
| 09.02.26 | Stan Ghouls | Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT | GROUP | GROUP | |
| 05.02.26 | Amaranth-Dragon | Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia | GROUP | APT | |
| 03.02.26 | APT28 | APT28 Leverages CVE-2026-21509 in Operation Neusploit | GROUP | APT | |
| 02.02.26 | UAT-8099 | Dissecting UAT-8099: New persistence mechanisms and regional focus | GROUP | GROUP | |
| 28.01.26 | HoneyMyte | HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns | GROUP | APT | |
| 25.01.26 | UAT-9686 | UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager | GROUP | GROUP | |
| 23.01.26 | Osiris Ransomware | Osiris Ransomware: New Addition to the Locky Family | GROUP | RANSOM | |
| 22.01.26 | PurpleBravo | PurpleBravo’s Targeting of the IT Software Supply Chain | GROUP | GROUP | |
| 17.01.26 | KIMSUKI | Kimsuki, an advanced persistent threat (APT) group active since at least 2012, is suspected to be operating out of North Korea in direct support of the regime’s strategic objectives. | GROUP | APT | |
| 16.01.26 | UAT-8837 | UAT-8837 targets critical infrastructure sectors in North America | GROUP | GROUP | |
| 08.01.26 | UAT-7290 | UAT-7290 targets high value telecommunications infrastructure in South Asia | GROUP | GROUP | |
| 07.01.26 | UAC-0184 | UAC-0184 | GROUP | GROUP | |
| 02.01.26 | APT36 | APT36 : Multi-Stage LNK Malware Campaign Targeting Indian Government Entities | GROUP | APT |