THREAT GROUPS AND HACKER   2026()  2025()  2024()

H  APT(180)  CYBERCRIME()  CLUSTER(2)  HACKTIVISTS()  MaaS()  NATION STATE()  RaaS()  VISHING(1)  | ABECEDNĚ  |  GROUP LIST | Group Records


DATE NAME INFO CATEGORY SUBCATE GROUP

5.10.26

TA419 Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles GROUPS GROUPS  

3.10.26

UAT-11587 China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor GROUPS GROUPS  

28.9.26

JADEPUFFER Storm-3168: Agentic-driven cloud attacks using compromised service principals GROUPS GROUPS  

24.9.26

UNK_CondorFiltration Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts GROUPS CLUSTER  

19.9.26

Lemmings Data posted to a darknet forum by an account named okenit_hackers in October 2025 reveals that Russian actors have potentially upgraded their disinformation methods through the automated creation and management of fake personae. GROUPS GROUPS  

19.9.26

Sudeep Singh Tracking nation-state adversaries — hunting their malware, infrastructure and tradecraft across China-, Russia-, Iran-, Pakistan- and North Korea-nexus operations. GROUPS GROUPS  

16.9.26

Tajin Group’s Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. GROUPS GROUPS  

15.9.26

Red Heron Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit GROUPS HACKER  
11.09.26 Mantax Otax Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration GROUP RANSOM  
31.08.26 Fire Ant Fire Ant Evolves: From Hypervisors to Trusted Infrastructure GROUP APT  
28.08.26 BlueDelta  BlueDelta Targets Defense and Diplomacy with HOOKEDGE GROUP GROUP  
24.08.26 UAT-10147  deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities GROUP GROUP  
24.08.26 UAT-10147 Chinese-speaking adversary integrates agentic AI into post-compromise operations GROUP GROUP  
19.08.26 Medusa Ransomware Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. GROUP RANSOM  
19.08.26 MAJINAHANASHI RANSOMWARE This is the initial intelligence gathering and analysis based on the newly found IOCs of Ransomware and also uncovered new File Servers and Communication Channel of the Group. GROUP RANSOM  
19.08.26 CRPX0 Ransomware CRPX0 Ransomware Group, releasing samples (which has not yet been public as of now) and uncovering a Scam Service which was running by the same group, GROUP RANSOM  
19.08.26 TENGU RANSOMWARE This is the initial report of Tengu Ransomware. New Information was last added on 16th March 2026. GROUP RANSOM  
19.08.26 SilkParasite SilkParasite: Tracking a China-Nexus APT Across Central Asia GROUP APT  
14.08.26 Jewelbug Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side GROUP APT  
12.08.26 Head Mare Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants GROUP APT  
11.08.26 DeadLock ransomware DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure GROUP RANSOM  
11.08.26 Gunra Ransomware Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations.  GROUP RANSOM  
11.08.26 Gunra Ransomware The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. GROUP RANSOM  
08.08.26 Pink New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits GROUP GROUP  
08.08.26 UNC6671 UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments GROUP GROUP  
03.08.26 Larva-24009 Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor GROUP GROUP  
30.07.26 Toy Ghouls Toy Ghouls’ new toy: the GenieLocker ransomware GROUP RANSOM  
30.07.26 Toy Ghouls Toy Ghouls’ new toy: the GenieLocker ransomware GROUP GROUP  
30.07.26 SilverFox Evolves Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan GROUP GROUP  
30.07.26 TA488 Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit GROUP GROUP  
25.07.26 The Gentlemen RaaS The Gentlemen RaaS: Origins, OPSEC & OSINT GROUP RaaS  
25.07.26 DEVMAN Ransomware DEVMAN Ransomware: Analysis of New DragonForce Variant  GROUP RANSOM  
25.07.26 Funky Mantis Funky Mantis operates as a centralized ransomware-as-a-service model. GROUP GROUP  
24.07.26 TAG-195 TAG-195 Upgrades MaaS Ecosystem with Modular Tools GROUP GROUP  
23.07.26 Chaos RaaS Unmasking the new Chaos RaaS group attacks GROUP GROUP  
21.07.26 JADEPUFFER  JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models GROUP AI  
18.07.26 SuccessKey ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey GROUP GROUP  
18.07.26 UAT-11795 Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. GROUP GROUP  
17.07.26 GoldenEyeDog Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident GROUP GROUP  
12.07.26 Helix Helix, a New Name in the Data Extortion Ecosystem?  GROUP Vishing  
12.07.26 UNK_MassTraction One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation GROUP Cluster  
09.07.26 Beast Ransomware The Nature of the Beast Ransomware GROUP RANSOM  
09.07.26 GodDamn Ransomware GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses GROUP RANSOM  
07.07.26 Cavern Manticore Cavern Manticore: Exposing Iran-Linked Modular C2 Framework GROUP GROUP  
02.07.26 JADEPUFFER JADEPUFFER: Agentic ransomware for automated database extortion GROUP RANSOM  
02.07.26 ToddyCat ToddyCat: your hidden email assistant. Part 2 GROUP APT  
29.06.26 Payouts King Ransomware Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malware GROUP RANSOM  
29.06.26 Mustang Panda Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON GROUP APT  
29.06.26 Gamaredon in 2025 Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances GROUP APT  
21.06.26 Prinz Eugen ransomware Prinz Eugen ransomware: a deep dive into a new Go-based encryptor GROUP RANSOM  
13.06.26 Velvet Ant China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence GROUP GROUP  
11.06.26 OceanLotus OceanLotus: From external espionage to domestic targeting GROUP APT  
08.06.26 UNC3753 Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms GROUP GROUP  
06.06.26 TA505 exploits SolarWinds Serv-U NCC Group’s global Cyber Incident Response Team has observed an increase in Clop ransomware victims in the past weeks.  GROUP GROUP  
05.06.26 Cluster OP-512 ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512  GROUP GROUP  
04.06.26 TA4922 TA4922: The Suspected Chinese Crime Group is Going Global GROUP GROUP  
03.06.26 UAC-0184 UAC-0184: From HTA to a Signed Network Stack GROUP GROUP  
29.05.26 GREYVIBE GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations GROUP GROUP  
28.05.26 JINX-0164 Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure GROUP GROUP  
23.05.26 Storm-2949 How Storm-2949 turned a compromised identity into a cloud-wide breach GROUP GROUP  
20.05.26 Disrupting Fox Tempest Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware  GROUP RANSOM  
18.05.26 Fast16 Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations GROUP GROUP  
14.05.26 UNC1151 UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign  GROUP GROUP  
14.05.26 FrostyNeighbor FrostyNeighbor: Fresh mischief and digital shenanigans GROUP GROUP  
14.05.26 APT ActivityApril– September 2025 RUSSIA-ALIGNED APTs RAMP UP ATTACKS AGAINST UKRAINE AND ITS STRATEGIC PARTNERS GROUP APT  
13.05.26 FamousSparrow FamousSparrow APT Targets Azerbaijani Oil and Gas Industry GROUP APT  
06.05.26 UAT-8302 UAT-8302 and its box full of malware GROUP GROUP  
06.05.26 MuddyWater Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware GROUP APT  
04.05.26 Silver Fox Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India GROUP APT  
04.05.26 South-East Asian Military Entitiesl On April 29th 2026, watchTowr Labs published research on CVE-2026-41940, a critical authentication bypass in cPanel & WHM.) GROUP APT  
01.05.26 Cordial Spider CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025.  GROUP GROUP  
01.05.26 Snarky Spider SNARKY SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion and cryptocurrency theft since at least October 2025. T GROUP GROUP  
01.05.26 Shadow-Earth-053 Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia GROUP GROUP  
28.04.26 VECT 2.0 Ransomware A new ransomware gang calling itself Vect is recruiting affiliates and preparing for further operations. GROUP RANSOM  
26.04.26 Cordial Spider CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. GROUP GROUP  
25.04.26 UNC6692 Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, GROUP GROUP  
25.04.26 UAT-4356's Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). GROUP GROUP  
24.04.26 UNC6692   GROUP GROUP  
23.04.26 GopherWhisper GopherWhisper: A burrow full of malware GROUP APT  
23.04.26 Harvester Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor GROUP APT  
22.04.26 Kyber Ransomware Kyber Ransomware Double Trouble: Windows and ESXi Attacks Explained GROUP RANSOM  
22.04.26 DFIR– The Gentlemen & SystemBC DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy GROUP RANSOM  
22.04.26 Mustang Panda Same packet, different magic: Mustang Panda hits India's banking sector and Korea geopolitics GROUP APT  
17.04.26 UAC-0247 Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247  GROUP GROUP  
14.04.26 APT37 APT37’s Pretexting-Based Targeted Intrusion: Analysis of Facebook Reconnaissance and Software Tampering Attacks GROUP APT  
12.04.26 Storm-2755 Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees GROUP GROUP  
10.04.26 BITTER APT Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation Linked to BITTER APT GROUP APT  
08.04.26 FrostArmada A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. GROUP GROUP  
08.04.26 Pay2Key Pay2Key Iranian-Linked Ransomware is Back, Back Again GROUP RANSOM  
08.04.26 Storm-1175 Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations GROUP GROUP  
08.04.26 PIONEER KITTEN Who Is PIONEER KITTEN? GROUP APT  
08.04.26 APT28  APT28 exploit routers to enable DNS hijacking operations GROUP APT  
05.04.26 TA416  I’d come running back to EU again: TA416 resumes European government espionage campaigns GROUP GROUP  
03.04.26 UAT-10608 UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications GROUP GROUP  
01.04.26 UNC1069 North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack GROUP GROUP  
27.03.26 Bearlyfy  Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware GROUP GROUP  
14.03.26 Handala Hack Handala Hack is an online persona operated by Void Manticore (aka Red Sandstorm, Banished Kitten), an actor affiliated with... GROUP GROUP  
14.03.26 CL-STA-1087 Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia GROUP CLUSTER  
14.03.26 Storm-2561 Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft GROUP GROUP  
10.03.26 Sednit  Sednit reloaded: Back in the trenches GROUP GROUP  
08.03.26 Anubis Anubis: A New Ransomware Threat GROUP RANSOM  
08.03.26 Jasper Sleet Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations GROUP GROUP  
06.03.26 UAT-9244 UAT-9244 targets South American telecommunication providers with three new malware implants GROUP GROUP  
06.03.26 Dust Specter Dust Specter APT Targets Government Officials in Iraq GROUP APT  
04.03.26 Silver Dragon Silver Dragon Targets Organizations in Southeast Asia and Europe GROUP APT  
03.03.26 SloppyLemming SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, GROUP GROUP  
01.03.26 COOKIE SPIDER  COOKIE SPIDER (active since at least October 2018) develops and rents Atomic macOS Stealer (AMOS).. GROUP GROUP  
01.03.26 Diesel Vortex Diesel Vortex: Inside the Russian cybercrime group targeting US & EU freight GROUP GROUP  
27.02.26 APT37 APT37 Adds New Capabilities for Air-Gapped Networks GROUP GROUP  
26.02.26 Scattered LAPSUS$ Hunters Cyber Intel Brief: Scattered Lapsus$ Hunters (SLH) Kicks Off Campaign to Recruit Women GROUP GROUP  
26.02.26 UNC2814 Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign GROUP GROUP  
15.02.26 Storm-2603 Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware  GROUP GROUP  
14.02.26 UAT-9921 New threat actor, UAT-9921, leverages VoidLink framework in campaigns GROUP GROUP  
11.02.26 UNC1069 UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering GROUP GROUP  
10.02.26 UNC3886 Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector GROUP GROUP  
09.02.26 Stan Ghouls Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT GROUP GROUP  
05.02.26 Amaranth-Dragon Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia GROUP APT  
03.02.26 APT28 APT28 Leverages CVE-2026-21509 in Operation Neusploit GROUP APT  
02.02.26 UAT-8099 Dissecting UAT-8099: New persistence mechanisms and regional focus GROUP GROUP  
28.01.26 HoneyMyte HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns GROUP APT  
25.01.26 UAT-9686 UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager GROUP GROUP  
23.01.26 Osiris Ransomware Osiris Ransomware: New Addition to the Locky Family GROUP RANSOM  
22.01.26 PurpleBravo PurpleBravo’s Targeting of the IT Software Supply Chain GROUP GROUP  
17.01.26 KIMSUKI Kimsuki, an advanced persistent threat (APT) group active since at least 2012, is suspected to be operating out of North Korea in direct support of the regime’s strategic objectives. GROUP APT  
16.01.26 UAT-8837 UAT-8837 targets critical infrastructure sectors in North America GROUP GROUP  
08.01.26 UAT-7290 UAT-7290 targets high value telecommunications infrastructure in South Asia GROUP GROUP  
07.01.26 UAC-0184  UAC-0184 GROUP GROUP  
02.01.26 APT36 APT36 : Multi-Stage LNK Malware Campaign Targeting Indian Government Entities GROUP APT