Skip to main content
Mallory
Back to intelligence

Trending Adversaries

Who's moving, and how fast. Mallory tracks named threat actors across vendor reports, researcher analysis, and underground chatter, then surfaces the ones picking up momentum right now.

Ranked by Mallory's mention-velocity model across sources.

Mention map · Last day

Sized by mentions
Tile size: mentions · Color: mention volume·HighestHighMediumLowLowest

Top 24 threat actors · Last day

#1Blackwater

Blackwater is a ransomware and data-extortion threat group that emerged in 2026 and operates a leak site used to name victims and threaten publication of stolen data. Reported activity links the group to intrusions affecting organizations in healthcare, energy and utilities, hospitality and tourism, professional services, and other sectors across multiple countries. Victim reporting and leak-site claims indicate Blackwater conducts ransomware operations involving system disruption, data theft, and public extortion deadlines tied to release of allegedly stolen information. In some incidents, victims were described as experiencing system breaches and data blocking consistent with encryption-based ransomware, while other cases emphasized threatened publication of confidential data on the group’s leak site. Blackwater has claimed attacks against organizations in the United States, India, Argentina, Brazil, China, and Turkey. Publicly reported healthcare-related activity includes a claim of responsibility for the April 2026 cyber incident at Minidoka Memorial Hospital in Idaho, where the victim reported temporary disruption to internal systems and imaging services. Blackwater appears to be a newly surfaced actor or possible rebrand; however, no high-confidence attribution to a state sponsor or specific criminal ecosystem is established from the available facts. No corroborated sub-groups or additional aliases are established beyond Blackwater.

Mentions2
#2TA505
Financially Motivated

TA505 is a financially motivated cybercrime threat actor active since at least 2014 and widely associated with large-scale malware distribution, phishing-led intrusions, and ransomware deployment. The group is commonly linked with or tracked under aliases including Graceful Spider, Gold Tahoe, Hive0065, DEV-0950, Lace Tempest, Monty Spider, Spandex Tempest, and Chimborazo. TA505 has also been closely associated with the Clop/Cl0p ransomware and extortion ecosystem, including activity in which Clop was delivered after earlier TA505 intrusions, and some reporting treats TA505, FIN11, and Lace Tempest as overlapping or substantially related clusters. TA505 is known for initial access via spearphishing emails carrying malicious attachments, followed by staged malware delivery and post-compromise tooling. Reported tradecraft includes use of PowerShell to download and execute payloads and reconnaissance scripts, downloading additional malware onto victim systems, and abuse of msiexec to retrieve and execute malicious Windows Installer packages. The group has used malware such as Get2 and SDBbot and has leveraged commodity and criminally sourced tooling including Azorult and Cobalt Strike. TA505 has also been tied to Truebot-related activity and to intrusions in which Clop ransomware was later deployed. In ransomware operations associated with TA505 and the broader Clop ecosystem, the actor has conducted encryption, data theft, and extortion, including leak-site operations and pressure tactics directed at victims and, in some cases, victims' customers, partners, or executives. Clop-linked campaigns attributed to this ecosystem include mass exploitation of managed file transfer software vulnerabilities, notably in GoAnywhere MFT, MOVEit Transfer, and earlier Accellion file-transfer incidents. In some campaigns, the actor emphasized theft of data from exposed transfer systems and extortion based on publication threats; in others, Clop ransomware was used for network encryption after intrusion. The actor has also been observed exploiting vulnerabilities in products such as PaperCut NG/MF. TA505 primarily operates as a profit-driven criminal actor rather than a state-sponsored espionage group. Its operations have targeted enterprises, government-related entities, education, healthcare, manufacturing, information and communications organizations, and other large organizations across multiple regions, with especially broad impact in North America, Europe, and Japan.

Mentions1OriginRU
#3Qilin
Financially Motivated

Qilin, also tracked as Agenda, Gold Feather, Phantom Mantis, Water Galura, Qiring/Qirin, and related naming variants, is a prolific ransomware-as-a-service operation active since at least the early 2020s. It is widely recognized as one of the most active ransomware groups in 2026 and has repeatedly ranked among the top operators by published victim volume. The operation has been associated with broad, opportunistic targeting across North America, Europe, Asia, and South America, with especially heavy activity against organizations in the United States and Canada. Qilin conducts financially motivated ransomware intrusions that combine data theft with file encryption, consistent with double-extortion operations. Victim reporting and ransomware trend data show repeated targeting of construction, professional services, manufacturing, healthcare, education, agriculture and food production, hospitality, information technology-related manufacturing, and government or defense-linked organizations. Reported victim geography includes the United States, Canada, Argentina, Belgium, Spain, Singapore, Denmark, the Netherlands, Austria, Italy, and other countries across multiple regions. Operational reporting indicates Qilin has been a leading actor in multiple quarterly and monthly ransomware tallies, including being described as the most prolific operator for several consecutive quarters in 2026. In the Americas, it was assessed as the most active ransomware group in H1 2026, with particularly strong concentration in North America. Sector reporting also indicates a notable preference for construction and professional services in that region. The group’s intrusion lifecycle is consistent with mainstream modern RaaS tradecraft: gaining initial access through exploitation of known and newly disclosed vulnerabilities, stealing data, encrypting systems, and disrupting business operations to pressure victims into payment. Broader reporting tied to Qilin activity indicates use of multi-stage attack chains designed to establish persistence and maximize impact after compromise. Qilin is also linked by aliasing and industry reporting to the Agenda ransomware lineage; developers associated with the family have been reported to port code from Go to Rust, indicating ongoing malware development and adaptation. Qilin should be understood as a mature criminal ransomware enterprise rather than a state-directed espionage actor. Its dominant objective is monetary gain through extortion, and its scale, affiliate-driven branding, and sustained victim publication cadence place it among the major ransomware ecosystems active in 2026.

Mentions1OriginRU
#4Volt Typhoon

Volt Typhoon is a China-linked, state-sponsored advanced persistent threat group focused primarily on cyber espionage and long-term pre-positioning in critical infrastructure. The actor is also tracked as Bronze Silhouette, DEV-0391, Insidious Taurus, Storm-0391, UNC3236, Vanguard Panda, Voltzite, and Volt Typhoon (G1017). Reporting places the group’s activity from at least 2021 onward, with operations centered on stealthy access, operational security, and persistence in environments that could support future disruptive action. The group is best known for targeting critical infrastructure and network edge environments, especially in the United States and Guam, with victims spanning communications, utilities, energy, water, transportation, manufacturing, construction, maritime, government, information technology, education, and defense-related organizations. Additional reporting links the actor to activity affecting telecommunications in Singapore and to targeting of U.S. energy and defense sectors. Its targeting pattern is consistent with strategic intelligence collection and contingency preparation rather than overtly destructive operations. Volt Typhoon has repeatedly abused vulnerable internet-facing appliances and small-office/home-office equipment, including routers, firewalls, VPN appliances, and other embedded edge devices. Public reporting associates the actor with compromised-device proxy and botnet infrastructure, notably the KV Botnet and the JDY cluster, used to conceal operator traffic, support covert data transfer, and conduct scanning and reconnaissance. The actor has been linked to exploitation or probing involving edge technologies such as Cisco RV320/325 devices, Citrix NetScaler ADC, and Ivanti Connect Secure, although successful compromise is not always directly observed in every reported cluster. A defining characteristic of Volt Typhoon is extensive living-off-the-land tradecraft. The actor has been described as relying heavily on legitimate administrative tools already present in victim environments instead of deploying conventional malware, particularly in energy, water, and communications networks. At the same time, reporting also links Volt Typhoon-associated operations to tunneling and proxy tooling seen in broader PRC intrusion ecosystems, including use of compromised relay infrastructure and commodity tunneling techniques to hinder attribution and disruption. Observed behaviors include reconnaissance, scanning, theft of browser-stored data from network administrators, credential theft, exfiltration, persistence, lateral movement, post-exploitation, and defense evasion. The actor has targeted browser data such as browsing history and stored credentials, and has used compromised devices as operational relay nodes to mask follow-on intrusion activity. Reporting on associated clusters also indicates interest in maintaining covert access to critical infrastructure over extended periods, including through non-persistent malware on edge devices that can be rapidly re-established after disruption. Volt Typhoon is widely assessed as a PRC-origin espionage actor whose operations align with Chinese state interests. Its campaigns emphasize stealth, infrastructure obfuscation, and access into sectors whose disruption could have strategic effects during a geopolitical crisis, particularly involving U.S. military logistics and regional contingencies in the Indo-Pacific.

Mentions1OriginCN
#5CyberAv3ngers

CyberAv3ngers is an Iran-linked threat actor widely associated with the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC). The group is also tracked under aliases including Bauxite, Hydro Kitten, Shahid Kaveh Group, Soldiers of Solomon, Storm-0784, and UNC5691. It has been publicly characterized as a disruptive, propaganda-oriented actor focused on operational technology and industrial control systems, particularly internet-exposed programmable logic controllers, HMIs, SCADA environments, and adjacent IoT infrastructure. CyberAv3ngers is best known for targeting civilian critical infrastructure, especially water and wastewater utilities, fuel management systems, and other industrial environments in the United States and Israel. Reported activity includes compromises of Unitronics controllers at U.S. water facilities, disruptive operations affecting water services in Ireland, and campaigns against fuel-management and payment-terminal infrastructure tied to gas stations in Israel and the United States. The group has also been linked to broader targeting of government, manufacturing, and energy-related environments. Observed tradecraft emphasizes opportunistic exploitation of weakly secured OT assets rather than highly sophisticated initial access. The actor has repeatedly been associated with abuse of default or weak credentials, direct access to internet-exposed PLCs and HMIs, use of vendor engineering and configuration software, manipulation of PLC project files and controller settings, and disruption through password changes, IP reconfiguration, and forced loss of operator visibility or control. Public reporting also links the group to custom OT malware known as IOCONTROL, a modular Linux-based tool designed for IoT and OT devices that supports persistence, encrypted configuration, secure command-and-control, remote command execution, self-deletion, and scanning. IOCONTROL has been assessed as capable of affecting routers, PLCs, HMIs, firewalls, IP cameras, and fuel-management systems. The actor’s operations align primarily with espionage-adjacent pre-positioning and disruptive coercive activity in support of Iranian state interests rather than financially motivated crime. Its campaigns have frequently coincided with geopolitical tensions involving Iran and have often targeted infrastructure associated with the United States, Israel, and allied interests. CyberAv3ngers has also used public claims and messaging to amplify psychological impact and project capability, reinforcing its role as an Iran-aligned disruptive actor operating against critical infrastructure.

Mentions1OriginIR
#6spacebears

Space Bears is a ransomware and data-extortion operation that emerged in April 2024 and is associated with the Phobos ransomware-as-a-service ecosystem. The group operates a dedicated leak site and has repeatedly claimed intrusions against organizations in multiple regions, including Europe, the Americas, Asia, and Australia. Reported victims span retail, information technology, telecommunications, managed services, health care, industrial and logistics-related businesses, and other commercial enterprises. Space Bears follows a leak-site-driven extortion model centered on data theft and public exposure of stolen information. Victim postings commonly claim exfiltration of databases, financial records, employee and customer information, and other internal business documents, and the group has threatened staged publication when payment is not made. Reporting also indicates that the operation has published stolen data and, in some cases, offered valuable data to third parties, indicating a mature extortion workflow rather than encryption-only ransomware. Infrastructure reporting has linked Space Bears-related systems to hosting environments and bulletproof-hosting ecosystems also associated with other criminal operations, including ShadowSyndicate-linked infrastructure. One reported overlap tied Space Bears infrastructure to Layer7 Networks, and broader reporting connected related infrastructure patterns with malware and ransomware activity involving BlackCat/ALPHV affiliates, Clop, and SystemBC. These overlaps suggest Space Bears operates within a broader cybercriminal service ecosystem rather than as an isolated actor. Known aliases include spacebears and space_bears. High-confidence reporting supports characterization of Space Bears as a financially motivated cybercriminal ransomware actor using leak-site extortion, data exfiltration, and post-compromise coercion against a geographically diverse victim set.

Mentions1
#7SECUROTROP

Securotrop is a ransomware and data-extortion threat actor that emerged in 2024 and has been publicly linked to multiple intrusions against U.S. organizations. It is described as a ransomware-as-a-service operation associated with the Qilin ecosystem, including reporting that it splintered from the main Qilin gang while continuing to use Qilin network resources and code but maintaining its own leak infrastructure. Securotrop has operated a dedicated leak site since at least August 2025 and has publicly claimed attacks across sectors including manufacturing, energy, transportation and logistics, retail, and technology. The group’s operations are characterized by ransomware deployment combined with theft of victim data and public shaming on a leak site. Reported tradecraft supports the use of double extortion, with an apparent emphasis on closely examining and leveraging exfiltrated data to pressure victims. Publicly attributed incidents indicate repeated compromises of U.S.-based organizations, with claimed victims including industrial and manufacturing firms, an energy-sector drilling company, transportation and logistics businesses, media or technology-related organizations, and a retailer. Available reporting supports extortion-driven criminal activity rather than espionage or destructive state objectives. Known aliases include securotrop and securotrop_ransomware. Securotrop is best understood as a financially motivated ransomware crew operating in the broader Qilin-linked criminal ecosystem, using ransomware, data theft, leak-site publication, and extortion to monetize intrusions.

Mentions1
#8UNC5221

UNC5221 is a China-nexus, state-sponsored cyber-espionage threat actor focused on long-term intelligence collection and stealthy persistence, particularly through the compromise of edge infrastructure and virtualization platforms. The group is also tracked as UTA0178, VerdantBamboo, and WARP PANDA. Reporting consistently characterizes it as an espionage actor rather than a financially motivated cluster. UNC5221 is notable for exploiting zero-day and recently disclosed vulnerabilities in internet-facing security and networking products, especially Ivanti Connect Secure and related appliances. It was identified as the only cluster observed exploiting Ivanti Connect Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure period beginning in December 2023, and it was later linked to exploitation of CVE-2024-21893. The actor has also been associated with exploitation of additional Ivanti flaws in 2025 and with exploitation of edge-device weaknesses more broadly. Its tradecraft shows a strong preference for entering through firewalls, VPN gateways, storage appliances, NAS devices, and similar systems that often lack robust endpoint monitoring. Post-compromise, UNC5221 has demonstrated durable persistence, credential abuse, session hijacking, lateral movement, and data theft. In intrusions overlapping with public reporting on the actor, operators bypassed MFA by abusing compromised edge appliances, used hijacked sessions to access internal environments, profiled VMware infrastructure, manipulated virtual machines, and staged or exfiltrated sensitive data. The group has repeatedly leveraged valid credentials after initial compromise and has re-entered victim environments after remediation using retained administrative access. A defining feature of UNC5221 operations is the deployment of custom malware on edge and virtualized systems. Malware associated with the actor includes BRICKSTORM, a backdoor observed on Linux, Windows, FreeBSD, VMware, and Microsoft 365-adjacent intrusion paths; ROOTROT, BUSHWALK, WIREFIRE/GIFTEDVISITOR, and BEEFLUSH web shells; and later tooling such as PLENET and AGENTPSD. BRICKSTORM has been used for proxying, file operations, tunneling, persistence, and command execution, enabling the actor to pivot through trusted infrastructure and blend malicious traffic with legitimate enterprise activity. PLENET has been used as an additional foothold backdoor, while AGENTPSD has served as a fallback reverse shell. UNC5221 has targeted government and public-sector entities, defense and aerospace-related environments, information technology organizations, legal services, managed services providers, and other organizations of strategic intelligence value. Confirmed victimology includes U.S. law firms and technology organizations, as well as compromises affecting VMware and appliance-heavy enterprise environments. The actor has also been linked to long-term access in a major technology vendor environment and to campaigns against European industries of strategic interest to the People’s Republic of China. Its operations indicate an emphasis on theft of legal, trade, national security, and other sensitive enterprise information. The group’s operational style reflects mature espionage tradecraft: early exploitation of zero-days, abuse of trusted administrative pathways, persistence on under-monitored appliances, use of malware families tailored for edge and hypervisor environments, and rapid infrastructure changes after public exposure. UNC5221 is part of the broader pattern of PRC-linked intrusion activity prioritizing edge-device exploitation as an initial-access vector and maintaining covert access for extended periods to support strategic intelligence collection.

Mentions1OriginCN
#9Handala

Handala is an Iran-linked cyber persona widely assessed to be operated by the Iranian Ministry of Intelligence and Security (MOIS). It has also been tracked under aliases including VOID MANTICORE, Homeland Justice, Red Sandstorm, Storm-0842, Banished Kitten, Dune, and related Handala-branded variants. U.S. government reporting has described Handala as a fictitious persona within an MOIS-controlled cyber ecosystem, and an FBI affidavit has linked Handala, Homeland Justice, and Karma Below to the same operators. The actor combines ideological messaging, psychological operations, disruptive activity, credential theft, surveillance, and data theft. Its operations have prominently targeted Israel, Albania, and the United States, including government entities, media, healthcare-related organizations, payment services, and water-sector infrastructure. Handala has publicly framed some intrusions as retaliation tied to regional conflict and has used Telegram and similar channels to amplify reputational and psychological impact by publicizing claimed breaches and stolen data. Handala and closely linked personas have been associated with destructive and extortion-oriented operations against Albania since 2022, including campaigns affecting government systems, border-control functions, telecommunications, aviation, and parliamentary targets. Those operations included ransomware and destructive activity, as well as wiper deployment intended to render systems unbootable. The actor has also been tied to attacks and claims involving U.S. and Israeli organizations, including healthcare and water-sector victims, though some operational-technology disruption claims have exceeded publicly verified impact. Tradecraft attributed to Handala or the linked VOID MANTICORE cluster includes use of trojanized applications for persistent surveillance, PowerShell executed in hidden windows, credential extraction from Windows registry hives, automated file discovery and collection, exploitation of public-facing applications, and DNS-based command-and-control. Reporting also links the actor to distribution or use of commodity malware such as Rhadamanthys in at least one campaign, as well as use of remote administration, proxying, and lateral-movement tooling in destructive operations. The actor’s behavior reflects a blend of espionage-style access and collection with coercive, disruptive, and influence-oriented effects.

Mentions1OriginIR
#10NSO Group

NSO Group is an Israeli private-sector offensive actor and commercial spyware vendor best known for developing Pegasus, a highly sophisticated surveillance platform used in targeted operations against mobile devices. The company has also been associated with the Android spyware Chrysaor and related Pegasus tooling and infrastructure. NSO Group markets its capabilities to government customers, while multiple investigations and legal actions have linked its products to surveillance of journalists, human rights defenders, activists, dissidents, diplomats, politicians, lawyers, and other members of civil society across numerous countries. Pegasus operations attributed to NSO Group and its customers have repeatedly relied on advanced exploit chains, including zero-click compromises delivered through messaging and communications services such as iMessage and WhatsApp. Publicly documented Pegasus exploit chains include FORCEDENTRY, BLASTPASS, FINDMYPWN, PWNYOURHOME, LATENTIMAGE, KISMET, Dragonfly, Diablo, and other vectors targeting Apple and Android ecosystems. Documented infection methods have included malicious message content, one-click phishing and spearphishing, network injection, and other covert delivery mechanisms. Technical reporting has shown Pegasus capable of device fingerprinting, privilege escalation, persistence, anti-forensics, self-removal, credential and data collection, microphone and camera activation, geolocation tracking, screenshot capture, keylogging on Android, and broad exfiltration from communications apps, email, browser data, contacts, calendars, calls, messages, and cloud-linked data. NSO Group has operated anonymized, customer-segregated infrastructure for Pegasus and maintained dedicated support functions for covert service delivery. Reporting has described a dedicated White Services function and a Pegasus Anonymizing Transmission Network used to provision distinct infrastructure for individual government clients. Researchers have used recurring forensic artifacts, exploit behavior, and infrastructure patterns to attribute multiple campaigns to Pegasus and, in some cases, to distinguish separate customer environments. The actor is widely associated with mercenary spyware activity rather than conventional financially motivated cybercrime. High-profile reporting and litigation have tied NSO Group activity to exploitation of WhatsApp users and to later phishing and social-engineering attempts targeting WhatsApp users despite court-imposed restrictions. NSO Group has been placed on the U.S. Entity List, and its operations have become a central example in debates over the commercial spyware industry, cyber-mercenary services, and transnational digital repression. Known aliases and related names include NSO, Pegasus, and Chrysaor. Pegasus is the company’s most widely recognized spyware platform rather than a separate threat actor identity.

Mentions1OriginIL
#11Swiping Squirrel

Swiping Squirrel is a financially motivated cybercriminal traffic-monetization actor tracked for acquiring expired domains that had previously been used in malicious infrastructure and then exploiting the inherited traffic from compromised websites still referencing those domains. The actor has been active since at least 2022 and has acquired more than 3,000 domains, making it the most prolific of a cluster of related scavenger actors that also includes Stuffy Squirrel and Shady Squirrel. Swiping Squirrel commonly overlaps with Shady Squirrel on the same compromised websites, and the two actors have at times acquired domains from one another. Rather than newly compromising websites at scale, Swiping Squirrel benefits from residual malicious links and scripts already embedded on previously compromised sites. This allows the actor to inherit victim traffic and monetize it through affiliate programs and zero-click advertising ecosystems. Observed downstream outcomes include scams and malware delivery. Swiping Squirrel primarily resells fraudulently acquired traffic through ZeroPark and has also been associated with commerce affiliate programs including AliExpress and other comparison-shopping or affiliate platforms. Operationally, Swiping Squirrel uses client-side JavaScript fingerprinting and cloaking to restrict visibility of malicious behavior. The infrastructure returns active script content only when requests originate from the expected compromised-site context and otherwise responds benignly, such as with not-found behavior. Observed relay chains include cloaking and meta-refresh steps that pass users onward to affiliate monetization platforms or to downstream scam and malware content. A documented downstream case involved traffic sold onward into a ClickFix-style social-engineering chain using a fake CAPTCHA. High-confidence reporting supports traffic resale, cloaking, and malware/scam enablement, but does not support attribution to a nation state.

Mentions1
#12Stuffy Squirrel

Stuffy Squirrel is a financially motivated cybercriminal traffic-monetization actor that has been active since at least 2020. The actor specializes in acquiring expired domains that were previously used in malicious infrastructure and reusing the inherited traffic from compromised websites that still reference those domains. This allows Stuffy Squirrel to exploit existing infection pathways without newly compromising the affected sites. The actor has operated a traffic distribution system across multiple generations of dedicated infrastructure and has controlled hundreds of domains. Stuffy Squirrel has reused domains previously associated with other malicious ecosystems, including TA2726, Magecart, and Balada injection activity. A defining tradecraft element is concealment of malicious logic inside legitimate-looking JavaScript resources, including insertion of self-removing code into benign libraries to blend into normal web content. Stuffy Squirrel employs layered evasion techniques, including path validation, selective traffic-distribution responses, and user-interaction gating so that malicious behavior is only triggered under specific conditions. Its operations are centered on redirecting and monetizing inherited web traffic through popunder advertising and affiliate networks, particularly in adult-content, e-commerce affiliate fraud, online gambling, and related scam-adjacent ecosystems. The actor is best characterized as a web-traffic broker and cloaked redirection operator rather than a traditional espionage or destructive intrusion set.

Mentions1
#13Shady Squirrel

Shady Squirrel is a financially motivated cybercriminal traffic-distribution and malware-delivery actor assessed to be Russian-speaking and active since at least July 2023. The group specializes in acquiring expired domains, particularly domains previously used in malicious infrastructure or embedded in compromised websites, and repurposing the inherited traffic for downstream monetization, scams, and malware delivery. More than 700 domains have been attributed to the actor since 2023. Shady Squirrel is notable for partnering with SocGholish and helping restore access to large volumes of compromised-site traffic after disruption of that ecosystem in 2026. The actor has also routed victims to tech support scam operations, a gambling platform, push-monetization services, and Keitaro-based traffic distribution chains. In addition to malicious-domain reuse, the actor has been linked to a supply-chain-style hijack involving acquisition of a formerly legitimate CDN domain that was then used to redirect visitors from prominent websites to malware. Operationally, Shady Squirrel uses custom JavaScript injections, Keitaro traffic distribution, and server-side fingerprinting to cloak malicious behavior and selectively redirect victims. Observed tradecraft includes showing benign or original content to bots and scanners while delivering malicious flows only to selected users, as well as conditional redirection based on factors such as referral source and operating system. The actor has delivered malware through scareware and call-center-assisted tech support scam chains and later fed traffic into SocGholish fake-update infrastructure operated by TA569. Known associations include SocGholish and TA569. Shady Squirrel is one of several so-called scavenger actors focused on reusing expired malicious domains rather than newly compromising websites, allowing it to inherit existing infection and referral traffic at scale.

Mentions1OriginRU
#14UNC5174

UNC5174 is a China-nexus intrusion set and opportunistic initial access actor assessed to conduct access operations against internet-facing systems and to broker or transfer footholds to downstream espionage operators. The actor is associated with the personas Uteus and Uetus and has been linked to the Houken intrusion set; reporting has also connected it to the alias CL-STA-1015. Multiple assessments indicate ties to Chinese-speaking ecosystems and possible contractor-like support to China’s Ministry of State Security, with activity patterns aligned to UTC+8. UNC5174 is known for rapid exploitation of public-facing vulnerabilities, particularly in edge appliances and enterprise software. Reported exploitation includes flaws affecting F5 BIG-IP, ConnectWise ScreenConnect, Ivanti Cloud Service Appliance, GeoServer, VMware products, Atlassian Confluence, Zyxel firewalls, and other exposed services. The actor has repeatedly targeted organizations of intelligence value while also showing behavior consistent with access monetization. Observed victimology spans government and public-sector entities, defense-related organizations, research and education institutions, telecommunications, media, finance, transport, businesses, and charities or NGOs. Confirmed targeting includes organizations in the United States, United Kingdom, Canada, France, Hong Kong, Southeast Asia, Australia, and South America. French incident response linked Houken activity to compromises across government, telecommunications, media, finance, and transport, and assessed that the same actor later exfiltrated a large volume of emails from a South American foreign ministry. Tradecraft emphasizes initial access, credential harvesting, persistence, and post-compromise enablement. UNC5174 has been observed stealing credentials from compromised appliances, deploying webshells, modifying legitimate server-side scripts for persistence, self-patching exploited resources to exclude competing actors, and in some cases installing Linux rootkit capability. The actor also conducts reconnaissance, scanning, lateral movement, and use of proxying and tunneling tools after compromise. Public and custom tooling associated with UNC5174 includes VShell, SNOWLIGHT, GOREVERSE, Sliver, SUPERSHELL, Neo-reGeorg, Behinder, suo5, reverse SSH tooling, and a range of scanning, relay, and tunneling utilities. VShell and SNOWLIGHT are especially recurrent in reporting and overlap with broader China-aligned intrusion ecosystems. UNC5174 has also been associated with Operational Relay Box infrastructure usage alongside other China-linked actors, reinforcing assessments that it operates within a broader shared access and espionage ecosystem rather than as an isolated cluster. Its dominant role is best characterized as opportunistic access acquisition and enablement for state-linked intelligence objectives, although some incidents indicate occasional direct profit-seeking through data theft or cryptominer deployment.

Mentions1OriginCN
#15Sable Squirrel

Sable Squirrel is a large cybercriminal actor associated with the acquisition and repurposing of thousands of expired domains to support a dual-use ecosystem spanning illegal sports streaming, gambling promotion, traffic redirection, mobile app distribution, and malware command-and-control. The actor has been assessed as controlling more than 10,000 domains and investing more than $7 million in dropcatch acquisitions to exploit inherited domain reputation, backlinks, residual traffic, and historical trust signals. The operation is strongly tied to Asian sports-piracy and betting activity. It has operated streaming brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom, and has been linked to betting brands including VSBet, ColaScore, 8xbet, and 6686. Its streaming infrastructure has targeted users in Vietnam, South Korea, Japan, and Australia, presenting consumer-facing football streaming services while directing traffic toward gambling platforms. A subset of Sable Squirrel infrastructure has also been used as malware command-and-control. Observed malware families communicating with its domains include Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, as well as samples carrying HiddenTear ransomware signatures. In some cases, the same domain simultaneously served live streaming content to human visitors and command-and-control traffic to infected systems. Reporting has identified hundreds of domains in this role and more than 31,000 malware samples communicating with the actor’s infrastructure. Activity indicates a malware weaponization surge beginning in late 2025, with AsyncRAT use giving way to DCRat as a primary payload in early 2026. The actor’s infrastructure demonstrates rapid operationalization of newly acquired domains, with most domains becoming active within days of registration. Its streaming fleet has been described as relying heavily on shared backend services and stock WordPress deployments across multiple brands. Sable Squirrel has also registered fresh lookalike domains derived from its streaming brands in addition to buying expired domains. Sable Squirrel is financially motivated and operates as a cybercriminal enterprise rather than a state-sponsored intrusion set. Available reporting indicates strong overlap with the Vietnamese Xoi Lac TV network that faced law-enforcement action in early 2026, although definitive identity equivalence has not been publicly confirmed.

Mentions1OriginVN
#16CRPx0

CRPx0 is a cyber extortion and ransomware-linked threat actor active by mid-2026. The group is known for coercive post-compromise monetization, including operating public leak sites on both the clear web and dark web and listing victims that allegedly refused to pay. It has also been reported to escalate pressure by offering stolen victim data for sale after payment deadlines expire, indicating a data-theft extortion model and use of a leak site as part of its victim pressure strategy. CRPx0 has been associated with social-engineering-based initial access, including lures offering free OnlyFans accounts to entice targets into clicking malicious links that deploy malware. This demonstrates use of themed phishing or lure-based delivery for initial compromise, followed by malware execution and extortion. Public reporting also places CRPx0 among the more active extortion actors in July 2026 by claimed victim volume. High-confidence reporting supports characterizing CRPx0 as a financially motivated criminal actor focused on extortion. Specific national affiliation, organizational structure, and stable sub-group taxonomy are not established from the available information.

Mentions1
#17Barracuda

Barracuda is a ransomware and data-extortion threat actor observed publicly naming victims and monetizing stolen data. Reported victimology includes organizations in Brazil, the United States, South Korea, and China across legal services, health care, technology, and manufacturing. The group has been associated with intrusions followed by theft of large volumes of corporate and personal data, including client records, medical information, employee and partner data, engineering materials, source code, and database dumps. Barracuda has used coercive pressure by threatening to publish or sell stolen information when victims do not respond, and has advertised stolen datasets for sale with leak status indicators such as upcoming, selling, or free. Based on observed operations, Barracuda is best characterized as an extortion-focused ransomware actor whose confirmed behavior centers on data theft and leak-site style pressure rather than clearly documented encryption activity in the available reporting.

Mentions1
#18LAUNDRY BEAR

Laundry Bear is a Russia-aligned cyberespionage threat actor also tracked as Void Blizzard, TA488, and UAC-0190, with additional reporting linking it to CL-STA-1114 and the former designation UNK_PitStop. The group is assessed to operate on behalf of Russian state interests and has been described as state-supported, with reporting and legal action tying elements of its activity to Russian individuals and infrastructure associated with Russian intelligence-linked entities. The actor is primarily focused on intelligence collection against Western and Ukrainian targets. Reported targeting includes NATO member states, Ukraine, the United States, and European organizations. Victim sectors include government, defense, education, telecommunications, financial services, hospitality, aerospace, energy, media, law enforcement, technology, and other commercial organizations. A recurring operational objective is covert access to email systems and long-term collection of mailbox contents, directories, credentials, tokens, and related sensitive communications data. Laundry Bear is notable for repeated exploitation of webmail platforms using "half-click" or view-based attacks in which opening or previewing a malicious email is sufficient to trigger code execution in the victim's authenticated browser session. In campaigns against Zimbra Collaboration Suite, the group exploited CVE-2025-66376 to deliver the JavaScript payload known as ZimReaper, which harvested recent email content, credentials, CSRF material, two-factor authentication data, and application passwords, while also enumerating address lists and maintaining persistent mail access. In later operations against on-premises Microsoft Exchange Outlook Web Access, the group exploited CVE-2026-42897 to deploy OWAReaper, a browser-resident implant that executes entirely within the OWA reading pane. OWAReaper demonstrates unusually mature tradecraft for browser-based mailbox compromise. It collects mailbox and configuration data, attempts credential theft through browser autofill abuse, steals OAuth tokens via permissive Outlook add-ins, rewrites malicious messages to remove exploit content after execution, and establishes persistence through multiple layers. These include encrypted storage in browser state, poisoning of offline cached messages, and server-side mailbox permission abuse that can preserve access even after password changes or device reimaging. The malware also supports covert command-and-control through public code-hosting commit messages and attacker-sent emails, and exfiltrates stolen data over encrypted web channels with DNS-based fallback. Beyond exploit-driven mailbox compromise, Laundry Bear has also been associated with credential phishing, spoofed login pages, password spraying, and session-token replay against cloud email environments, especially Office 365. Reported operations used geographically proximate proxy infrastructure to evade geo-blocking and were frequently followed by data exfiltration. The group has therefore demonstrated both credential-theft and session-hijacking tradecraft, alongside broader post-compromise mailbox abuse and persistence. Overall, Laundry Bear is a Russian cyberespionage actor specializing in email-centric intrusion operations, combining phishing, token abuse, stealthy browser implants, and exploitation of webmail vulnerabilities to obtain durable access to high-value communications for intelligence collection.

Mentions1OriginRU
#19Anubis

Anubis is a ransomware-as-a-service operation active since late 2024 that conducts double-extortion attacks combining file encryption with data theft and leak threats. The group is distinct from the older Android banking malware that shares the same name. Reporting also describes Anubis as a rebrand of the earlier Sphinx ransomware operation. By early 2025, Anubis had launched an affiliate program and publicly promoted revenue-sharing arrangements for ransomware deployment, data extortion, and initial-access brokering, indicating a structured RaaS ecosystem with separate operator and affiliate roles. Anubis has targeted organizations across multiple sectors, with confirmed victims including healthcare providers, manufacturers, retailers, financial-services firms, food and beverage companies, and maritime infrastructure operators. Observed victim geography includes the United States, France, Italy, and the United Kingdom. Publicly reported incidents show the group causing both data breaches and operational disruption, including temporary production outages and business interruption. Tradecraft attributed to Anubis includes initial access via spear-phishing, exploitation of exposed internet-facing systems, and abuse of weakly secured remote-access and cloud environments. Reported intrusion paths include exploitation of known vulnerabilities in perimeter technologies and movement from an initial foothold into core enterprise systems. The group has been linked to exploitation of unpatched edge infrastructure, insecure VPN deployments, and weaknesses in cloud-managed environments such as Microsoft 365 and Azure. Post-compromise behavior includes lateral movement, encryption of systems, exfiltration of sensitive corporate and employee data, and extortion through a public leak site. Anubis has also been described as having a destructive wiper capability that can permanently delete victim files and impede recovery. Known aliases include Anubis RaaS, Anubis ransomware group, and Anubis ransomware operation. The actor’s dominant motivation is financial gain through ransomware and extortion.

Mentions1OriginRU
#20Panzer

Panzer is an emerging ransomware-as-a-service operation active by August 2026. It has been advertised on a Russian-speaking cybercriminal forum with an affiliate model that reportedly offers automated management, revenue sharing, victim negotiation portals, and a leak site. Reported platform support includes Windows, Linux, ESXi, and FreeBSD. Public reporting also indicates affiliate restrictions against targeting CIS countries and certain categories of victims. At the same time, early claims about the service’s capabilities were not independently verified, and no public malware sample was available during initial reporting. Panzer has been publicly associated with ransomware incidents and claimed data breaches affecting organizations in Germany, Thailand, Nigeria, Switzerland, and Indonesia. Reported victims span multiple sectors, including manufacturing, energy, consumer-facing food businesses, media, retail, and education. The operation’s extortion model appears to include both encryption and data-leak pressure through a leak site and victim negotiation infrastructure. Observed and claimed tradecraft associated with Panzer includes data encryption for impact, data exfiltration, defense evasion, and remote-access-enabled post-compromise activity. Its operating model is consistent with financially motivated cybercrime rather than state-directed espionage. Based on available reporting, Panzer should be tracked as a ransomware/extortion actor with a RaaS structure, but some technical and operational claims remain preliminary due to limited independent verification.

Mentions1
#21Cobalt Group

Cobalt Group is a financially motivated cybercrime threat actor known for targeted spearphishing campaigns against organizations, particularly in the financial sector. The group is also tracked under aliases including Cobalt, Cobalt Gang, Cobalt Spider, and Gold Kingswood. It has been associated with the operational use and abuse of Cobalt Strike and has weaponized Microsoft Office exploits, including CVE-2017-11882, to gain execution on victim systems. The group commonly relies on email-based initial access, sending spearphishing messages with malicious attachments such as RTF, Office documents, archives, and macro-enabled files that require user interaction. Observed execution chains include malicious VBA macros, JavaScript or JScript scriptlets, PowerShell downloaders, and use of regsvr32 to launch scripts. Post-compromise activity includes command execution through the Windows shell, staged payload retrieval from public file-hosting or code-sharing services, and use of HTTPS for command-and-control communications. Cobalt Group has demonstrated persistence through Windows Scheduled Tasks, Registry Run keys, and Startup-folder-based mechanisms, including PowerShell-based launchers used to retrieve follow-on tooling. The group has also shown privilege-escalation capability through User Account Control bypass and has performed security software discovery by collecting information on defensive products installed on victim machines. Defense-evasion behavior includes deletion of droppers and other artifacts to reduce forensic visibility. The actor’s tradecraft reflects a multi-stage intrusion model centered on phishing-led compromise, script-based execution, persistence establishment, and post-exploitation control of infected systems. Available evidence in this dataset supports characterization as a cybercriminal intrusion set rather than a state-sponsored espionage actor.

Mentions0OriginRU
#22Rocke

Rocke is a cryptojacking threat group focused on compromising Linux and cloud-hosted environments to deploy Monero mining malware. The group has been associated with cloud-targeted campaigns since at least 2019 and is also referred to as Iron Group. Its operations emphasize monetization through illicit cryptocurrency mining rather than espionage or destructive effects. Rocke commonly targets exposed or weakly secured internet-facing services and cloud workloads, including vulnerable enterprise applications and misconfigured infrastructure. Reported intrusion vectors and propagation methods include exploitation of Apache ActiveMQ via CVE-2016-3088, Oracle WebLogic via CVE-2017-10271, Jenkins via CVE-2018-1000861 and CVE-2019-1003000, unsecured Redis instances, and brute-force activity against SSH and Redis. The group has shown particular interest in cloud environments associated with Chinese providers such as Alibaba Cloud and Tencent Cloud. Operationally, Rocke uses staged shell-script infection chains to download and execute additional payloads, often with redundant retrieval paths and public code-hosting or paste services for resilience. The group has also used compile-after-delivery tradecraft, delivering malware as C source files and compiling them locally with GCC. Payloads have included Go-based loaders and managers, Python-based loader stages, and XMRig-derived mining components. Rocke malware has been observed extracting compressed archives, embedding or unpacking miner components, and using modified UPX-style packing markers such as LSD! to hinder static detection. Persistence and stealth are central to Rocke operations. The group establishes persistence through cron jobs, boot-time services, and in some cases startup-folder artifacts on Windows. On Linux, Rocke has deployed LD_PRELOAD-based userland rootkit functionality, including libprocesshider-style capabilities, to conceal files, processes, network activity, and resource consumption. Malware associated with the group can falsify process or CPU-related information returned to monitoring tools. Rocke also performs process discovery and system profiling, including collecting kernel or architecture information with uname -m and identifying running process IDs. Rocke routinely removes competing miners and other malware, deletes artifacts, and attempts to disable or uninstall defensive tooling. Reported behavior includes terminating rival mining processes, uninstalling antivirus or cloud monitoring agents, and disabling host firewall controls in some campaigns. Lateral movement and worm-like propagation have also been documented through subnet scanning, exploitation of adjacent systems, and attempts to reuse SSH keys or trust relationships to spread within cloud environments. The group’s known capabilities include initial access through exploitation and brute force, reconnaissance and scanning of local or internet-reachable targets, persistence, defense evasion through rootkit-style hiding and packing changes, post-exploitation payload staging, and cryptocurrency theft via unauthorized mining.

Mentions0
#23ZIRCONIUM

APT31 is a China-linked cyber espionage threat actor tracked under numerous aliases including ZIRCONIUM, Judgment Panda, Judgement Panda, Violet Typhoon, TA412, Bronze Vinewood, Chameleon, Red Keres, and WebFans. Public reporting and law-enforcement actions have associated the group with the Chinese Ministry of State Security. The actor is known for long-term intelligence collection operations and infrastructure development in support of espionage. APT31 has targeted government and military organizations and has also been linked to operations involving network edge devices and routers used to build covert command-and-control and reconnaissance infrastructure. Reported activity includes campaigns against government agencies and military structures in Russia, as well as operations affecting entities in France through compromised network equipment. The group has also been associated with activity involving Korean organizations through use of the Rekoobe Linux backdoor. Tradecraft attributed to APT31 includes acquisition of domains for targeted operations, browser credential theft, host and user discovery, network and proxy configuration discovery, ingress tool transfer, command-shell execution, persistence via Registry Run keys, encrypted command-and-control, and exfiltration over cloud-backed channels. Observed procedures include stealing credentials from Chromium- and Internet Explorer-based browsers, collecting usernames, processor architecture, and system time from compromised hosts, enumerating proxy settings, downloading additional malicious files, and opening remote Windows command shells. APT31 has used AES-encrypted command-and-control communications and has exfiltrated collected files through Dropbox-based command-and-control. Reporting has also described a third-stage implant used by the group to send collected files through Dropbox. APT31 has been linked to the Rekoobe backdoor in Linux environments. Rekoobe is derived from Tiny SHell and supports file upload, file download, and reverse-shell command execution, reinforcing the group’s cross-platform post-compromise capability. Separate reporting has also described APT31 tradecraft involving compromised Pakedge, Cyberoam, and Cisco routers to support command-and-control and reconnaissance infrastructure. Overall, APT31 is best characterized as a mature Chinese state-linked espionage actor focused on stealthy access, victim profiling, credential collection, persistent footholds, and data theft rather than disruptive or financially motivated operations.

Mentions0OriginCN
#24PROMETHIUM

StrongPity, also tracked as Promethium, Blue Magic Eye, APT-C-41, Magenta Dust, SmallPity, and StrongPity, is a long-running espionage-oriented threat actor active since at least 2012. The group is known for covert surveillance operations and repeated use of trojanized legitimate software, watering-hole compromises, and fake or repackaged installers to gain initial access. Public reporting has linked the actor to campaigns centered on poisoned downloads of widely used utilities and encryption-related software, including WinRAR and TrueCrypt, as well as later trojanized installers for common consumer applications. Activity has been concentrated in the Middle East and Europe, with notable targeting and victim exposure in Turkey, Italy, Belgium, and Syria. StrongPity is characterized by modular spyware and backdoor tooling for both Windows and Android. On Windows, the actor has used disguised installers that deliver legitimate decoy software alongside malicious components, then establish persistence through Registry Run keys and related autostart mechanisms. Reported tooling includes staged payloads that search for and collect documents and other sensitive files, compress and encrypt stolen data, upload it to command-and-control infrastructure, and download and execute additional payloads. The group has also created self-signed digital certificates to support HTTPS command-and-control traffic. On Android, StrongPity has deployed repackaged applications, fake apps, and compromised websites to distribute mobile spyware. Its Android malware has used broadcast receivers for persistence and event-triggered execution, including boot, connectivity, screen, and user-presence events. Documented mobile surveillance capabilities include collection of call logs and contact lists, modular expansion through downloaded components, and use of accessibility- and notification-related functionality in newer variants. The actor’s tooling shows sustained incremental development, reuse of code and infrastructure patterns across campaigns, and a consistent emphasis on stealthy intelligence collection rather than disruptive or destructive effects. StrongPity has been described as a technically capable actor that often operates with relatively low visibility. It is widely assessed as an espionage-focused group, and some reporting has suggested it may work on behalf of state interests without being clearly identified as a formal state organization.

Mentions0