Who's moving, and how fast. Mallory tracks named threat actors across vendor reports, researcher analysis, and underground chatter, then surfaces the ones picking up momentum right now.
Ranked by Mallory's mention-velocity model across sources.
Flax Typhoon is a China-based, state-sponsored cyberespionage threat actor also tracked as Ethereal Panda and Storm-0919, with associated activity tracked as Red Juliett. It is linked to Integrity Technology Group, a Beijing-based cybersecurity contractor holding Chinese government contracts. Its targets include Taiwanese universities and critical infrastructure, U.S. organizations, and airports in Japan and Poland. Targeted sectors include government, education, information technology, manufacturing, energy, utilities, healthcare, and nongovernmental and religious organizations. The group combines automated reconnaissance with hands-on exploitation, using vulnerability scanners, command-line exploit utilities, spear phishing, cross-site scripting credential harvesting, and password spraying against Microsoft Exchange and Microsoft 365. Associated operations use MicroScan, a web-based platform containing more than 1,300 penetration-testing scripts, and FishHub, which supports spear-phishing intrusions and delivery of additional malware for remote access and file theft. Flax Typhoon relies heavily on living-off-the-land techniques and legitimate remote-access software. It installs SoftEther VPN clients for persistent access, configures reconnection at startup, and disguises components as legitimate Windows software. Collection activities include database theft, Active Directory credential harvesting through DCSync, and email exfiltration from on-premises and cloud services. Flax Typhoon is associated with Raptor Train, a Mirai-based botnet of compromised small-office/home-office and Internet-of-Things devices operated by Integrity Technology Group. This infrastructure supports reconnaissance and conceals the origin of malicious traffic. U.S. authorities disrupted the botnet in September 2024 and seized infrastructure supporting MicroScan, FishHub, and persistent VPN connections in October 2026.
Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, UNC3753, Storm-0252, and Silent Ransom, is a Russia-based, financially motivated cybercriminal group that emerged in 2022 following Conti's shutdown. Its operators previously conducted BazarCall callback-phishing operations that supplied access to Ryuk and Conti. Despite its name, SRG primarily conducts data-theft extortion without encrypting victims' files. The group has focused heavily on U.S. law firms since 2023, exploiting the sensitivity of privileged client documents and the reputational consequences of disclosure. Its targeting also includes other professional services organizations, financial services, and real estate. SRG steals confidential information and threatens to publish or sell it unless victims pay, maintaining a leak site to expose non-paying organizations. Initial access centers on callback phishing and telephone-based impersonation. Fraudulent subscription invoices induce recipients to call operators, while other approaches impersonate internal IT personnel using help-desk or data-migration pretexts. Operators persuade employees to initiate screen-sharing sessions or grant remote access through legitimate administration software. They use legitimate file-transfer tools and consumer file-sharing services to collect and exfiltrate documents, reducing reliance on conspicuous malware. The group has also used impostors posing as IT personnel to seek physical access to victims' offices and computers.
UmBra is a ransomware and extortion group associated with attacks reported in October 2026 against educational institutions, technology businesses, a mining company, and a furniture wholesaler. Named targets include IIT Roorkee and Manipal Academy of Higher Education in India; FSE, Cairo University and Beni Suef Technological University in Egypt; and Four Hands LLC in the United States. The group also claimed responsibility for an attack against Tharisa, a Cyprus-based mining group with major operations in South Africa. UmBra uses threats of public disclosure to pressure victims into negotiations. In its October 7, 2026 claim against Tharisa, it threatened to publish allegedly sensitive information unless a company representative contacted the group. That claim was not independently confirmed. Its country of origin, organizational structure, initial-access methods, malware families, and encryption practices are not established. No distinct aliases or subgroups are established.
TraderTraitor is a North Korean government-backed, financially motivated subgroup of Lazarus focused on cryptocurrency theft. It is also tracked as Jade Sleet, UNC4899, PUKCHONG, Slow Pisces, Storm-0954, and Pressure Chollima. Its targets include cryptocurrency exchanges, blockchain and Web3 organizations, financial-technology personnel, and developers with privileged access to cloud infrastructure and source code. The FBI attributed the approximately $1.5 billion theft from Bybit on February 21, 2025, to North Korea under the TraderTraitor designation; the cluster has also been associated with the DMM Bitcoin theft. The group uses recruitment-themed social engineering, impersonated companies, and fake technical assessments to compromise developer workstations. Its Terraform-based lures manipulate dependency lock files to redirect provider retrieval to attacker-controlled registries, causing malicious provider modules to execute during initialization. A confirmed campaign compromised a DevOps engineer’s macOS workstation at an Indian IT services provider without cryptocurrency ties, demonstrating targeting beyond digital-asset businesses. TraderTraitor uses the FLATROOF and ROOFDECK backdoors for remote command execution, reconnaissance, credential collection, data exfiltration, and persistent access. Their capabilities include collecting browser data, shell histories, system information, keychain material, and clipboard contents; transferring files; and establishing reverse shells. FLATROOF supports Telegram-based command-and-control and exfiltration, while ROOFDECK uses Nostr metadata to resolve command-and-control infrastructure and supports LaunchAgent persistence. Operations involving LayerZero included API-key collection and privilege escalation into AWS and Google Cloud environments. Operators have refreshed implants and removed earlier components to sustain access and reduce forensic evidence. Proceeds from attributed cryptocurrency thefts are dispersed across multiple blockchains and routed through bridges and cross-chain exchange services.
Integrity Technology Group, also known as Integrity Tech, is a Beijing-based, for-profit cybersecurity company with Chinese government links and government contracts that enables China-linked cyberespionage operations. Its personnel develop and acquire offensive tools, sell capabilities, host infrastructure, and compromise networks worldwide. Associated activity overlaps with operations tracked as Flax Typhoon, Ethereal Panda, and Red Juliett; these tracking labels are not interchangeable with the company and may include activity independent of it. Its targeting includes government and law enforcement agencies, healthcare systems, information technology organizations, manufacturers, religious institutions, nongovernmental organizations, universities, and critical infrastructure. Documented reconnaissance targets include U.S. power infrastructure, Japanese and Polish airports, and Taiwanese natural gas companies, power companies, and universities. Approximately 20 Taiwanese universities were confirmed victims of FishHub activity. Reconnaissance against an organization does not by itself establish successful compromise. Integrity Tech operates MicroScan, a vulnerability-reconnaissance platform used since at least 2017 with more than 1,300 penetration-testing scripts, and FishHub, which supports spear phishing and malware delivery for remote access and file theft. It built and operated the Mirai-based Raptor Train botnet, using compromised consumer and Internet of Things devices to support scanning and obscure malicious traffic. Associated intrusion methods include exploitation of internet-facing applications, credential-harvesting webpages, password spraying against Microsoft Exchange and Microsoft 365, webshells, privilege-escalation tools, and DCSync credential theft. Operators maintain persistent access using SoftEther VPN, abuse legitimate system utilities, disguise malicious artifacts, and automate collection and exfiltration of email from on-premises and cloud services. Company-associated infrastructure also provides third parties access to stolen email. A September 2024 disruption targeted its botnet of more than 200,000 compromised devices. The United States sanctioned the company in January 2025, and the United Kingdom sanctioned it in December 2025. An October 2026 court-authorized operation disrupted infrastructure supporting MicroScan, FishHub, malware delivery, and persistent remote access.
Eclipse is a ransomware threat group associated with attacks against organizations in Singapore, India, the United States, Brazil, France, and Japan. Its attributed activity spans at least August through October 2026 and affects manufacturing, transportation and logistics, media, hospitality, software, legal services, food distribution, and public education. Named targets include Simplex Engineering & Foundry Works, Global AirFreight International, The Japan Times, TTG Asia Media, Royal Plaza On Scotts, ETNA Software, The Zhou Law Group, Rosello et Fils, Dublin City Schools GA, DIPECARR, and Moscord. The group's targeting encompasses multiple unrelated industries and geographic regions. Its country of origin, organizational structure, initial-access techniques, malware tooling, and specific encryption or data-extortion practices are not established.
UAC-0099, also tracked as Earth Sirrush and previously designated SHADOW-EARTH-065, is a cyberespionage group active since at least 2022. Its operations target Ukrainian government organizations, military and defense entities, border guards, financial institutions, media outlets, and transportation, logistics, manufacturing, and energy organizations. The group has also conducted initial-access operations associated with subsequent activity by Sandworm, the Russian military intelligence-linked threat actor. UAC-0099 primarily obtains access through spear-phishing emails carrying malicious attachments or links to archives. Delivery chains use VBScript, Windows shortcuts, HTA files, institutional decoys such as court summonses, and exploitation of the WinRAR vulnerability CVE-2023-38831. Other deployment methods include VHD containers, DLL sideloading, and malicious components masquerading as Notepad++ plugins. Its malware provides remote command execution, browser password and cookie theft, keylogging, screenshot capture, file collection, system fingerprinting, and network scanning. The group's toolkit includes LONEPAGE, the MATCHBOIL downloader, the MATCHWOK backdoor, the information stealers THUMBCHOP, DRAGSTARE and ASHVEIN, and the CLOGFLAG keylogger. MATCHBOIL downloads and installs additional payloads, usually MATCHWOK, and establishes persistence through scheduled tasks or Windows Run-key entries. Successive variants introduced recurring payload retrieval, commercial .NET Reactor obfuscation, debugger and sandbox checks, deceptive graphical interfaces, and DLL-based execution through custom C# loaders. UAC-0099 also uses encrypted communications, concealed payloads, and Cloudflare-fronted command-and-control infrastructure to impede detection and analysis. The group has used GuardBreaker, an anti-analysis technique that embeds safety-sensitive text in a malicious script comment to attempt to interrupt LLM-assisted malware analysis without altering the script's runtime behavior.
HAFNIUM, now tracked by Microsoft as Silk Typhoon and also known as Murky Panda and TIMMY, is a China-based, state-sponsored cyberespionage group. It targets organizations in the United States, including law firms and defense contractors, to obtain sensitive information and maintain access to compromised environments. The group is associated with the 2021 exploitation of the ProxyLogon zero-day vulnerabilities in on-premises Microsoft Exchange Server: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. These attacks enabled access to email accounts, data theft, and deployment of web shells for persistent remote access. Its deployed web shells include SIMPLESEESHARP, SPORTSBALL, China Chopper, and ASPXSpy. HAFNIUM has also exploited Log4Shell, CVE-2021-44228, against virtualization infrastructure, using DNS-based testing to fingerprint systems. In March 2024, Silk Typhoon exploited CVE-2024-3400 as a zero-day against Palo Alto Networks GlobalProtect gateways to compromise multiple organizations. Post-compromise activity includes dumping LSASS process memory with ProcDump, stealing copies of the Active Directory database, and creating domain accounts with additional privileges. The group compresses stolen data with 7-Zip and WinRAR before exfiltration and has used TCP for command-and-control communications. Its tooling includes publicly available offensive frameworks and utilities such as Covenant, Nishang, and PowerCat.
ShinyHunters is a financially motivated cybercriminal operation specializing in large-scale data theft, stolen-database distribution, and encryption-less extortion. Also known as ShinyHunter, Shiny_Hunters, and Bling Libra, its associated activity is tracked under the identifiers UNC6040 and UNC6240. Criminals using the name have claimed breaches dating to at least 2019. Its original membership was predominantly French, while later operations evolved into a franchise-like network with changing operators and affiliates supplying stolen corporate SaaS credentials in exchange for shares of extortion proceeds. ShinyHunters targets technology and cloud-service providers, healthcare organizations, government agencies, transportation businesses, agricultural organizations, food distributors, retailers, and telecommunications companies. Initial-access methods include social engineering, voice phishing, impersonation of IT support personnel to obtain Okta access, abuse of OAuth tokens, and exploitation of internet-facing enterprise applications. In 2026, the operation mass-exploited Oracle PeopleSoft vulnerability CVE-2026-35273 to steal information from dozens of systems across multiple sectors. It also used URL encoding to bypass defensive web application firewall rules. A compromise of the FBI recruitment platform exposed sensitive information concerning more than 5,000 personnel. The operation monetizes stolen personal information and corporate records through underground database distribution and pay-or-leak demands. It uses a public leak site, imposes negotiation deadlines, and publishes stolen information to pressure victims. Its extortion activity has included Neogen and data-center operator CyrusOne. Pressure tactics also include threatening calls and messages, harassment of victims and their relatives, swatting, and fabricated claims of possessing compromising material. ShinyHunters has participated in underground database-sharing communities, including Raid Forums, and operators associated with it have been linked to the Scattered Lapsus$ Hunters coalition.
Qilin, formerly known as Agenda and also tracked as GOLD FEATHER and Water Galura, is a Russian-speaking, financially motivated ransomware-as-a-service operation active since 2022. Its core operators develop ransomware and maintain affiliate infrastructure, negotiation portals, and data-leak services, while affiliates compromise networks, steal data, and deploy encryption payloads. Qilin uses double extortion, combining encryption with threats to publish stolen information. Its targets include healthcare providers, manufacturers, professional-services firms, financial institutions, government entities, and cloud service providers across multiple continents. The June 2024 attack on UK pathology provider Synnovis severely disrupted services at several London NHS hospitals. Qilin's original Go-based ransomware evolved into Rust-based variants, including Qilin.B, supporting Windows, Linux, and VMware ESXi environments. Its configurable lockers support intermittent and percentage-based encryption, selective targeting, and propagation through PsExec and VMware vCenter. Encryption uses AES-256-CTR or ChaCha20, with RSA-4096 protecting encryption key material. Operators compromise backup infrastructure, delete shadow copies, stop backup and security services, and clear event logs to impede recovery and investigation. Affiliates obtain access through phishing, exposed remote-access services, purchased or compromised credentials, brute-force attacks, and exploitation of vulnerable internet-facing systems. Documented activity includes exploitation of Fortinet appliances and CVE-2023-27532 in Veeam Backup & Replication, credential harvesting with Mimikatz and browser-password theft, Active Directory reconnaissance, privilege escalation, and lateral movement using legitimate administrative tools. Data-exfiltration tools include Rclone, WinSCP, and FileZilla. Qilin attacks have also used Killer Ultra, which exploits a vulnerable Zemana driver through bring-your-own-vulnerable-driver techniques to terminate endpoint security processes and maintain startup persistence. Documented affiliates include Devman and Hastalamuerte. The North Korean state-sponsored actor Moonstone Sleet has deployed Qilin ransomware, but that use does not establish state sponsorship or North Korean origin for the Qilin operation itself.
Payload, also known as Payload ransomware and tracked as payload_ransomware, is a financially motivated ransomware and data-extortion operation first identified in February 2026. It targets mid-to-large-sized organizations internationally, including manufacturing, technology, healthcare, telecommunications, financial services, logistics, retail, and professional services. Its country of origin is not established. Payload affiliates obtain initial access through compromised VPN credentials, including access supplied by initial access brokers associated with the FortiBleed campaign against Fortinet FortiGate devices. In an attack against a Middle Eastern manufacturer, Payload obtained domain administrator privileges and abused Active Directory Group Policy Objects linked at the domain root to distribute ransom notes, change desktop wallpapers, deactivate local administrator accounts, and disable Windows Firewall. That operation involved data exfiltration and publication on the dark web without file encryption or deployment of conventional ransomware executables, demonstrating an encryption-less extortion approach alongside its ransomware operations. Payload's ransomware family includes Windows and Linux variants, with the Linux variant targeting VMware ESXi environments. Both use Curve25519 key exchange and ChaCha20 encryption, multithreaded processing, and partial encryption of large files. The ESXi variant enumerates virtual machines, powers them off, and encrypts large virtual disk files. The Windows variant can encrypt local drives and network shares, terminate backup, database, and security services, delete Volume Shadow Copies, disable Event Tracing for Windows, clear event logs, and delete itself. String obfuscation and anti-debugging checks further impede analysis. Encryption and key generation occur locally without requiring an online key-exchange service.
Sandworm is a Russian state-sponsored cyber threat actor associated with the Main Intelligence Directorate (GRU), military Unit 74455. It is also tracked as Sandworm Team, APT44, Voodoo Bear, Seashell Blizzard, IRIDIUM, FROZENBARENTS, TeleBots, BlackEnergy Group, Electrum, Iron Viking, and Blue Echidna. The group conducts destructive and disruptive operations, alongside credential theft, information collection, and data exfiltration. Its documented targets include Ukrainian electricity infrastructure and software providers, Georgian government and non-government organizations, and organizations associated with the 2018 Winter Olympics in South Korea. Sandworm gains access through spearphishing links and malicious Microsoft Office attachments, exploitation of client vulnerabilities, compromised software updates, stolen credentials, and trusted connections between organizations. It compromised the Ukrainian accounting application M.E.Doc to distribute NotPetya through a malicious software update. Its reconnaissance includes vulnerability scanning, employee research, Active Directory enumeration through LDAP, and collection of network diagrams and remote-access information. Credential-harvesting methods include modified Mimikatz tooling, browser-password collection, keylogging, network-traffic interception, and password spraying. The group maintains access through newly created domain accounts, account manipulation, web shells, and backdoored SSH services. It transfers tools through network shares and has distributed Prestige ransomware through Active Directory Group Policy. Its command-and-control infrastructure uses encrypted or encoded communications, proxying, and legitimate services. Defense-evasion behaviors include disabling event logging, deleting attack artifacts, disguising binaries, and executing credential-harvesting tools in memory. Sandworm's destructive operations include NotPetya, Olympic Destroyer, and BlackEnergy's KillDisk component. It has overwritten files and corrupted boot records on industrial systems, maliciously operated electricity breakers using remote administration or industrial-control software, and defaced approximately 15,000 Georgian websites in 2019. It has also stolen internal documents and disseminated sensitive victim information through social media.
APT29 is a Russian state-sponsored cyberespionage group attributed to Russia’s Foreign Intelligence Service (SVR), active since at least 2008. Widely known as Cozy Bear, The Dukes, CozyDuke, Midnight Blizzard, and NOBELIUM, it is also tracked under names including BlueBravo, Cloaked Ursa, and YTTRIUM. Its SolarWinds-related activity has been tracked as UNC2452 and Dark Halo. The group targets government networks, particularly in Europe and NATO member countries, as well as research institutes and think tanks. APT29 gains access through spearphishing links and exploit-bearing attachments, compromised accounts, software supply-chain compromise, and exploitation of internet-facing applications. It compromised the SolarWinds Orion software supply chain to distribute trojanized updates and obtain access to downstream organizations. Its exploitation activity includes vulnerabilities in Citrix, Pulse Secure, FortiGate, Zimbra, Microsoft Exchange, and JetBrains TeamCity, including CVE-2023-42793. It also conducts vulnerability scanning and password-spraying attacks. After compromise, APT29 uses stolen credentials for remote access and lateral movement through SSH, VPNs, RDP, and other remote services. It enumerates systems with AdFind, creates scheduled tasks on remote hosts, and executes commands through shells and encoded PowerShell. Credential-access techniques include requesting Kerberos service tickets for offline cracking and attempting to retrieve Group Managed Service Account passwords. Its toolkit includes Mimikatz, Cobalt Strike, Tor, meek, and SDelete. APT29 collects and exfiltrates sensitive information, including email, and has compressed stolen messages into password-protected archives using 7-Zip. Its defense-evasion practices include making command-and-control hostnames resemble legitimate victim infrastructure and using VPN infrastructure located in victims’ countries. It has also used a backdoor exposing internal remote-access services through Tor to maintain external access.
Conti was a financially motivated, Russia-associated ransomware syndicate that emerged in 2020 and operated a ransomware-as-a-service ecosystem. Also known as the Conti gang, Conti group, and Conti ransomware group, it supplied ransomware and operational guidance to deployers and maintained relationships with initial access brokers, including EXOTIC LILY. Conti attacked organizations internationally, including U.S. healthcare and emergency-service networks, Ireland's Health Service Executive, and Costa Rican government institutions. By February 2022, reported Conti attacks exceeded 1,000. Conti combined network-wide encryption with data theft and threats of public disclosure. Its operators obtained access through spearphishing, compromised remote-access credentials, malware distribution networks, and exploitation of exposed systems. Attack chains involved malware such as TrickBot, Emotet, and IcedID. After entry, operators used Cobalt Strike, Mimikatz, AdFind, and BloodHound for post-exploitation, credential theft, and Active Directory reconnaissance. They exploited vulnerabilities including Zerologon and PrintNightmare to obtain elevated privileges, used password guessing and Kerberoasting, and moved laterally to enable broad ransomware deployment. Legitimate remote-access applications provided persistent access, while Rclone and cloud storage supported data exfiltration. Operators disabled security and backup services and deleted shadow copies to obstruct detection and recovery. The syndicate also sold access to compromised networks beginning in October 2021. Karakurt functioned as an associated data-extortion operation: when Conti encryption was blocked, attackers could demand payment under the Karakurt brand using information already stolen. Leaks of affiliate documentation in 2021 and internal communications and source code in 2022 exposed substantial operational detail. Conti shut down its branded operation in 2022, while former members continued participating in other cybercriminal operations.
LockBit is a financially motivated ransomware-as-a-service (RaaS) operation active under that name since early 2020, with a lineage extending to ABCD ransomware in 2019. Its core operators develop ransomware and maintain affiliate infrastructure, while affiliates compromise organizations, steal information, and deploy encryptors. The operation typically allocates 80% of ransom proceeds to affiliates and 20% to its operators. LockBit became one of the most prolific ransomware operations and was identified by an international joint advisory as the most active ransomware in 2022. Major ransomware generations include LockBit 2.0, also called LockBit Red; LockBit 3.0, or LockBit Black; and LockBit Green, which incorporated encryption code derived from leaked Conti source code. Its tooling includes encryptors for Windows, Linux, and VMware ESXi, with macOS samples also observed. LockBitSupp is the operation's public representative rather than a separate ransomware family or affiliate group. LockBit affiliates use vulnerability exploitation, compromised remote-access credentials, exposed RDP services, phishing, drive-by compromise, and access purchased from initial access brokers. Documented exploitation includes Citrix Bleed (CVE-2023-4966), PaperCut vulnerabilities, and ConnectWise ScreenConnect vulnerabilities. Citrix Bleed campaigns enabled authentication bypass through compromised sessions, persistent access, and lateral movement. The operation has also recruited insiders to provide corporate credentials or infect employer devices. Affiliates use living-off-the-land techniques, legitimate administration tools, StealBit, rclone, and external file-sharing services for post-compromise activity and data exfiltration. LockBit primarily uses double extortion, combining encryption with threats to publish stolen information, and also supports data-theft-only extortion partners. Its leak infrastructure provides victim-specific countdowns, stolen-data samples, negotiation facilities, and paid publication extensions or data access. Defense-evasion capabilities include disabling security software, Safe Mode execution, anti-analysis measures, and tampering with Windows event-channel access permissions; its ransomware can also delete shadow copies. Documented targeting includes Boeing, Portugal's Port of Lisbon Administration, and nonprofit customers exposed through a compromised managed service provider. A publicly leaked LockBit 3.0 builder enabled unrelated actors to generate working encryptors and decryptors, so use of LockBit-derived malware does not by itself establish affiliation with the operation. Law-enforcement disruption and subsequent compromises reduced LockBit's prominence by the first half of 2025.
NoName057(16) is a Russia-linked, pro-Russian hacktivist group that publicly emerged in March 2022. Also known as NoName057, NoName05716, and NNM05716, it primarily conducts politically motivated distributed denial-of-service attacks against countries supporting Ukraine. Danish authorities have identified links between the group and the Russian state. Its campaigns target government and diplomatic services, transportation infrastructure, banks, and health care organizations, seeking service disruption, political pressure, and publicity. The group uses Telegram to announce targets, claim attacks, coordinate activity, and amplify political messaging. Its attack infrastructure has included the Bobik botnet and DDoSia, also called DDosia, a crowdsourced DDoS project linked to the group. Campaigns frequently coincide with diplomatic events and geopolitical tensions. Italian campaigns have targeted ministries, banks, airports, and ports, including attacks associated with Ukrainian President Volodymyr Zelensky’s January 2025 visit to Rome and retaliatory messaging concerning Italian President Sergio Mattarella’s criticism of Russia. Other activity includes attacks against French websites and Danish websites ahead of the 2025 local elections. Beyond DDoS, NoName057(16) has compromised exposed IP cameras belonging to Estonian and Canadian targets. It has collaborated with Zarya and is associated with the pro-Russian group Server Killers, although these relationships do not establish that either group is a subordinate unit. International law enforcement disrupted NoName057(16)’s infrastructure in July 2025 through Operation Eastwood; subsequent activity demonstrates that the group continued operating.
NetRunner is a financially motivated cybercriminal threat actor associated with ransomware, data exfiltration, and extortion operations. Its documented targeting includes organizations in Japan, the United States, and Malaysia, spanning healthcare, marine construction and transportation services, and retail. During 2026, its healthcare activity included targeting providers and healthcare-related service organizations, with an emphasis on stealing sensitive information for extortion. NetRunner demanded $100 million from Nippon Medical School Musashi Kosugi Hospital in Japan in an incident affecting 131,700 people; the ransom was not paid. Other attributed victims include Mid Atlantic Gynecologic Oncology and Pelvic Surgery Associates, Precon Marine Inc, and Main Place Mall. Its country of origin, organizational structure, initial-access methods, and specific malware tooling are not established.
Xuanye Group is a previously unknown threat actor that claimed responsibility for an October 2026 data breach affecting ASOS, a UK-based online fashion retailer. The group used unauthorized push notifications delivered through ASOS’s own mobile application to demand contact from the company and threaten publication of customer data. It maintained a Telegram channel to publicize its claims and communicate its threats. The ASOS intrusion involved impersonating a trusted contact to obtain an employee’s login credentials. Credentials obtained through the compromised account were subsequently used to access third-party platforms containing customer information. ASOS confirmed exposure of customer names, contact details, and certain non-personal account-related information, while stating that payment-card information and customer account passwords were not accessed. The attackers abused customer-facing messaging infrastructure to publicize the incident directly to customers and pressure the retailer. Xuanye Group’s observed activity centers on credential-based intrusion and threatened data disclosure rather than confirmed ransomware deployment. Its geographic origin, organizational structure, and relationship to other threat actors are not established.
APT10, also known as menuPass, Stone Panda, Cicada, POTASSIUM, Purple Typhoon, Red Apollo, and Bronze Riverside, is a China-based, Chinese state-backed threat actor associated with cyberespionage operations. It targets government organizations, cloud-computing managed service providers (MSPs), and their customer networks worldwide. Compromising service providers allows the group to reach downstream customers by abusing valid accounts shared between provider and client environments. The group has also targeted SAP applications. APT10 obtains access through spearphishing emails containing malicious Microsoft Office documents or executables disguised as documents, as well as exploitation of vulnerable internet-facing services. It has exploited Pulse Secure VPN vulnerabilities to hijack sessions and used tools targeting Zerologon, CVE-2020-1472, against Windows domain infrastructure. Its toolkit includes PlugX and QuasarRAT, alongside modified or repurposed tools such as Impacket, Mimikatz, and pwdump. Within compromised environments, APT10 enumerates network address ranges and remote systems using scripts and Windows network-discovery utilities, including commands issued through PlugX implants. It dumps Active Directory credentials using Ntdsutil and moves laterally through RDP, shared valid accounts, and remote command execution. Execution methods include command-line interfaces, reverse shells, malicious Office macros, Windows Management Instrumentation, and Task Scheduler. The group conceals malicious activity through document masquerading, misleading file extensions, and Base64 or single-byte XOR string obfuscation. It prepares collected files for exfiltration using TAR and RAR compression.
APT40, also known as Leviathan, is a Chinese government-backed cyberespionage actor targeting organizations internationally, including U.S. engineering and maritime industries. Other aliases include Bronze Mohawk, Feverdream, Gadolinium, Gingham Typhoon, JJDoor, Kryptonite Panda, Mudcarp, Red Ladon, TEMP.Jumper, and TEMP.Periscope. The group has operated through the front company Hainan Xiandun, which recruited English-language graduates for espionage-related work. APT40 gains initial access through spearphishing links and malicious Office attachments, compromised accounts, and external remote services such as VPNs. Its phishing operations use lookalike domains, stolen branding, and compromised email accounts to impersonate trusted senders. It has successfully targeted internet-facing routers and VPN infrastructure and uses web shells both to establish footholds and maintain persistence. Credential theft includes password-hash dumping with ProcDump, Windows Credential Editor, and HOMEFRY; stolen RDP credentials support lateral movement. The group's tooling includes BADFLICK, a backdoor providing reverse-shell access, alongside JavaScript and XML-based JavaScript scriptlets for execution. Defense-evasion techniques include Base64 encoding, gzip compression, compromised-account abuse, and multi-hop proxies that conceal traffic origins. In late August 2023, APT40 targeted Papua New Guinea with phishing archives exploiting WinRAR vulnerability CVE-2023-38831. That operation used the XOR-encoded ISLANDSTAGER loader, registry-based persistence, and the BOXRAT backdoor, which communicates through the Dropbox API.
APT28 is a Russian military cyberespionage group attributed to the Main Intelligence Directorate (GRU), specifically the 85th Main Special Service Center, military unit 26165. Active since at least 2004, it is also known as Fancy Bear, Forest Blizzard, STRONTIUM, Sednit, Sofacy, Pawn Storm, Fighting Ursa, SNAKEMACKEREL, Swallowtail, Group 74, Tsar Team, and Threat Group-4127. Its targets include governments, military organizations, political organizations, anti-doping bodies, and chemical-weapons institutions. Espionage is its principal activity, although it has also conducted operations supporting political interference, including compromises of U.S. Democratic Party organizations and the Hillary Clinton campaign in 2016. Sandworm Team, associated with the separate GRU unit 74455, assisted some operations; it is not an APT28 subgroup. APT28 obtains access through credential-harvesting spearphishing, malicious Office documents and archives, distributed brute-force and password-spraying attacks, exploitation of public-facing services, and default credentials on network-connected devices. It conducts large-scale vulnerability scanning and uses Tor, commercial VPN services, proxies, and compromised infrastructure to obscure operations. Post-compromise techniques include Windows privilege-escalation exploits, credential dumping with Mimikatz and custom tools, Active Directory database extraction, keylogging, OAuth token abuse, pass-the-hash, and SMB exploitation for lateral movement. The group collects email, documents, screenshots, and information from network shares and repositories, stages data in password-protected archives, and exfiltrates through HTTPS and cloud services. Persistence mechanisms include web shells, startup and registry modifications, COM hijacking, bootkits, and the LoJax UEFI rootkit. USB-based tooling supports collection and transfer of information from air-gapped systems. Associated malware includes CHOPSTICK, X-Agent, XTunnel, JHUHUGIT, Downdelph, and USBStealer. Defense-evasion practices include payload obfuscation, utility renaming, timestomping, event-log clearing, and artifact deletion. APT28 also conducted a distributed denial-of-service attack against the World Anti-Doping Agency in 2016.
APT38 is a North Korean state-sponsored threat actor active since at least 2014, specializing in financially motivated operations against banks and other financial institutions. Associated tracking names include Bluenoroff, BlueNoroff, Stardust Chollima, and Nickel Gladstone. It shares tools and malware with other North Korean actors, including Lazarus Group and TEMP.Hermit, but is distinguished by its focus on financial theft. Its operations include fraudulent SWIFT transfers, bank fraud, cryptocurrency-exchange intrusions, and cryptocurrency theft. APT38 conducts preparatory reconnaissance of target personnel, infrastructure, and third-party vendors, particularly those connected to SWIFT systems. Documented initial-access methods include watering-hole attacks and exploitation of vulnerable Linux servers. After gaining access, it scans compromised environments, performs internal reconnaissance, and moves toward financial transaction infrastructure. It installs backdoors and reconnaissance malware on SWIFT servers and uses specialized malware to insert fraudulent transactions and manipulate financial data. Its tooling includes Mimikatz for credential theft and NACHOCHEESE for tunneling and remote shell access. Other documented behaviors include keylogging, clipboard collection, command-shell execution, and persistence through Windows services and scheduled tasks. APT38 uses log deletion, file deletion, software packing, and disk wiping to conceal activity and obstruct investigation. It has also deployed Hermes ransomware to encrypt files with AES-256, with encryption and destructive activity used to hinder detection and recovery following financial theft.
Volt Typhoon is a People's Republic of China state-sponsored threat actor active since at least mid-2021 and primarily associated with intrusions into U.S. critical infrastructure. It is also tracked as Bronze Silhouette, DEV-0391, Storm-0391, Insidious Taurus, UNC3236, and Vanguard Panda. Dragos tracks an overlapping activity cluster as VOLTZITE. Targeted sectors include electricity, water, energy, telecommunications, rail transportation, and aviation. Its strategic mission centers on establishing persistent access that could enable disruptive or destructive operations during a major crisis or conflict, rather than conventional intelligence collection alone. The group emphasizes stealth, hands-on-keyboard operations, and living-off-the-land techniques. It abuses legitimate administrative utilities, including PowerShell, WMIC, ntdsutil, and netsh, for discovery, credential collection, remote execution, and traffic forwarding. Documented initial-access techniques include exploitation of CVE-2021-40539 in ManageEngine ADSelfService Plus and CVE-2021-27860 in FatPipe products. Credential-access activity includes copying Active Directory databases and associated registry data, searching for stored credentials, and conducting password spraying and brute-force attempts. Webshells support persistence and exfiltration, while Impacket and native remote-management tools facilitate movement within compromised environments. Volt Typhoon routes malicious traffic through compromised small-office/home-office routers and other edge devices, including infrastructure associated with the KV botnet, to obscure its origin and make connections resemble local ISP traffic. It also uses Earthworm and customized Fast Reverse Proxy tooling and selectively clears logs to conceal intrusions. The overlapping VOLTZITE cluster maintains access in U.S. electric and telecommunications environments and collects grid topology, geographic information system data, SCADA configurations, and operational documentation. Its access to engineering-workstation configuration and alarm data supports investigation of process-shutdown conditions and preparation for future disruption.
Lazarus Group is a North Korean state-sponsored threat actor associated with financially motivated cybercrime, espionage, and destructive operations. Its activities include cryptocurrency theft, attacks against financial institutions, and compromise of software supply chains. Associated tracking names include HIDDEN COBRA, ZINC, Diamond Sleet, Labyrinth Chollima, Nickel Academy, Black Artemis, Guardians of Peace, APT-C-26, Selective Pisces, TA404, and TEMP.Hermit; these designations do not necessarily represent identical operational scopes. APT38 is a separately tracked North Korean financial threat actor whose malware arsenal overlaps with Lazarus and TEMP.Hermit. Lazarus has been associated with the destructive 2014 Sony Pictures Entertainment attack, the 2016 Bangladesh Bank theft involving fraudulent SWIFT transactions, and the 2017 WannaCry ransomware outbreak. More recent targeting includes cryptocurrency companies, cryptocurrency engineers, and aerospace professionals, with individuals targeted to obtain access to their employers’ networks. The group compromised the 3CX software supply chain to distribute trojanized Windows and macOS applications, selectively deploying the modular Gopuram backdoor to cryptocurrency-company victims. Its techniques include spearphishing with malicious Microsoft Word attachments, command-shell execution, reflective DLL injection, and persistence through Windows services and scheduled tasks. Lazarus malware propagates using RDP and attempts lateral movement through Windows shares using generated administrative usernames and weak passwords. Defense evasion includes payload encryption and encoding, malicious templates disguised as images, timestomping, and deletion of malware artifacts. Lazarus uses sophisticated kernel-level evasion. FudModule has exploited CVE-2021-21551 in a legitimately signed Dell driver through bring-your-own-vulnerable-driver techniques to interfere with security callbacks, monitoring, and forensic tracing. The group also exploited the Windows vulnerability CVE-2024-38193 as a zero-day and used FudModule to conceal its activity.