Threat Actors

Threat Actors

Threat Actors

Explore an extensive collection of the most popular Threat Actors.

Search...

Search...

Top 10 Threat Actors

Top 10 Threat Actors

Top 10 Threat Actors

faq

Frequently
asked questions

Frequently
asked questions

Frequently
asked questions

Why Does Threat Actor Profiling Matter Today?

In 2026, with AI-assisted attacks, complex supply chains, and rampant ransomware campaigns, understanding who is behind cyber threats is crucial to navigating the threat landscape and anticipating evolving and emerging threats. Profiling shifts cybersecurity from reactive to proactive, enabling teams to pre-position defenses and allocate resources where risk is highest. It also strengthens threat intelligence by connecting activity to specific threat actors and improving response during a security incident. Modern profiling also accounts for identity-based attacks against both human and non-human identities. In practice, nation state actors and each APT group are often linked to particular countries, while cybercriminals are typically financially motivated and may target any sector with weak defenses.

Who Are the Main Types of Threat Actors?

  • Nation-State APT Groups: These threat actor profiles often describe a threat group active since at least a known date, conducting espionage, infiltrating critical infrastructure, and carrying out targeted attacks tied to intellectual property theft. They may also target intellectual property and sometimes launch destructive operations.


  • Cybercriminal Organizations: Focus on financial gain through ransomware, extortion, and fraud. Some operate ransomware as a service models, conduct financially motivated operations, and use stolen data for extortion after cyber attacks.


  • Hacktivists: Driven by ideological or political motives aiming to disrupt systems or embarrass targets.


  • Low-Sophistication Actors: Script kiddies often rely on publicly available tools and pre-existing automated tooling to hack.


  • Insiders: Malicious or compromised individuals with trusted access inside organizations, and they may leak proprietary data or exploit system vulnerabilities.

How Does Profiling Help Security Teams?

  • Predictive Security Intelligence: Focus defenses on the most likely adversaries and attack vectors by mapping adversary initial access patterns so teams can anticipate phishing, credential abuse, exploitation, and supply chain attacks. Profiling also helps flag tactics like Agent Serpens using sophisticated social engineering techniques and Evasive Serpens using macro-enabled documents for initial access. Tracking known campaigns by specific threat actors also supports faster attribution and more accurate detection across targeted organizations.


  • Resource Optimization: Prioritize patching and monitoring for likely targets such as government entities, government agencies, financial institutions, and industrial control systems when profiling shows they are common focuses. Alloy Taurus is known for primarily targeting telecommunications companies, also hitting financial institutions, and exploiting vulnerabilities in internet-facing applications. Cloaked Ursa is tied to russia's foreign intelligence service and targets government entities and critical infrastructure, while Fighting Ursa has compromised military-related organizations since 2016. Jumpy Pisces has targeted South Korean entities since 2013, Mocking Draco has impacted South Asian sectors, and some campaigns focus on the Middle East. Bling Libra targets telecommunications and financial services, uses infostealer malware for credential theft, and Slow Pisces stole over $1 billion in cryptocurrency in 2023. Some state-linked groups are associated with the chinese government, may show significant interest in regional or ethnic targets, and in some cases also conducts financially motivated operations. The Democratic National Committee and the Democratic Congressional Campaign Committee have both been examples of election-related espionage against targeted organizations.

Why does the same threat actor have so many different names?

Each security vendor maintains its own tracking system, so a single threat actor often accumulates multiple aliases over time. CrowdStrike uses animal-themed names, Microsoft uses weather-themed names, Mandiant relies on APT and FIN designations, and other vendors follow their own conventions. This is especially common with well-known nation state actors and major cyber espionage groups that have been active since at least several years across multiple campaigns. The best threat actor profiles list all known aliases to help analysts connect research from different sources.

How do analysts attribute an attack to a specific threat actor?

Attribution is based on layers of evidence rather than a single indicator. Analysts examine infrastructure, malware families, attack vectors, victimology, timing, and operational behavior. They also compare activity against previous cyber operations, strategic web compromises, and documented campaigns linked to specific threat actors. Because sophisticated groups can imitate one another, attribution is usually presented with varying levels of confidence rather than absolute certainty.

Can attribution be wrong or intentionally misleading?

Yes. Threat actors frequently attempt to disguise their identity by reusing publicly available tools, adopting another group’s techniques, or routing activity through shared infrastructure. False flags are a common challenge in threat intelligence, particularly when investigating cyber threats involving nation state actors or highly capable criminal organizations. Strong attribution relies on multiple independent sources of evidence rather than a single indicator.

What’s the difference between a threat actor, a campaign, and malware?

A threat actor is the individual, group, or organization conducting the activity. A campaign refers to a specific operation or set of operations conducted over a period of time. Malware is simply one of the tools used during those operations. A threat group may run separate campaigns focused on financial gain, intellectual property theft, ransomware deployment, or cyber espionage against government entities and critical infrastructure organizations.

How often do threat actors change their infrastructure and tactics?

Most active groups rotate infrastructure regularly. Domains, IP addresses, certificates, hosting providers, and malware delivery mechanisms often change after a security incident, infrastructure exposure, or loss of initial access. Sophisticated actors continuously evolve their techniques to evade detection, making long-term infrastructure tracking far more valuable than relying on static indicators alone.

How do I figure out which threat actors are likely to target my organization?

Start by evaluating your industry, geographic footprint, and the information or systems you manage. Different actors focus on different targets. Some groups specialize in targeting government networks, while others focus on financial institutions, legal services, managed service providers, defense organizations, investment firms, healthcare providers, or critical infrastructure. Reviewing threat actor profiles associated with your sector is often the fastest way to understand your exposure.

Should small and mid-sized companies worry about nation-state actors?

In most cases, financially motivated operations pose a greater risk than direct nation-state targeting. However, smaller organizations can still become victims through supply chain attacks, trusted partner relationships, or access to larger targets. Organizations supporting government agencies, telecommunications providers, defense organizations, or strategic industries may attract attention from nation state actors even if they are not the primary target.

What are TTPs, and how does MITRE ATT&CK fit in?

TTPs refer to tactics, techniques, and procedures used during cyber operations. MITRE ATT&CK provides a common framework for documenting and analyzing those behaviors. Security teams use ATT&CK to map attack vectors, understand how specific threat actors operate, and identify gaps in detection coverage. Comparing actor profiles through ATT&CK often reveals patterns that are difficult to spot through indicators alone.

Can threat actors actually be caught or shut down?

Some of the less well-connected criminal groups have been knocked back by law enforcement action, either by getting their people arrested, seizing their infrastructure and other resources. The ones who are only in it for the cash are generally more vulnerable to that sort of thing. Even when they do get knocked back, though, it's not always the end of the world. They can just regroup, rebrand and carry on as before after a bit of a gap.

Where does threat intelligence about actors come from?

Well, there are loads of different sources, including people scanning for new infrastructure, analysing malware to see what other actors are up to, dealing with the aftermath of security breaches, running honeypots to see if anyone is interested in them, reading the reports from industry associations, looking at government advice - the list goes on. Analysts take a bunch of different observations from all these places and compare them to figure out what's going on with the different threat actors - what they're up to, how they're operating and what they're after. And the best intelligence is usually the result of mixing and matching technical evidence with lots of observation over a long period.

Find the threat
before it finds you

Hunt adversary infrastructure in real time. Surface C2 servers, enrich IOCs,
and map attacker activity at scale with our unified threat hunting platform.

Find the threat
before it finds you

Hunt adversary infrastructure in real time. Surface C2 servers, enrich IOCs,
and map attacker activity at scale with our unified threat hunting platform.

Find the threat
before it finds you

Hunt adversary infrastructure in real time. Surface C2 servers, enrich IOCs,
and map attacker activity at scale with our unified threat hunting platform.