Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.
500+ Threat Actors
100K+ IOC Indicators
10K+ ATT&CK Techniques
Target Country All Countries
Lazarus Group APT APT 38 · APT-C-26 · APT38 · ATK117
Target Sectors
Hospitals Public Administration Internet Publishing Space & Defense +58 Associated Malware
win.bookcodesrat win.cheesetray win.deltas osx.yort+82 Related CVEs
CVE-2026-68820 CVE-2026-59310 CVE-2026-58644 CVE-2026-56164 +270 ATT&CK IDs
T1588.002 - Tool T1497.001 - System Checks T1556.001 - Domain Controller Authentication T1585.001 +553 Related CVEs
CVE-2025-3248 CVE-2021-29441 ATT&CK IDs
T1190 - Exploit Public-Facing Application T1059.006 - Python T1203 - Exploitation for Client Execution T1053.003 +1
TeamPcp APT ShellForce · Persy_PCP · CipherForce · PCPcat
Target Sectors
Public Administration Outpatient Care Centers Motion Picture and Video Production Data Processing, Hosting, and Related Services +10 Associated Malware
CanisterWormRelated CVEs
CVE-2026-60004 CVE-2026-54316 CVE-2026-48027 CVE-2026-45321 +11 ATT&CK IDs
T1585.001 T1078.004 - Cloud Accounts T1567.002 - Exfiltration to Cloud Storage T1543.002 - Systemd Service +138
NoName057 APT 05716nnm · Nnm05716 · NoName057(16) · NoName05716
Target Sectors
Food Manufacturing Other Information Services Monetary Authorities-Central Bank Credit Unions +119 Associated Malware
blacknix_rat TINY Smoke Loader backnet+57 Related CVEs
CVE-2026-20245 CVE-2026-20182 CVE-2026-20127 CVE-2025-64669 +16 ATT&CK IDs
T1546.015 T1090 - Proxy Use T1504 T1123 +223 Target Sectors
Construction of Buildings Food Manufacturing Other Information Services Software Publishers +193 Related CVEs
CVE-2026-62145 CVE-2026-62144 CVE-2026-50752 CVE-2026-50751 +41 ATT&CK IDs
T1486 T1490 T1078 T1071.001 +1
thegentlemen Ransomware The Gentlemen Ransomware · the gentlemen
Target Sectors
Construction of Buildings Food Manufacturing Other Information Services Rail Transportation +155 Related CVEs
CVE-2025-7771 CVE-2025-33073 CVE-2025-32433 CVE-2024-55591 +2 ATT&CK IDs
T1190 T1078 T1087 T1046 +4
akira Ransomware Storm-1567 · GOLD SAHARA · PUNK SPIDER
Target Sectors
Construction of Buildings Food Manufacturing Other Information Services Rail Transportation +174 Associated Malware
Mimikatz win.orcus_rat osx.amos win.tofsee+7 Related CVEs
CVE-2025-9242 CVE-2025-62215 CVE-2025-40605 CVE-2025-40604 +30 ATT&CK IDs
T1011 - Exfiltration Over Other Network Medium T1112 - Modify Registry T1657 T1133 +64
shinyhunters Ransomware UNC6040 · Scattered Lapsus$ Hunters (SLH) · ShinyCorp
Target Sectors
Food Manufacturing Other Information Services Credit Unions Rail Transportation +97 Related CVEs
CVE-2026-35273 CVE-2025-61884 CVE-2025-61882 CVE-2025-55234 +16 ATT&CK IDs
T1210 T1078.004 T1573 T1036 +60 SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.
F.A.Q. Common questions about threat actors and APT groups
What is the Threat Actor Intelligence database? The SOCRadar Threat Actor Intelligence database is a free, continuously updated repository of profiles for nation-state groups, cybercriminal organizations, ransomware gangs, hacktivists, and advanced persistent threat (APT) actors. Each profile aggregates intelligence from open-source research, dark web monitoring, and SOCRadar's proprietary telemetry to give security teams a comprehensive view of who is operating in the current threat landscape.
What information is included in a threat actor profile? Each threat actor profile includes: known aliases and group names, country of origin or suspected attribution, motivation (financial, espionage, ideological, destructive), active since date, targeted industries and geographies, preferred attack techniques mapped to MITRE ATT&CK, malware families and tools used, associated campaigns, recent activity timeline, and key indicators of compromise (IOCs). Ransomware group profiles additionally include confirmed victim counts and leak site details.
How is threat actor attribution determined? Attribution is based on multiple convergent evidence sources: shared malware code and tooling, infrastructure overlaps (shared IPs, domains, hosting providers), operational patterns and working hours, language artifacts in malware samples, target selection consistency, and dark web communications. SOCRadar clearly distinguishes between high-confidence attribution (multiple corroborating sources) and low-confidence attribution (circumstantial evidence), following industry-standard intelligence assessment practices.
How can I use threat actor intelligence to protect my organization? Identify which threat actors target your industry and geography, then use their known TTPs (tactics, techniques, and procedures) to assess your defensive coverage. If an actor known to target your sector uses specific attack vectors (spear-phishing, VPN exploitation, supply chain compromise), you can prioritize defenses accordingly. Threat actor IOCs can be loaded into SIEM, EDR, and firewall blocklists for proactive detection. During incident response, actor profiles help predict attacker behavior and lateral movement patterns.
What is the difference between APT groups and cybercriminal groups? APT (Advanced Persistent Threat) groups are typically state-sponsored or state-affiliated actors whose primary motivation is espionage, intellectual property theft, or strategic disruption. They operate with significant resources, sophisticated tooling, and long dwell times. Cybercriminal groups are primarily financially motivated — ransomware, fraud, credential theft, and cryptomining. The distinction matters for response: APT intrusions often require a full forensic investigation and potential law enforcement engagement, while criminal incidents typically follow faster remediation and recovery patterns.