Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.
500+ Threat Actors
100K+ IOC Indicators
10K+ ATT&CK Techniques
Target Country All Countries
Lazarus Group APT APT 38 · APT-C-26 · APT38 · ATK117
Target Sectors
Finance Public Administration Hospitals Computer Design & Services +58 Related CVEs
CVE-2026-58644 CVE-2026-56164 CVE-2026-50522 CVE-2026-45659 +263 ATT&CK IDs
T1598 T1591.002 - Business Relationships T1221 - Template Injection T1608.002 +548 Related CVEs
CVE-2025-3248 CVE-2021-29441 ATT&CK IDs
T1190 - Exploit Public-Facing Application T1059.006 - Python T1203 - Exploitation for Client Execution T1053.003 +1
NoName057 APT 05716nnm · Nnm05716 · NoName057(16) · NoName05716
Target Sectors
Food Manufacturing Other Information Services Monetary Authorities-Central Bank Credit Unions +113 Associated Malware
Loki Bot Revenge RAT graftor backnet+58 Related CVEs
CVE-2026-20245 CVE-2026-20182 CVE-2026-20127 CVE-2025-64669 +16 ATT&CK IDs
T1055 - Process Injection T1450 - Exploit SS7 to Track Device Location T1003 T1573 - Encrypted Channel +223
SCATTERED SPIDER APT 0ktapus · DEV-0971 · Muddled Libra · Octo Tempest
Target Sectors
Hospitals Accommodation Air Transportation Public Administration +55 Related CVEs
CVE-2025-6558 CVE-2025-6554 CVE-2025-61884 CVE-2025-61882 +69 ATT&CK IDs
T1598 T1591.002 - Business Relationships T1583 - Acquire Infrastructure T1136.001 +341 Target Sectors
Construction of Buildings Food Manufacturing Other Information Services Software Publishers +191 Related CVEs
CVE-2026-50752 CVE-2026-50751 CVE-2026-0257 CVE-2025-5777 +35 ATT&CK IDs
T1486 T1490 T1078 T1071.001 +1
thegentlemen Ransomware The Gentlemen Ransomware · the gentlemen
Target Sectors
Construction of Buildings Food Manufacturing Other Information Services Rail Transportation +152 Related CVEs
CVE-2025-7771 CVE-2025-33073 CVE-2025-32433 CVE-2024-55591 +2 ATT&CK IDs
T1190 T1078 T1087 T1046 +4
shinyhunters Ransomware UNC6040 · Scattered Lapsus$ Hunters (SLH) · ShinyCorp
Target Sectors
Food Manufacturing Other Information Services Credit Unions Rail Transportation +96 Related CVEs
CVE-2026-35273 CVE-2025-61884 CVE-2025-61882 CVE-2025-55234 +16 ATT&CK IDs
T1560 T1587 T1105 T1530 +60
DragonForce Ransomware Water Tambanakua
Target Sectors
Construction of Buildings Food Manufacturing Other Information Services Monetary Authorities-Central Bank +135 Related CVEs
CVE-2025-6264 CVE-2025-61155 CVE-2025-59287 CVE-2025-47176 +22 ATT&CK IDs
T1071.001 T1499 T1569.002 SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.
F.A.Q. Common questions about threat actors and APT groups
What is the Threat Actor Intelligence database? The SOCRadar Threat Actor Intelligence database is a free, continuously updated repository of profiles for nation-state groups, cybercriminal organizations, ransomware gangs, hacktivists, and advanced persistent threat (APT) actors. Each profile aggregates intelligence from open-source research, dark web monitoring, and SOCRadar's proprietary telemetry to give security teams a comprehensive view of who is operating in the current threat landscape.
What information is included in a threat actor profile? Each threat actor profile includes: known aliases and group names, country of origin or suspected attribution, motivation (financial, espionage, ideological, destructive), active since date, targeted industries and geographies, preferred attack techniques mapped to MITRE ATT&CK, malware families and tools used, associated campaigns, recent activity timeline, and key indicators of compromise (IOCs). Ransomware group profiles additionally include confirmed victim counts and leak site details.
How is threat actor attribution determined? Attribution is based on multiple convergent evidence sources: shared malware code and tooling, infrastructure overlaps (shared IPs, domains, hosting providers), operational patterns and working hours, language artifacts in malware samples, target selection consistency, and dark web communications. SOCRadar clearly distinguishes between high-confidence attribution (multiple corroborating sources) and low-confidence attribution (circumstantial evidence), following industry-standard intelligence assessment practices.
How can I use threat actor intelligence to protect my organization? Identify which threat actors target your industry and geography, then use their known TTPs (tactics, techniques, and procedures) to assess your defensive coverage. If an actor known to target your sector uses specific attack vectors (spear-phishing, VPN exploitation, supply chain compromise), you can prioritize defenses accordingly. Threat actor IOCs can be loaded into SIEM, EDR, and firewall blocklists for proactive detection. During incident response, actor profiles help predict attacker behavior and lateral movement patterns.
What is the difference between APT groups and cybercriminal groups? APT (Advanced Persistent Threat) groups are typically state-sponsored or state-affiliated actors whose primary motivation is espionage, intellectual property theft, or strategic disruption. They operate with significant resources, sophisticated tooling, and long dwell times. Cybercriminal groups are primarily financially motivated — ransomware, fraud, credential theft, and cryptomining. The distinction matters for response: APT intrusions often require a full forensic investigation and potential law enforcement engagement, while criminal incidents typically follow faster remediation and recovery patterns.