Threat Actor Database

Know Your
Enemy

Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.

500+Threat Actors
100K+IOC Indicators
10K+ATT&CK Techniques

Top Threat Actors

1,183

Lazarus Group

APT

APT 38 · APT-C-26 · APT38 · ATK117

#1
1178.9MAudience
9kNews
41kIOCs

Target Countries

United Arab EmiratesAustraliaBangladeshBelgium

Target Sectors

HospitalsPublic AdministrationInternet PublishingSpace & Defense

Associated Malware

win.bookcodesratwin.cheesetraywin.deltasosx.yort

Related CVEs

CVE-2026-68820CVE-2026-59310CVE-2026-58644CVE-2026-56164

ATT&CK IDs

T1588.002 - ToolT1497.001 - System ChecksT1556.001 - Domain Controller AuthenticationT1585.001
View Details

JadePuffer

APT
#2
601.1MAudience
615News
7IOCs

Target Countries

Target Sectors

Associated Malware

Related CVEs

CVE-2025-3248CVE-2021-29441

ATT&CK IDs

T1190 - Exploit Public-Facing ApplicationT1059.006 - PythonT1203 - Exploitation for Client ExecutionT1053.003
View Details

TeamPcp

APT

ShellForce · Persy_PCP · CipherForce · PCPcat

#3
589.6MAudience
2kNews
497IOCs

Target Countries

AustraliaGermanyFranceIndonesia

Target Sectors

Public AdministrationOutpatient Care CentersMotion Picture and Video ProductionData Processing, Hosting, and Related Services

Associated Malware

CanisterWorm

Related CVEs

CVE-2026-60004CVE-2026-54316CVE-2026-48027CVE-2026-45321

ATT&CK IDs

T1585.001T1078.004 - Cloud AccountsT1567.002 - Exfiltration to Cloud StorageT1543.002 - Systemd Service
View Details

NoName057

APT

05716nnm · Nnm05716 · NoName057(16) · NoName05716

#4
547.8MAudience
5kNews
31kIOCs

Target Countries

United Arab EmiratesArmeniaArgentinaAustria

Target Sectors

Food ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit Unions

Associated Malware

blacknix_ratTINYSmoke Loaderbacknet

Related CVEs

CVE-2026-20245CVE-2026-20182CVE-2026-20127CVE-2025-64669

ATT&CK IDs

T1546.015T1090 - Proxy UseT1504T1123
View Details

Top Ransomware Groups

442

Qilin

Ransomware

agenda

#1
3304.5MAudience
24kNews
3kIOCs

Target Countries

United Arab EmiratesAlbaniaAngolaArgentina

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware Publishers

Associated Malware

Qilin

Related CVEs

CVE-2026-62145CVE-2026-62144CVE-2026-50752CVE-2026-50751

ATT&CK IDs

T1486T1490T1078T1071.001
View Details

thegentlemen

Ransomware

The Gentlemen Ransomware · the gentlemen

#2
1987.8MAudience
11kNews
213IOCs

Target Countries

United Arab EmiratesArgentinaAustriaAustralia

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesRail Transportation

Associated Malware

Related CVEs

CVE-2025-7771CVE-2025-33073CVE-2025-32433CVE-2024-55591

ATT&CK IDs

T1190T1078T1087T1046
View Details

akira

Ransomware

Storm-1567 · GOLD SAHARA · PUNK SPIDER

#3
1210.0MAudience
17kNews
4kIOCs

Target Countries

AndorraUnited Arab EmiratesArgentinaAustria

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesRail Transportation

Associated Malware

Mimikatzwin.orcus_ratosx.amoswin.tofsee

Related CVEs

CVE-2025-9242CVE-2025-62215CVE-2025-40605CVE-2025-40604

ATT&CK IDs

T1011 - Exfiltration Over Other Network MediumT1112 - Modify RegistryT1657T1133
View Details

shinyhunters

Ransomware

UNC6040 · Scattered Lapsus$ Hunters (SLH) · ShinyCorp

#4
1175.9MAudience
8kNews
718IOCs

Target Countries

ArgentinaAustriaAustraliaBelgium

Target Sectors

Food ManufacturingOther Information ServicesCredit UnionsRail Transportation

Associated Malware

Related CVEs

CVE-2026-35273CVE-2025-61884CVE-2025-61882CVE-2025-55234

ATT&CK IDs

T1210T1078.004T1573T1036
View Details

SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.

F.A.Q.

Common questions about threat actors and APT groups