Threat Actor Database

Know Your
Enemy

Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.

500+Threat Actors
100K+IOC Indicators
10K+ATT&CK Techniques

Top Threat Actors

1,120

Lazarus Group

APT

APT 38 · APT-C-26 · APT38 · ATK117

#1
2.3MAudience
87News
47kIOCs

Target Countries

United Arab EmiratesAustraliaBangladeshBelgium

Target Sectors

Food ManufacturingReal EstateHospitalsAir Transportation

Associated Malware

win.bistromathwin.brambulwin.buffetlinewin.touchmove

Related CVEs

CVE-2025-9491CVE-2025-9074CVE-2025-8088CVE-2025-7775

ATT&CK IDs

T1404 - Exploit OS VulnerabilityT1220T1072 - Software Deployment ToolsT1070 - Indicator Removal on Host
View Details

GOLD SOUTHFIELD

APT
#2
2.2MAudience
1News
11kIOCs

Target Countries

United States

Target Sectors

Performing Arts CompaniesNational SecurityHealthCare & Social AssistanceInternet Publishing

Associated Malware

Related CVEs

CVE-2018-0802

ATT&CK IDs

T1071 - Application Layer ProtocolT1195.002T1553.002 - Code SigningT1557 - Man-in-the-Middle
View Details

SideCopy

APT
#3
1.6MAudience
7News
85IOCs

Target Countries

HungaryIndiaUnited States

Target Sectors

National Security and International AffairsData Processing, Hosting, and Related ServicesComputer Systems Design and Related ServicesAdvertising Agencies

Associated Malware

Xena

Related CVEs

CVE-2024-3094CVE-2024-21893CVE-2024-21887CVE-2023-46805

ATT&CK IDs

T1559T1547.013 - XDG Autostart EntriesT1185T1587.001 - Malware
View Details

Safe

APT
#4
1.5MAudience
0News
1kIOCs

Target Countries

United Arab EmiratesAustraliaBangladeshBulgaria

Target Sectors

Real EstateHospitalsAir TransportationConstruction

Associated Malware

Related CVEs

CVE-2022-23943CVE-2021-44790CVE-2021-23017CVE-2019-12521

ATT&CK IDs

T1195 - Supply Chain CompromiseT1140 - Deobfuscate/Decode Files or InformationT1199 - Trusted RelationshipT1003 - OS Credential Dumping
View Details

Top Ransomware Groups

402

Team Underground

Ransomware

Underground · TeamUnderground

#1
10.9MAudience
0News
42IOCs

Target Countries

United Arab EmiratesAustraliaBrazilCanada

Target Sectors

Construction of BuildingsOther Information ServicesHospitalsManufacturing

Associated Malware

Related CVEs

CVE-2023-36884

ATT&CK IDs

T1021.002T1059.003T1018T1105
View Details

el dorado

Ransomware

El-Dorado · Global · BlackLock · Eldorado

#2
4.1MAudience
62News
9kIOCs

Target Countries

United Arab EmiratesArgentinaAustraliaAruba

Target Sectors

Construction of BuildingsOther Information ServicesSoftware PublishersReal Estate

Associated Malware

Related CVEs

CVE-2021-21974

ATT&CK IDs

View Details

payload

Ransomware
#3
4.0MAudience
77News
23kIOCs

Target Countries

United Arab EmiratesAustriaAustraliaBahrain

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware Publishers

Associated Malware

Related CVEs

CVE-2025-59287

ATT&CK IDs

View Details

VoidCrypt

Ransomware

Chaos · Dark · Void

#4
3.4MAudience
0News
18kIOCs

Target Countries

AustraliaCanadaGermanyUnited Kingdom

Target Sectors

Construction of BuildingsSoftware PublishersEnterprises & HoldingAir Transportation

Associated Malware

Related CVEs

ATT&CK IDs

View Details

SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.

F.A.Q.

Common questions about threat actors and APT groups