Threat Actor Database

Know Your
Enemy

Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.

500+Threat Actors
100K+IOC Indicators
10K+ATT&CK Techniques

Top Threat Actors

1,146

SCATTERED SPIDER

APT

0ktapus · DEV-0971 · Muddled Libra · Octo Tempest

#1
296.6MAudience
6kNews
488IOCs

Target Countries

AustraliaBelgiumColombiaUnited Kingdom

Target Sectors

HospitalsAccommodationAir TransportationPublic Administration

Associated Malware

WarzoneRATRaccoon Stealerzhmimikatz

Related CVEs

CVE-2025-6558CVE-2025-6554CVE-2025-61884CVE-2025-61882

ATT&CK IDs

T1213.005T1047T1595.003T1484.002
View Details

NoName057

APT

05716nnm · Nnm05716 · NoName057(16) · NoName05716

#2
242.6MAudience
4kNews
30kIOCs

Target Countries

United Arab EmiratesArmeniaArgentinaAustria

Target Sectors

Food ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit Unions

Associated Malware

BlackNETfeodohupigonZbot

Related CVEs

CVE-2025-64669CVE-2025-5777CVE-2025-34067CVE-2025-2857

ATT&CK IDs

T1453T1105 - Ingress Tool TransferT1095 - Non Application Layer ProtocolT1497 - Virtualization/Sandbox Evasion
View Details

Lazarus Group

APT

APT 38 · APT-C-26 · APT38 · ATK117

#3
233.8MAudience
8kNews
40kIOCs

Target Countries

United Arab EmiratesAustraliaBangladeshBelgium

Target Sectors

HospitalsPublic AdministrationInternet PublishingSpace & Defense

Associated Malware

Volgmerwin.alreayBankshotosx.3cx_backdoor

Related CVEs

CVE-2025-9491CVE-2025-9074CVE-2025-8088CVE-2025-7775

ATT&CK IDs

T1055.002 - Portable Executable InjectionT1047T1218 - Signed Binary Proxy ExecutionT1547.011 - Plist Modification
View Details

TeamPcp

APT

ShellForce · Persy_PCP · CipherForce · PCPcat

#4
212.4MAudience
2kNews
443IOCs

Target Countries

GermanyFranceIndonesiaPeru

Target Sectors

Motion Picture and Video ProductionData Processing, Hosting, and Related ServicesBankingComputer Systems Design and Related Services

Associated Malware

Related CVEs

CVE-2026-48027CVE-2026-45321CVE-2026-33634CVE-2026-1731

ATT&CK IDs

T1059.003 - Windows Command ShellT1059.004 - Unix ShellT1204.002 - Malicious FileT1552.004 - Private Keys
View Details

Top Ransomware Groups

411

Qilin

Ransomware

agenda

#1
1110.2MAudience
21kNews
2kIOCs

Target Countries

United Arab EmiratesAlbaniaAngolaArgentina

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware Publishers

Associated Malware

Qilin

Related CVEs

CVE-2026-50752CVE-2026-50751CVE-2025-5777CVE-2025-53771

ATT&CK IDs

T1486T1490T1078T1071.001
View Details

thegentlemen

Ransomware

The Gentlemen Ransomware · the gentlemen

#2
915.5MAudience
8kNews
222IOCs

Target Countries

United Arab EmiratesArgentinaAustriaAustralia

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesRail Transportation

Associated Malware

Related CVEs

CVE-2025-7771CVE-2025-33073CVE-2025-32433CVE-2024-55591

ATT&CK IDs

T1190T1078T1087T1046
View Details

DragonForce

Ransomware

Water Tambanakua

#3
654.5MAudience
6kNews
1kIOCs

Target Countries

United Arab EmiratesAlbaniaArgentinaAustria

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central Bank

Associated Malware

Related CVEs

CVE-2025-6264CVE-2025-61155CVE-2025-59287CVE-2025-47176

ATT&CK IDs

T1071.001T1499T1569.002
View Details

shinyhunters

Ransomware

UNC6040 · Scattered Lapsus$ Hunters (SLH) · ShinyCorp

#4
630.9MAudience
7kNews
683IOCs

Target Countries

ArgentinaAustriaAustraliaBelgium

Target Sectors

Food ManufacturingOther Information ServicesCredit UnionsRail Transportation

Associated Malware

Related CVEs

CVE-2026-35273CVE-2025-61884CVE-2025-61882CVE-2025-55234

ATT&CK IDs

View Details

SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.

F.A.Q.

Common questions about threat actors and APT groups