Threat Actor Database

Know Your
Enemy

Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.

500+Threat Actors
100K+IOC Indicators
10K+ATT&CK Techniques

Top Threat Actors

1,133

Turla Group

APT

Turla · ATK13 · Blue Python · G0010

#1
3.2MAudience
25News
15kIOCs

Target Countries

AfghanistanArmeniaAustriaAustralia

Target Sectors

Energy & Utilities RetailEducational ServicesPublic Administration

Associated Malware

win.nautiluswin.tiny_turlaHyperStackasp.twoface

Related CVEs

CVE-2025-6543CVE-2025-5777CVE-2025-52579CVE-2025-31199

ATT&CK IDs

T1082T1572 - Protocol TunnelingT1047 - Windows Management InstrumentationT1132.001 - Standard Encoding
View Details

GOLD SOUTHFIELD

APT
#2
2.2MAudience
0News
11kIOCs

Target Countries

Target Sectors

HealthCare & Social AssistanceInternet PublishingPerforming Arts CompaniesComputer Systems Design and Related Services

Associated Malware

Related CVEs

CVE-2018-0802

ATT&CK IDs

T1562.003 - Impair Command History LoggingT1568.002 - Domain Generation AlgorithmsT1060 - Registry Run Keys / Startup FolderT1055 - Process Injection
View Details

Cobalt

APT

COBALT SPIDER · Cobalt Gang · Cobalt Group · G0080

#3
2.0MAudience
0News
40kIOCs

Target Countries

ArmeniaArgentinaAustriaAzerbaijan

Target Sectors

RetailFinanceElectrical&Electronical ManufacturingHospitals

Associated Malware

NimzaLoaderUrsnifVenomRATMimikatz

Related CVEs

CVE-2025-19872CVE-2024-13161CVE-2024-13160CVE-2022-30190

ATT&CK IDs

T1082T1572 - Protocol TunnelingT1537 - Transfer Data to Cloud AccountT1047 - Windows Management Instrumentation
View Details

Safe

APT
#4
1.8MAudience
0News
1kIOCs

Target Countries

United Arab EmiratesAustraliaBangladeshBulgaria

Target Sectors

Real EstateHospitalsAir TransportationConstruction

Associated Malware

Related CVEs

CVE-2022-23943CVE-2021-44790CVE-2021-23017CVE-2019-12521

ATT&CK IDs

T1195 - Supply Chain CompromiseT1140 - Deobfuscate/Decode Files or InformationT1199 - Trusted RelationshipT1003 - OS Credential Dumping
View Details

Top Ransomware Groups

402

Team Underground

Ransomware

Underground · TeamUnderground

#1
4.5MAudience
0News
46IOCs

Target Countries

United Arab EmiratesAustraliaBrazilCanada

Target Sectors

Construction of BuildingsOther Information ServicesHospitalsManufacturing

Associated Malware

Related CVEs

CVE-2023-36884

ATT&CK IDs

T1021.002T1059.003T1018T1105
View Details

VoidCrypt

Ransomware

Chaos · Dark · Void

#2
3.9MAudience
0News
18kIOCs

Target Countries

AustraliaCanadaGermanyUnited Kingdom

Target Sectors

Construction of BuildingsSoftware PublishersEnterprises & HoldingAir Transportation

Associated Malware

Related CVEs

ATT&CK IDs

View Details

el dorado

Ransomware

El-Dorado · Global · BlackLock · Eldorado

#3
3.4MAudience
51News
9kIOCs

Target Countries

United Arab EmiratesArgentinaAustraliaAruba

Target Sectors

Construction of BuildingsOther Information ServicesSoftware PublishersReal Estate

Associated Malware

Related CVEs

CVE-2021-21974

ATT&CK IDs

View Details

mindware

Ransomware

SFile2 · SFile · Escal

#4
3.3MAudience
0News
29IOCs

Target Countries

ArgentinaCanadaFranceItaly

Target Sectors

Construction of BuildingsFood ManufacturingMonetary Authorities-Central BankCredit Unions

Associated Malware

Related CVEs

ATT&CK IDs

T1566T1490T1176T1090
View Details

SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.

F.A.Q.

Common questions about threat actors and APT groups