Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.
500+Threat Actors
100K+IOC Indicators
10K+ATT&CK Techniques
Top Threat Actors
1,133
Turla Group
APT
Turla · ATK13 · Blue Python · G0010
#1
3.2MAudience
25News
15kIOCs
Target Countries
AfghanistanArmeniaAustriaAustralia
Target Sectors
Energy & Utilities RetailEducational ServicesPublic Administration
T1195 - Supply Chain CompromiseT1140 - Deobfuscate/Decode Files or InformationT1199 - Trusted RelationshipT1003 - OS Credential Dumping
View Details
Top Ransomware Groups
402
Team Underground
Ransomware
Underground · TeamUnderground
#1
4.5MAudience
0News
46IOCs
Target Countries
United Arab EmiratesAustraliaBrazilCanada
Target Sectors
Construction of BuildingsOther Information ServicesHospitalsManufacturing
Associated Malware
—
Related CVEs
CVE-2023-36884
ATT&CK IDs
T1021.002T1059.003T1018T1105
View Details
VoidCrypt
Ransomware
Chaos · Dark · Void
#2
3.9MAudience
0News
18kIOCs
Target Countries
AustraliaCanadaGermanyUnited Kingdom
Target Sectors
Construction of BuildingsSoftware PublishersEnterprises & HoldingAir Transportation
Associated Malware
—
Related CVEs
—
ATT&CK IDs
—
View Details
el dorado
Ransomware
El-Dorado · Global · BlackLock · Eldorado
#3
3.4MAudience
51News
9kIOCs
Target Countries
United Arab EmiratesArgentinaAustraliaAruba
Target Sectors
Construction of BuildingsOther Information ServicesSoftware PublishersReal Estate
Associated Malware
—
Related CVEs
CVE-2021-21974
ATT&CK IDs
—
View Details
mindware
Ransomware
SFile2 · SFile · Escal
#4
3.3MAudience
0News
29IOCs
Target Countries
ArgentinaCanadaFranceItaly
Target Sectors
Construction of BuildingsFood ManufacturingMonetary Authorities-Central BankCredit Unions
Associated Malware
—
Related CVEs
—
ATT&CK IDs
T1566T1490T1176T1090
View Details
SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.
F.A.Q.
Common questions about threat actors and APT groups
We value your privacy
We use cookies to improve your experience, analyze traffic, and personalize content. We won't set non-essential cookies until you agree. Privacy Policy