Threat Actors
The groups behind the attacks — state APTs and ransomware operations. Who they are, where they come from and how they operate. Source: MITRE ATT&CK and ransomware.live.
0aptRansomware
0day SyndicateRansomware
0megaRansomware
8baseRansomware
Abrahams_AxRansomware
Origin: Irã
abyssRansomware
admin@338APT / State
Origin: China
G0018
adminlockerRansomware
againstthewestRansomware
aGl0bGVyCgRansomware
AgriusAPT / State
Origin: Irã
G1030
AiLockRansomware
Ajax Security TeamAPT / State
Origin: Irã
G0130
AkiraAPT / State
G1024
akoRansomware
ALP-001Ransomware
alphalockerRansomware
alphvRansomware
AndarielAPT / State
Origin: Coreia do Norte
G0138
anubisRansomware
Aoqin DragonAPT / State
Origin: China
G1007
aposRansomware
AppleJeusAPT / State
Origin: Coreia do Norte
G1049
APT1APT / State
Origin: China
G0006
APT12APT / State
Origin: China
G0005
APT16APT / State
Origin: China
G0023
APT17APT / State
Origin: China
G0025
APT18APT / State
G0026
APT19APT / State
Origin: China
G0073
APT28APT / State
Origin: Rússia
G0007
APT29APT / State
Origin: Rússia
G0016
APT3APT / State
Origin: China
G0022
APT30APT / State
Origin: China
G0013
APT32APT / State
Origin: Vietnã
G0050
APT33APT / State
Origin: Irã
G0064
APT37APT / State
Origin: Coreia do Norte
G0067
APT38APT / State
Origin: Coreia do Norte
G0082
APT39APT / State
Origin: Irã
G0087
APT41APT / State
Origin: China
G0096
APT42APT / State
Origin: Irã
G1044
APT5APT / State
Origin: China
G1023
apt73Ransomware
APT-C-23APT / State
G1028
APT-C-36APT / State
G0099
Aquatic PandaAPT / State
Origin: China
G0143
arcusmediaRansomware
argonautsRansomware
arkanaRansomware
arvinclubRansomware
Origin: Irã
atomsiloRansomware
Origin: China
AuditTeamRansomware
auroraRansomware
avaddonRansomware
avosRansomware
avoslockerRansomware
awareRansomware
AxiomAPT / State
Origin: China
G0001
aztroteamRansomware
babukRansomware
babuk2Ransomware
babyduckRansomware
BackdoorDiplomacyAPT / State
G0135
beastRansomware
benzonaRansomware
bertRansomware
bianlianRansomware
BITTERAPT / State
Origin: China
G1002
blackbastaRansomware
BlackByteAPT / State
G1043
BlackfieldRansomware
blacklockRansomware
blackmatterRansomware
blacknevasRansomware
BlackOasisAPT / State
G0063
blackoutRansomware
blackshadowRansomware
Origin: Irã
blackshrantacRansomware
blacksuitRansomware
BlackTechAPT / State
Origin: China
G0098
blacktorRansomware
blackwaterRansomware
Black XRansomware
blueboxRansomware
bluelockerRansomware
Origin: Paquistão
Blue MockingbirdAPT / State
G0108
blueskyRansomware
Origin: Rússia
bonacigroupRansomware
bqtlockRansomware
BrainCipherRansomware
bravoxRansomware
BRONZE BUTLERAPT / State
Origin: China
G0060
brotherhoodRansomware
cactusRansomware
CarbanakAPT / State
G0008
cephalusRansomware
chaosRansomware
cheersRansomware
chilelockerRansomware
ChimeraAPT / State
Origin: China
G0114
chortRansomware
Origin: Rússia
cicada3301Ransomware
Cinnamon TempestAPT / State
Origin: China
G1021
ciphbitRansomware
cipherforceRansomware
Origin: China
CleaverAPT / State
Origin: Irã
G0003
cloakRansomware
clopRansomware
CMDOrganizationRansomware
Cobalt GroupAPT / State
G0080
coinbasecartelRansomware
ConfuciusAPT / State
G0142
Contagious InterviewAPT / State
Origin: Coreia do Norte
G1052
ContFRRansomware
contiRansomware
Origin: Rússia
coomingRansomware
CopyKittensAPT / State
Origin: Irã
G0052
crazyhunterRansomware
crosslockRansomware
Origin: Brasil
cry0Ransomware
crylockRansomware
Origin: Rússia
cryp70n1c0d3Ransomware
cryptbbRansomware
Origin: Rússia
cryptnetRansomware
crypto24Ransomware
Origin: Vietnã
cubaRansomware
Origin: Rússia
CURIUMAPT / State
Origin: Irã
G1012
cyclopsRansomware
d4rk4rmyRansomware
DaggerflyAPT / State
Origin: China
G1034
dagonlockerRansomware
daixinRansomware
dAn0nRansomware
darkangelsRansomware
darkbitRansomware
Origin: Irã
Dark CaracalAPT / State
G0070
DarkhotelAPT / State
Origin: Coreia do Norte
G0012
DarkHydrusAPT / State
G0079
darkleakmarketRansomware
darkpowerRansomware
darkraceRansomware
darksideRansomware
darkvaultRansomware
DarkVishnyaAPT / State
G0105
datacarryRansomware
datakeeperRansomware
dataleakRansomware
Origin: Brasil
DeadlockRansomware
Deep PandaAPT / State
Origin: China
G0009
desolatorRansomware
devmanRansomware
diavolRansomware
direwolfRansomware
dispossessorRansomware
donexRansomware
donutleaksRansomware
doppelpaymerRansomware
DragonflyAPT / State
Origin: Rússia
G0035
dragonforceRansomware
DragonOKAPT / State
G0017
dragonransomwareRansomware
dreadRansomware
dunghillRansomware
Earth LuscaAPT / State
Origin: China
G1006
ech0raixRansomware
ElderwoodAPT / State
Origin: China
G0066
ElDoradoRansomware
embargoRansomware
Ember BearAPT / State
Origin: Rússia
G1003
entropyRansomware
ep918Ransomware
EquationAPT / State
G0020
esxiargsRansomware
everestRansomware
EvilnumAPT / State
G0120
exitiumRansomware
Origin: Brasil
exorcistRansomware
EXOTIC LILYAPT / State
G1011
Ferocious KittenAPT / State
Origin: Irã
G0137
FIN10APT / State
G0051
FIN13APT / State
G1016
FIN4APT / State
G0085
FIN5APT / State
Origin: Rússia
G0053
FIN6APT / State
G0037
FIN7APT / State
G0046
FIN8APT / State
G0061
fletchenRansomware
flockerRansomware
fogRansomware
Fox KittenAPT / State
Origin: Irã
G0117
fragRansomware
freecivilianRansomware
Origin: Rússia
fsteamRansomware
fulcrumsecRansomware
funksecRansomware
GALLIUMAPT / State
Origin: China
G0093
GallmakerAPT / State
G0084
Gamaredon GroupAPT / State
Origin: Rússia
G0047
GCMANAPT / State
G0036
GDLockerSecRansomware
Origin: Coreia do Norte
genesisRansomware