Threat Actors
50+ tracked groups with attribution, TTPs, and activity monitoring
Tracked Groups
50+
Active This Month
12
State-Sponsored
7
MITRE Techniques
245
Groups by Origin
Iran
3
Russia
3
North Korea
1
Tunisia
1
Sudan
1
Unknown
1
APT34 (OilRig)
๐ฎ๐ท Iran ยท State-Sponsored ยท Active since 2014
Iranian cyber espionage group targeting Middle East energy, government, and telecommunications sectors. Known for custom malware including POWBAT, BONDUPDATER, and QUADAGENT. Active campaigns against UAE and Saudi Arabian infrastructure.
15
MITRE Techniques
23
Attack Claims
8
Validated Attacks
5
Malware Families
T1566.001 SpearphishingT1059.001 PowerShellT1078 Valid AccountsT1071 App Layer ProtocolT1003 Credential Dumping
All Tracked Groups
| Group | Origin | Target Sectors | Techniques | Risk | Status |
|---|---|---|---|---|---|
| ๐ฎ๐ท APT34 (OilRig) | Iran | Energy, Government, Telecom | 15 | Critical | Active |
| ๐ฎ๐ท MuddyWater | Iran | Government, Defense, Telecom | 12 | High | Active |
| ๐ฎ๐ท APT33 (Elfin) | Iran | Aviation, Energy, Petrochemical | 11 | High | Active |
| ๐น๐ณ Tunisian Maskers | Tunisia | Government, Education | 6 | Medium | Active |
| ๐ท๐บ LockBit 3.0 | Russia | Cross-sector (Ransomware) | 14 | Critical | Active |
| ๐ธ๐ฉ Anonymous Sudan | Sudan | Government, Finance, Tech | 4 | Medium | Active |
| ๐ท๐บ BlackCat/ALPHV | Russia | Healthcare, Finance | 13 | Critical | Active |
| ๐ฐ๐ต Lazarus Group | North Korea | Finance, Crypto, Defense | 18 | Critical | Active |
| โ SandViper | Unknown | Energy, Government (GCC) | 7 | High | Emerging |
| ๐ท๐บ Cl0p | Russia | Cross-sector (Ransomware) | 10 | High | Active |
Showing 10 of 50+ groups โ Start trial for full access