Threat Actor Database

Know Your
Enemy

Track and analyze APT groups, ransomware gangs, hacktivists and cybercrime organizations — their targets, malware, techniques and IOCs updated in real time.

500+Threat Actors
100K+IOC Indicators
10K+ATT&CK Techniques

Top Threat Actors

1,138

DEV-0147

APT
#1
61.5MAudience
3kNews
0IOCs

Target Countries

United Arab EmiratesChinaUnited KingdomIsrael

Target Sectors

Funds, Trusts, and Other Financial VehiclesHospitalsOil & GasEnergy & Utilities

Associated Malware

win.flash_develop

Related CVEs

CVE-2025-59287

ATT&CK IDs

T1078.001T1068T1105T1193
View Details

Storm-0324

APT

DEV-0324 · Sagrid · TA543

#2
49.3MAudience
249News
1IOCs

Target Countries

ArgentinaAustraliaCanadaGermany

Target Sectors

Public AdministrationHospitalsRestaurantsAerospace Product and Parts Manufacturing

Associated Malware

Related CVEs

CVE-2023-36884CVE-2023-21715CVE-2023-20198

ATT&CK IDs

T1059.001T1071.001T1027T1566.001
View Details

NoName057

APT

05716nnm · Nnm05716 · NoName057(16) · NoName05716

#3
38.4MAudience
1kNews
24kIOCs

Target Countries

United Arab EmiratesArmeniaArgentinaAustria

Target Sectors

Food ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit Unions

Associated Malware

wannacryptorwebmonitorSmoke Loaderlimerat

Related CVEs

CVE-2025-64669CVE-2025-5777CVE-2025-34067CVE-2025-2857

ATT&CK IDs

T1453T1105 - Ingress Tool TransferT1095 - Non Application Layer ProtocolT1497 - Virtualization/Sandbox Evasion
View Details

APT 28

APT

APT-C-20 · ATK5 · Blue Athena · BlueDelta

#4
36.3MAudience
1kNews
12kIOCs

Target Countries

AfghanistanArmeniaAustraliaAzerbaijan

Target Sectors

Rail TransportationHospitalsAir TransportationConstruction

Associated Malware

win.arguepatchP.A.S. WebshellAgent Teslawin.unidentified_078

Related CVEs

CVE-2026-24858CVE-2026-24423CVE-2026-24061CVE-2026-23800

ATT&CK IDs

T1021 - Remote ServicesT1550 - Use Alternate Authentication MaterialT1583.006T1060 - Registry Run Keys / Startup Folder
View Details

Top Ransomware Groups

402

Qilin

Ransomware

agenda

#1
244.3MAudience
10kNews
3kIOCs

Target Countries

United Arab EmiratesAlbaniaAngolaArgentina

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware Publishers

Associated Malware

Qilin

Related CVEs

CVE-2026-50752CVE-2026-50751CVE-2025-5777CVE-2025-53771

ATT&CK IDs

T1486T1490T1078T1071.001
View Details

thegentlemen

Ransomware

The Gentlemen Ransomware · the gentlemen

#2
224.2MAudience
5kNews
210IOCs

Target Countries

United Arab EmiratesArgentinaAustriaAustralia

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesRail Transportation

Associated Malware

Related CVEs

CVE-2025-7771CVE-2025-33073CVE-2025-32433CVE-2024-55591

ATT&CK IDs

T1190T1078T1087T1046
View Details

shinyhunters

Ransomware

UNC6040 · Scattered Lapsus$ Hunters (SLH) · ShinyCorp

#3
137.0MAudience
4kNews
910IOCs

Target Countries

AustriaAustraliaBelgiumBrazil

Target Sectors

Food ManufacturingOther Information ServicesRail TransportationSoftware Publishers

Associated Malware

Related CVEs

CVE-2026-35273CVE-2025-61884CVE-2025-61882CVE-2025-55234

ATT&CK IDs

View Details

DragonForce

Ransomware

Water Tambanakua

#4
121.6MAudience
3kNews
2kIOCs

Target Countries

United Arab EmiratesAlbaniaArgentinaAustria

Target Sectors

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central Bank

Associated Malware

Related CVEs

CVE-2025-6264CVE-2025-59287CVE-2025-47176CVE-2025-47171

ATT&CK IDs

T1071.001T1499T1569.002
View Details

SOCRadar Threat Actor Database is a free repository of structured intelligence profiles covering over 500 documented cyber threat actors — nation-state APT groups, ransomware operations, hacktivist collectives and financially motivated cybercrime organizations. Each profile aggregates origin country, targeted sectors and geographies, attributed malware families, known aliases, historical campaigns, MITRE ATT&CK technique coverage and indicators of compromise. No account required.

F.A.Q.

Common questions about threat actors and APT groups