Black Axe: West African Cybercrime Network
Black Axe is a West African organized crime group identified by INTERPOL as a major perpetrator of cyber-enabled financial fraud, including romance…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Black Axe is a West African organized crime group identified by INTERPOL as a major perpetrator of cyber-enabled financial fraud, including romance…
UNC3886 is a threat group documented by Mandiant that used VMware VMCI sockets for persistence between compromised ESXi hosts and guest VMs.…
Red Menshen is a threat actor known for using passive backdoors like BPFDoor in telecom operator networks. Their activities were documented by…
AnonyMousKIT is a phishing-as-a-service platform that uses AI voice agents and multi-channel lures to steal Apple device passcodes and 2FA codes from…
Kratos, a cybercrime platform, was dismantled in July 2026 by German and U.S. authorities, with over 200 servers taken offline. The developer…
The Mabna Institute is a Tehran-based cyber group linked to Iran's Ministry of Intelligence and Security (MOIS). Five of its members were…
The MOIS cyber group is a network of threat actors directed by Iran's Ministry of Intelligence and Security. They conduct cyber espionage…
ClearFake is a threat cluster known for compromising legitimate websites and planting fake CAPTCHA lures that use ClickFix-style social engineering decoys. It…
MarlboroMan is a threat actor who advertised RedC2 on Hack Forums and operates the Red Offsec website, selling the C2 framework for…
MoYu Group is a threat actor group attributed with high confidence to the BADBOX ad fraud and residential proxy scheme. They were…