CyberSecurityBoardThreat Intel · CVEs · Products

Category: Attack Groups

MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.

Attack Groups

Medusa Group

[Medusa Group](https://attack.mitre.org/groups/G1051) has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a…

G1051 Medusa Group
October 24, 2025
Attack Groups

UNC3886

[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in…

G1048 UNC3886
October 24, 2025
Attack Groups

Storm-0501

[Storm-0501](https://attack.mitre.org/groups/G1053) is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. [Storm-0501](https://attack.mitre.org/groups/G1053) has been active…

G1053 Storm-0501
October 24, 2025
Attack Groups

Scattered Spider

[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest…

G1015 Octo Tempest Roasted 0ktapus Scattered Spider
October 24, 2025
Attack Groups

Water Galura

[Water Galura](https://attack.mitre.org/groups/G1050) are the operators of the [Qilin](https://attack.mitre.org/software/S1242) Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data…

G1050 GOLD FEATHER Water Galura
October 23, 2025
Attack Groups

AppleJeus

[AppleJeus](https://attack.mitre.org/groups/G1049) is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader [Lazarus Group](https://attack.mitre.org/groups/G0032) umbrella of…

AppleJeus Citrine Sleet G1049 Gleaming Pisces
October 23, 2025
Attack Groups

TeamTNT

[TeamTNT](https://attack.mitre.org/groups/G0139) is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October…

G0139 TeamTNT
October 22, 2025
Attack Groups

Higaisa

[Higaisa](https://attack.mitre.org/groups/G0126) is a threat group suspected to have South Korean origins. [Higaisa](https://attack.mitre.org/groups/G0126) has targeted government, public, and trade organizations in North Korea;…

G0126 Higaisa
October 22, 2025
Attack Groups

Tropic Trooper

[Tropic Trooper](https://attack.mitre.org/groups/G0081) is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. [Tropic…

G0081 KeyBoy Pirate Panda Tropic Trooper
October 21, 2025
Attack Groups

ZIRCONIUM

[ZIRCONIUM](https://attack.mitre.org/groups/G0128) is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020…

APT31 G0128 Violet Typhoon ZIRCONIUM
October 15, 2025