CyberSecurityBoardThreat Intel · CVEs · Products

Category: Attack Groups

MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.

Attack Groups

LAPSUS$

[LAPSUS$](https://attack.mitre.org/groups/G1004) is cyber criminal threat group that has been active since at least mid-2021. [LAPSUS$](https://attack.mitre.org/groups/G1004) specializes in large-scale social engineering and extortion…

DEV-0537 G1004 LAPSUS$ Strawberry Tempest
April 21, 2025
Attack Groups

APT16

[APT16](https://attack.mitre.org/groups/G0023) is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)

APT16 G0023
April 16, 2025
Attack Groups

MoustachedBouncer

[MoustachedBouncer](https://attack.mitre.org/groups/G1019) is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.(Citation: MoustachedBouncer ESET August 2023)

G1019 MoustachedBouncer
April 16, 2025
Attack Groups

Deep Panda

[Deep Panda](https://attack.mitre.org/groups/G0009) is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. (Citation: Alperovitch 2014)…

Black Vine Deep Panda G0009 KungFu Kittens
April 16, 2025
Attack Groups

Cleaver

[Cleaver](https://attack.mitre.org/groups/G0003) is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. (Citation:…

Cleaver G0003 TG-2889 Threat Group 2889
April 16, 2025
Attack Groups

Volatile Cedar

[Volatile Cedar](https://attack.mitre.org/groups/G0123) is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. [Volatile Cedar](https://attack.mitre.org/groups/G0123) has been operating since 2012…

G0123 Lebanese Cedar Volatile Cedar
April 16, 2025
Attack Groups

GOLD SOUTHFIELD

[GOLD SOUTHFIELD](https://attack.mitre.org/groups/G0115) is a financially motivated threat group active since at least 2018 that operates the [REvil](https://attack.mitre.org/software/S0496) Ransomware-as-a Service (RaaS). [GOLD SOUTHFIELD](https://attack.mitre.org/groups/G0115)…

G0115 GOLD SOUTHFIELD Pinchy Spider
April 16, 2025
Attack Groups

SideCopy

[SideCopy](https://attack.mitre.org/groups/G1008) is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least…

G1008 SideCopy
April 16, 2025
Attack Groups

Nomadic Octopus

[Nomadic Octopus](https://attack.mitre.org/groups/G0133) is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals,…

DustSquad G0133 Nomadic Octopus
April 16, 2025
Attack Groups

Axiom

[Axiom](https://attack.mitre.org/groups/G0001) is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least…

Axiom G0001 Group 72
April 16, 2025