CyberSecurityBoardThreat Intel · CVEs · Products

Category: Attack Groups

MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.

Attack Groups

GOLD SOUTHFIELD

[GOLD SOUTHFIELD](https://attack.mitre.org/groups/G0115) is a financially motivated threat group active since at least 2018 that operates the [REvil](https://attack.mitre.org/software/S0496) Ransomware-as-a Service (RaaS). [GOLD SOUTHFIELD](https://attack.mitre.org/groups/G0115)…

G0115 GOLD SOUTHFIELD Pinchy Spider
April 16, 2025
Attack Groups

SideCopy

[SideCopy](https://attack.mitre.org/groups/G1008) is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least…

G1008 SideCopy
April 16, 2025
Attack Groups

Nomadic Octopus

[Nomadic Octopus](https://attack.mitre.org/groups/G0133) is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals,…

DustSquad G0133 Nomadic Octopus
April 16, 2025
Attack Groups

Axiom

[Axiom](https://attack.mitre.org/groups/G0001) is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least…

Axiom G0001 Group 72
April 16, 2025
Attack Groups

TA551

[TA551](https://attack.mitre.org/groups/G0127) is a financially-motivated threat group that has been active since at least 2018. (Citation: Secureworks GOLD CABIN) The group has primarily…

G0127 GOLD CABIN Shathak TA551
April 16, 2025
Attack Groups

Confucius

[Confucius](https://attack.mitre.org/groups/G0142) is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia…

Confucius Confucius APT G0142
April 16, 2025
Attack Groups

Winnti Group

[Winnti Group](https://attack.mitre.org/groups/G0044) is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted…

Blackfly G0044 Winnti Group
April 16, 2025
Attack Groups

FIN8

[FIN8](https://attack.mitre.org/groups/G0061) is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in…

FIN8 G0061 Syssphinx
April 16, 2025
Attack Groups

Cobalt Group

[Cobalt Group](https://attack.mitre.org/groups/G0080) is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted…

Cobalt Gang Cobalt Group Cobalt Spider G0080
April 16, 2025
Attack Groups

EXOTIC LILY

[EXOTIC LILY](https://attack.mitre.org/groups/G1011) is a financially motivated group that has been closely linked with [Wizard Spider](https://attack.mitre.org/groups/G0102) and the deployment of ransomware including [Conti](https://attack.mitre.org/software/S0575)…

EXOTIC LILY G1011
April 16, 2025