CyberSecurityBoardThreat Intel · CVEs · Products

Category: Attack Groups

MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.

Attack Groups

APT30

[APT30](https://attack.mitre.org/groups/G0013) is a threat group suspected to be associated with the Chinese government. While [Naikon](https://attack.mitre.org/groups/G0019) shares some characteristics with [APT30](https://attack.mitre.org/groups/G0013), the two…

APT30 G0013
November 17, 2024
Attack Groups

APT17

[APT17](https://attack.mitre.org/groups/G0025) is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology…

APT17 Deputy Dog G0025
November 17, 2024
Attack Groups

APT37

[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims…

APT37 G0067 Group123 InkySquid
November 17, 2024
Attack Groups

FIN6

[FIN6](https://attack.mitre.org/groups/G0037) is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group…

Camouflage Tempest FIN6 G0037 ITG08
November 17, 2024
Attack Groups

FIN10

[FIN10](https://attack.mitre.org/groups/G0051) is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group…

FIN10 G0051
November 17, 2024
Attack Groups

Windshift

[Windshift](https://attack.mitre.org/groups/G0112) is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and…

Bahamut G0112 Windshift
November 17, 2024
Attack Groups

CopyKittens

[CopyKittens](https://attack.mitre.org/groups/G0052) is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi…

CopyKittens G0052
November 17, 2024
Attack Groups

Daggerfly

[Daggerfly](https://attack.mitre.org/groups/G1034) is a People's Republic of China-linked APT entity active since at least 2012. [Daggerfly](https://attack.mitre.org/groups/G1034) has targeted individuals, government and NGO entities,…

BRONZE HIGHLAND Daggerfly Evasive Panda G1034
October 31, 2024
Attack Groups

Indrik Spider

[Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384)…

DEV-0243 Evil Corp G0119 Indrik Spider
October 28, 2024
Attack Groups

INC Ransom

[INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since…

G1032 GOLD IONIC INC Ransom
October 28, 2024