CyberSecurityBoardThreat Intel · CVEs · Products

Category: Attack Groups

MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.

Attack Groups

Transparent Tribe

[Transparent Tribe](https://attack.mitre.org/groups/G0134) is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research…

APT36 COPPER FIELDSTONE G0134 Mythic Leopard
April 10, 2024
Attack Groups

Orangeworm

[Orangeworm](https://attack.mitre.org/groups/G0071) is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least…

G0071 Orangeworm
April 10, 2024
Attack Groups

Whitefly

[Whitefly](https://attack.mitre.org/groups/G0107) is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in…

G0107 Whitefly
April 10, 2024
Attack Groups

Cinnamon Tempest

[Cinnamon Tempest](https://attack.mitre.org/groups/G1021) is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on…

BRONZE STARLIGHT Cinnamon Tempest DEV-0401 Emperor Dragonfly
April 4, 2024
Attack Groups

Malteiro

[Malteiro](https://attack.mitre.org/groups/G1026) is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019.…

G1026 Malteiro
March 29, 2024
Attack Groups

Mustard Tempest

[Mustard Tempest](https://attack.mitre.org/groups/G1020) is an initial access broker that has operated the [SocGholish](https://attack.mitre.org/software/S1124) distribution network since at least 2017. [Mustard Tempest](https://attack.mitre.org/groups/G1020) has partnered…

DEV-0206 G1020 GOLD PRELUDE Mustard Tempest
March 25, 2024
Attack Groups

ToddyCat

[ToddyCat](https://attack.mitre.org/groups/G1022) is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection…

G1022 ToddyCat
February 14, 2024
Attack Groups

Rancor

[Rancor](https://attack.mitre.org/groups/G0075) is a threat group that has led targeted campaigns against the South East Asia region. [Rancor](https://attack.mitre.org/groups/G0075) uses politically-motivated lures to entice…

G0075 Rancor
February 9, 2024
Attack Groups

POLONIUM

[POLONIUM](https://attack.mitre.org/groups/G1005) is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at…

G1005 Plaid Rain POLONIUM
January 8, 2024
Attack Groups

Dragonfly

[Dragonfly](https://attack.mitre.org/groups/G0035) is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.(Citation: DOJ Russia Targeting Critical…

Berserk Bear BROMINE Crouching Yeti Dragonfly
January 8, 2024