UNC1069: North Korean Cyber Espionage Group
UNC1069 is a threat group attributed to North Korea, associated with the WAVESHAPER.V2 backdoor and activities overlapping with Sapphire Sleet. It has…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
UNC1069 is a threat group attributed to North Korea, associated with the WAVESHAPER.V2 backdoor and activities overlapping with Sapphire Sleet. It has…
Famous Chollima is the name used by CrowdStrike to describe North Korea's IT worker operation, which involves placing operatives in companies worldwide…
APT31, also known as Zirconium, is a Chinese state-sponsored cyber espionage group that has used Tailscale for tunneling in attacks against Russian…
Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, is an extortion crew known for data extortion, SIM swapping, and social…
Threat actors associated with the DragonForce ransomware group have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to…
Hackledorb is the threat actor behind DragonForce ransomware, known for pivoting to a highly organized cartel structure and deploying sophisticated backdoors like…
Medusa ransomware is a threat group that has previously used the custom malicious driver ABYSSWORKER in its attacks.
Magecart is a collective of cybercriminal groups that specialize in web skimming attacks, injecting malicious scripts into e-commerce checkout pages to steal…
LockBit was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
BlackCat, also known as ALPHV, is a ransomware-as-a-service group that emerged in 2021. It targeted numerous organizations globally, using sophisticated encryption and…