The Gentlemen — Attack group profile
The Gentlemen was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
The Gentlemen was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Qilin is a ransomware operation that DevMan initially affiliated with before launching its own RaaS. The group is known for its ransomware-as-a-service…
MedusaLocker was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
DragonForce was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
LapDogs is an attack group tracked by Mandiant that operates operational relay box networks (ORBs) using compromised end-of-life routers and IoT devices.…
Russian GRU-linked group whose tradecraft overlaps with CaptiveCrunch, but attribution was not made due to lack of direct technical linkage.
Volt Typhoon is a Chinese state-sponsored hacking group that has been observed using the JDY botnet for reconnaissance and targeting of vulnerable…
GrayBravo is a threat activity cluster attributed to distributing CastleLoader and CastleStealer malware. The group is known for using ClickFix-style lures and…
PolinRider is a threat cluster assessed to be related to the Contagious Interview campaign, known for using multi-blockchain resolver structures (Tron, Aptos,…
A financially motivated Russian-speaking initial access broker (IAB) is assessed to be behind the FortiBleed campaign, which has targeted over 430,000 FortiGate…