//
All
Actors
Incidents
Nation-State
eCrime
ICS / OT
Vulnerabilities
Threat Actor Profiles
CyberAv3ngers
TLP:CLEAR CRITICAL
NATION-STATE (HACKTIVIST PERSONA) · IRGC-CEC / IRAN · ACTIVE SINCE 2020
Iranian IRGC-CEC unit posing as a hacktivist collective, escalating from default-credential Unitronics PLC compromises (2023) to an unpatched Rockwell auth-bypass campaign and a coordinated strike on 30+ Minnesota water utilities (Jul 2026). Now carries the 21 static IPs published in CISA AA26-097A, the group's Dropbear SSH modem persistence, and its abuse of vendor PLC engineering software to steal and weaponize plant project files.
DarkSide
TLP:CLEAR HIGH
ECRIME (RAAS) · NO CONFIRMED SPONSOR · ACTIVE SINCE AUG 2020
A Russian-speaking ransomware-as-a-service operation that netted $90M+ from 80+ victims in nine months before its Colonial Pipeline attack forced a national fuel emergency — the brand shut itself down within a week, but its code and personnel are documented to have persisted through two further RaaS generations, BlackMatter and BlackCat/ALPHV.
BlackCat / ALPHV
TLP:CLEAR HIGH
ECRIME (RAAS) · NO CONFIRMED SPONSOR · ACTIVE SINCE NOV 2021
The Rust-based third generation of the DarkSide lineage, BlackCat/ALPHV compromised 1,000+ victims and collected $300M+ before elite affiliate Scattered Spider's help-desk vishing brought down MGM Resorts and Caesars in 2023 — the group survived an FBI takedown only to implode months later in an apparent $22M exit scam against its own affiliate after the Change Healthcare attack.
The Gentlemen
TLP:CLEAR CRITICAL
ECRIME · RAAS (INDEPENDENT) · ACTIVE SINCE JUL 2025
A Qilin-affiliate splinter group that became the most active ransomware operation on Earth within a year — 328+ victims across 66 countries by mid-2026, driven by a 90% affiliate profit share and a five-platform Go/C encryptor. A May 2026 leak of its own internal backend gave researchers an unusually direct look inside the operation.
menuPass
TLP:CLEAR CRITICAL
NATION-STATE · CHINESE MSS (TIANJIN BUREAU) · ACTIVE SINCE 2006
A two-decade Chinese state espionage operation best known for Operation Cloud Hopper — compromising 45+ managed IT service providers to reach the networks of their downstream Fortune 500 and government clients — and still active today, having pivoted to direct SSL-VPN and file-appliance exploitation against Japan and Taiwan.
Akira
TLP:CLEAR CRITICAL
ECRIME · RAAS / CONTI DIASPORA · ACTIVE SINCE MAR 2023
A prolific Ransomware-as-a-Service operation, run in part by former Conti-affiliated operators, that has extorted an estimated $244M+ from 1,584+ victims by weaponizing eight VPN/edge-device CVEs — encrypting entire networks in as little as 55 minutes.
Sandworm Team
TLP:CLEAR CRITICAL
NATION-STATE · GRU / RUSSIA · ACTIVE SINCE 2009
Russian GRU Unit 74455 (Mandiant's APT44), the only actor with a confirmed record of using cyberattacks to cause physical power-grid blackouts (2015, 2016, 2022) and author of NotPetya, the costliest cyberattack in history — now pivoting toward edge-device compromise of Western critical infrastructure.
Kimsuky
TLP:CLEAR HIGH
NATION-STATE · RGB / NORTH KOREA (DPRK) · ACTIVE SINCE 2012
North Korean espionage collective (MITRE G0094 / APT43) blending individually-tailored spear-phishing and QR-code "quishing" against diplomats and think tanks with abuse of legitimate platforms like GitHub and Google Drive as C2 — now augmented by a self-hosted offline AI stack for phishing and malware development (Operation GitPower, Aug 2026).
Scattered Spider
TLP:CLEAR CRITICAL
ECRIME — SOCIAL ENGINEERING / RANSOMWARE AFFILIATE · INDEPENDENT / "THE COM" · ACTIVE SINCE MAY 2022
Vishing-driven eCrime collective that defeats MFA via help-desk social engineering and has pivoted to hijacking VMware ESXi/vSphere for direct hypervisor-level ransomware deployment across retail, insurance, and aviation targets.
TeamPCP
TLP:CLEAR CRITICAL
ECRIME · INDEPENDENT · ACTIVE SINCE MID-2025
Financially motivated cloud-native supply-chain actor behind the 2026 Trivy/KICS/LiteLLM compromise cascade that hit the European Commission and thousands of downstream orgs; two alleged members arrested and indicted in Australia on 2026-08-27.
JADEPUFFER
TLP:CLEAR CRITICAL
AGENTIC THREAT ACTOR — OPERATOR UNKNOWN · ECRIME-STYLE EXTORTION · ACTIVE SINCE JUL 2026
The first documented fully AI-agent-driven ransomware operation: an LLM autonomously exploited a Langflow RCE, self-corrected mid-attack in 31 seconds, and destroyed a production database — then resurfaced weeks later with "ENCFORGE," a locker built specifically to destroy AI model files.
REvil
TLP:CLEAR HIGH (HISTORICAL)
ECRIME — RANSOMWARE-AS-A-SERVICE · RUSSIA-BASED, NO CONFIRMED STATE TIE · ACTIVE APR 2019 – JAN 2022
Sodinokibi RaaS operation behind JBS Foods, Travelex, and the Kaseya VSA supply-chain attack that hit up to 1,500 businesses in one shot; dismantled by a 2021-2022 US-Russia law enforcement campaign, with its true current status still unresolved.
Gonjeshke Darande
TLP:CLEAR CRITICAL
SUSPECTED NATION-STATE-ALIGNED (ISRAEL, UNCONFIRMED) · SELF-STYLED HACKTIVIST · ACTIVE SINCE 2021
"Predatory Sparrow" — destructive hacktivist persona behind Iran's railway wiper attack, the Khouzestan Steel mill fire (first cyber-to-physical damage since Stuxnet), and the 2025 Bank Sepah/Nobitex operations that burned $90M in crypto.
Salt Typhoon
TLP:CLEAR CRITICAL
NATION-STATE · CHINA (MSS, CONTRACTOR-ENABLED) · ACTIVE SINCE 2019
Chinese state-sponsored group that breached nine major US telecom carriers' lawful-intercept and call-record systems, exploiting Cisco edge devices to gain SIGINT-style access now confirmed across 80+ countries.
APT1
TLP:CLEAR HIGH (HISTORICAL)
NATION-STATE · PLA UNIT 61398 (CHINA) · ACTIVE SINCE 2006
The military cyber-espionage unit Mandiant's landmark 2013 report publicly named and traced to a Shanghai building, compromising 141+ organizations and prompting the first-ever US indictment of state-sponsored hackers.
LAPSUS$
TLP:CLEAR HIGH
ECRIME EXTORTION COLLECTIVE · INDEPENDENT / "THE COM" · ACTIVE SINCE MID-2021
Social-engineering-driven extortion collective that breached Microsoft, Nvidia, Samsung, Okta and others in 2022 with no custom malware; resurgent in 2026 as "Scattered LAPSUS$ Hunters."
Vulnerability Advisories
GitLab Commits API Path Traversal
TLP:CLEAR PATCH NOW KEV LISTED
CVE-2026-85706 · CWE-22 + CWE-306 · CVSS 10.0 · GitLab CE/EE (self-managed)
One unauthenticated HTTP request reads arbitrary files off a self-managed GitLab server — and on a CI/CD platform those files are the secrets that unlock every pipeline and cloud account it deploys to. Patched 10 Sep 2026, probed internet-wide within 20 hours, KEV-listed the next day; the patch closes the door on a room already emptied, so credential rotation is the real remediation.
Chrome WebGL OOB Write
TLP:CLEAR PATCH NOW
CVE-2026-85050 · CWE-787 · CVSS 9.6 · Google Chrome (Android)
A WebGL memory-corruption bug lets a crafted web page escape Chrome's sandbox entirely — the same September 2026 release patched a lower-scored, actively-exploited V8 bug that grabbed every headline, while this more severe sandbox-escape sat one CVE ID away, uncovered by anyone not reading the full advisory.
SonicWall SonicOS Access Control Bypass
TLP:CLEAR PATCH NOW KEV
CVE-2024-40766 · CWE-284 · CVSS 9.3 · SonicWall Gen 5/6/7 Firewalls (TZ/NSA/SM/SOHO)
An unauthenticated access-control bypass in SonicOS's management interface and SSLVPN became Akira ransomware's primary way in — but a same-day patch never touched the stale local-user credentials firewalls carried forward across firmware migrations, so a June 2026 audit still found operators inside "patched" devices nearly two years later.
WatchGuard Firebox Auth Bypass
TLP:CLEAR RESOLVED KEV
CVE-2022-23176 · CWE-863 (analyst) · CVSS 8.8 · WatchGuard Firebox & XTM
A privilege-escalation flaw in WatchGuard's Fireware OS let Sandworm Team turn ordinary perimeter firewalls into Cyclops Blink botnet nodes for over two years before disclosure — patched quietly in Dec 2021, publicly tied to the malware only after DOJ authorized a covert March 2022 takedown operation.
Rockwell Logix Auth Bypass
TLP:CLEAR NO FIX KEV
CVE-2021-22681 · CWE-522 · CVSS 9.8 · Rockwell Automation Logix Controllers
A shared cryptographic key baked into every copy of Rockwell's engineering software authenticates connections to Logix PLCs — Rockwell has determined this cannot be patched. Five years after disclosure, CyberAv3ngers/IRGC-CEC weaponized it against U.S. water and energy infrastructure; 4,400+ controllers remain internet-exposed globally.
PaperCut
TLP:CLEAR PATCH NOW KEV
CVE-2023-27350/27351 · CVE-2026-81578/82078 · CVSS up to 9.8 · PaperCut MF/NG
Two unauthenticated RCE chains, three years apart, in the same print-management admin console. Both 2026-generation CVEs hit CISA's KEV catalog on 2026-08-31 after attackers were caught deploying RATs and dumping databases on compromised servers; a third emergency patch shipped 2026-09-01.
Spectre / Meltdown
TLP:CLEAR RESOLVED · HISTORICAL
CVE-2017-5753/5715/5754 · CWE-1303 · CVSS 5.6 · Intel / AMD / ARM / IBM
The CPU speculative-execution flaws that opened an entire vulnerability class: patched cleanly in weeks, but still producing new named variants (Retbleed, Downfall, Zenbleed) eight years later — with zero confirmed real-world breaches to date.
Heartbleed
TLP:CLEAR RESOLVED · HISTORICAL KEV
CVE-2014-0160 · CWE-125 · CVSS 7.5 · OpenSSL / TLS Heartbeat Extension
Memory-disclosure bug in OpenSSL's TLS heartbeat that exposed ~17% of the internet's secure servers in 2014; the patch closed cleanly, but legacy/embedded exposure and unrotated keys kept it exploitable — and KEV-listed — for years after.
PrintNightmare
TLP:CLEAR PATCH — TEST FIRST KEV
CVE-2021-34527 · CWE-269 · CVSS 8.8 · Microsoft / Windows Print Spooler
Windows Print Spooler privilege-escalation/RCE family that took five CVEs and 38 months to close; weaponized by Vice Society, Magniber, and Conti ransomware operators within weeks of disclosure.
Incident Case Files
US Water Sector PLC Campaign
TLP:CLEAR ICS/OT DISRUPTION
JAN 2025 – JUL 2026 · ATTRIBUTED TO: CYBERAV3NGERS / IRGC-CEC [MEDIUM] · DWELL TIME: ~18 MONTHS
Iranian-affiliated actors spent eighteen months inside internet-exposed PLCs across US water, energy and government facilities, stealing plant project files and rewriting Add-On Instructions to disable shutdown and alarm logic — then triggered coordinated disruption at ~36 Minnesota water systems and utilities in twelve states on 26–27 July 2026, four days after CISA updated advisory AA26-097A. No zero-day was used: internet exposure, default credentials and an unpatchable Rockwell auth bypass were sufficient.
Cyclops Blink
TLP:CLEAR NATION-STATE ESPIONAGE
JUN 2019 – MAR 2022 · ATTRIBUTED TO: SANDWORM TEAM / GRU UNIT 74455 [HIGH] · DWELL TIME: ~2.5 YEARS
Sandworm's VPNFilter successor quietly turned thousands of WatchGuard firewalls and ASUS routers into durable botnet infrastructure for two and a half years, undetected until a joint CISA/NCSC advisory exposed it one day before Russia's invasion of Ukraine — a DOJ court-authorized operation remotely disabled the botnet the following month.
Colonial Pipeline Ransomware Attack
TLP:CLEAR RANSOMWARE / EXTORTION CRITICAL
APR–MAY 2021 · ATTRIBUTED TO: DARKSIDE (RAAS) [HIGH] · DWELL TIME: ~8 DAYS
A single compromised, MFA-less legacy VPN password let a DarkSide affiliate sit inside Colonial Pipeline's IT network for eight days before encrypting its billing systems — the resulting precautionary shutdown of the largest U.S. fuel pipeline, without any OT/ICS compromise, triggered a six-day East Coast fuel crisis, a $4.4M ransom, and the first mandatory federal pipeline cybersecurity regulations.
Maersk NotPetya Attack
TLP:CLEAR NATION-STATE DESTRUCTIVE
JUN 2017 · ATTRIBUTED TO: SANDWORM TEAM / GRU UNIT 74455 [HIGH] · DWELL TIME: ~10 WEEKS
A Russian military wiper disguised as ransomware, delivered through a hijacked Ukrainian tax-software update, spread worldwide and wiped Maersk's entire global IT estate in minutes — the company rebuilt 4,000 servers and 45,000 PCs in 10 days after a lone surviving domain controller in Ghana, saved by a power outage, became the only copy of its Active Directory left anywhere on Earth.
Bangladesh Bank SWIFT Heist
TLP:CLEAR FINANCIAL CRIME
FEB 2016 · ATTRIBUTED TO: LAZARUS GROUP / APT38 [HIGH] · DWELL TIME: ~13 MONTHS
North Korean state hackers used stolen SWIFT credentials and custom anti-forensic malware to attempt a $951M theft from Bangladesh's central bank; a misspelled word blocked most of it, but $81M still reached Manila and vanished into the Philippine casino system.
JPMorgan Chase Data Breach
TLP:CLEAR FINANCIAL CRIME
JUN–AUG 2014 · ATTRIBUTED TO: SHALON/AARON/ORENSTEIN/TYURIN CRIMINAL ENTERPRISE [HIGH] · DWELL TIME: ~2 MONTHS
One overlooked server in an otherwise complete two-factor authentication rollout let intruders roam 90 JPMorgan servers for two months, stealing contact data on 83 million accounts — a breach the FBI first suspected was Russian state retaliation, until a 2015 indictment unmasked it as a transnational pump-and-dump securities fraud ring instead.
Operation Ababil
TLP:CLEAR HACKTIVISM / DDOS
SEP 2012 – MAY 2013 · ATTRIBUTED TO: IRGC / ITSECTEAM & MERSAD CO. [HIGH] · DWELL TIME: N/A (DDoS)
A self-declared "hacktivist" collective knocked dozens of major U.S. banks offline with unprecedented DDoS volumes over three announced phases — a front that took the DOJ over three years to formally unmask as an IRGC-run operation, whose operators separately breached a small New York dam's control system along the way.
Sony BMG XCP Rootkit
TLP:CLEAR SUPPLY CHAIN — VENDOR NEGLIGENCE
APR 2005 – JAN 2007 · ATTRIBUTED TO: FIRST4INTERNET / SUNNCOMM (VENDORS) · DWELL TIME: ~6–7 MONTHS
Sony BMG shipped kernel-level cloaking DRM (XCP, MediaMax) on tens of millions of audio CDs; independent researcher Mark Russinovich exposed it as rootkit-class software in Oct 2005, and criminal malware weaponized the cloak within ten days.
Melissa Virus
TLP:CLEAR WORM / SELF-PROPAGATING
MAR 1999 – MAY 2002 · ATTRIBUTED TO: DAVID L. SMITH (INDIVIDUAL) · DWELL TIME: N/A — IMMEDIATE IMPACT
The first mass-mailing macro virus to hit internet scale, spreading through Word documents that auto-emailed themselves to a victim's first 50 Outlook contacts and forcing Microsoft, Intel, and Lockheed Martin to shut down email entirely within 72 hours.
The Morris Worm
TLP:CLEAR SELF-PROPAGATING WORM
NOV 1988 · ATTRIBUTED TO: ROBERT TAPPAN MORRIS · DWELL TIME: HOURS
First self-propagating worm to achieve mass spread across the early Internet, disabling ~6,000 of ~60,000 connected hosts via a miscalibrated reinfection check; led directly to the founding of CERT/CC and the first CFAA prosecution.
The Iceman Carding Empire
TLP:CLEAR ECRIME — CARDING MARKETPLACE CONSOLIDATION
2005 – SEP 2007 · ATTRIBUTED TO: MAX RAY BUTLER ("ICEMAN") [HIGH — CONVICTED] · DWELL TIME: ~2+ YEARS
Subject of Kevin Poulsen's "Kingpin" — a former FBI informant turned hacker who hijacked four rival carding forums in a single night, trafficked ~2M stolen cards, and drew the longest US hacking sentence of its time.
2007 Estonia Cyberattacks
TLP:CLEAR NATION-STATE — DDOS / HYBRID WARFARE
APR 27 – MAY 18, 2007 · ATTRIBUTED TO: RUSSIA-LINKED NATIONALIST HACKTIVISTS [LOW–MEDIUM] · DWELL TIME: N/A (DDOS)
Widely regarded as "Web War I" — a 22-day DDoS campaign that paralyzed Estonian banking, government, and media after the Bronze Soldier statue's relocation, directly leading to NATO's Tallinn cyber-defense centre and the Tallinn Manual.
Operation Aurora
TLP:CLEAR NATION-STATE ESPIONAGE
MID-2009 – JAN 2010 · ATTRIBUTED TO: ELDERWOOD GROUP (CHINA-NEXUS) · DWELL TIME: ~6 MONTHS
Zero-day-enabled espionage campaign that breached Google and 30+ other companies to steal source code and target Gmail accounts of Chinese human-rights activists; prompted Google's exit from mainland Chinese search.