Iranian destructive-attack cluster operating wipers under ransomware cover.
Loose hacktivist collective targeting government and infrastructure with defacements and DDoS.
DPRK financially-motivated cluster targeting cryptocurrency.
PLA Unit 61398 cyber-espionage group; subject of the 2013 Mandiant APT1 report.
Russian SVR cyber-espionage group; perpetrators of the SolarWinds supply-chain compromise.
DPRK cluster engaged in IT-worker fraud and ransomware development.
Iranian MOIS-affiliated cyber-espionage and disruption group.
China-aligned cyber-espionage group targeting NGOs, religious orgs, and governments across Asia and Europe.
IRGC-aligned cluster opportunistically deploying ransomware.
IRGC-affiliated cluster involved in espionage and access brokering.
Native-English-speaking eCrime collective known for social-engineering helpdesks.