DPRK financially-motivated cluster targeting cryptocurrency.
PLA Unit 61398 cyber-espionage group; subject of the 2013 Mandiant APT1 report.
Russian SVR cyber-espionage group; perpetrators of the SolarWinds supply-chain compromise.
Dual-purpose Chinese threat group conducting espionage and financially motivated operations.
APT9 (also known as NIGHTSHADE PANDA and Red Pegasus) is a Chinese state-sponsored threat actor engaged in cyber espionage operations primarily targeting organizations in the United States, Japan, South Korea, and across Europe and Southeast Asia. The group focuses on intellectual property and competitive data theft, with a historically strong emphasis on the pharmaceuticals, biotechnology, healthcare, and aerospace sectors. APT9 employs a range of intrusion techniques including spearphishing, abuse of valid accounts, exploitation of trusted inter-organizational relationships, and a diverse malware toolkit comprising both publicly available and custom backdoors shared across multiple Chinese APT groups.
DPRK IT-worker fraud operation.
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, the Middle East, and Southeast Asia. The actor exploits web application vulnerabilities, such as CVE-2025-55182, and employs techniques like SQL injection, DLL sideloading, and the deployment of custom backdoors like PULSEPACK and BypassBoss. Earth Lamia conducts reconnaissance, file operations, and credential theft, often utilizing tools like Cobalt Strike and VShell.
DPRK cluster engaged in IT-worker fraud and ransomware development.
Emotet botnet operators.
Native-English-speaking eCrime collective known for social-engineering helpdesks.