DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
BACK TO EXPLORE INDEX
THREAT ACTOR DOSSIERS

Advanced Persistent Threats & Cybercrime Syndicates

TRACKED CLUSTERS: 5 APTS
ORIGIN: Democratic People’s Republic of Korea active

Lazarus Group (APT38 / Hidden Cobra / BlueNoroff)

ACTIVE SINCE: 2009 · 4 MAJOR OPERATIONS

Prolific state-backed cyber warfare and financial cyber-heist collective responsible for billions in cryptocurrency theft, defense espionage, and disruptive attacks.

MOTIVATION: financialCONFIRMED ATTRIBUTION
ORIGIN: People’s Republic of China active

Volt Typhoon (Bronze Silhouette / Vanguard Panda)

ACTIVE SINCE: 2021 · 2 MAJOR OPERATIONS

State-sponsored threat actor focused on stealth pre-positioning within critical infrastructure networks to enable disruptive kinetic or cyber sabotage.

MOTIVATION: sabotageCONFIRMED ATTRIBUTION
ORIGIN: Russian Federation active

Sandworm (Unit 74455 / Main Center for Special Technologies)

ACTIVE SINCE: 2009 · 3 MAJOR OPERATIONS

The Russian military intelligence agency’s premier cyber-sabotage unit, notorious for devastating wiper malware, power grid blackouts, and NotPetya.

MOTIVATION: sabotageCONFIRMED ATTRIBUTION
ORIGIN: Russian Federation active

Midnight Blizzard (APT29 / Nobelium / Cozy Bear)

ACTIVE SINCE: 2008 · 2 MAJOR OPERATIONS

Elite Russian Foreign Intelligence Service (SVR) cyber espionage apparatus celebrated for high-level government infiltration, SolarWinds supply chain poisoning, and cloud token manipulation.

MOTIVATION: espionageCONFIRMED ATTRIBUTION
ORIGIN: United States / United Kingdom / Canada active

Scattered Spider (UNC3944 / Octo Tempest / Starfraud)

ACTIVE SINCE: 2022 · 1 MAJOR OPERATIONS

Hyper-aggressive, English-speaking cybercrime syndicate mastering identity provider compromise, SIM swapping, helpdesk social engineering, and cloud infrastructure ransom.

MOTIVATION: financialCONFIRMED ATTRIBUTION