← Pwnsy Data

Threat Groups

APTs, ransomware cartels, and sanctioned actors — merged from MITRE ATT&CK, MISP, ransomwatch and OFAC/UK-NCA sanctions lists. Featured nation-state briefings first, then the full searchable database.

Featured Briefings
DPRK Crypto Heists
$3.04B
stolen, tracked
8
major heists
6
named units
  • $1.46BBybitExchangeLazarus / TraderTraitor2025-02 source
  • $624MRonin Network (Axie Infinity)ValidatorLazarus / APT382022-03 source
  • $281MKuCoinExchangeLazarus (suspected)2020-09 source
  • $235MWazirXExchangeLazarus (suspected)2024-07 source
  • $200MAlphaPo / CoinsPaid / Atomic WalletWalletBlueNoroff2023-07 source
  • $100MAtomic Wallet usersWalletLazarus2023-06 source
  • $100MHarmony Horizon BridgeBridgeLazarus / TraderTraitor2022-06 source
  • $41MStake.comExchangeLazarus2023-09 source
UnitTagsAffiliationActivity
Lazarus GroupOFFICIALaka HIDDEN COBRA · APT38 (umbrella) · Guardians of Peace · ZINC · Diamond SleetOFACOffice of Foreign Assets Control — the US Treasury arm that imposes sanctions; OFAC-listed groups are illegal to pay ransoms to. 2019MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0032Reconnaissance General Bureau (RGB)Umbrella for DPRK state-sponsored cyber ops; financial theft + espionage. Hit Sony, WannaCry, plus the bulk of the heists below.
APT38aka BeagleBoyz · Bluenoroff (operational arm) · Stardust ChollimaMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0082Lazarus / RGBBank-heist specialists. Original SWIFT attacks (Bangladesh Bank $81M, 2016) and the original FASTCash ATM cash-outs.
BlueNoroffaka APT38 sub-unit · Stardust Chollima · Sapphire Sleet · TA444MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G1032Lazarus / RGBCrypto-exchange and DeFi operator since ~2018. SnatchCrypto campaign, fake-VC LinkedIn lures. Behind Ronin and AlphaPo.
AndarielOFFICIALaka Silent Chollima · PLUTONIUM · Onyx Sleet · StoneflyOFACOffice of Foreign Assets Control — the US Treasury arm that imposes sanctions; OFAC-listed groups are illegal to pay ransoms to. 2019MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0138Lazarus / RGBMixed: Maui ransomware against US healthcare, dual-use crypto theft for revenue.
Kimsukyaka Velvet Chollima · Black Banshee · Emerald Sleet · THALLIUMMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0094RGB (separate from Lazarus)Espionage-focused (think tanks, defectors, nuclear policy) but increasingly mixes in crypto-credential theft.
AppleJeus / TraderTraitorOFFICIALaka Lazarus crypto trojan campaignLazarusLong-running fake crypto-trading-app campaign (UnionCryptoTrader, JMTTrader). FBI publicly tied to Harmony Bridge theft.
China State APTs — Espionage + Pre-Positioning
ActorTagsAffiliationActivity
Volt TyphoonOFFICIALaka VANGUARD PANDA · BRONZE SILHOUETTE · Insidious TaurusMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G1017PLA / MSS-aligned (CISA assesses)Pre-positions in US critical infrastructure (energy, water, transport, comms) using living-off-the-land techniques. Goal: disruptive options in a Taiwan crisis. CISA + FBI + NSA joint advisory Feb 2024.
Salt TyphoonOFFICIALaka GhostEmperor · FamousSparrow · Earth EstriesMSS-linkedBreached at least 9 US telecom carriers (Verizon, AT&T, T-Mobile, Lumen…) in 2024 — accessed CALEA wiretap systems and intercepted communications of Trump/Harris campaigns and senior US officials. Largest-ever US telecom hack per FCC.
APT41OFFICIALaka BARIUM · Winnti · Wicked Panda · BRONZE ATLASDOJ-indicted 2020MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0096Chengdu 404 (DOJ-indicted, 2020)Dual hat — state espionage by day, cybercrime by night (game-studio supply-chain hits, crypto theft). 5 members indicted by DOJ Sept 2020.
APT1OFFICIALaka Comment Crew · PLA Unit 61398 · Comment PandaDOJ-indicted 2014MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0006PLA Unit 61398 (Shanghai)First publicly-attributed PLA APT — Mandiant 2013 report exposed 7-year IP-theft campaign across 141 victims. 5 PLA officers DOJ-indicted 2014.
Mustang PandaOFFICIALaka RedDelta · BRONZE PRESIDENT · TA416 · Earth PretaMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0129MSS-linkedPlugX backdoor specialist; targets European governments, EU foreign ministries, NGOs working in Asia. DOJ + FBI court-authorized takedown of PlugX on 4,200+ US machines, Jan 2025.
APT40OFFICIALaka Leviathan · BRONZE MOHAWK · GADOLINIUM · TEMP.PeriscopeDOJ-indicted 2021MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0065MSS Hainan Provincial State Security DeptMaritime/naval espionage. 4 MSS officers DOJ-indicted 2021 for hacking 12+ countries' research orgs.
Russia State APTs — GRU + SVR + FSB
ActorTagsAffiliationActivity
APT28OFFICIALaka Fancy Bear · Sofacy · STRONTIUM · Forest Blizzard · Pawn StormOFACOffice of Foreign Assets Control — the US Treasury arm that imposes sanctions; OFAC-listed groups are illegal to pay ransoms to. 2016MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0007GRU Unit 26165 (85th GTsSS)Election interference (DNC 2016), WADA, OPCW. 7 GRU officers DOJ-indicted 2018; EU + UK sanctioned 2020.
APT29OFFICIALaka Cozy Bear · The Dukes · NOBELIUM · Midnight Blizzard · BlueBravoOFACOffice of Foreign Assets Control — the US Treasury arm that imposes sanctions; OFAC-listed groups are illegal to pay ransoms to. 2021MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0016SVR (Foreign Intelligence Service)SolarWinds supply-chain compromise (2020) — 18,000 orgs poisoned, 9 federal agencies confirmed breached. Re-emerged 2024 to breach Microsoft corporate email (HPE, Microsoft executives).
SandwormOFFICIALaka BlackEnergy · Voodoo Bear · TeleBots · IRIDIUM · Seashell BlizzardDOJ-indicted 2020MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0034GRU Unit 74455 (Main Centre for Special Technologies)The destructive arm. Ukraine power-grid attacks (2015, 2016), NotPetya ($10B+ damage, 2017), 2018 Olympics opening-ceremony wiper. 6 GRU officers DOJ-indicted 2020.
TurlaOFFICIALaka Snake · Venomous Bear · Uroburos · Secret BlizzardMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0010FSB Center 16Quietest of the three — 25+ year run. Snake malware dismantled by FBI Operation MEDUSA, May 2023.
Gamaredonaka Primitive Bear · Trident Ursa · Aqua Blizzard · ACTINIUMMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0047FSB Center 18 (Crimea)Ukraine-focused since 2014; high-volume / lower-stealth. Most prolific actor against Ukrainian government per CERT-UA.
Iran State APTs — IRGC + MOIS
ActorTagsAffiliationActivity
APT33aka Elfin · Refined Kitten · Magnallium · Peach SandstormMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0064IRGC-linkedAerospace + petrochemical targeting (US/Saudi). Linked to the Shamoon wiper that destroyed 30,000 Saudi Aramco workstations (2012).
APT34aka OilRig · Helix Kitten · Hazel Sandstorm · Cobalt GypsyMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0049MOISLong-running Middle-East telecom + financial espionage. Source code leaked publicly via 'Lab Dookhtegan' Telegram, 2019.
APT35OFFICIALaka Charming Kitten · Phosphorus · Mint Sandstorm · NewscasterDOJ-indicted 2024MITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0059IRGC-IOSpear-phishes academics, journalists, US officials and 2020 / 2024 election campaigns. DOJ-indicted 4 IRGC members Sep 2024 for hacking Trump campaign.
MuddyWaterOFFICIALaka Static Kitten · Mango Sandstorm · TEMP.Zagros · MercuryMITREMITRE ATT&CK — the standard catalog of attacker techniques and named threat-actor groups. G0069MOISGovernment-targeting espionage across Middle East + Asia. CYBERCOM publicly attributed 2022.
Pioneer KittenOFFICIALaka Fox Kitten · PARISITE · UNC757 · Lemon SandstormIRGC-affiliated contractorInitial-access broker — sells footholds to ransomware affiliates (NoEscape, RansomHouse, ALPHV). FBI flash advisory Aug 2024.
Ransomware Cartels
CartelStatusEst. revenueCurrent stateNotable hits
LockBitOFFICIALaka LockBit 2.0/3.0/BlackDISRUPTED$120M+ (DOJ est.)Op Cronos (NCA + FBI + Europol, Feb 2024) seized infra, leaked decryptors. Admin 'LockBitSupp' (Dmitry Khoroshev) doxxed + sanctioned May 2024. Limping but not dead.Largest RaaS by volume 2022–2024. Hit Boeing, ICBC, UK Royal Mail, US/UK governments via ConnectWise.
ALPHV / BlackCatOFFICIALaka NoberusEXIT-SCAMMED$300M+ (FBI)Exit-scammed Mar 2024 after collecting $22M ransom from Change Healthcare and stiffing affiliate. Operators rebranded as RansomHub.First major Rust-based ransomware. Hit Change Healthcare ($22M paid), MGM Resorts, Reddit.
Cl0pOFFICIALaka TA505 affiliateACTIVEPivoted to mass-exploitation of file-transfer 0-days: Accellion FTA, GoAnywhere, MOVEit (2,700+ victims), Cleo (2024).MOVEit campaign (May 2023) hit US DoE, BBC, British Airways, Shell — possibly the most prolific single ransomware op ever.
ContiOFFICIALaka Wizard Spider (lineage)REBRANDED$180M (Chainalysis 2021)Imploded May 2022 after pro-Russia stance triggered 'Conti Leaks' (insider dumped chats + source). Affiliates respawned as BlackBasta, Karakurt, Royal/BlackSuit, Akira.Hit Costa Rica's government (forced national emergency, 2022) and Ireland's HSE healthcare system.
RansomHubOFFICIALaka ALPHV rebootACTIVEAscendant 2024–2025. Picked up the affiliates orphaned by ALPHV exit-scam and LockBit takedown.Hit Halliburton, Frontier Comms, Christie's, Patelco Credit Union.
PlayOFFICIALaka PlayCrypt · BalloonflyACTIVEClosed-shop crew (no public affiliates). 300+ victims since 2022 incl. Rackspace, Arnold Clark, City of Oakland.Steady drumbeat of mid-market victims; less flashy than LockBit but very persistent.
AkiraOFFICIALaka Conti splinterACTIVEConti-lineage operators. FBI / CISA estimate $42M+ collected from 250+ orgs as of early 2024.Heavy on small/mid US + EU manufacturers and law firms.
Scattered SpiderOFFICIALaka UNC3944 · Octo Tempest · 0ktapus · Muddled LibraACTIVENative English-speaking teen/young-adult crew (US + UK). Social-engineers help-desks for MFA reset; partners with ALPHV / RansomHub for the encryptor.MGM Resorts ($100M cost), Caesars ($15M paid), Marks & Spencer, Coop UK, Snowflake-customer mass campaign.
Landmark Campaigns
  1. 2025-02
    Bybit $1.46B heistLazarus / TraderTraitor (DPRK)
    Largest crypto theft in history; multi-sig wallet UI compromise, drained ETH to mixers within hours.
  2. 2024-10
    Compromised 9+ US carriers, accessed CALEA lawful-intercept systems, snooped on senior officials and presidential campaigns.
  3. 2024-06
    Snowflake customer breachesScattered Spider / UNC5537
    Stolen credentials → no-MFA Snowflake tenants. 165+ orgs (AT&T, Ticketmaster, Santander, Advance Auto Parts) lost data.
  4. 2024-03
    XZ Utils backdoor (CVE-2024-3094)'Jia Tan' (suspected state-aligned long-con)
    Multi-year social-engineering of an open-source maintainer to plant SSH-bypass backdoor in xz/liblzma. Caught by Microsoft engineer pre-release.
  5. 2024-02
    $22M ransom paid; 100M+ patient records leaked when ALPHV stiffed its affiliate. Disrupted US pharmacy/insurance billing for weeks.
  6. 2023-09
    MGM + CaesarsScattered Spider + ALPHV
    Help-desk vishing → admin reset → encryption. MGM lost $100M; Caesars paid $15M.
  7. 2023-05
    0-day SQLi (CVE-2023-34362) used to exfil data from 2,700+ orgs incl. US DoE, BBC, British Airways, Shell, Sony.
  8. 2022-03
    Ronin Bridge $624MLazarus / APT38 (DPRK)
    Compromised 5 of 9 validator keys via fake-job lure on Sky Mavis engineer. First $-billion-class crypto heist.
  9. 2021-12
    Log4Shell (CVE-2021-44228)Multiple (criminal + state)
    Trivial RCE in Log4j logging library; near-universal Java exposure. Patched globally over months; long-tail exploitation continues.
  10. 2021-05
    Single leaked VPN password → 5-day shutdown of US East-Coast fuel supply. $4.4M paid; FBI clawed back $2.3M.
  11. 2020-12
    Trojanized SolarWinds Orion update reached 18,000 orgs; 9 US federal agencies + Microsoft, FireEye confirmed breached.
  12. 2017-06
    NotPetyaSandworm (GRU)
    Wiper disguised as ransomware via M.E.Doc supply chain in Ukraine; spread globally. Maersk + Merck + FedEx-TNT alone took ~$3B in damage. Total: $10B+.
  13. 2017-05
    WannaCryLazarus (DPRK)
    EternalBlue worm + leaked NSA exploit. 200K+ machines in 150 countries; UK NHS hardest hit.
All Threat Actors
MITRE ATT&CK + MISP + ransomwatch + sanctions