Skip to content
Weekly Signal

Evidence-linked profiles

Threat Actors

Named groups and tracked identifiers found across current reporting. Aliases are normalised so related activity is easier to follow.

Profiles connect names, aliases, history and current evidence.
Attribution needs care.Profiles reflect names used by source reporting. Open the original reports before relying on attribution for an operational decision.

Highest signal 49

STORM-2945

Also tracked as STORM-2945

STORM-2945 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
3
Sources
2

Defence · Government · Healthcare

Open profile →

Highest signal 49

APT29

Also tracked as APT29, Cozy Bear, Midnight Blizzard, NOBELIUM

APT29 is a Russian state-linked espionage group attributed by governments and security researchers to the Russian Foreign Intelligence Service, the SVR. It has targeted government, diplomatic, policy, technology and research organisations, often…

Reports
5
Sources
2

Defence · Government · Healthcare

Open profile →

Highest signal 49

UNC6293

Also tracked as UNC6293

UNC6293 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence · Government · Healthcare

Open profile →

Highest signal 49

UNC7005

Also tracked as UNC7005

UNC7005 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence · Government · Healthcare

Open profile →

Highest signal 49

UNC5976

Also tracked as UNC5976

UNC5976 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence · Government · Healthcare

Open profile →

Highest signal 49

UNC6671

Also tracked as UNC6671

UNC6671 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence · Financial services

Open profile →

Highest signal 49

UNC4736

Also tracked as UNC4736

UNC4736 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

No sector confidently resolved

Open profile →

Highest signal 49

UNC6780

Also tracked as UNC6780

UNC6780 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence · Manufacturing

Open profile →

Highest signal 49

UNC1069

Also tracked as UNC1069

UNC1069 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
2
Sources
1

Defence

Open profile →

Highest signal 49

Sandworm

Also tracked as Sandworm, Seashell Blizzard

Sandworm is a Russian state-linked group associated by governments with the GRU. It is known for espionage, disruptive and destructive operations, with a particularly strong focus on Ukraine and critical infrastructure. Public…

Reports
1
Sources
1

Defence · Energy

Open profile →

Highest signal 49

FIN7

Also tracked as FIN7

FIN7 is a financially motivated group known for targeting payment environments and enterprise networks, particularly in retail, hospitality and related industries. Reported methods include social engineering, malicious documents, point-of-sale targeting, custom malware…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT28

Also tracked as APT28, Fancy Bear, Forest Blizzard, Sofacy

APT28 is a Russian state-linked espionage group associated by multiple governments with the Main Intelligence Directorate of the Russian General Staff, the GRU. Reporting commonly connects the group with operations against governments,…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT40

Also tracked as APT40, Leviathan

APT40 is a China-linked espionage group reported to target organisations connected with maritime affairs, defence, research, engineering, government and strategic infrastructure. Public reporting describes phishing and the exploitation of vulnerable internet-facing systems…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT41

Also tracked as APT41, Double Dragon

APT41 is a China-linked threat group associated with both state-aligned espionage and financially motivated activity. Reporting spans government, healthcare, telecommunications, technology, gaming, travel and retail targets. The group has used phishing, software…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT33

Also tracked as APT33

APT33 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT34

Also tracked as APT34

APT34 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT35

Also tracked as APT35, Charming Kitten, Mint Sandstorm

APT35 is an Iran-linked espionage group associated in public reporting with operations against government, defence, academia, media, technology and civil-society targets. The group is well known for social engineering and credential-focused campaigns…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT39

Also tracked as APT39

APT39 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT42

Also tracked as APT42

APT42 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT37

Also tracked as APT37

APT37 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT45

Also tracked as APT45

APT45 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT15

Also tracked as APT15

APT15 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

APT20

Also tracked as APT20

APT20 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →

Highest signal 49

UNC1088

Also tracked as UNC1088

UNC1088 is an identifier found in current source reporting. Threat-research teams may use different names for overlapping activity, and the available evidence does not always support a permanent or universally agreed group…

Reports
1
Sources
1

Defence

Open profile →