Threat Intelligence

Threat Actor Groups

Profiles of 27+ known cyber threat actors — nation-state APTs, ransomware gangs, and organised crime groups — with mapped TTPs and target sectors.

FEISTY FOX :: GLOBAL THREAT MONITOR v2.4.1
● 15 ACTIVE THREATSUPLINK: NOMINAL
SECTOR::APACSECTOR::EMEASECTOR::AMERTARGET::AUTARGET::USTARGET::EUAPT40CHINAAPT28RUSSIAAPT29RUSSIAVOLT_TYPHOONCHINAAPT38N. KOREAFAMOUSSPARROWCHINALOCKBITRUSSIARANSOMHUBUNKNOWNCL0PRUSSIASCATTERED_SPIDERWORLDWIDESHINYHUNTERSUNKNOWNINTELBROKERUNKNOWNRHYSIDAUNKNOWNAKIRAUNKNOWNALPHVRUSSIAAU_NODEUS_NODEEU_NODE
Nation State (L6)
Supply Chain (L5)
APT/RaaS (L4)
Exfil (L3)

HOVER NODE FOR TTP SIGNATURE

LIVE ATTACK TELEMETRY
INITIALISING SENSOR ARRAY...
EVENTS/MIN147
ACTIVE C231
COUNTRIES12

Threat Levels: Cyber Adversary Capabilities

A six-tier classification of adversary sophistication — from opportunistic to nation-state.

Level 1 — LowestLevel 6 — Highest

Profiled Threat Actors

27 groups profiled with TTPs and target sectors.

27 of 27 actors
6
Level 6 — Full-Spectrum State Actor

APT40

BRONZE MOHAWK / Kryptonite Panda / TEMP.Periscope

People's Republic of China (MSS Hainan)Maritime, defence & government espionage

APT40 is a Chinese state-sponsored threat group under the MSS. Publicly attributed by Australian, US, and UK governments in 2021 and 2024. Known for rapid exploitation of newly disclosed CVEs and deep persistence within government, maritime, and defence networks.

APT28
Level 6 — Full-Spectrum State Actor

APT28

Fancy Bear / Sofacy / Sednit / Forest Blizzard / Strontium

Russia (GRU Unit 26165)Political espionage, election interference, NATO targeting

APT28, also known as Fancy Bear, is a Russian GRU cyber espionage group responsible for high-profile breaches including the 2016 US election interference, the French election attack, and ongoing targeting of NATO member governments. One of the most prolific and sophisticated state-sponsored groups in operation.

APT29
Level 6 — Full-Spectrum State Actor

APT29

Cozy Bear / The Dukes / Midnight Blizzard / Yttrium

Russia (SVR Foreign Intelligence Service)Long-term intelligence collection from government & diplomatic targets

APT29 is the SVR's primary cyber espionage arm, responsible for the SolarWinds supply chain attack (2020), Microsoft executive email breach (2024), and sustained operations against Western intelligence services. Known for extreme patience and operational sophistication.

APT38
Level 6 — Full-Spectrum State Actor

APT38

Lazarus Group / Bluenoroff / Stardust Chollima / Sapphire Sleet

North Korea (Reconnaissance General Bureau)Financial theft for regime funding & destructive cyber attacks

APT38 / Lazarus Group is North Korea's primary financially motivated cyber unit, responsible for the $81M Bangladesh Bank heist, the WannaCry ransomware attack, and billions in cryptocurrency theft. They target financial institutions globally to fund the DPRK regime under UN sanctions.

5
Level 5 — Supply Chain / State Actor

FamousSparrow

Earth Estries / Salt Typhoon / GhostEmperor

China (MSS)Telecommunications carrier infiltration & lawful intercept compromise

FamousSparrow / Salt Typhoon is the MSS operation responsible for compromising US telecommunications carriers including AT&T and Verizon, accessing CALEA lawful intercept infrastructure. Assessed as a top-tier supply chain threat with long-term access to carrier backbone systems.

6
Level 6 — Full-Spectrum State Actor

Volt Typhoon

BRONZE SILHOUETTE / Vanguard Panda

China (PLA)Pre-positioning on critical infrastructure for conflict enablement

Volt Typhoon is a PLA operation pre-positioning on US and allied critical infrastructure — water, power, transport, and communications. Publicly attributed by CISA and Five Eyes partners. Assessed as preparing for disruptive strikes at the onset of a military conflict over Taiwan.

4
Level 4 — Ransomware-as-a-Service

LockBit

LockBit 3.0 / LockBit Black

RussiaHigh-volume ransomware operations across all sectors

LockBit is the world's most prolific ransomware-as-a-service operation by victim count, responsible for thousands of attacks globally including major Australian organisations. Disrupted by Operation Cronos (Feb 2024) but subsequently relaunched as LockBit 3.0.

RansomHub
Level 4 — Ransomware-as-a-Service

RansomHub

Cyclops / Knight

UnknownRapidly growing RaaS platform targeting critical infrastructure

RansomHub emerged in 2024 and rapidly became one of the most active RaaS platforms after the LockBit law enforcement action, absorbing many former LockBit and BlackCat affiliates. Responsible for attacks on US critical infrastructure including Change Healthcare and Christie's auction house.

ALPHV
Level 4 — Ransomware-as-a-Service

ALPHV

BlackCat

RussiaCross-platform ransomware targeting Windows, Linux, and VMware ESXi

ALPHV/BlackCat is a sophisticated RaaS operation notable as the first widely deployed ransomware written in Rust, enabling cross-platform attacks. Responsible for the Change Healthcare attack (2024) costing billions in healthcare disruption. Disrupted by FBI in late 2023 but continued operations under a new affiliate model.

BlackSuit
Level 4 — Ransomware-as-a-Service

BlackSuit

Royal Ransomware / Conti

Unknown (ex-Conti members)Enterprise ransomware operations targeting critical sectors

BlackSuit is widely assessed as the rebrand of Royal Ransomware, itself formed from former Conti members following Conti's dissolution in 2022. Responsible for attacks on Dallas city systems and several critical infrastructure organisations. Uses selective encryption for high-speed deployment.

Rhysida
Level 4 — Ransomware-as-a-Service

Rhysida

Rhysida Ransomware Group

UnknownHealthcare and education ransomware with auction-based extortion

Rhysida emerged in mid-2023 and quickly became prolific, targeting healthcare and education institutions. Notable for conducting auctions of stolen data on their dark web leak site. Responsible for attacks on the British Library, Lurie Children's Hospital, and multiple Australian health services.

Akira Ransomware Gang
Level 4 — Ransomware-as-a-Service

Akira Ransomware Gang

Akira

UnknownSME and enterprise ransomware with retro-aesthetic leak site

Akira emerged in 2023 and rapidly accumulated over 250 victims across North America, Europe, and Australia. Known for targeting Cisco VPN vulnerabilities and for their retro 1980s-style ASCII art dark web site. Uses a Linux variant targeting VMware ESXi environments.

4
Level 4 — Advanced Persistent Threat (APT)

Scattered Spider

UNC3944 / 0ktapus / Scatter Swine

Anglophone Cybercriminal NetworkSocial engineering, MFA bypass & ransomware deployment

Scattered Spider is a financially motivated group notorious for sophisticated telephony-based social engineering. They bypass MFA through SIM swapping, help desk impersonation, and real-time phishing proxies. Responsible for breaches of MGM Resorts, Caesars Entertainment, and multiple APAC financial institutions.

LAPSUS$
Level 4 — Advanced Persistent Threat (APT)

LAPSUS$

DEV-0537 / Strawberry Tempest / Slippy Spider

Worldwide (primarily UK/Brazil)Source code theft and insider recruitment via social engineering

LAPSUS$ is a loosely organised extortion group that recruited insiders and used social engineering to breach Microsoft, Nvidia, Samsung, Okta, and Uber. Notably young members (including teenagers) achieved access to major tech companies' source code repositories. Disrupted by UK/Brazil law enforcement in 2022.

Cl0p
Level 4 — Ransomware-as-a-Service

Cl0p

TA505 / Clop

Russia / Ukraine (linked)Mass exploitation of zero-day vulnerabilities in file transfer platforms

Cl0p is a prolific ransomware operation best known for mass exploitation of zero-day vulnerabilities in enterprise file transfer tools. The MOVEit Transfer zero-day (2023) gave them access to data from hundreds of organisations including Australian superannuation funds, government agencies, and global enterprises.

IntelBroker
Level 3 — Data Exfiltration Specialist

IntelBroker

IntelBroker

UnknownHigh-profile data theft and sale on criminal forums

IntelBroker is a prolific threat actor known for compromising and selling data from major US government agencies, tech companies, and global enterprises. Responsible for breaches of Apple, AMD, Europol, and multiple US government departments. Operates primarily on BreachForums.

ShinyHunters
Level 3 — Data Exfiltration Specialist

ShinyHunters

White Dev 100

UnknownCloud storage and database breaches for data sale

ShinyHunters is a prolific data theft group responsible for breaches of Ticketmaster (560M records), Snowflake customer accounts, AT&T, and numerous SaaS platforms. They exploit misconfigured cloud storage and weak authentication on cloud-hosted databases.

UNC5537
Level 3 — Data Exfiltration Specialist

UNC5537

Scattered Spider (related) / Snowflake threat cluster

WorldwideIdentity-based attacks against cloud data warehouses

UNC5537 is the threat cluster identified by Mandiant as responsible for the mass Snowflake credential theft campaign (2024), affecting 165+ organisations including Ticketmaster, Santander, and AT&T. They used info-stealer malware to harvest credentials then authenticated without MFA.

BianLian
Level 4 — Ransomware-as-a-Service

BianLian

BianLian Ransomware Group

ChinaExtortion-only model after FBI/CISA released decryptor

BianLian pivoted from ransomware to pure extortion in 2023 after the FBI released a decryptor. They gain access via compromised RDP credentials, conduct extensive reconnaissance, and exfiltrate data to leverage extortion threats. Active against Australian and US healthcare and professional services.

Qilin
Level 4 — Ransomware-as-a-Service

Qilin

Agenda Ransomware

RussiaHealthcare and critical infrastructure ransomware

Qilin (Agenda) is a RaaS operation using Rust and Go-based ransomware, making it highly portable across Windows and Linux. Responsible for the attack on UK NHS blood transfusion services (2024), causing critical disruptions to patient care across London hospitals.

BlackBasta
Level 4 — Ransomware-as-a-Service

BlackBasta

BlackBasta Ransomware

Russia (ex-Conti members)Rapid enterprise-wide encryption using QakBot initial access

BlackBasta emerged in April 2022 from former Conti members and rapidly became a top-tier ransomware threat. Known for using QakBot malware for initial access and deploying encryption within 48 hours of compromise. Internal chat logs leaked in 2025 revealed sophisticated operations against CISA and global enterprises.

Vice Society
Level 4 — Ransomware-as-a-Service

Vice Society

Vice Spider / DEV-0832 / Vanilla Tempest

UnknownEducation and healthcare sector ransomware

Vice Society is a ransomware operator with a strong focus on education and healthcare, including attacks on the LA Unified School District and multiple UK NHS trusts. They use pre-existing ransomware variants (HelloKitty, BlackCat) rather than custom code, and are known for rapid escalation to extortion.

BlackByte
Level 4 — Ransomware-as-a-Service

BlackByte

BlackByte Ransomware Group

RussiaCritical infrastructure ransomware with self-propagating worm capability

BlackByte is a ransomware group that has attacked multiple US critical infrastructure entities including the San Francisco 49ers. Known for using a self-propagating worm to spread across networks and for exploiting ProxyShell vulnerabilities in Microsoft Exchange.

Monti Gang
Level 4 — Ransomware-as-a-Service

Monti Gang

Monti Ransomware

UnknownPublic sector and legal targeting with Conti codebase

Monti Gang is a ransomware group that emerged using the leaked Conti source code, targeting government, legal, and public sector organisations. Active against Australian and NZ law firms and local government entities.

Brain Cipher
Level 4 — Ransomware-as-a-Service

Brain Cipher

Brain Cipher Ransomware

UnknownGovernment and critical infrastructure targeting

Brain Cipher is a newer ransomware group responsible for the attack on Indonesia's National Data Centre (2024), disrupting 282 government agencies. They demanded $8M ransom before later releasing the decryption key for free — raising speculation about their true motives.

Inc Ransom
Level 4 — Ransomware-as-a-Service

Inc Ransom

INC Ransomware

UnknownHealthcare and education ransomware with unusual partial-file leaks

Inc Ransom emerged in 2023 and targets healthcare, education, and government sectors. They use an unusual tactic of publishing partial data previews on their leak site before the ransom deadline as pressure. Responsible for attacks on NHS Scotland and multiple US health systems.

Sp1d3r
Level 3 — Data Exfiltration Specialist

Sp1d3r

Spider Threat Actor

UnknownDatabase theft and credential harvesting from cloud environments

Sp1d3r is a data theft threat actor active on criminal forums, known for selling large databases of customer PII from compromised organisations. They appear to exploit third-party integrations and cloud storage misconfigurations rather than deploying ransomware.

Operation: US Telco Breach

In-depth assessment — Volt, Flax & Salt Typhoon campaign against US telecommunications carriers

Assessed: Most Significant Telecommunications Security Breach in US History

Between 2022 and 2024, three distinct Chinese state-sponsored groups — Volt Typhoon, Flax Typhoon, and Salt Typhoon — conducted coordinated but operationally distinct campaigns against US telecommunications carriers. Collectively they achieved access to core routing infrastructure, lawful intercept systems, and communications of senior government officials. The FBI recommended all senior officials switch to end-to-end encrypted communications as a direct consequence.

Volt Typhoon

Pre-position for disruption

Flax Typhoon

Covert relay infrastructure (KV-Botnet)

Salt Typhoon

Intercept lawful surveillance systems

Simulation Lab

Step through interactive attack chains and learn which defensive controls would stop each phase.

Step 1 — Select a Threat Actor

Live Threat Intelligence

Australian Threat Landscape

Real-time CVEs and active adversary TTPs targeting Australian organisations — updated continuously.

CVE data is AI-synthesised from public NVD and ACSC sources for situational awareness. TTP profiles are curated from ASD advisories, ACSC alerts, and open-source threat intelligence. For authoritative advisories, consult cyber.gov.au.

Classification Notice: Threat actor profiles are derived from open-source intelligence including MITRE ATT&CK, CISA advisories, FBI flash alerts, and public security research. Operational indicators of compromise (IoCs) and classified attribution are available under formal engagement.

Intelligence-Led Defence

Commission a bespoke threat actor assessment

Understand which adversary groups are likely to target your sector, and what capabilities they bring to bear.

Request a Confidential Briefing
Feisty Fox LogoFeisty Fox Security

© 2026 Feisty Fox Security. All rights reserved.