
Profiles of 27+ known cyber threat actors — nation-state APTs, ransomware gangs, and organised crime groups — with mapped TTPs and target sectors.
A six-tier classification of adversary sophistication — from opportunistic to nation-state.
27 groups profiled with TTPs and target sectors.
BRONZE MOHAWK / Kryptonite Panda / TEMP.Periscope
APT40 is a Chinese state-sponsored threat group under the MSS. Publicly attributed by Australian, US, and UK governments in 2021 and 2024. Known for rapid exploitation of newly disclosed CVEs and deep persistence within government, maritime, and defence networks.

Fancy Bear / Sofacy / Sednit / Forest Blizzard / Strontium
APT28, also known as Fancy Bear, is a Russian GRU cyber espionage group responsible for high-profile breaches including the 2016 US election interference, the French election attack, and ongoing targeting of NATO member governments. One of the most prolific and sophisticated state-sponsored groups in operation.

Cozy Bear / The Dukes / Midnight Blizzard / Yttrium
APT29 is the SVR's primary cyber espionage arm, responsible for the SolarWinds supply chain attack (2020), Microsoft executive email breach (2024), and sustained operations against Western intelligence services. Known for extreme patience and operational sophistication.

Lazarus Group / Bluenoroff / Stardust Chollima / Sapphire Sleet
APT38 / Lazarus Group is North Korea's primary financially motivated cyber unit, responsible for the $81M Bangladesh Bank heist, the WannaCry ransomware attack, and billions in cryptocurrency theft. They target financial institutions globally to fund the DPRK regime under UN sanctions.
Earth Estries / Salt Typhoon / GhostEmperor
FamousSparrow / Salt Typhoon is the MSS operation responsible for compromising US telecommunications carriers including AT&T and Verizon, accessing CALEA lawful intercept infrastructure. Assessed as a top-tier supply chain threat with long-term access to carrier backbone systems.
BRONZE SILHOUETTE / Vanguard Panda
Volt Typhoon is a PLA operation pre-positioning on US and allied critical infrastructure — water, power, transport, and communications. Publicly attributed by CISA and Five Eyes partners. Assessed as preparing for disruptive strikes at the onset of a military conflict over Taiwan.
LockBit 3.0 / LockBit Black
LockBit is the world's most prolific ransomware-as-a-service operation by victim count, responsible for thousands of attacks globally including major Australian organisations. Disrupted by Operation Cronos (Feb 2024) but subsequently relaunched as LockBit 3.0.

Cyclops / Knight
RansomHub emerged in 2024 and rapidly became one of the most active RaaS platforms after the LockBit law enforcement action, absorbing many former LockBit and BlackCat affiliates. Responsible for attacks on US critical infrastructure including Change Healthcare and Christie's auction house.

BlackCat
ALPHV/BlackCat is a sophisticated RaaS operation notable as the first widely deployed ransomware written in Rust, enabling cross-platform attacks. Responsible for the Change Healthcare attack (2024) costing billions in healthcare disruption. Disrupted by FBI in late 2023 but continued operations under a new affiliate model.

Royal Ransomware / Conti
BlackSuit is widely assessed as the rebrand of Royal Ransomware, itself formed from former Conti members following Conti's dissolution in 2022. Responsible for attacks on Dallas city systems and several critical infrastructure organisations. Uses selective encryption for high-speed deployment.

Rhysida Ransomware Group
Rhysida emerged in mid-2023 and quickly became prolific, targeting healthcare and education institutions. Notable for conducting auctions of stolen data on their dark web leak site. Responsible for attacks on the British Library, Lurie Children's Hospital, and multiple Australian health services.

Akira
Akira emerged in 2023 and rapidly accumulated over 250 victims across North America, Europe, and Australia. Known for targeting Cisco VPN vulnerabilities and for their retro 1980s-style ASCII art dark web site. Uses a Linux variant targeting VMware ESXi environments.
UNC3944 / 0ktapus / Scatter Swine
Scattered Spider is a financially motivated group notorious for sophisticated telephony-based social engineering. They bypass MFA through SIM swapping, help desk impersonation, and real-time phishing proxies. Responsible for breaches of MGM Resorts, Caesars Entertainment, and multiple APAC financial institutions.

DEV-0537 / Strawberry Tempest / Slippy Spider
LAPSUS$ is a loosely organised extortion group that recruited insiders and used social engineering to breach Microsoft, Nvidia, Samsung, Okta, and Uber. Notably young members (including teenagers) achieved access to major tech companies' source code repositories. Disrupted by UK/Brazil law enforcement in 2022.

TA505 / Clop
Cl0p is a prolific ransomware operation best known for mass exploitation of zero-day vulnerabilities in enterprise file transfer tools. The MOVEit Transfer zero-day (2023) gave them access to data from hundreds of organisations including Australian superannuation funds, government agencies, and global enterprises.

IntelBroker
IntelBroker is a prolific threat actor known for compromising and selling data from major US government agencies, tech companies, and global enterprises. Responsible for breaches of Apple, AMD, Europol, and multiple US government departments. Operates primarily on BreachForums.

White Dev 100
ShinyHunters is a prolific data theft group responsible for breaches of Ticketmaster (560M records), Snowflake customer accounts, AT&T, and numerous SaaS platforms. They exploit misconfigured cloud storage and weak authentication on cloud-hosted databases.

Scattered Spider (related) / Snowflake threat cluster
UNC5537 is the threat cluster identified by Mandiant as responsible for the mass Snowflake credential theft campaign (2024), affecting 165+ organisations including Ticketmaster, Santander, and AT&T. They used info-stealer malware to harvest credentials then authenticated without MFA.

BianLian Ransomware Group
BianLian pivoted from ransomware to pure extortion in 2023 after the FBI released a decryptor. They gain access via compromised RDP credentials, conduct extensive reconnaissance, and exfiltrate data to leverage extortion threats. Active against Australian and US healthcare and professional services.

Agenda Ransomware
Qilin (Agenda) is a RaaS operation using Rust and Go-based ransomware, making it highly portable across Windows and Linux. Responsible for the attack on UK NHS blood transfusion services (2024), causing critical disruptions to patient care across London hospitals.

BlackBasta Ransomware
BlackBasta emerged in April 2022 from former Conti members and rapidly became a top-tier ransomware threat. Known for using QakBot malware for initial access and deploying encryption within 48 hours of compromise. Internal chat logs leaked in 2025 revealed sophisticated operations against CISA and global enterprises.

Vice Spider / DEV-0832 / Vanilla Tempest
Vice Society is a ransomware operator with a strong focus on education and healthcare, including attacks on the LA Unified School District and multiple UK NHS trusts. They use pre-existing ransomware variants (HelloKitty, BlackCat) rather than custom code, and are known for rapid escalation to extortion.

BlackByte Ransomware Group
BlackByte is a ransomware group that has attacked multiple US critical infrastructure entities including the San Francisco 49ers. Known for using a self-propagating worm to spread across networks and for exploiting ProxyShell vulnerabilities in Microsoft Exchange.

Monti Ransomware
Monti Gang is a ransomware group that emerged using the leaked Conti source code, targeting government, legal, and public sector organisations. Active against Australian and NZ law firms and local government entities.

Brain Cipher Ransomware
Brain Cipher is a newer ransomware group responsible for the attack on Indonesia's National Data Centre (2024), disrupting 282 government agencies. They demanded $8M ransom before later releasing the decryption key for free — raising speculation about their true motives.

INC Ransomware
Inc Ransom emerged in 2023 and targets healthcare, education, and government sectors. They use an unusual tactic of publishing partial data previews on their leak site before the ransom deadline as pressure. Responsible for attacks on NHS Scotland and multiple US health systems.

Spider Threat Actor
Sp1d3r is a data theft threat actor active on criminal forums, known for selling large databases of customer PII from compromised organisations. They appear to exploit third-party integrations and cloud storage misconfigurations rather than deploying ransomware.
In-depth assessment — Volt, Flax & Salt Typhoon campaign against US telecommunications carriers
Assessed: Most Significant Telecommunications Security Breach in US History
Between 2022 and 2024, three distinct Chinese state-sponsored groups — Volt Typhoon, Flax Typhoon, and Salt Typhoon — conducted coordinated but operationally distinct campaigns against US telecommunications carriers. Collectively they achieved access to core routing infrastructure, lawful intercept systems, and communications of senior government officials. The FBI recommended all senior officials switch to end-to-end encrypted communications as a direct consequence.
Volt Typhoon
Pre-position for disruption
Flax Typhoon
Covert relay infrastructure (KV-Botnet)
Salt Typhoon
Intercept lawful surveillance systems
Step through interactive attack chains and learn which defensive controls would stop each phase.
Step 1 — Select a Threat Actor
Real-time CVEs and active adversary TTPs targeting Australian organisations — updated continuously.
CVE data is AI-synthesised from public NVD and ACSC sources for situational awareness. TTP profiles are curated from ASD advisories, ACSC alerts, and open-source threat intelligence. For authoritative advisories, consult cyber.gov.au.
Classification Notice: Threat actor profiles are derived from open-source intelligence including MITRE ATT&CK, CISA advisories, FBI flash alerts, and public security research. Operational indicators of compromise (IoCs) and classified attribution are available under formal engagement.
Intelligence-Led Defence
Understand which adversary groups are likely to target your sector, and what capabilities they bring to bear.
Request a Confidential Briefing