Political, military and logistics collection against the US and NATO
Cyber threat actors targeting the US
Curated reference on state-sponsored APT groups from China, Russia, Iran and North Korea, plus financially motivated ransomware crews, their tactics, techniques and procedures (mapped to MITRE ATT&CK), and a timeline of recent public incidents. Sourced from CISA, Mandiant, Microsoft, and DOJ filings.
Top threat actors, activity and targets
Tracked state and criminal actors with their objectives, target sets, and techniques mapped to the MITRE ATT&CK framework.
Strategic intelligence collection against US government and cloud tenants
Revenue generation for the regime plus strategic collection
Strategic SIGINT collection against US carriers and senior officials
Identity-centric intrusion for extortion
Pre-position for disruption of US critical infrastructure in a Taiwan contingency
Ransomware against mid-market US businesses and municipalities
Double-extortion ransomware against high-impact US operators
Steal defense and nuclear technology, fund operations through ransomware
Surveillance of officials, campaigns, journalists, and dissidents
Naval, maritime, and defense research collection
Dual-mission espionage and financially motivated intrusion
Mass exploitation of file-transfer software for bulk extortion
Build and operate ORB relay infrastructure for obfuscated collection
Policy intelligence on US and allied Korea-watchers
Ransomware-as-a-service extortion at scale
Access and collection across government and telecom networks
Broker network access to ransomware affiliates while serving state collection
Destructive and disruptive effects against infrastructure
Credential theft against Russia-focused policy and civil-society targets
Long-dwell espionage against US government and defense research
Denial-of-service disruption for political signaling
Collection against US defense, aerospace, and energy targets
Publicized manipulation of small US utility control systems
Symbolic OT disruption at small US utilities
- T1078 Valid AccountsInitial Access18 actors
- T1190 Exploit Public-Facing ApplicationInitial Access13 actors
- T1486 Data Encrypted for ImpactImpact9 actors
- T1566.001 Spearphishing AttachmentInitial Access8 actors
- T1567.002 Exfiltration to Cloud StorageExfiltration7 actors
- T1114.002 Email Collection: Remote Email CollectionCollection6 actors
- T1071.001 Application Layer Protocol: Web ProtocolsCommand and Control5 actors
- T1505.003 Server Software Component: Web ShellPersistence5 actors
- T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement4 actors
Technique and group identifiers link to MITRE ATT&CK (Enterprise). ATT&CK is a registered trademark of The MITRE Corporation.
Volt Typhoon
PRC state-sponsored (MSS-aligned) · since Mid-2021
Pre-positioning operations against US critical infrastructure (water, energy, transport, communications) with the apparent goal of disruption during a Taiwan contingency.
- US critical infrastructure
- Guam telecom
- Water utilities
- Energy sector
- Initial Access: exploitation of edge devices (Fortinet, Cisco, Netgear)
- Persistence: web shells on perimeter routers/SOHO botnets
- Defense Evasion: living-off-the-land (LOLBins, no malware)
- Credential Access: LSASS dumping, ntds.dit theft
- Discovery: WMI / PowerShell network enumeration
Salt Typhoon
PRC state-sponsored (MSS contractor) · since 2020
Long-running telecom intrusion campaign. In 2024 breached multiple US carriers and accessed CALEA lawful-intercept systems, exposing communications of senior US officials.
- US telecom carriers
- ISPs
- Government communications
- Political campaigns
- Initial Access: Microsoft Exchange / edge router exploits
- Persistence: GhostSpider kernel rootkit
- Collection: SIGINT-style metadata exfiltration
- Command & Control: Demodex rootkit, custom HTTPS tunnels
Flax Typhoon
Integrity Technology Group (Beijing), MSS contractor · since Mid-2021
Built and operated the Raptor Train IoT botnet (260k+ devices) used for intermediate routing and operational obfuscation. Targets Taiwan especially.
- Taiwan government
- Education
- Manufacturing
- IoT/SOHO routers globally
- Initial Access: public-facing app exploitation (VPNs, IIS)
- Persistence: legitimate RMM tools (Sysinternals, SoftEther VPN)
- C2: Raptor Train botnet relay layer
APT41
MSS contractor (Chengdu 404) · since 2012
Dual-mission group conducting both state-directed espionage and financially motivated operations (game studios, cryptocurrency). 5 members indicted by DOJ in 2020.
- Healthcare
- Telecom
- Game studios
- Government
- Higher education
- Initial Access: supply-chain compromise (CCleaner, ASUS Live Update)
- Persistence: Winnti malware family, ShadowPad
- Lateral Movement: Cobalt Strike, custom loaders
APT40
MSS Hainan State Security Department · since 2009
Maritime, defense and naval research espionage in support of PRC modernization. 4 officers indicted by DOJ in 2021.
- Naval R&D
- Maritime industry
- Universities
- Biomedical research
- Defense contractors
- Initial Access: spearphishing, edge-device exploits (SOHO routers as ORBs)
- Discovery: rapid recon within hours of compromise
- Exfiltration: web shells, custom backdoors (BADFLICK, MURKYTOP)
APT31
MSS, Wuhan State Security Bureau · since 2010
Intellectual property and political intelligence collection. Indicted by DOJ in 2024 for targeting US political dissidents, journalists, and members of IPAC.
- Politicians
- Journalists
- Think tanks
- Aerospace
- Defense
- Initial Access: spearphishing with tracking pixels for recon
- Credential Access: home router compromise to harvest creds
- Collection: targeted mailbox exfiltration
APT10
MSS Tianjin State Security Bureau · since 2009
Operation Cloud Hopper, global managed service provider (MSP) compromise enabling downstream access to thousands of client organizations.
- Managed Service Providers
- Engineering
- Aerospace
- Healthcare
- Government
- Initial Access: MSP supply chain trust relationships
- Persistence: ChChes, RedLeaves, PlugX backdoors
- Lateral Movement: stolen credentials across customer tenants
Mustang Panda
PRC state-sponsored · since 2014
Targets NGOs, religious groups, ASEAN governments, and the Tibetan/Mongolian diaspora. Heavy use of PlugX delivered via USB and themed lures.
- ASEAN governments
- Vatican
- Tibetan diaspora
- European foreign ministries
- Initial Access: spearphishing with topical political lures
- Initial Access: USB-spreading PlugX variants
- Defense Evasion: DLL side-loading via signed binaries
Naikon
PLA, Chengdu MR Second Technical Reconnaissance Bureau · since 2010
Focused on South China Sea regional intelligence, military, diplomatic and economic targets in ASEAN states.
- ASEAN militaries
- Philippines
- Vietnam
- Indonesia
- Malaysia
- Initial Access: spearphishing with regional lures
- Persistence: Aria-body backdoor
- Exfiltration: long-dwell collection
Hafnium
PRC state-sponsored · since 2017
Author of the 2021 ProxyLogon Microsoft Exchange zero-day campaign that compromised 30,000+ servers worldwide.
- Defense contractors
- Higher education
- Law firms
- Think tanks
- Infectious disease researchers
- Initial Access: Exchange Server zero-days (CVE-2021-26855 chain)
- Persistence: web shells (China Chopper variants)
- Collection: full mailbox exports
Brass Typhoon
PRC state-sponsored (umbrella designator) · since Pre-2019
Microsoft umbrella designation for clusters using ShadowPad, frequently overlapping with APT41 tradecraft against telecom and government.
- Telecom
- Government
- IT service providers
- Initial Access: public-facing exploits
- Persistence: ShadowPad modular backdoor
- Defense Evasion: legitimate signed binaries for DLL side-loading
APT29
Russian Foreign Intelligence Service (SVR) · since 2008
SVR-attributed espionage group behind the SolarWinds supply-chain compromise and sustained targeting of US government, think-tank and cloud-provider networks.
- US federal agencies
- Cloud/SaaS providers
- Think tanks
- Diplomatic missions
- Initial Access: supply-chain compromise (SolarWinds Orion)
- Initial Access: password spray and OAuth token theft against cloud tenants
- Persistence: golden SAML, malicious OAuth applications
- Collection: mailbox and cloud-storage exfiltration
Sandworm
Russian GRU Unit 74455 · since 2009
GRU military intelligence unit responsible for destructive attacks including the Ukrainian power-grid outages, NotPetya, and the Olympic Destroyer wiper.
- Energy grids
- Ukrainian government
- Allied critical infrastructure
- Industrial control systems
- Impact: ICS-tailored malware (Industroyer/Industroyer2) causing power outages
- Impact: destructive wiper malware (NotPetya, WhisperGate)
- Initial Access: spearphishing and edge-device exploitation
- Command & Control: living-off-the-land against OT networks
APT33
Iranian state-sponsored (IRGC-linked) · since 2013
Espionage and destructive-capable group targeting US and allied aerospace, defense and energy sectors, with reported password-spray campaigns against satellite and defense companies.
- Aerospace
- Defense contractors
- Energy sector
- Satellite/telecom
- Initial Access: large-scale password spraying
- Persistence: web shells and custom backdoors (TURNEDUP)
- Collection: credential harvesting for follow-on espionage
APT35
Iranian state-sponsored (IRGC-linked) · since 2011
Long-running social-engineering-heavy espionage group targeting US officials, journalists, and dissidents, including reported attempts against presidential campaign staff.
- US officials
- Journalists
- Academics
- Political campaigns
- Initial Access: elaborate spearphishing personas and fake conference invites
- Credential Access: fake login-portal phishing kits
- Collection: mailbox and social-media account takeover
CyberAv3ngers
Iranian state-sponsored (IRGC Cyber-Electronic Command linked) · since 2020
Hacktivist-branded persona conducting operations against Israeli and US industrial control systems, notably exploiting default credentials on water-utility programmable logic controllers.
- Water utilities
- Industrial control systems
- Unitronics PLCs
- Initial Access: exploitation of default/weak PLC credentials
- Impact: defacement and manipulation of ICS human-machine interfaces
Lazarus Group
North Korean state-sponsored (Reconnaissance General Bureau) · since 2009
Regime-directed group combining espionage, destructive attacks (Sony Pictures), and large-scale cryptocurrency theft to fund sanctioned weapons programs.
- Cryptocurrency exchanges
- Defense contractors
- Media/entertainment
- Financial institutions
- Initial Access: trojanized cryptocurrency trading applications
- Impact: destructive wiper malware and data destruction
- Exfiltration: laundering stolen crypto through mixers and bridges
Kimsuky
North Korean state-sponsored (Reconnaissance General Bureau) · since 2012
Intelligence-collection group focused on Korean Peninsula policy experts and US think tanks, using elaborate spearphishing and credential-harvesting personas.
- Think tanks
- Korean Peninsula policy experts
- Government officials
- Journalists
- Initial Access: spearphishing with fabricated expert personas
- Credential Access: fake webmail login portals
- Collection: mailbox exfiltration for intelligence reporting
LockBit
Ransomware-as-a-service criminal enterprise · since 2019
One of the most prolific ransomware-as-a-service operations, responsible for thousands of attacks on US hospitals, schools, and government entities before a 2024 international law-enforcement disruption.
- Healthcare
- Manufacturing
- Government
- Education
- Initial Access: exploitation of public-facing applications and stolen RDP credentials
- Impact: double-extortion ransomware encryption and data leak sites
- Defense Evasion: disabling of security tooling prior to encryption
ALPHV/BlackCat
Ransomware-as-a-service criminal enterprise · since 2021
Rust-based ransomware-as-a-service operation responsible for the 2024 Change Healthcare attack, which disrupted prescription processing and payments across the US healthcare system.
- Healthcare
- Financial services
- Critical infrastructure
- Initial Access: compromised credentials, sometimes via initial-access brokers
- Impact: double-extortion ransomware with cross-platform (Rust) encryptors
- Exfiltration: bulk data theft prior to encryption for leverage
Scattered Spider
Financially motivated criminal collective (loosely organized, English-speaking) · since 2022
Social-engineering-focused group known for SIM-swapping and help-desk impersonation attacks against major US casino, telecom and technology companies, often partnering with ransomware operators.
- Casinos/hospitality
- Telecom
- Technology companies
- BPO/help-desk providers
- Initial Access: help-desk social engineering to reset MFA/credentials
- Initial Access: SIM-swapping for SMS-based MFA bypass
- Impact: ransomware deployment via partnerships with RaaS operators
APT28
Russian military intelligence (GRU 85th GTsSS, Unit 26165) · since 2004
GRU signals-intelligence unit conducting political, military and election-related intrusions against the United States, NATO members and Ukraine, including the 2016 DNC compromise and later router-exploitation campaigns.
- Political organizations
- Defense ministries
- Logistics firms supporting Ukraine
- Energy sector
- Initial Access: credential phishing and password spraying against webmail
- Initial Access: exploitation of Outlook and edge-device vulnerabilities
- Persistence: router implants and compromised small office network devices
- Collection: mailbox harvesting and NTLM relay theft
Turla
Russian Federal Security Service (FSB Center 16) · since 1996
Technically sophisticated FSB espionage group behind the Snake implant network, known for long-dwell collection against US government, defense and research targets and for hijacking other actors' infrastructure.
- Federal agencies
- Defense research
- Diplomatic missions
- Universities
- Persistence: kernel-level Snake implant and peer-to-peer covert network
- Command & Control: satellite-link hijacking and piggybacking on other actors' infrastructure
- Collection: selective document theft over years-long dwell times
Star Blizzard
Russian Federal Security Service (FSB Center 18) · since 2017
Spearphishing-focused FSB group targeting US and UK policy experts, former intelligence officials, journalists and non-governmental organizations working on Russia.
- Think tanks
- NGOs
- Former officials
- Journalists
- Initial Access: impersonation personas and long-running rapport building
- Credential Access: bespoke phishing portals harvesting session cookies
- Collection: mailbox rules and forwarding for persistent access
MuddyWater
Iranian Ministry of Intelligence and Security (MOIS) · since 2017
MOIS-subordinate group conducting espionage and access operations across the Middle East and against US government and telecommunications interests, frequently abusing legitimate remote-management software.
- Government
- Telecom
- Oil and gas
- Defense
- Initial Access: phishing with archive lures delivering remote monitoring tools
- Defense Evasion: abuse of legitimate RMM software (Atera, ScreenConnect)
- Command & Control: compromised infrastructure and cloud file services
Pioneer Kitten
Iran-based actors with IRGC-aligned reporting relationships · since 2017
Access broker that exploits internet-facing appliances to sell footholds in US networks to ransomware affiliates while also supporting Iranian state collection requirements.
- Healthcare
- Education
- Defense
- State and local government
- Initial Access: exploitation of VPN and remote-access appliance vulnerabilities
- Persistence: web shells and creation of new privileged accounts
- Impact: hand-off of access to ransomware operators for extortion
Andariel
North Korean state-sponsored (Reconnaissance General Bureau 3rd Bureau) · since 2009
RGB subunit indicted by the US Justice Department for stealing defense and nuclear-technology information while funding operations through ransomware attacks on American hospitals.
- Defense industrial base
- Nuclear research
- Healthcare
- Aerospace
- Initial Access: exploitation of known vulnerabilities in public-facing servers
- Impact: Maui and other ransomware against healthcare providers
- Collection: theft of defense technical data and research
Cl0p
Russian-speaking extortion enterprise · since 2019
Extortion group specializing in mass exploitation of managed file-transfer products, including the MOVEit campaign that affected hundreds of US companies and government agencies at once.
- Managed file-transfer users
- Federal and state agencies
- Financial services
- Education
- Initial Access: zero-day exploitation of file-transfer software (MOVEit, GoAnywhere, Accellion)
- Exfiltration: bulk data theft without deploying encryption
- Impact: public leak-site extortion of downstream victims
Akira
Ransomware-as-a-service criminal enterprise · since 2023
Fast-growing ransomware operation hitting US small and mid-sized businesses, manufacturers and municipalities, typically entering through VPN accounts without multifactor authentication.
- Manufacturing
- Professional services
- Education
- Local government
- Initial Access: VPN credentials without multifactor authentication
- Credential Access: LSASS and credential-store harvesting
- Impact: encryption of Windows and ESXi hosts with data-leak extortion
Anonymous Sudan
Non-state hacktivist persona with alleged Russian alignment · since 2023
Distributed denial-of-service operation that disrupted US hospital, airport and cloud-service websites for political signaling; US prosecutors charged two operators in 2024.
- Healthcare
- Airports
- Cloud and technology providers
- Government websites
- Impact: high-volume application-layer denial-of-service attacks
- Resource Development: rented cloud infrastructure and paid proxy services
- Influence: Telegram-based claims and amplification
Cyber Army of Russia Reborn
Pro-Russia hacktivist persona with reported Sandworm links · since 2022
Hacktivist front that manipulated human-machine interfaces at small US and European water and wastewater utilities, publicizing the intrusions for psychological effect; sanctioned by the US Treasury in 2024.
- Water and wastewater utilities
- Small energy operators
- Agriculture
- Initial Access: internet-exposed HMIs with default or absent credentials
- Impact: manipulation of operational technology setpoints and tank levels
- Influence: video posts of intrusions for propaganda value