Cyber Activity

Cyber threat actors targeting the US

Curated reference on state-sponsored APT groups from China, Russia, Iran and North Korea, plus financially motivated ransomware crews, their tactics, techniques and procedures (mapped to MITRE ATT&CK), and a timeline of recent public incidents. Sourced from CISA, Mandiant, Microsoft, and DOJ filings.

Top threat actors, activity and targets

Tracked state and criminal actors with their objectives, target sets, and techniques mapped to the MITRE ATT&CK framework.

Full actor desk
Akira
High activity
Criminal

Ransomware against mid-market US businesses and municipalities

Targets
ManufacturingProfessional servicesEducationLocal government
LockBit
High activity
Criminal

Ransomware-as-a-service extortion at scale

Targets
HealthcareState and local governmentEducation
ATT&CK techniques
Anonymous Sudan
Moderate activity
Hacktivist

Denial-of-service disruption for political signaling

Targets
HealthcareAirportsCloud providersGovernment websites
ATT&CK techniques

Technique and group identifiers link to MITRE ATT&CK (Enterprise). ATT&CK is a registered trademark of The MITRE Corporation.

Volt Typhoon

PRC state-sponsored (MSS-aligned) · since Mid-2021

TTPs & targets

Pre-positioning operations against US critical infrastructure (water, energy, transport, communications) with the apparent goal of disruption during a Taiwan contingency.

Vanguard PandaBRONZE SILHOUETTEInsidious Taurus
Primary targets
  • US critical infrastructure
  • Guam telecom
  • Water utilities
  • Energy sector
Primary TTPs
  • Initial Access: exploitation of edge devices (Fortinet, Cisco, Netgear)
  • Persistence: web shells on perimeter routers/SOHO botnets
  • Defense Evasion: living-off-the-land (LOLBins, no malware)
  • Credential Access: LSASS dumping, ntds.dit theft
  • Discovery: WMI / PowerShell network enumeration

Salt Typhoon

PRC state-sponsored (MSS contractor) · since 2020

TTPs & targets

Long-running telecom intrusion campaign. In 2024 breached multiple US carriers and accessed CALEA lawful-intercept systems, exposing communications of senior US officials.

FamousSparrowGhostEmperorEarth Estries
Primary targets
  • US telecom carriers
  • ISPs
  • Government communications
  • Political campaigns
Primary TTPs
  • Initial Access: Microsoft Exchange / edge router exploits
  • Persistence: GhostSpider kernel rootkit
  • Collection: SIGINT-style metadata exfiltration
  • Command & Control: Demodex rootkit, custom HTTPS tunnels

Flax Typhoon

Integrity Technology Group (Beijing), MSS contractor · since Mid-2021

TTPs & targets

Built and operated the Raptor Train IoT botnet (260k+ devices) used for intermediate routing and operational obfuscation. Targets Taiwan especially.

Ethereal Panda
Primary targets
  • Taiwan government
  • Education
  • Manufacturing
  • IoT/SOHO routers globally
Primary TTPs
  • Initial Access: public-facing app exploitation (VPNs, IIS)
  • Persistence: legitimate RMM tools (Sysinternals, SoftEther VPN)
  • C2: Raptor Train botnet relay layer

APT41

MSS contractor (Chengdu 404) · since 2012

TTPs & targets

Dual-mission group conducting both state-directed espionage and financially motivated operations (game studios, cryptocurrency). 5 members indicted by DOJ in 2020.

Double DragonWicked PandaBARIUMWinnti
Primary targets
  • Healthcare
  • Telecom
  • Game studios
  • Government
  • Higher education
Primary TTPs
  • Initial Access: supply-chain compromise (CCleaner, ASUS Live Update)
  • Persistence: Winnti malware family, ShadowPad
  • Lateral Movement: Cobalt Strike, custom loaders

APT40

MSS Hainan State Security Department · since 2009

TTPs & targets

Maritime, defense and naval research espionage in support of PRC modernization. 4 officers indicted by DOJ in 2021.

LeviathanKryptonite PandaTEMP.PeriscopeGADOLINIUM
Primary targets
  • Naval R&D
  • Maritime industry
  • Universities
  • Biomedical research
  • Defense contractors
Primary TTPs
  • Initial Access: spearphishing, edge-device exploits (SOHO routers as ORBs)
  • Discovery: rapid recon within hours of compromise
  • Exfiltration: web shells, custom backdoors (BADFLICK, MURKYTOP)

APT31

MSS, Wuhan State Security Bureau · since 2010

TTPs & targets

Intellectual property and political intelligence collection. Indicted by DOJ in 2024 for targeting US political dissidents, journalists, and members of IPAC.

ZirconiumJudgment PandaViolet Typhoon
Primary targets
  • Politicians
  • Journalists
  • Think tanks
  • Aerospace
  • Defense
Primary TTPs
  • Initial Access: spearphishing with tracking pixels for recon
  • Credential Access: home router compromise to harvest creds
  • Collection: targeted mailbox exfiltration

APT10

MSS Tianjin State Security Bureau · since 2009

TTPs & targets

Operation Cloud Hopper, global managed service provider (MSP) compromise enabling downstream access to thousands of client organizations.

Stone PandamenuPassPOTASSIUM
Primary targets
  • Managed Service Providers
  • Engineering
  • Aerospace
  • Healthcare
  • Government
Primary TTPs
  • Initial Access: MSP supply chain trust relationships
  • Persistence: ChChes, RedLeaves, PlugX backdoors
  • Lateral Movement: stolen credentials across customer tenants

Mustang Panda

PRC state-sponsored · since 2014

TTPs & targets

Targets NGOs, religious groups, ASEAN governments, and the Tibetan/Mongolian diaspora. Heavy use of PlugX delivered via USB and themed lures.

BRONZE PRESIDENTRedDeltaEarth PretaTA416
Primary targets
  • ASEAN governments
  • Vatican
  • Tibetan diaspora
  • European foreign ministries
Primary TTPs
  • Initial Access: spearphishing with topical political lures
  • Initial Access: USB-spreading PlugX variants
  • Defense Evasion: DLL side-loading via signed binaries

Naikon

PLA, Chengdu MR Second Technical Reconnaissance Bureau · since 2010

TTPs & targets

Focused on South China Sea regional intelligence, military, diplomatic and economic targets in ASEAN states.

Override PandaPLA Unit 78020
Primary targets
  • ASEAN militaries
  • Philippines
  • Vietnam
  • Indonesia
  • Malaysia
Primary TTPs
  • Initial Access: spearphishing with regional lures
  • Persistence: Aria-body backdoor
  • Exfiltration: long-dwell collection

Hafnium

PRC state-sponsored · since 2017

TTPs & targets

Author of the 2021 ProxyLogon Microsoft Exchange zero-day campaign that compromised 30,000+ servers worldwide.

Silk Typhoon
Primary targets
  • Defense contractors
  • Higher education
  • Law firms
  • Think tanks
  • Infectious disease researchers
Primary TTPs
  • Initial Access: Exchange Server zero-days (CVE-2021-26855 chain)
  • Persistence: web shells (China Chopper variants)
  • Collection: full mailbox exports

Brass Typhoon

PRC state-sponsored (umbrella designator) · since Pre-2019

TTPs & targets

Microsoft umbrella designation for clusters using ShadowPad, frequently overlapping with APT41 tradecraft against telecom and government.

BARIUM (legacy)ShadowPad cluster
Primary targets
  • Telecom
  • Government
  • IT service providers
Primary TTPs
  • Initial Access: public-facing exploits
  • Persistence: ShadowPad modular backdoor
  • Defense Evasion: legitimate signed binaries for DLL side-loading

APT29

Russian Foreign Intelligence Service (SVR) · since 2008

TTPs & targets

SVR-attributed espionage group behind the SolarWinds supply-chain compromise and sustained targeting of US government, think-tank and cloud-provider networks.

Midnight BlizzardCozy BearNOBELIUMThe Dukes
Primary targets
  • US federal agencies
  • Cloud/SaaS providers
  • Think tanks
  • Diplomatic missions
Primary TTPs
  • Initial Access: supply-chain compromise (SolarWinds Orion)
  • Initial Access: password spray and OAuth token theft against cloud tenants
  • Persistence: golden SAML, malicious OAuth applications
  • Collection: mailbox and cloud-storage exfiltration

Sandworm

Russian GRU Unit 74455 · since 2009

TTPs & targets

GRU military intelligence unit responsible for destructive attacks including the Ukrainian power-grid outages, NotPetya, and the Olympic Destroyer wiper.

Voodoo BearAPT44Seashell BlizzardIridium
Primary targets
  • Energy grids
  • Ukrainian government
  • Allied critical infrastructure
  • Industrial control systems
Primary TTPs
  • Impact: ICS-tailored malware (Industroyer/Industroyer2) causing power outages
  • Impact: destructive wiper malware (NotPetya, WhisperGate)
  • Initial Access: spearphishing and edge-device exploitation
  • Command & Control: living-off-the-land against OT networks

APT33

Iranian state-sponsored (IRGC-linked) · since 2013

TTPs & targets

Espionage and destructive-capable group targeting US and allied aerospace, defense and energy sectors, with reported password-spray campaigns against satellite and defense companies.

ElfinPeach SandstormRefined Kitten
Primary targets
  • Aerospace
  • Defense contractors
  • Energy sector
  • Satellite/telecom
Primary TTPs
  • Initial Access: large-scale password spraying
  • Persistence: web shells and custom backdoors (TURNEDUP)
  • Collection: credential harvesting for follow-on espionage

APT35

Iranian state-sponsored (IRGC-linked) · since 2011

TTPs & targets

Long-running social-engineering-heavy espionage group targeting US officials, journalists, and dissidents, including reported attempts against presidential campaign staff.

Charming KittenMint SandstormPhosphorus
Primary targets
  • US officials
  • Journalists
  • Academics
  • Political campaigns
Primary TTPs
  • Initial Access: elaborate spearphishing personas and fake conference invites
  • Credential Access: fake login-portal phishing kits
  • Collection: mailbox and social-media account takeover

CyberAv3ngers

Iranian state-sponsored (IRGC Cyber-Electronic Command linked) · since 2020

TTPs & targets

Hacktivist-branded persona conducting operations against Israeli and US industrial control systems, notably exploiting default credentials on water-utility programmable logic controllers.

IRGC-CEC affiliated
Primary targets
  • Water utilities
  • Industrial control systems
  • Unitronics PLCs
Primary TTPs
  • Initial Access: exploitation of default/weak PLC credentials
  • Impact: defacement and manipulation of ICS human-machine interfaces

Lazarus Group

North Korean state-sponsored (Reconnaissance General Bureau) · since 2009

TTPs & targets

Regime-directed group combining espionage, destructive attacks (Sony Pictures), and large-scale cryptocurrency theft to fund sanctioned weapons programs.

Hidden CobraDiamond SleetAPT38
Primary targets
  • Cryptocurrency exchanges
  • Defense contractors
  • Media/entertainment
  • Financial institutions
Primary TTPs
  • Initial Access: trojanized cryptocurrency trading applications
  • Impact: destructive wiper malware and data destruction
  • Exfiltration: laundering stolen crypto through mixers and bridges

Kimsuky

North Korean state-sponsored (Reconnaissance General Bureau) · since 2012

TTPs & targets

Intelligence-collection group focused on Korean Peninsula policy experts and US think tanks, using elaborate spearphishing and credential-harvesting personas.

Velvet ChollimaEmerald SleetAPT43
Primary targets
  • Think tanks
  • Korean Peninsula policy experts
  • Government officials
  • Journalists
Primary TTPs
  • Initial Access: spearphishing with fabricated expert personas
  • Credential Access: fake webmail login portals
  • Collection: mailbox exfiltration for intelligence reporting

LockBit

Ransomware-as-a-service criminal enterprise · since 2019

TTPs & targets

One of the most prolific ransomware-as-a-service operations, responsible for thousands of attacks on US hospitals, schools, and government entities before a 2024 international law-enforcement disruption.

LockBit 3.0LockBit Black
Primary targets
  • Healthcare
  • Manufacturing
  • Government
  • Education
Primary TTPs
  • Initial Access: exploitation of public-facing applications and stolen RDP credentials
  • Impact: double-extortion ransomware encryption and data leak sites
  • Defense Evasion: disabling of security tooling prior to encryption

ALPHV/BlackCat

Ransomware-as-a-service criminal enterprise · since 2021

TTPs & targets

Rust-based ransomware-as-a-service operation responsible for the 2024 Change Healthcare attack, which disrupted prescription processing and payments across the US healthcare system.

BlackCatNoberus
Primary targets
  • Healthcare
  • Financial services
  • Critical infrastructure
Primary TTPs
  • Initial Access: compromised credentials, sometimes via initial-access brokers
  • Impact: double-extortion ransomware with cross-platform (Rust) encryptors
  • Exfiltration: bulk data theft prior to encryption for leverage

Scattered Spider

Financially motivated criminal collective (loosely organized, English-speaking) · since 2022

TTPs & targets

Social-engineering-focused group known for SIM-swapping and help-desk impersonation attacks against major US casino, telecom and technology companies, often partnering with ransomware operators.

UNC3944Muddled LibraOcto Tempest
Primary targets
  • Casinos/hospitality
  • Telecom
  • Technology companies
  • BPO/help-desk providers
Primary TTPs
  • Initial Access: help-desk social engineering to reset MFA/credentials
  • Initial Access: SIM-swapping for SMS-based MFA bypass
  • Impact: ransomware deployment via partnerships with RaaS operators

APT28

Russian military intelligence (GRU 85th GTsSS, Unit 26165) · since 2004

TTPs & targets

GRU signals-intelligence unit conducting political, military and election-related intrusions against the United States, NATO members and Ukraine, including the 2016 DNC compromise and later router-exploitation campaigns.

Fancy BearForest BlizzardSofacyUnit 26165
Primary targets
  • Political organizations
  • Defense ministries
  • Logistics firms supporting Ukraine
  • Energy sector
Primary TTPs
  • Initial Access: credential phishing and password spraying against webmail
  • Initial Access: exploitation of Outlook and edge-device vulnerabilities
  • Persistence: router implants and compromised small office network devices
  • Collection: mailbox harvesting and NTLM relay theft

Turla

Russian Federal Security Service (FSB Center 16) · since 1996

TTPs & targets

Technically sophisticated FSB espionage group behind the Snake implant network, known for long-dwell collection against US government, defense and research targets and for hijacking other actors' infrastructure.

Secret BlizzardVenomous BearSnakeWaterbug
Primary targets
  • Federal agencies
  • Defense research
  • Diplomatic missions
  • Universities
Primary TTPs
  • Persistence: kernel-level Snake implant and peer-to-peer covert network
  • Command & Control: satellite-link hijacking and piggybacking on other actors' infrastructure
  • Collection: selective document theft over years-long dwell times

Star Blizzard

Russian Federal Security Service (FSB Center 18) · since 2017

TTPs & targets

Spearphishing-focused FSB group targeting US and UK policy experts, former intelligence officials, journalists and non-governmental organizations working on Russia.

CallistoSEABORGIUMCOLDRIVER
Primary targets
  • Think tanks
  • NGOs
  • Former officials
  • Journalists
Primary TTPs
  • Initial Access: impersonation personas and long-running rapport building
  • Credential Access: bespoke phishing portals harvesting session cookies
  • Collection: mailbox rules and forwarding for persistent access

MuddyWater

Iranian Ministry of Intelligence and Security (MOIS) · since 2017

TTPs & targets

MOIS-subordinate group conducting espionage and access operations across the Middle East and against US government and telecommunications interests, frequently abusing legitimate remote-management software.

Mango SandstormStatic KittenSeedworm
Primary targets
  • Government
  • Telecom
  • Oil and gas
  • Defense
Primary TTPs
  • Initial Access: phishing with archive lures delivering remote monitoring tools
  • Defense Evasion: abuse of legitimate RMM software (Atera, ScreenConnect)
  • Command & Control: compromised infrastructure and cloud file services

Pioneer Kitten

Iran-based actors with IRGC-aligned reporting relationships · since 2017

TTPs & targets

Access broker that exploits internet-facing appliances to sell footholds in US networks to ransomware affiliates while also supporting Iranian state collection requirements.

Lemon SandstormFox KittenUNC757Br0k3r
Primary targets
  • Healthcare
  • Education
  • Defense
  • State and local government
Primary TTPs
  • Initial Access: exploitation of VPN and remote-access appliance vulnerabilities
  • Persistence: web shells and creation of new privileged accounts
  • Impact: hand-off of access to ransomware operators for extortion

Andariel

North Korean state-sponsored (Reconnaissance General Bureau 3rd Bureau) · since 2009

TTPs & targets

RGB subunit indicted by the US Justice Department for stealing defense and nuclear-technology information while funding operations through ransomware attacks on American hospitals.

Onyx SleetSilent ChollimaStonefly
Primary targets
  • Defense industrial base
  • Nuclear research
  • Healthcare
  • Aerospace
Primary TTPs
  • Initial Access: exploitation of known vulnerabilities in public-facing servers
  • Impact: Maui and other ransomware against healthcare providers
  • Collection: theft of defense technical data and research

Cl0p

Russian-speaking extortion enterprise · since 2019

TTPs & targets

Extortion group specializing in mass exploitation of managed file-transfer products, including the MOVEit campaign that affected hundreds of US companies and government agencies at once.

Lace TempestTA505FIN11
Primary targets
  • Managed file-transfer users
  • Federal and state agencies
  • Financial services
  • Education
Primary TTPs
  • Initial Access: zero-day exploitation of file-transfer software (MOVEit, GoAnywhere, Accellion)
  • Exfiltration: bulk data theft without deploying encryption
  • Impact: public leak-site extortion of downstream victims

Akira

Ransomware-as-a-service criminal enterprise · since 2023

TTPs & targets

Fast-growing ransomware operation hitting US small and mid-sized businesses, manufacturers and municipalities, typically entering through VPN accounts without multifactor authentication.

Akira ransomwareStorm-1567
Primary targets
  • Manufacturing
  • Professional services
  • Education
  • Local government
Primary TTPs
  • Initial Access: VPN credentials without multifactor authentication
  • Credential Access: LSASS and credential-store harvesting
  • Impact: encryption of Windows and ESXi hosts with data-leak extortion

Anonymous Sudan

Non-state hacktivist persona with alleged Russian alignment · since 2023

TTPs & targets

Distributed denial-of-service operation that disrupted US hospital, airport and cloud-service websites for political signaling; US prosecutors charged two operators in 2024.

Storm-1359
Primary targets
  • Healthcare
  • Airports
  • Cloud and technology providers
  • Government websites
Primary TTPs
  • Impact: high-volume application-layer denial-of-service attacks
  • Resource Development: rented cloud infrastructure and paid proxy services
  • Influence: Telegram-based claims and amplification

Cyber Army of Russia Reborn

Pro-Russia hacktivist persona with reported Sandworm links · since 2022

TTPs & targets

Hacktivist front that manipulated human-machine interfaces at small US and European water and wastewater utilities, publicizing the intrusions for psychological effect; sanctioned by the US Treasury in 2024.

CARRPeople's Cyber Army
Primary targets
  • Water and wastewater utilities
  • Small energy operators
  • Agriculture
Primary TTPs
  • Initial Access: internet-exposed HMIs with default or absent credentials
  • Impact: manipulation of operational technology setpoints and tank levels
  • Influence: video posts of intrusions for propaganda value