Skip to content

Threat Actor Intelligence

Every major adversary.One profile. Every source cited.

Building a threat profile normally means nine tabs — MITRE for T-codes, a vendor blog for the alias, NVD for the CVE, a DOJ press release for the attribution. Adversary Atlas puts all of it on one page, with the citation attached to every claim.

Activity Feed

Exploitation, breaches, campaigns, tooling, advisories, and indictments — each linked to the actors and CVEs involved.

42 curated · 6 auto-ingested from 8/8 primary sources, last refreshed 2026-07-30

Type
Origin

48 of 48 items

  1. AdvisoryyesterdayUnreviewed

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of th

  2. Advisory3d agoUnreviewed

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requir

  3. Advisory11mo ago

    Thirteen countries name three Chinese firms behind Salt Typhoon telecom intrusions

    A joint advisory co-sealed by agencies in thirteen countries named Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong, and Sichuan Zhixin Ruijie as suppliers of cyber products and services to Chinese intelligence services supporting the telecom campaign. The advisory highlights continued exploitation of network devices unpatched since 2018.

  4. Indictment1.1y ago

    Chinese national arrested in Italy over 2021 HAFNIUM Exchange campaign

    The U.S. Department of Justice unsealed charges against Xu Zewei and Zhang Yu, identifying Shanghai Powerock Network Co. as a contractor operating at the direction of the Shanghai State Security Bureau. The indictment covers both the Exchange campaign and 2020 intrusions targeting COVID-19 vaccine research.

Most-referenced actors

The groups most likely to appear in an incoming report.

All 35 actors

APT28

Russia·State-Sponsored·2004

Active

GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.

GRU · Unit 26165

Fancy BearForest BlizzardIRON TWILIGHT+13
16 aliases7 CVEs19 T-codesProfile

APT29

Russia·State-Sponsored·2008

Active

Russia's SVR foreign intelligence service. Executed the SolarWinds supply-chain compromise and remains the benchmark for patient, cloud-native espionage.

Cozy BearMidnight BlizzardIRON RITUAL+13
16 aliases6 CVEs16 T-codesProfile

Sandworm

Russia·State-Sponsored·2009

Active

The only actor to have caused blackouts with malware — twice. GRU Unit 74455, responsible for NotPetya, Industroyer, and the Ukrainian grid attacks.

GRU · Unit 74455

Voodoo BearSeashell BlizzardAPT44+11
14 aliases5 CVEs16 T-codesProfile

Lazarus Group

North Korea·State-Sponsored·2009

Active

The only state actor whose primary mission is theft. Stole $1.5 billion from a single exchange in 2025 — the largest heist in history, of any kind.

RGB · Lab 110 / 3rd Bureau

Labyrinth ChollimaDiamond SleetTEMP.Hermit+10
13 aliases5 CVEs11 T-codesProfile

Volt Typhoon

China·State-Sponsored·2021

Active

Pre-positioning inside U.S. critical infrastructure with no collection payoff — access held for five years for use in a future conflict.

VANGUARD PANDAUNC3236BRONZE SILHOUETTE+6
9 aliases5 CVEs13 T-codesProfile

Salt Typhoon

China·State-Sponsored·2019

Active

Compromised the core of U.S. telecommunications — including the lawful intercept systems used for court-ordered wiretaps.

OPERATOR PANDAUNC5807+6
8 aliases6 CVEs11 T-codesProfile

Ask it the way you'd ask a colleague

Country, sector, and CVE filters intersect — combine any two or all three. Results return the matching actors and the specific campaigns that matched.