Skip to content

Threat Actor Intelligence

Every major adversary.One profile. Every source cited.

Building a threat profile normally means nine tabs — MITRE for T-codes, a vendor blog for the alias, NVD for the CVE, a DOJ press release for the attribution. Adversary Atlas puts all of it on one page, with the citation attached to every claim.

Activity Feed

Exploitation, breaches, campaigns, tooling, advisories, and indictments — each linked to the actors and CVEs involved.

42 curated · 9 auto-ingested from 8/8 primary sources, last refreshed 2026-08-07

Type
Origin

51 of 51 items

  1. Advisory2d agoUnreviewed

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog

  2. Advisory3d agoUnreviewed

    CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on

  3. Advisory4d agoUnreviewed

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importanc

  4. Breach7d agoUnreviewed

    CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

    Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog .

    SOURCEMicrosoft Threat IntelligenceAUTO-MATCHED ONMidnight Blizzard
  5. Advisory9d agoUnreviewed

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of th

  6. Advisory11mo ago

    Thirteen countries name three Chinese firms behind Salt Typhoon telecom intrusions

    A joint advisory co-sealed by agencies in thirteen countries named Sichuan Juxinhe Network Technology, Beijing Huanyu Tianqiong, and Sichuan Zhixin Ruijie as suppliers of cyber products and services to Chinese intelligence services supporting the telecom campaign. The advisory highlights continued exploitation of network devices unpatched since 2018.

  7. Indictment1.1y ago

    Chinese national arrested in Italy over 2021 HAFNIUM Exchange campaign

    The U.S. Department of Justice unsealed charges against Xu Zewei and Zhang Yu, identifying Shanghai Powerock Network Co. as a contractor operating at the direction of the Shanghai State Security Bureau. The indictment covers both the Exchange campaign and 2020 intrusions targeting COVID-19 vaccine research.

Most-referenced actors

The groups most likely to appear in an incoming report.

All 35 actors

APT28

Russia·State-Sponsored·2004

Active

GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.

GRU · Unit 26165

Fancy BearForest BlizzardIRON TWILIGHT+13
16 aliases7 CVEs19 T-codesProfile

APT29

Russia·State-Sponsored·2008

Active

Russia's SVR foreign intelligence service. Executed the SolarWinds supply-chain compromise and remains the benchmark for patient, cloud-native espionage.

Cozy BearMidnight BlizzardIRON RITUAL+13
16 aliases6 CVEs16 T-codesProfile

Sandworm

Russia·State-Sponsored·2009

Active

The only actor to have caused blackouts with malware — twice. GRU Unit 74455, responsible for NotPetya, Industroyer, and the Ukrainian grid attacks.

GRU · Unit 74455

Voodoo BearSeashell BlizzardAPT44+11
14 aliases5 CVEs16 T-codesProfile

Lazarus Group

North Korea·State-Sponsored·2009

Active

The only state actor whose primary mission is theft. Stole $1.5 billion from a single exchange in 2025 — the largest heist in history, of any kind.

RGB · Lab 110 / 3rd Bureau

Labyrinth ChollimaDiamond SleetTEMP.Hermit+10
13 aliases5 CVEs11 T-codesProfile

Volt Typhoon

China·State-Sponsored·2021

Active

Pre-positioning inside U.S. critical infrastructure with no collection payoff — access held for five years for use in a future conflict.

VANGUARD PANDAUNC3236BRONZE SILHOUETTE+6
9 aliases5 CVEs13 T-codesProfile

Salt Typhoon

China·State-Sponsored·2019

Active

Compromised the core of U.S. telecommunications — including the lawful intercept systems used for court-ordered wiretaps.

OPERATOR PANDAUNC5807+6
8 aliases6 CVEs11 T-codesProfile

Ask it the way you'd ask a colleague

Country, sector, and CVE filters intersect — combine any two or all three. Results return the matching actors and the specific campaigns that matched.