Directory
Actors by country of origin
35 groups across 10 origins. Each country's operations reflect the structure of the state behind them — the note under each heading explains how that country organises its services, which is usually the fastest way to make sense of the groups beneath it.
Russia
7 groupsOperations split across three services with distinct tradecraft: the GRU (military intelligence) for disruptive and destructive effect, the SVR (foreign intelligence) for patient strategic espionage, and the FSB (security service) for both domestic and foreign collection. GRU units accept far more operational risk than the SVR.
APT28
Russia·State-Sponsored·2004–
GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.
GRU · Unit 26165
APT29
Russia·State-Sponsored·2008–
Russia's SVR foreign intelligence service. Executed the SolarWinds supply-chain compromise and remains the benchmark for patient, cloud-native espionage.
Sandworm
Russia·State-Sponsored·2009–
The only actor to have caused blackouts with malware — twice. GRU Unit 74455, responsible for NotPetya, Industroyer, and the Ukrainian grid attacks.
GRU · Unit 74455
Turla
Russia·State-Sponsored·1996–
FSB Centre 16. The oldest continuously active espionage group on record — known for hijacking satellite links and stealing other nations' operations outright.
FSB · Centre 16
Gamaredon
Russia·State-Sponsored·2013–
FSB officers operating from occupied Crimea, publicly named by Ukraine's security service. Enormous volume, minimal sophistication, relentlessly focused on Ukraine.
FSB · 18th Centre / Crimean directorate
Berserk Bear
Russia·State-Sponsored·2010–
FSB Centre 16's energy-sector programme. Spent a decade inside Western electric utilities collecting engineering data — access, not effect.
FSB · Centre 16
Star Blizzard
Russia·State-Sponsored·2015–
FSB Centre 18 credential phishing against academics, journalists, NGOs, and former intelligence officials — with hack-and-leak as the follow-through.
FSB · Centre 18
China
9 groupsThe dominant volume actor. Operations largely migrated from PLA units to the Ministry of State Security after the 2015 military reforms, executed through a contractor ecosystem — the i-Soon leak of February 2024 exposed how deep that private-sector layer runs. Recent emphasis has shifted from IP theft toward pre-positioning in critical infrastructure.
Volt Typhoon
China·State-Sponsored·2021–
Pre-positioning inside U.S. critical infrastructure with no collection payoff — access held for five years for use in a future conflict.
Salt Typhoon
China·State-Sponsored·2019–
Compromised the core of U.S. telecommunications — including the lawful intercept systems used for court-ordered wiretaps.
APT41
China·State-Sponsored·2012–
State espionage by day, cybercrime by night. Indicted operators ran MSS-aligned intrusions and personal money-making schemes from the same infrastructure.
Silk Typhoon
China·State-Sponsored·2020–
Ran the ProxyLogon mass exploitation that web-shelled tens of thousands of Exchange servers, then pivoted to attacking the IT supply chain.
APT10
China·State-Sponsored·2006–
Operation Cloud Hopper — compromised managed service providers to reach their clients' networks, turning outsourced IT into a single point of failure.
Ministry of State Security (MSS) · Huaying Haitai Science and Technology Development Co. (front company)
APT40
China·State-Sponsored·2009–
MSS Hainan bureau running maritime and naval technology collection — and among the fastest actors at weaponising new vulnerabilities.
Ministry of State Security (MSS) · Hainan Xiandun Technology Development Co. (front company)
Mustang Panda
China·State-Sponsored·2014–
The highest-volume Chinese espionage operation against Europe and Southeast Asia — and the subject of an FBI operation that deleted its malware from 4,258 U.S. computers.
APT31
China·State-Sponsored·2010–
MSS Hubei bureau targeting politicians, election infrastructure, and dissidents — sanctioned by both the U.S. and U.K. in March 2024.
Ministry of State Security (MSS) · Wuhan Xiaoruizhi Science and Technology Company (front company)
APT1
China·State-Sponsored·2006–2014
PLA Unit 61398. The first threat group ever publicly attributed to a specific military unit — the report that created the modern threat intelligence industry.
People's Liberation Army · Unit 61398
Iran
5 groupsSplit between the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS), heavily reliant on contractor front companies. Distinguished by willingness to cross from espionage into destructive attacks and hack-and-leak information operations, and by unusually aggressive social engineering.
APT35
Iran·State-Sponsored·2013–
IRGC-linked social engineering specialists. Will spend weeks impersonating a journalist or academic before ever sending a link.
Islamic Revolutionary Guard Corps (IRGC) · IRGC-affiliated contractors, including Emennet Pasargad and Mahak Rayan Afraz
APT34
Iran·State-Sponsored·2014–
MOIS operation against Gulf energy and government. Had its source code and operator identities leaked on Telegram — then kept operating.
MuddyWater
Iran·State-Sponsored·2017–
Iran's Ministry of Intelligence, named as such by U.S. Cyber Command. Runs espionage almost entirely on legitimate remote-management software.
APT33
Iran·State-Sponsored·2013–
Aerospace and petrochemical collection with a destructive edge — linked to the Shamoon wiper attacks that destroyed 30,000 Saudi Aramco workstations.
CyberAv3ngers
Iran·State-Sponsored·2020–
IRGC cyber unit operating under a hacktivist persona. Defaced water-utility PLCs across the U.S. by exploiting a default password.
IRGC · IRGC-CEC
North Korea
5 groupsUniquely fuses espionage with revenue generation — the Reconnaissance General Bureau runs both intelligence collection and large-scale cryptocurrency theft that funds the weapons programme. The only state apparatus for which financial crime is a primary, sanctioned mission rather than a sideline.
Lazarus Group
North Korea·State-Sponsored·2009–
The only state actor whose primary mission is theft. Stole $1.5 billion from a single exchange in 2025 — the largest heist in history, of any kind.
RGB · Lab 110 / 3rd Bureau
APT38
North Korea·State-Sponsored·2014–
The bank-robbery specialists. Attempted $1.1 billion in theft from financial institutions, and destroys the evidence on the way out.
RGB · Bluenoroff / financial operations element
Kimsuky
North Korea·State-Sponsored·2012–
DPRK's policy-intelligence collectors. Impersonate journalists and academics to reach the small community of people who shape North Korea policy.
RGB · Assessed within the RGB structure
APT37
North Korea·State-Sponsored·2012–
Prolific browser zero-day developer, focused on South Korean targets and North Korean defectors.
Andariel
North Korea·State-Sponsored·2015–
Steals defence and nuclear technology, then funds the operation with ransomware against hospitals. An indicted RGB officer remains at large.
RGB · 3rd Bureau (Andariel / Onyx Sleet)
Vietnam
1 groupRegionally focused collection against neighbouring states, foreign firms operating in-country, and diaspora dissidents.
Pakistan
1 groupCollection concentrated almost entirely on Indian military, government, and defence targets.
India
1 groupRegional collection against Pakistan, China, and Nepal, alongside a notable commercial hack-for-hire sector.
Belarus
1 groupLimited independent capability, closely aligned with and reinforcing Russian information operations.
Israel
1 groupAssessed origin of several high-impact disruptive operations against Iranian infrastructure, conducted under hacktivist cover.
Multiple / Non-state
4 groupsFinancially motivated and hacktivist groups without a single state sponsor. Membership is frequently transnational, and affiliates rotate between brands as law-enforcement pressure lands.
Scattered Spider
Multiple / Non-state·Criminal·2022–
Native English-speaking teenagers who talk their way past help desks. No exploits, no zero-days — just a convincing phone call.
Cl0p
Multiple / Non-state·Criminal·2019–
Abandoned encryption for pure data-theft extortion. Its MOVEit campaign hit 2,700+ organisations from a single vulnerability.
LockBit
Multiple / Non-state·Criminal·2019–
The most prolific ransomware-as-a-service operation ever run — until law enforcement seized its infrastructure and used its own leak site to publish the takedown.
FIN7
Multiple / Non-state·Criminal·2013–
Ran a fake security company that hired real penetration testers who did not know they were committing crimes. Stole over $1 billion.