Skip to content

Directory

Actors by country of origin

35 groups across 10 origins. Each country's operations reflect the structure of the state behind them — the note under each heading explains how that country organises its services, which is usually the fastest way to make sense of the groups beneath it.

Russia

7 groups

Operations split across three services with distinct tradecraft: the GRU (military intelligence) for disruptive and destructive effect, the SVR (foreign intelligence) for patient strategic espionage, and the FSB (security service) for both domestic and foreign collection. GRU units accept far more operational risk than the SVR.

APT28

Russia·State-Sponsored·2004

Active

GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.

GRU · Unit 26165

Fancy BearForest BlizzardIRON TWILIGHT+13
16 aliases7 CVEs19 T-codesProfile

APT29

Russia·State-Sponsored·2008

Active

Russia's SVR foreign intelligence service. Executed the SolarWinds supply-chain compromise and remains the benchmark for patient, cloud-native espionage.

Cozy BearMidnight BlizzardIRON RITUAL+13
16 aliases6 CVEs16 T-codesProfile

Sandworm

Russia·State-Sponsored·2009

Active

The only actor to have caused blackouts with malware — twice. GRU Unit 74455, responsible for NotPetya, Industroyer, and the Ukrainian grid attacks.

GRU · Unit 74455

Voodoo BearSeashell BlizzardAPT44+11
14 aliases5 CVEs16 T-codesProfile

Turla

Russia·State-Sponsored·1996

Active

FSB Centre 16. The oldest continuously active espionage group on record — known for hijacking satellite links and stealing other nations' operations outright.

FSB · Centre 16

Venomous BearSecret BlizzardIRON HUNTER+10
13 aliases3 CVEs14 T-codesProfile

Gamaredon

Russia·State-Sponsored·2013

Active

FSB officers operating from occupied Crimea, publicly named by Ukraine's security service. Enormous volume, minimal sophistication, relentlessly focused on Ukraine.

FSB · 18th Centre / Crimean directorate

Primitive BearAqua BlizzardUNC530+8
11 aliases2 CVEs11 T-codesProfile

Berserk Bear

Russia·State-Sponsored·2010

Active

FSB Centre 16's energy-sector programme. Spent a decade inside Western electric utilities collecting engineering data — access, not effect.

FSB · Centre 16

Ghost BlizzardTEMP.IsotopeIRON LIBERTY+9
12 aliases4 CVEs11 T-codesProfile

Star Blizzard

Russia·State-Sponsored·2015

Active

FSB Centre 18 credential phishing against academics, journalists, NGOs, and former intelligence officials — with hack-and-leak as the follow-through.

FSB · Centre 18

Gossamer BearUNC4057+8
10 aliases0 CVEs9 T-codesProfile

China

9 groups

The dominant volume actor. Operations largely migrated from PLA units to the Ministry of State Security after the 2015 military reforms, executed through a contractor ecosystem — the i-Soon leak of February 2024 exposed how deep that private-sector layer runs. Recent emphasis has shifted from IP theft toward pre-positioning in critical infrastructure.

Volt Typhoon

China·State-Sponsored·2021

Active

Pre-positioning inside U.S. critical infrastructure with no collection payoff — access held for five years for use in a future conflict.

VANGUARD PANDAUNC3236BRONZE SILHOUETTE+6
9 aliases5 CVEs13 T-codesProfile

Salt Typhoon

China·State-Sponsored·2019

Active

Compromised the core of U.S. telecommunications — including the lawful intercept systems used for court-ordered wiretaps.

OPERATOR PANDAUNC5807+6
8 aliases6 CVEs11 T-codesProfile

APT41

China·State-Sponsored·2012

Active

State espionage by day, cybercrime by night. Indicted operators ran MSS-aligned intrusions and personal money-making schemes from the same infrastructure.

Wicked PandaBrass TyphoonBRONZE ATLAS+9
12 aliases6 CVEs12 T-codesProfile

Silk Typhoon

China·State-Sponsored·2020

Active

Ran the ProxyLogon mass exploitation that web-shelled tens of thousands of Exchange servers, then pivoted to attacking the IT supply chain.

MURKY PANDA+6
7 aliases6 CVEs9 T-codesProfile

APT10

China·State-Sponsored·2006

Active

Operation Cloud Hopper — compromised managed service providers to reach their clients' networks, turning outsourced IT into a single point of failure.

Ministry of State Security (MSS) · Huaying Haitai Science and Technology Development Co. (front company)

Stone PandaBRONZE RIVERSIDE+8
10 aliases4 CVEs10 T-codesProfile

APT40

China·State-Sponsored·2009

Active

MSS Hainan bureau running maritime and naval technology collection — and among the fastest actors at weaponising new vulnerabilities.

Ministry of State Security (MSS) · Hainan Xiandun Technology Development Co. (front company)

Kryptonite PandaGingham TyphoonBRONZE MOHAWK+9
12 aliases6 CVEs10 T-codesProfile

Mustang Panda

China·State-Sponsored·2014

Active

The highest-volume Chinese espionage operation against Europe and Southeast Asia — and the subject of an FBI operation that deleted its malware from 4,258 U.S. computers.

Twill TyphoonBRONZE PRESIDENTStately Taurus+9
12 aliases3 CVEs10 T-codesProfile

APT31

China·State-Sponsored·2010

Active

MSS Hubei bureau targeting politicians, election infrastructure, and dissidents — sanctioned by both the U.S. and U.K. in March 2024.

Ministry of State Security (MSS) · Wuhan Xiaoruizhi Science and Technology Company (front company)

Judgment PandaViolet TyphoonBRONZE VINEWOOD+6
9 aliases3 CVEs9 T-codesProfile

APT1

China·State-Sponsored·2006–2014

Defunct

PLA Unit 61398. The first threat group ever publicly attributed to a specific military unit — the report that created the modern threat intelligence industry.

People's Liberation Army · Unit 61398

Comment PandaTG-8223+6
8 aliases1 CVEs9 T-codesProfile

Iran

5 groups

Split between the Islamic Revolutionary Guard Corps (IRGC) and the Ministry of Intelligence and Security (MOIS), heavily reliant on contractor front companies. Distinguished by willingness to cross from espionage into destructive attacks and hack-and-leak information operations, and by unusually aggressive social engineering.

North Korea

5 groups

Uniquely fuses espionage with revenue generation — the Reconnaissance General Bureau runs both intelligence collection and large-scale cryptocurrency theft that funds the weapons programme. The only state apparatus for which financial crime is a primary, sanctioned mission rather than a sideline.

Vietnam

1 group

Regionally focused collection against neighbouring states, foreign firms operating in-country, and diaspora dissidents.

Pakistan

1 group

Collection concentrated almost entirely on Indian military, government, and defence targets.

India

1 group

Regional collection against Pakistan, China, and Nepal, alongside a notable commercial hack-for-hire sector.

Belarus

1 group

Limited independent capability, closely aligned with and reinforcing Russian information operations.

Israel

1 group

Assessed origin of several high-impact disruptive operations against Iranian infrastructure, conducted under hacktivist cover.

Multiple / Non-state

4 groups

Financially motivated and hacktivist groups without a single state sponsor. Membership is frequently transnational, and affiliates rotate between brands as law-enforcement pressure lands.