PROJECT

CTI-AI

CTI Workbench

LIVE OPERATIONS

Threat Actor Dossiers

STRATEGIC INTEL HUB

Attributed Nation-State Threat Clusters, Ransomware Syndicates, Historical Breach Catalogs & Known TTPs

This View: Strategic Actor Dossiers (`/actors`)

Focuses on WHO adversaries are—country origin, threat group aliases, targeted industries, historical breach catalog, and MITRE ATT&CK technique mapping.

Operational View: Active Campaign Radar (`/tracking`)

Focuses on WHAT adversaries are doing right now—live C2 IPs/domains, active intrusion steps, detection trigger rates, and real-time IOC feeds.

Adversary Group Matrix (10 Active Threat Groups)
Sorted By: latestDate (desc)
No
Title & Aliases
Latest Date
Breach Count
IOCsTTPsCVEsDetectionsTechnologyIndustryTarget LocationMalware12-Month Activity
1
🏴‍☠️
Toy GhoulsGenieLocker Gang, UNC9012
31 Jul 262272108Windows ServerFinancialRussia1
85
2
🇷🇺
Void BlizzardCL-STA-1114, LAUNDRY BEAR, APT28, Fancy Bear
30 Jul 26310458214WindowsFinancialUkraine5
140
3
🇰🇵
BlueNoroffAPT38, TA444, Stardust Chollima
29 Jul 26110925011WindowsFinancialUnited States3
120
4
🇨🇳
JadeProxUNC4891, Earth Lusca
27 Jul 261672849WindowsGovernmentIsrael11
90
5
🏴‍☠️
LockBit Supporter GroupLockBit 3.0, LockBit Black
24 Jul 2614412289319Windows ServerFinancialUnited States4
220
6
🏴‍☠️
UNC6671 (BlackFile)BlackFile, UNC6671, Storm-1892, BlackFile Gang
13 Aug 26314246318WindowsFinancial ServicesUnited States4
175
7
🇰🇵
DPRK State Cyber Cluster (Lazarus / RGB / Kimsuky)RGB, Lazarus Group, Hidden Cobra, APT38, Kimsuky, Andariel, Ricochet Chollima
13 Aug 268310142438Financial SWIFTFinancialUnited States8
260
8
🏴‍☠️
ShinyHuntersShinyHunters, UNC5537, ShinyHunters Crime Syndicate
12 Aug 26618576122Snowflake Cloud Data WarehouseFinancialUnited States3
240
9
🇷🇺
CL0P Ransomware Group (TA505 / Lace Tempest)CL0P, TA505, Lace Tempest, FIN11, Evil Corp affiliate
11 Aug 2618520215542MOVEit Transfer MFTFinancial ServicesUnited States5
380
10
🇮🇷
CyberAv3ngersIRGC Cyber Command, Cotton Sandstorm
01 Aug 2626854224Unitronics PLCUtilitiesUnited States (7 States)2
86
LIVE OSINT FEED
[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.[--:--:--]RansomHub infrastructure detected actively scanning public repositories for secrets.[--:--:--]New leak: 14k internal developer credentials tied to corporate git repos posted on BreachForums.[--:--:--]OSINT Warning: Known ShinyHunters OAuth app redirect domains resurfacing via dynamic DNS.[--:--:--]Active exploit attempting to abuse Salesforce Experience Cloud Aura endpoints detected on multiple enterprise portals.[--:--:--]AI Security Alert: Abnormal volume of OpenAI API token requests from hijacked cloud GPU instances.[--:--:--]Threat group UNC6780 (Team PCP) observed pushing poisoned NPM package updates.[--:--:--]GitHub Breach Alert: Actor selling access to compromised corporate developer repositories.