Loose hacktivist collective targeting government and infrastructure with defacements and DDoS.
DPRK financially-motivated cluster targeting cryptocurrency.
Russian military intelligence cyber-espionage group attributed to GRU Unit 26165.
Russian SVR cyber-espionage group; perpetrators of the SolarWinds supply-chain compromise.
DPRK financial-heist cluster attributed to the Reconnaissance General Bureau.
DEV-0537, widely known as Lapsus$, is an extortion-focused cybercriminal collective active since 2021, composed of members spanning multiple countries and notable for including younger individuals among its ranks. The group primarily pursues financial gain and notoriety by compromising high-profile organizations through social engineering, credential theft, and insider recruitment rather than traditional malware-heavy intrusion methods. Their targeting is broad and opportunistic, spanning sectors such as technology, telecommunications, government, finance, and retail across North America, South America, Europe, and Asia.
DPRK IT-worker fraud operation.
DPRK RGB cyber unit responsible for high-impact financial heists and espionage.
DPRK cluster engaged in IT-worker fraud and ransomware development.
Native-English-speaking eCrime collective known for social-engineering helpdesks.
Ransomware crew historically targeting education and healthcare.