THREAT GROUPS   2026()  2025()  2024() | PODLE ABECEDY | PODLE ZEMĚ | PODLE ROKU  PODLE MĚSÍCŮ
H 
APT  CYBERCRIME  HACKTIVISTS  MaaS  NATION STATE  RaaS  ABECEDNĚ | GROUPS  GROUP LIST

DATE

NAME

INFO

CATEGORY

SUBCATE

11.8.26

#StopRansomware: Gunra Ransomware Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. GROUP RANSOM

11.8.26

AA26-222A StopRansomware Gunra Ransomware The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. GROUP RANSOM

8.8.26

Pink New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits GROUP GROUP

8.8.26

UNC6671 UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments GROUP GROUP

3.8.26

Larva-24009 Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor GROUP GROUP

30.7.26

Toy Ghouls Toy Ghouls’ new toy: the GenieLocker ransomware GROUP GROUP

30.7.26

SilverFox Evolves Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan GROUP GROUP

30.7.26

TA488 Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit GROUP GROUP

25.7.26

Funky Mantis Funky Mantis operates as a centralized ransomware-as-a-service model. Administrators manage affiliates, distribute access, and support extortion through private communications and a dedicated web platform. The platform combines payload building, finance, negotiation, support, and victim management, giving the service control over affiliate access and operational progress. GROUP GROUP

24.7.26

TAG-195 TAG-195 Upgrades MaaS Ecosystem with Modular Tools GROUP GROUP

23.7.26

Chaos RaaS Unmasking the new Chaos RaaS group attacks GROUP GROUP

18.7.26

SuccessKey ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey

GROUP

GROUP

18.7.26

UAT-11795 Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

GROUP

GROUP

17.7.26

GoldenEyeDog

Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

GROUP

GROUP

12.7.26 Helix Helix, a New Name in the Data Extortion Ecosystem? GROUP Vishing
12.7.26 UNK_MassTraction One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation GROUP Cluster
7.7.26 Cavern Manticore Cavern Manticore: Exposing Iran-Linked Modular C2 Framework GROUP GROUP

13.6.26

Velvet Ant

China-Nexus Threat Group ‘Velvet Ant’ Abuses F5 Load Balancers for Persistence

GROUP

GROUP

8.6.26 UNC3753 Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms GROUP GROUP
6.6.26 TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access NCC Group’s global Cyber Incident Response Team has observed an increase in Clop ransomware victims in the past weeks. The surge can be traced back to a vulnerability in SolarWinds Serv-U that is being abused by the TA505 threat actor. GROUP GROUP
5.6.26 Cluster OP-512 ReliaQuest's Agentic AI Uncovers New China-Linked Cluster OP-512 GROUP GROUP
4.6.26 TA4922 TA4922: The Suspected Chinese Crime Group is Going Global GROUP GROUP
3.6.26 UAC-0184 UAC-0184: From HTA to a Signed Network Stack GROUP GROUP
29.5.26 GREYVIBE GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations GROUP GROUP
28.5.26 JINX-0164 Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure GROUP GROUP
23.5.26 Storm-2949 How Storm-2949 turned a compromised identity into a cloud-wide breach GROUP GROUP
20.5.26 Disrupting Fox Tempest Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware  GROUPS RANSOMWARE
18.5.26 Fast16 Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations GROUP GROUP
14.5.26 UNC1151 UNC1151 exploiting Roundcube to steal user credentials in a spearphishing campaign GROUP GROUP
14.5.26 FrostyNeighbor FrostyNeighbor: Fresh mischief and digital shenanigans GROUP GROUP
6.5.26 UAT-8302 UAT-8302 and its box full of malware GROUP GROUP
1.5.26 Cordial Spider CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. CORDIAL SPIDER gains initial access to victim systems via voice phishing (vishing) calls in which they direct targeted users to single sign-on (SSO)–themed phishing pages. GROUP GROUP
1.5.26 Snarky Spider SNARKY SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion and cryptocurrency theft since at least October 2025. T GROUP GROUP
1.5.26 Shadow-Earth-053 Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia GROUP GROUP
26.4.26 Cordial Spider CORDIAL SPIDER is a financially motivated eCrime adversary that has performed data theft and extortion since at least October 2025. CORDIAL SPIDER gains initial access to victim systems via voice phishing (vishing) calls in which they direct targeted users to single sign-on (SSO)–themed phishing pages. GROUP GROUP
25.4.26 UNC6692 Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. GROUP GROUP
25.4.26 UAT-4356's Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices. GROUP GROUP
24.4.26 UNC6692   GROUP GROUP
17.4.26 UAC-0247 Лікарні, органи місцевого самоврядування та оператори FPV - у фокусі кластера кіберзагроз UAC-0247 GROUP GROUP
12.4.26 Storm-2755 Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees GROUP GROUP
8.4.26 FrostArmada A DNS setting change on a single router can quietly reroute an entire network’s authentication traffic. In FrostArmada, Lumen observed Forest Blizzard using that technique to feed targeted logins into Attacker-in-the-Middle (AitM) infrastructure, scaling from limited activity to thousands of victims worldwide. GROUP GROUP
8.4.26 Pay2Key Pay2Key Iranian-Linked Ransomware is Back, Back Again GROUP RANSOMWARE
8.4.26 Storm-1175 Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations GROUP GROUP
8.4.26 PIONEER KITTEN Who Is PIONEER KITTEN? GROUP APT
5.4.26 TA416 I’d come running back to EU again: TA416 resumes European government espionage campaigns GROUP GROUP
3.4.26 UAT-10608 UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications GROUP GROUP
1.4.26 UNC1069 North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack GROUP GROUP
27.3.26 Bearlyfy Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware GROUP GROUP
14.3.26 Handala Hack Handala Hack is an online persona operated by Void Manticore (aka Red Sandstorm, Banished Kitten), an actor affiliated with Iranian Ministry of Intelligence and Security (MOIS) GROUP GROUP
14.3.26 CL-STA-1087 Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia GROUP CLUSTER
14.3.26 Storm-2561 Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft GROUP GROUP
10.3.26 Sednit Sednit reloaded: Back in the trenches GROUP GROUP
8.3.26 Jasper Sleet Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations GROUP GROUP
6.3.26 UAT-9244 UAT-9244 targets South American telecommunication providers with three new malware implants GROUP GROUP
3.3.26 SloppyLemming SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvesting, malware delivery and command and control (C2). This actor conducts extensive operations targeting Pakistani, Sri Lanka, Bangladesh, and China. GROUP GROUP
1.3.26 COOKIE SPIDER COOKIE SPIDER (active since at least October 2018) develops and rents Atomic macOS Stealer (AMOS), an information stealer targeting macOS victims via multiple delivery methods, including search engine optimization (SEO) poisoning, fake job advertisements, and malicious VSCode extensions. GROUP GROUP
1.3.26 Diesel Vortex Diesel Vortex: Inside the Russian cybercrime group targeting US & EU freight GROUP GROUP
27.2.26 APT37 APT37 Adds New Capabilities for Air-Gapped Networks GROUP GROUP
26.2.26 Scattered LAPSUS$ Hunters Cyber Intel Brief: Scattered Lapsus$ Hunters (SLH) Kicks Off Campaign to Recruit Women GROUP GROUP
26.2.26 UNC2814 Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign GROUP GROUP
15.2.26 Storm-2603 Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware GROUP GROUP
14.2.26 UAT-9921 New threat actor, UAT-9921, leverages VoidLink framework in campaigns GROUP GROUP
11.2.26 UNC1069 UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering GROUP GROUP
10.2.26 UNC3886 Largest Multi-Agency Cyber Operation Mounted to Counter Threat Posed by Advanced Persistent Threat (APT) Actor UNC3886 to Singapore’s Telecommunications Sector GROUP GROUP
9.2.26 Stan Ghouls Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT GROUP GROUP
2.2.26 UAT-8099 Dissecting UAT-8099: New persistence mechanisms and regional focus GROUP GROUP
25.1.26 UAT-9686 UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager GROUP GROUP
22.1.26 PurpleBravo PurpleBravo’s Targeting of the IT Software Supply Chain GROUP GROUP
16.1.26 UAT-8837 UAT-8837 targets critical infrastructure sectors in North America GROUP GROUP
8.1.26 UAT-7290 UAT-7290 targets high value telecommunications infrastructure in South Asia GROUP GROUP
7.1.26 UAC-0184 UAC-0184 GROUP GROUP