OSIRIS THREAT INTELLIGENCE

Know the actors.
Understand the tradecraft.

Explore the complete MITRE ATT&CK group directory and connect reported activity to the adversaries named by credible sources. Attribution is presented as reported—not as certainty.

12TRACKED GROUPS

MITRE ATT&CK defines these as activity clusters. Names and aliases can overlap across reporting organizations.

Checking sourcesUpdated Sep 1, 2026, 10:00 PM · 24-hour refresh
12 groups shown
G0007

APT28

Fancy Bear / Forest Blizzard / Sofacy

A Russia-linked threat group attributed to GRU Unit 26165, known for long-running espionage and influence operations.

No newly sourced activity in today's feed.

Open MITRE profile
G0016

APT29

Cozy Bear / Midnight Blizzard / NOBELIUM

A Russia-linked espionage group attributed to the Foreign Intelligence Service (SVR), active against government, research, and policy organizations.

No newly sourced activity in today's feed.

Open MITRE profile
G0050

APT32

OceanLotus / BISMUTH

A suspected Vietnam-based group focused on government and private-sector targets across Southeast Asia.

No newly sourced activity in today's feed.

Open MITRE profile
G0046

FIN7

Carbon Spider / Sangria Tempest

A financially motivated group that has targeted retail, hospitality, technology, financial services, and cloud environments.

No newly sourced activity in today's feed.

Open MITRE profile
G0094

Kimsuky

APT43 / Emerald Sleet / TA427

A DPRK-linked espionage group focused on foreign policy, national security, research, and government targets.

No newly sourced activity in today's feed.

Open MITRE profile
G0032

Lazarus Group

HIDDEN COBRA / Diamond Sleet / ZINC

A North Korean state-sponsored umbrella group associated with espionage, destructive operations, and financially motivated activity.

No newly sourced activity in today's feed.

Open MITRE profile
G0059

Magic Hound

APT35 / Charming Kitten / Mint Sandstorm

An Iranian-sponsored group conducting resource-intensive espionage and social-engineering operations.

No newly sourced activity in today's feed.

Open MITRE profile
G0034

Sandworm Team

APT44 / Seashell Blizzard / Voodoo Bear

A destructive Russia-linked group attributed to GRU Unit 74455 and associated with disruptive critical-infrastructure attacks.

No newly sourced activity in today's feed.

Open MITRE profile
G1015

Scattered Spider

UNC3944 / Octo Tempest / Storm-0875

A financially motivated group known for help-desk impersonation, MFA bypass, identity compromise, and extortion.

No newly sourced activity in today's feed.

Open MITRE profile
G0092

TA505

Spandex Tempest / Hive0065

A cybercriminal group associated with large-scale malware distribution and ransomware campaigns.

No newly sourced activity in today's feed.

Open MITRE profile
G1055

VOID MANTICORE

Handala Hack / Red Sandstorm

An Iran-linked destructive actor associated with wiper attacks and hack-and-leak campaigns.

No newly sourced activity in today's feed.

Open MITRE profile
G1017

Volt Typhoon

Vanguard Panda / Voltzite / Bronze Silhouette

A PRC state-sponsored actor focused on critical infrastructure and stealthy living-off-the-land access.

No newly sourced activity in today's feed.

Open MITRE profile
ATTRIBUTION STANDARD

Group identities, aliases, and descriptions are sourced from MITRE ATT&CK. Recent activity appears only when a monitored source explicitly names the group or an associated name. Osiris Cyber does not infer attribution from technical similarity alone.

Review MITRE source