APT28
Fancy Bear / Forest Blizzard / Sofacy
A Russia-linked threat group attributed to GRU Unit 26165, known for long-running espionage and influence operations.
No newly sourced activity in today's feed.
Open MITRE profileOSIRIS THREAT INTELLIGENCE
Explore the complete MITRE ATT&CK group directory and connect reported activity to the adversaries named by credible sources. Attribution is presented as reported—not as certainty.
MITRE ATT&CK defines these as activity clusters. Names and aliases can overlap across reporting organizations.
Fancy Bear / Forest Blizzard / Sofacy
A Russia-linked threat group attributed to GRU Unit 26165, known for long-running espionage and influence operations.
No newly sourced activity in today's feed.
Open MITRE profileCozy Bear / Midnight Blizzard / NOBELIUM
A Russia-linked espionage group attributed to the Foreign Intelligence Service (SVR), active against government, research, and policy organizations.
No newly sourced activity in today's feed.
Open MITRE profileOceanLotus / BISMUTH
A suspected Vietnam-based group focused on government and private-sector targets across Southeast Asia.
No newly sourced activity in today's feed.
Open MITRE profileCarbon Spider / Sangria Tempest
A financially motivated group that has targeted retail, hospitality, technology, financial services, and cloud environments.
No newly sourced activity in today's feed.
Open MITRE profileAPT43 / Emerald Sleet / TA427
A DPRK-linked espionage group focused on foreign policy, national security, research, and government targets.
No newly sourced activity in today's feed.
Open MITRE profileHIDDEN COBRA / Diamond Sleet / ZINC
A North Korean state-sponsored umbrella group associated with espionage, destructive operations, and financially motivated activity.
No newly sourced activity in today's feed.
Open MITRE profileAPT35 / Charming Kitten / Mint Sandstorm
An Iranian-sponsored group conducting resource-intensive espionage and social-engineering operations.
No newly sourced activity in today's feed.
Open MITRE profileAPT44 / Seashell Blizzard / Voodoo Bear
A destructive Russia-linked group attributed to GRU Unit 74455 and associated with disruptive critical-infrastructure attacks.
No newly sourced activity in today's feed.
Open MITRE profileUNC3944 / Octo Tempest / Storm-0875
A financially motivated group known for help-desk impersonation, MFA bypass, identity compromise, and extortion.
No newly sourced activity in today's feed.
Open MITRE profileSpandex Tempest / Hive0065
A cybercriminal group associated with large-scale malware distribution and ransomware campaigns.
No newly sourced activity in today's feed.
Open MITRE profileHandala Hack / Red Sandstorm
An Iran-linked destructive actor associated with wiper attacks and hack-and-leak campaigns.
No newly sourced activity in today's feed.
Open MITRE profileVanguard Panda / Voltzite / Bronze Silhouette
A PRC state-sponsored actor focused on critical infrastructure and stealthy living-off-the-land access.
No newly sourced activity in today's feed.
Open MITRE profileGroup identities, aliases, and descriptions are sourced from MITRE ATT&CK. Recent activity appears only when a monitored source explicitly names the group or an associated name. Osiris Cyber does not infer attribution from technical similarity alone.