THREAT-WATCH logo

THREAT‑WATCH

THREAT INTELLIGENCE

Threat Actor Profiles

Who's actually behind the headlines. Sourced from public law enforcement advisories and government attributions, not speculation.

Attribution in this field is rarely a matter of courtroom-level proof; the summaries below reflect what has been publicly attributed by government agencies, law enforcement, and established security researchers, not independent claims by THREAT-WATCH. Status (active/disrupted/defunct) reflects the most recent public reporting available and can change.

LockBit

Disrupted

Ransomware-as-a-Service (financially motivated)

A ransomware-as-a-service operation that was, by volume, the most active ransomware group globally before an international law enforcement takedown in February 2024.

BlackCat / ALPHV

Defunct

Ransomware-as-a-Service (financially motivated)

A ransomware-as-a-service operation active from late 2021 that collapsed in an apparent exit scam in March 2024, stealing an affiliate's ransom payment instead of paying out.

Scattered Spider

Active

Financially motivated / extortion

A financially motivated group known for sophisticated social engineering, particularly help-desk impersonation and SIM swapping, that has evolved into deploying ransomware directly.

Akira

Active

Ransomware-as-a-Service (financially motivated)

A closed ransomware-as-a-service operation active since April 2023 that became one of the most prolific ransomware groups globally by ransom proceeds in 2025.

Cl0p

Active

Data extortion (financially motivated)

A group known for mass-exploiting vulnerabilities in file-transfer and enterprise software to steal data at scale, often without deploying encryption at all.

FIN7

Active

Financially motivated

A financially motivated group active since around 2013, historically known for targeting point-of-sale systems and, more recently, for links to multiple ransomware affiliate operations.

APT28

Active

State-sponsored (Russia)

A cyberespionage group widely attributed by Western governments to Russia's military intelligence agency (GRU), active since at least the mid-2000s.

APT29

Active

State-sponsored (Russia)

A cyberespionage group widely attributed by Western governments to Russia's foreign intelligence service (SVR), known for patient, stealthy, long-term intrusions.

Lazarus Group

Active

State-sponsored (North Korea)

A North Korean state-linked group that combines traditional espionage with large-scale financial theft, widely believed to help fund the North Korean regime.

Volt Typhoon

Active

State-sponsored (China)

A Chinese state-sponsored group focused on pre-positioning long-term access inside critical infrastructure, rather than immediate theft or disruption.

Sandworm

Active

State-sponsored (Russia)

A Russian military intelligence (GRU) unit specifically known for destructive operations against operational technology and critical infrastructure.