
THREAT‑WATCH
THREAT INTELLIGENCE
Threat Actor Profiles
Who's actually behind the headlines. Sourced from public law enforcement advisories and government attributions, not speculation.
Attribution in this field is rarely a matter of courtroom-level proof; the summaries below reflect what has been publicly attributed by government agencies, law enforcement, and established security researchers, not independent claims by THREAT-WATCH. Status (active/disrupted/defunct) reflects the most recent public reporting available and can change.
LockBit
DisruptedRansomware-as-a-Service (financially motivated)
A ransomware-as-a-service operation that was, by volume, the most active ransomware group globally before an international law enforcement takedown in February 2024.
BlackCat / ALPHV
DefunctRansomware-as-a-Service (financially motivated)
A ransomware-as-a-service operation active from late 2021 that collapsed in an apparent exit scam in March 2024, stealing an affiliate's ransom payment instead of paying out.
Scattered Spider
ActiveFinancially motivated / extortion
A financially motivated group known for sophisticated social engineering, particularly help-desk impersonation and SIM swapping, that has evolved into deploying ransomware directly.
Akira
ActiveRansomware-as-a-Service (financially motivated)
A closed ransomware-as-a-service operation active since April 2023 that became one of the most prolific ransomware groups globally by ransom proceeds in 2025.
Cl0p
ActiveData extortion (financially motivated)
A group known for mass-exploiting vulnerabilities in file-transfer and enterprise software to steal data at scale, often without deploying encryption at all.
FIN7
ActiveFinancially motivated
A financially motivated group active since around 2013, historically known for targeting point-of-sale systems and, more recently, for links to multiple ransomware affiliate operations.
APT28
ActiveState-sponsored (Russia)
A cyberespionage group widely attributed by Western governments to Russia's military intelligence agency (GRU), active since at least the mid-2000s.
APT29
ActiveState-sponsored (Russia)
A cyberespionage group widely attributed by Western governments to Russia's foreign intelligence service (SVR), known for patient, stealthy, long-term intrusions.
Lazarus Group
ActiveState-sponsored (North Korea)
A North Korean state-linked group that combines traditional espionage with large-scale financial theft, widely believed to help fund the North Korean regime.
Volt Typhoon
ActiveState-sponsored (China)
A Chinese state-sponsored group focused on pre-positioning long-term access inside critical infrastructure, rather than immediate theft or disruption.
Sandworm
ActiveState-sponsored (Russia)
A Russian military intelligence (GRU) unit specifically known for destructive operations against operational technology and critical infrastructure.