THREAT‑WATCH logo

THREAT‑WATCH

Threat Actors

State-Aligned Threat Groups

State-aligned groups are a different problem from ransomware crews, and the difference is patience. They are not optimising for a payout this quarter, so they will spend months inside a network doing nothing visible, and they generally do not want to be noticed at all. That inverts the detection problem: there is no encryption event to alert on, and the tradecraft deliberately blends into normal administrative activity. Mid-market companies often assume this is somebody else's threat model, which is usually wrong for two reasons. Suppliers to defence, energy, shipping, telecoms and government are targets by association, and several of these groups specifically compromise smaller organisations as a route into larger ones. The profiles below cover attribution, typical targeting and what their presence tends to look like.

Attribution in this field is rarely a matter of courtroom-level proof; the summaries below reflect what has been publicly attributed by government agencies, law enforcement, and established security researchers, not independent claims by THREAT‑WATCH. Status (active/disrupted/defunct) reflects the most recent public reporting available and can change.

APT28

Active

Fancy Bear, Sofacy, Sednit

State-sponsored (Russia)

A cyberespionage group widely attributed by Western governments to Russia's military intelligence agency (GRU), active since at least the mid-2000s.

APT28 focuses on political and military intelligence gathering, typically through spear-phishing and credential harvesting against government, military, and political targets. It was publicly attributed by US intelligence agencies to the compromise of the Democratic National Committee ahead of the 2016 US election, among many other documented operations across Europe and the Americas. It remains one of the most closely tracked state-sponsored groups by Western security agencies and continues active operations.

Target SectorsGovernment, military, defense contractors, and political organizations, with a strong focus on Europe and NATO member states.

24/7 SOC Monitoring & MDR

APT29

Active

Cozy Bear, Midnight Blizzard, Nobelium

State-sponsored (Russia)

A cyberespionage group widely attributed by Western governments to Russia's foreign intelligence service (SVR), known for patient, stealthy, long-term intrusions.

APT29 is generally considered one of the most technically sophisticated state-sponsored groups, favoring quiet, long-term access over disruptive attacks. It was publicly attributed to the 2020 SolarWinds supply chain compromise, which affected thousands of organizations including multiple US government agencies, by inserting malicious code into a legitimate software update. Its operations typically prioritize intelligence collection and go to significant lengths to avoid detection over long periods.

Target SectorsGovernment agencies, think tanks, and technology/software supply chains, with a pattern of targeting organizations that provide onward access to further targets.

24/7 SOC Monitoring & MDR

Lazarus Group

Active

Hidden Cobra, Guardians of Peace, APT38

State-sponsored (North Korea)

A North Korean state-linked group that combines traditional espionage with large-scale financial theft, widely believed to help fund the North Korean regime.

Lazarus Group has been publicly attributed to a wide range of operations, including the 2014 Sony Pictures breach, the 2016 theft of $81 million from Bangladesh Bank via the SWIFT banking network, and a long-running series of cryptocurrency exchange thefts totaling billions of dollars over the past decade. This financial motive, unusual for a state-sponsored actor, is generally understood to help fund North Korean government programs under international sanctions.

Target SectorsFinancial services and cryptocurrency exchanges specifically for theft, alongside media, defense, and technology organizations for espionage.

24/7 SOC Monitoring & MDR

Volt Typhoon

Active

Bronze Silhouette, Vanguard Panda

State-sponsored (China)

A Chinese state-sponsored group focused on pre-positioning long-term access inside critical infrastructure, rather than immediate theft or disruption.

Volt Typhoon is unusual among state-sponsored actors for rarely using malware, instead relying on 'living off the land' techniques, using legitimate built-in system tools rather than custom code, which makes its activity harder to distinguish from normal administrator behavior. US and allied intelligence agencies assess the group is establishing footholds in critical infrastructure to enable potential disruptive or destructive effects during a future geopolitical crisis, rather than for immediate financial or espionage gain. CISA issued a supplementary advisory in February 2026 noting intensified activity in the water and communications sectors since mid-2025.

Target SectorsEnergy, water and wastewater, communications, and transportation critical infrastructure.

24/7 SOC Monitoring & MDR

Sandworm

Active

Voodoo Bear, APT44, Unit 74455

State-sponsored (Russia)

A Russian military intelligence (GRU) unit specifically known for destructive operations against operational technology and critical infrastructure.

Sandworm is widely attributed to some of the most consequential OT-targeted attacks on record, including the 2015 and 2016 attacks on Ukraine's power grid that caused actual blackouts, and the 2017 NotPetya malware, which caused an estimated $10 billion in global damage after spreading far beyond its apparent original target. Unlike most espionage-focused state actors, Sandworm's operations are frequently destructive by design, making it one of the most closely watched threat actors for any organization running industrial control systems.

Target SectorsEnergy grids, industrial control systems, and government/military targets, with a particular historical focus on Ukraine but demonstrated capability for broader collateral impact.

24/7 SOC Monitoring & MDR