APT28
ActiveFancy Bear, Sofacy, Sednit
State-sponsored (Russia)
A cyberespionage group widely attributed by Western governments to Russia's military intelligence agency (GRU), active since at least the mid-2000s.
APT28 focuses on political and military intelligence gathering, typically through spear-phishing and credential harvesting against government, military, and political targets. It was publicly attributed by US intelligence agencies to the compromise of the Democratic National Committee ahead of the 2016 US election, among many other documented operations across Europe and the Americas. It remains one of the most closely tracked state-sponsored groups by Western security agencies and continues active operations.
Target SectorsGovernment, military, defense contractors, and political organizations, with a strong focus on Europe and NATO member states.
24/7 SOC Monitoring & MDR →APT29
ActiveCozy Bear, Midnight Blizzard, Nobelium
State-sponsored (Russia)
A cyberespionage group widely attributed by Western governments to Russia's foreign intelligence service (SVR), known for patient, stealthy, long-term intrusions.
APT29 is generally considered one of the most technically sophisticated state-sponsored groups, favoring quiet, long-term access over disruptive attacks. It was publicly attributed to the 2020 SolarWinds supply chain compromise, which affected thousands of organizations including multiple US government agencies, by inserting malicious code into a legitimate software update. Its operations typically prioritize intelligence collection and go to significant lengths to avoid detection over long periods.
Target SectorsGovernment agencies, think tanks, and technology/software supply chains, with a pattern of targeting organizations that provide onward access to further targets.
24/7 SOC Monitoring & MDR →Lazarus Group
ActiveHidden Cobra, Guardians of Peace, APT38
State-sponsored (North Korea)
A North Korean state-linked group that combines traditional espionage with large-scale financial theft, widely believed to help fund the North Korean regime.
Lazarus Group has been publicly attributed to a wide range of operations, including the 2014 Sony Pictures breach, the 2016 theft of $81 million from Bangladesh Bank via the SWIFT banking network, and a long-running series of cryptocurrency exchange thefts totaling billions of dollars over the past decade. This financial motive, unusual for a state-sponsored actor, is generally understood to help fund North Korean government programs under international sanctions.
Target SectorsFinancial services and cryptocurrency exchanges specifically for theft, alongside media, defense, and technology organizations for espionage.
24/7 SOC Monitoring & MDR →Volt Typhoon
ActiveBronze Silhouette, Vanguard Panda
State-sponsored (China)
A Chinese state-sponsored group focused on pre-positioning long-term access inside critical infrastructure, rather than immediate theft or disruption.
Volt Typhoon is unusual among state-sponsored actors for rarely using malware, instead relying on 'living off the land' techniques, using legitimate built-in system tools rather than custom code, which makes its activity harder to distinguish from normal administrator behavior. US and allied intelligence agencies assess the group is establishing footholds in critical infrastructure to enable potential disruptive or destructive effects during a future geopolitical crisis, rather than for immediate financial or espionage gain. CISA issued a supplementary advisory in February 2026 noting intensified activity in the water and communications sectors since mid-2025.
Target SectorsEnergy, water and wastewater, communications, and transportation critical infrastructure.
24/7 SOC Monitoring & MDR →Sandworm
ActiveVoodoo Bear, APT44, Unit 74455
State-sponsored (Russia)
A Russian military intelligence (GRU) unit specifically known for destructive operations against operational technology and critical infrastructure.
Sandworm is widely attributed to some of the most consequential OT-targeted attacks on record, including the 2015 and 2016 attacks on Ukraine's power grid that caused actual blackouts, and the 2017 NotPetya malware, which caused an estimated $10 billion in global damage after spreading far beyond its apparent original target. Unlike most espionage-focused state actors, Sandworm's operations are frequently destructive by design, making it one of the most closely watched threat actors for any organization running industrial control systems.
Target SectorsEnergy grids, industrial control systems, and government/military targets, with a particular historical focus on Ukraine but demonstrated capability for broader collateral impact.
24/7 SOC Monitoring & MDR →