ThreatBox · Threat Intelligence

ThreatBox

NivX ThreatBox is a curated intelligence library of actively-tracked adversary groups. Each dossier covers biography, known TTPs (MITRE ATT&CK), an incident timeline and related IOCs — reviewed by NivX analysts and updated as new intelligence emerges.

APT28
a.k.a. Fancy Bear, Sofacy, STRONTIUM
Espionage (state-sponsored, military intelligence) Russia (GRU Military Intelligence)since 2004
Government · Military · Defense contractors · Media
T1566.002T1190T1550.002+1
APT29
a.k.a. Cozy Bear, Nobelium, The Dukes
Espionage (state-sponsored) Russia (SVR)since 2008
Government · Diplomatic missions · Think tanks · Healthcare (COVID-19 research)
T1195.002T1078.004T1059.001+2
APT41
a.k.a. Winnti, BARIUM, BRONZE ATLAS
Dual-mission: Espionage + Financial (crypto theft, gaming abuse) China (Ministry of State Security contractor)since 2012
Video games · Healthcare · Telecom · Government
T1195.002T1190T1071.001+1
Black Basta
a.k.a. UNC4393, BlackBasta
Financial (RaaS) Russia (former Conti members attributed)since 2022-04
Healthcare · Manufacturing · Construction · Legal services
T1566.001T1105T1486+1
BlackCat / ALPHV
a.k.a. ALPHV, Noberus, Sphynx
Financial (RaaS) Russia (attributed — DarkSide/BlackMatter rebrand)since 2021-11
Healthcare · Financial services · Energy · Retail
T1486T1490T1567.002+2
Charming Kitten
a.k.a. APT35, Phosphorus, Mint Sandstorm
Espionage (state-sponsored) Iran (IRGC — Islamic Revolutionary Guard Corps)since 2013
Journalists · Human rights activists · Academia · Government policy
T1566.003T1102T1621
Clop
a.k.a. CL0P, TA505 (affiliate), FIN11 (related)
Financial (Extortion — data theft > encryption) Russia (attributed)since 2019-02
Software supply chain victims · Healthcare · Financial services · Higher education
T1190T1567.002T1657+1
FIN7
a.k.a. Carbanak, Carbon Spider, ITG14
Financial Ukraine / Russia (mixed attribution)since 2013
Retail · Hospitality · Restaurant · Point-of-Sale systems
T1566.002T1059.003T1005+1
Kimsuky
a.k.a. Velvet Chollima, Thallium, Black Banshee
Espionage + Cryptocurrency theft North Korea (RGB — Reconnaissance General Bureau)since 2012
Think tanks · Academia · Journalists · NGOs
T1566.001T1566.002T1102+1
Lazarus Group
a.k.a. Hidden Cobra, APT38, Guardians of Peace
Financial + Espionage (state-sponsored) North Korea (Reconnaissance General Bureau)since 2009
Banking · Cryptocurrency · Entertainment · Defense
T1566.001T1053.005T1573+1
LockBit
a.k.a. LockBit 3.0, LockBit Black, Bitwise Spider
Financial (RaaS) Russia (attributed)since 2019-09
Financial services · Healthcare · Manufacturing · Government
T1566.001T1078T1486+2
MuddyWater
a.k.a. Static Kitten, MERCURY, TEMP.Zagros
Espionage (state-sponsored) Iran (MOIS — Ministry of Intelligence and Security)since 2017
Government · Telecom · Oil & gas · Defense
T1059.001T1219T1566.001
Sandworm
a.k.a. Voodoo Bear, Iron Viking, TeleBots
Destructive espionage / Sabotage (state-sponsored) Russia (GRU Unit 74455)since 2009
Energy grid · Government · Media · Financial
T1485T1195.002T0800+1
Scattered Spider
a.k.a. UNC3944, 0ktapus, Scatter Swine
Financial (Ransomware affiliate + extortion) USA / UK (English-speaking, mostly teenagers)since 2022
Hospitality · Gaming (casinos) · Retail · Telecom
T1566.004T1621T1098.005+2
Turla
a.k.a. Snake, Venomous Bear, Waterbug
Espionage (state-sponsored) Russia (FSB — Center 16)since 1996
Government · Diplomatic · Military · Research
T1071.001T1090.003T1547.001+1
Volt Typhoon
a.k.a. Vanguard Panda, BRONZE SILHOUETTE, DEV-0391
Pre-positioning / Espionage China (PRC state-sponsored)since 2021
Critical infrastructure · Communications · Energy · Water
T1078T1059.001T1546+2

Made with Emergent