Skip to content

The Adversary Archive

106 adversary profiles across Major and Minor Arcana.

Origin:
Sector:
Volume:
0Nation-State
The Ghost
Equation Group
USA (NSA-linked)
5 TTPs
1Nation-State
The Phantom
APT28
Russia (GRU Unit 26165)
7 TTPs
2Nation-State
The Shadow Court
APT29
Russia (SVR)
7 TTPs
3Nation-State
The Destroyer
Sandworm
Russia (GRU Unit 74455)
6 TTPs
4Nation-State
The Serpent
Turla
Russia (FSB)
6 TTPs
5Nation-State
The Archivist
APT1
China (PLA Unit 61398)
5 TTPs
6Nation-State
The Ten Thousand
APT41
China (MSS-affiliated)
7 TTPs
7Nation-State
The Silent Dragon
Volt Typhoon
China (PLA-linked)
6 TTPs
8Nation-State
The Specter
Lazarus Group
North Korea (Reconnaissance General Bureau)
7 TTPs
9Nation-State
The Alchemist
APT38
North Korea (Reconnaissance General Bureau, financial unit)
5 TTPs
10Nation-State
The Whisperer
Kimsuky
North Korea (RGB)
5 TTPs
11Nation-State
The Flame Keeper
APT33
Iran (IRGC-affiliated)
5 TTPs
12Nation-State
The Oracle
APT34
Iran (Ministry of Intelligence)
6 TTPs
13Nation-State
The Charmed One
APT35
Iran (IRGC)
5 TTPs
14Criminal
The Merchant
FIN7
Criminal (Eastern Europe)
7 TTPs
15Criminal
The Reaper
REvil
Criminal (Russia, CIS-based)
6 TTPs
16Criminal
The Locked Tower
LockBit
Criminal (Russia-linked, global affiliates)
6 TTPs
17Criminal
The Plague
Conti
Criminal (Russia, St. Petersburg-linked)
7 TTPs
18Trickster
The Shape Shifter
Scattered Spider
Criminal (Anglophone, primarily US/UK teens)
6 TTPs
19Criminal
The Void
BlackCat / ALPHV
Criminal (Russia-linked, RaaS)
6 TTPs
20Hacktivist
The Thousand Masks
Anonymous
Hacktivist (decentralized, global)
4 TTPs
21Hacktivist
The Storm
KillNet
Russia (pro-Kremlin hacktivist)
3 TTPs
S1Nation-State
The Thousand Hands
APT10
China (MSS - Tianjin Bureau)
6 TTPs
S2Nation-State
The Tidal Current
APT40
China (MSS - Hainan State Security)
6 TTPs
S3Nation-State
The Hidden Key
Hafnium
China (MSS-linked)
6 TTPs
S4Nation-State
The Patient Archivist
Bronze Butler
China (PLA-linked)
5 TTPs
S5Nation-State
The Nomadic Eye
Mustang Panda
China (MSS-linked)
5 TTPs
S6Nation-State
The Wire
Salt Typhoon
China (MSS-linked)
5 TTPs
S7Nation-State
The Hunger
Gamaredon
Russia (FSB - Crimean officers)
6 TTPs
S8Nation-State
The Confessor
Callisto Group
Russia (FSB Centre 18)
6 TTPs
S9Nation-State
The Grudge
Bitter
South Asia (India-linked, suspected)
5 TTPs
S10Nation-State
The Viper
SideWinder
India (suspected)
5 TTPs
S11Nation-State
The Collage
Patchwork
India (suspected)
5 TTPs
S12Nation-State
The Long Shadow
Transparent Tribe
Pakistan (ISI-linked, suspected)
5 TTPs
S13Nation-State
The Lotus Eye
TA413
China (MSS - Tibet-focused)
5 TTPs
S14Nation-State
The Marsh
MuddyWater
Iran (MOIS - Ministry of Intelligence)
6 TTPs
W1Nation-State
The Arsonist
Predatory Sparrow
Israel (suspected)
5 TTPs
W2Nation-State
The Flood
Moses Staff
Iran (IRGC-linked)
5 TTPs
W3Nation-State
The Wrench
Cyber Av3ngers
Iran (IRGC - Islamic Revolutionary Guard Corps)
5 TTPs
W4Nation-State
The Invisible Chain
UNC2452
Russia (SVR-linked)
7 TTPs
W5Nation-State
The Saboteur
Stuxnet Operators
USA / Israel (joint NSA–Unit 8200)
5 TTPs
W6Hacktivist
The Thunderhead
Anonymous Sudan
Sudan / Russia (disputed - possible Russian front)
4 TTPs
W7Hacktivist
The Volunteer Corps
IT Army of Ukraine
Ukraine (government-coordinated volunteer collective)
3 TTPs
W8Hacktivist
The Fractured Flag
GhostSec
Hacktivist (international collective)
4 TTPs
W9Hacktivist
The Red Star
RedHack
Turkey (Marxist-Leninist hacktivist group)
4 TTPs
W10Hacktivist
The Jungle Eye
Guacamaya
Latin America (environmental/political hacktivist)
4 TTPs
W11Hacktivist
The Affiliate
UserSec
Russia (pro-Kremlin hacktivist affiliate)
3 TTPs
W12Nation-State
The Blind Eagle
APT-C-36
South America (Colombia-linked, suspected)
5 TTPs
W13Nation-State
The Mercenary Wing
Yellow Garuda
Unknown (Southeast Asia region, suspected state-linked)
5 TTPs
W14Nation-State
The Breach of Trust
Operation Aurora
China (PLA Unit 61398 adjacent)
5 TTPs
C1Trickster
The Jester
Lapsus$
Criminal (UK/Brazil, mostly teenagers)
6 TTPs
C2Trickster
The Sim Swap
UNC3944
Criminal (English-speaking, Western)
6 TTPs
C3Criminal
The Insider
FIN4
Criminal (financially motivated, suspected Western)
6 TTPs
C4Criminal
The Hospitality Thief
FIN8
Criminal (Eastern European, suspected)
6 TTPs
C5Criminal
The Broker
TA505
Criminal (Russian-speaking, suspected)
6 TTPs
C6Criminal
The False Itinerary
TA558
Criminal (Latin America focused)
5 TTPs
C7Nation-State
The Watering Hole
Tortoiseshell
Iran (IRGC-linked)
5 TTPs
C8Nation-State
The Gaza Whisper
Molerats
Palestine (Hamas-affiliated, suspected)
5 TTPs
C9Nation-State
The Persona Collective
Bahamut
Private sector (suspected Gulf state contractor)
5 TTPs
C10Criminal
The False KYC
Evilnum
Private sector (mercenary, suspected European)
5 TTPs
C11Nation-State
The Ghostwriter
UNC1151
Belarus (KGB-linked)
5 TTPs
C12Nation-State
The Supply Chain Reader
SilverFish
Russia (SVR-linked)
4 TTPs
C13Criminal
The Petty Face
Gorgon Group
Pakistan (suspected)
4 TTPs
C14Nation-State
The Latin Blade
Machete
Venezuela / Latin America (suspected state-linked)
5 TTPs
P1Criminal
The Silent Toll
Cl0p
Criminal (Russian-speaking)
6 TTPs
P2Criminal
The Dark Dividend
DarkSide
Criminal (Russian-speaking)
7 TTPs
P3Criminal
The Hospital Ward
Hive
Criminal (Eastern European)
6 TTPs
P4Criminal
The Rebrand
BlackMatter
Criminal (Russian-speaking, DarkSide successor)
6 TTPs
P5Criminal
The Schoolyard
Vice Society
Criminal (suspected Russian-speaking)
5 TTPs
P6Criminal
The Dark Counter
FIN6
Criminal (Eastern European, suspected)
6 TTPs
P7Criminal
The Banker
Carbanak
Criminal (Eastern European - Ukraine/Russia)
6 TTPs
P8Criminal
The Second Stage
TrickBot / Ryuk
Criminal (Russian-speaking - likely Saint Petersburg)
7 TTPs
P9Criminal
The Delivery Service
Emotet / Mealybug
Criminal (Eastern European)
5 TTPs
P10Criminal
The Payment Card Ghost
FIN5
Criminal (Eastern European, suspected)
5 TTPs
P11Criminal
The Invisible Skimmer
Magecart
Criminal (multiple groups, decentralized)
5 TTPs
P12Criminal
The Frozen Account
IcedID / Bokbot
Criminal (Eastern European)
6 TTPs
P13Criminal
The Side Door
BazaLoader
Criminal (TrickBot operators - Russian-speaking)
4 TTPs
P14Criminal
The False Tax
TA2101
Criminal (suspected Eastern European)
4 TTPs
II·79Nation-State
The Jade Censor
APT31
China (MSS - Ministry of State Security)
7 TTPs
II·80Nation-State
The Lotus Watcher
APT32
Vietnam (Ministry of Public Security, suspected)
7 TTPs
II·81Nation-State
The Scarlet Reaper
APT37
North Korea (RGB - Reconnaissance General Bureau)
7 TTPs
II·82Nation-State
The Veil of Chafer
APT39
Iran (MOIS - Ministry of Intelligence and Security)
7 TTPs
II·83Nation-State
The Damselfly
APT42
Iran (IRGC-IO - Islamic Revolutionary Guard Corps Intelligence Organization)
7 TTPs
II·84Nation-State
The Sunken Dragon
Aquatic Panda
China (MSS-affiliated)
7 TTPs
II·85Nation-State
The Circuit Phantom
BlackTech
China (PLA-affiliated, Taiwan operations)
7 TTPs
II·86Nation-State
The Dusty Archivist
Earth Lusca
China (MSS-affiliated contractor)
7 TTPs
II·87Nation-State
The Harvester of Roots
Flax Typhoon
China (MSS - Integrity Technology Group)
7 TTPs
II·88Nation-State
The Key Forger
Storm-0558
China (MSS - suspected)
7 TTPs
II·89Nation-State
The First Frost
Cadet Blizzard
Russia (GRU Unit 161)
7 TTPs
II·90Nation-State
The Patient Inheritor
Berserk Bear
Russia (FSB Centre 16)
7 TTPs
II·91Hacktivist
The Battering Ram
NoName057(16)
Russia (pro-Kremlin hacktivist collective)
6 TTPs
II·92Hacktivist
The Iron Tide
Cyber Army of Russia Reborn
Russia (GRU-linked hacktivist, Sandworm affiliate)
6 TTPs
II·93Nation-State
The Obsidian Hammer
Onyx Sleet
North Korea (RGB - 3rd Bureau)
7 TTPs
II·94Nation-State
The Jade Thief
Jade Sleet
North Korea (RGB - Lazarus sub-unit)
7 TTPs
II·95Nation-State
The Pale Deceiver
Moonstone Sleet
North Korea (RGB)
7 TTPs
II·96Nation-State
The Gate Merchant
Pioneer Kitten
Iran (IRGC - contractor network)
7 TTPs
II·97Criminal
The Sanctioned Serpent
Evil Corp
Russia (FSB-linked, Maksim Yakubets)
7 TTPs
II·98Criminal
The Black Choir
Black Basta
Criminal (Russian-speaking, Conti splinter group)
7 TTPs
II·99Criminal
The Neon Predator
Akira
Criminal (Russian-speaking, suspected)
7 TTPs
II·100Criminal
The Gambit
Play
Criminal (suspected Eastern European)
7 TTPs
II·101Criminal
The Centipede
Rhysida
Criminal (suspected Eastern European)
7 TTPs
II·102Criminal
The Auction House
RansomHub
Criminal (Russia-linked, global affiliates)
7 TTPs
II·103Unknown
The Signal Thief
LightBasin
Unknown (suspected nation-state, telecom specialist)
7 TTPs
II·104Trickster
The Data Magpie
ShinyHunters
Criminal (French and Moroccan nationals, suspected)
7 TTPs
II·105Trickster
The Chaos Court
The Com
Criminal (Anglophone, primarily US/UK teens and young adults)
7 TTPs
II·106Trickster
The Unmasked
ViLE
Criminal (US-based, young adults)
7 TTPs
Data sourced from MITRE ATT&CK. For educational purposes.