Operations Timeline
199 notable operations across 143 adversaries
1996 — 2025
1996
Moonlight Maze (1996-1999, attributed)
Turla2008
2009
GhostNet - 1,295 infected computers in 103 countries (2009, linked operations)
TA413Google breach - source code and Gmail accounts of Chinese dissidents (2009)
Operation AuroraNatanz centrifuge destruction - 1,000+ centrifuges damaged (2009–2010)
Stuxnet Operators2010
IE zero-day (CVE-2010-0249) exploitation at scale
Operation AuroraOperation Aurora (2010, jointly attributed)
APT17Operation Payback (RIAA/MPAA DDoS, 2010)
AnonymousStuxnet (joint with Unit 8200, 2010)
Equation Group2011
HBGary Federal breach and email release (2011)
Anonymous2012
Flame malware (2012)
Equation GroupJapan aerospace and defense sector campaigns (2012–present)
Bronze ButlerNew York Times intrusion (2012-2013)
APT12Sustained CIS-region diplomatic targeting since 2012
Inception2013
Bit9 trust certificate breach (2013)
APT17DeputyDog campaign (2013)
APT17European Ministries of Foreign Affairs intrusions (2013)
Ke3changMandiant APT1 report exposure (2013)
APT1Sustained campaign against Indian armed forces since 2013
Transparent TribeTurkish government email leak - corruption documents published (2013)
RedHack2014
Continuous Ukraine targeting since 2014 annexation of Crimea
GamaredonForbes.com watering hole (2014)
APT19Sony Pictures hack (2014)
Lazarus Group2015
Anti-ISIS website takedowns and account reporting (2015–2016)
GhostSecBundestag breach (2015)
APT28FireEye attribution report (April 2015)
APT30HDD firmware persistence (2015)
Equation GroupOperation Clandestine Wolf (Internet Explorer 0-day, 2015)
APT3OpISIS following Paris attacks (2015)
AnonymousSEC charges against alleged operators (2015)
FIN4Ukraine power grid attacks (2015, 2016)
Sandworm2016
Bangladesh Bank $81M SWIFT heist (2016)
APT38Bangladesh Bank SWIFT heist ($81M, 2016)
Lazarus GroupCitizen Lab disclosure of dissident targeting (2016)
Stealth FalconDNC breach (2016, separate from APT28)
APT29DNC hack and email leak (2016)
APT28ICAO compromise via supply-chain pivot (2016)
APT27Operation Cloud Hopper - global MSP compromise (2016–2017)
APT10Operation Daybreak (2016)
APT37Repurposed NSA EternalSynergy exploit (2016-2017)
APT3WADA doping agency hack (2016)
APT282017
Boyusec / Wu Yingzhuo / Dong Hao DOJ indictment (2017)
APT3CVE-2017-11882 Equation Editor exploitation
InceptionFrench election interference (2017)
APT28NotPetya global wiper (2017, $10B+ damage)
SandwormOperation Erebus (2017)
APT37UK government service provider supply-chain compromise (2017)
Ke3changUS electric grid intrusions (2017-2018, DHS/FBI alert)
Berserk BearWannaCry ransomware (2017)
Lazarus Group2018
Banco de Chile $10M theft (2018)
APT38British Airways breach - 380,000 payment cards skimmed (2018)
MagecartDNSpionage campaign (DNS hijacking, 2018)
APT34Olympic Destroyer (2018 Winter Olympics)
SandwormOlympic Destroyer (2018)
APT28Operation Parliament - senior government officials across Middle East (2018)
MoleratsResearchers accidentally infected own systems with BADNEWS RAT (2018)
PatchworkUK, US, Russian government entity targeting (2018)
Gorgon GroupUS Navy contractor breach - submarine warfare data theft (2018)
APT40US, UK, Australia, Canada, Japan advisory (2018)
APT102019
Asus Live Update supply chain attack (2019)
APT41BMW and Toyota network intrusions (2019)
APT32Georgia election infrastructure (2019)
SandwormHijacking Iranian APT34 infrastructure (2019)
TurlaLeaked toolset published by Lab Dookhtegan (2019)
APT34Mass VPN exploitation campaign (Pulse Secure, Fortinet, Citrix 2019-2020)
Pioneer KittenReuters Project Raven investigative reporting (2019)
Stealth FalconTargeting of Hong Kong universities and political organizations (2019-2020)
APT27US Treasury OFAC sanctions (2019) - first ransomware group sanctioned
Evil Corp2020
Aria-body loader campaigns (Check Point disclosure 2020)
NaikonBiden and Trump campaign phishing (2020)
APT31COVID-19 themed lures targeting Tibetan organizations (2020)
TA413COVID-19 vaccine research targeting (2020)
APT29COVID-19 vaccine research targeting (2020)
APT41COVID-19 vaccine research targeting (2020)
APT40Secondary exploitation of SolarWinds victim networks (2020–2021)
SilverFishSolarWinds Orion supply chain compromise - SUNBURST backdoor (2020)
UNC2452SolarWinds SUNBURST (2020)
APT29Targeting of 2020 US presidential campaigns
APT31Trend Micro Earth Akhlut attribution report (2020)
Tonto TeamUS hospital attacks during COVID-19 pandemic (2020)
TrickBot / RyukVatican network compromise ahead of China–Holy See negotiations (2020)
Mustang Panda2021
Accellion FTA zero-day campaign - financial and government sectors (2021)
Cl0pChinese nuclear energy organization spearphishing (2021)
BitterClaimed access to Israeli defense infrastructure (2021–2022)
Moses StaffColonial Pipeline - US East Coast fuel supply disruption (May 2021)
DarkSideDemodex Windows kernel-mode rootkit (Kaspersky disclosure 2021)
GhostEmperorEuropol/FBI global takedown operation (January 2021)
Emotet / MealybugIowa-based grain cooperative NEW Cooperative ransomware attack (2021)
BlackMatterIranian railway hack - fake delay messages and board disruption (2021)
Predatory SparrowJBS Foods $11M ransom (2021)
REvilKaseya VSA supply chain attack (1,500+ companies, 2021)
REvilLog4Shell exploitation campaign (December 2021)
Aquatic PandaMicrosoft DCU domain seizure operation (December 2021)
Ke3changMyanmar government targeting after 2021 coup
Mustang PandaPivot to Noberus/ALPHV ransomware affiliate (2021–2022)
FIN8ProxyLogon - Microsoft Exchange 0-day exploitation (March 2021)
HafniumProxyLogon Exchange exploitation against Eastern European targets (2021)
Tonto TeamResurrected by TrickBot operators in late 2021
Emotet / MealybugSimultaneous compromise of 13 global telecom providers (CrowdStrike 2021)
LightBasinTransportation and healthcare campaigns (Trend Micro disclosure 2021)
Tropic TrooperUS critical infrastructure pre-positioning (2021-present)
Volt TyphoonUS state government systems compromise (2021)
APT412022
$625M Ronin Network crypto theft (2022)
Lazarus Group0ktapus campaign - 130+ orgs via Okta credential phishing (2022)
UNC3944CISA advisory on Iran MOIS operations (2022)
MuddyWaterCISA advisory specifically warning education sector (2022)
Vice SocietyDecade-long surveillance of Southeast Asian governments (SentinelOne disclosure 2022)
Aoqin DragonF5 BIG-IP exploitation including CVE-2022-1388
Velvet AntFBI infiltration of Hive - decryption keys provided to 300+ victims (2022)
HiveInternal chat logs leaked by Ukrainian researcher (2022)
ContiIranian steel plant cyberattack causing physical fire (2022)
Predatory SparrowIsraeli critical infrastructure targeting (2022)
TortoiseshellLog4Shell exploitation against US municipalities (2022)
Cobalt MirageLos Angeles Unified School District attack - student mental health records leaked (2022)
Vice SocietyMexican military leak - 6TB of SEDENA emails (2022)
GuacamayaMost prolific ransomware group 2022-2024
LockBitNvidia source code theft - 1TB including DLSS (2022)
Lapsus$Post-invasion surge: thousands of phishing attacks per week (2022)
GamaredonRomanian and Lithuanian government DDoS (2022)
KillNetRonin bridge $625M theft (March 2022, attributed)
BlueNoroffRussia leaks following Ukraine invasion (2022)
AnonymousRussian banking system DDoS campaigns (2022–present)
IT Army of UkraineSecureworks and Microsoft public attribution (2022)
Cobalt MirageTwilio and Cloudflare phishing campaign (2022)
Scattered SpiderUkrainian military credential harvesting operations (2022)
GamaredonUS airport websites DDoS (2022)
KillNetWhisperGate wiper attack (January 2022, days before Russian invasion)
Cadet BlizzardWhisperGate wiper deployment against Ukraine (January 2022)
Ember Bear2023
Aliquippa, PA water authority - Unitronics PLC compromise (Nov 2023)
Cyber Av3ngersBoeing data leak (2023)
LockBitBritish Library attack (2023, months-long disruption to national services)
RhysidaChatGPT outages (2023)
Anonymous SudanCISA emergency alert for water sector (Dec 2023)
Cyber Av3ngersCitrix Bleed (CVE-2023-4966) opportunistic exploitation
INC RansomCity of Dallas attack disrupting municipal services (May 2023)
Royal / BlackSuitCity of Oakland ransomware attack (2023, state of emergency declared)
PlayDOJ and Europol operation dismantled infrastructure (Jan 2023)
HiveESET public disclosure (August 2023)
MoustachedBouncerFive Eyes joint advisory (2023)
Volt TyphoonForged Microsoft authentication tokens to access US government email (2023)
Storm-0558GhostLocker ransomware deployment (2023 pivot)
GhostSecGoAnywhere MFT zero-day - 130+ organizations (2023)
Cl0pIdaho National Laboratory employee data leak (November 2023)
SiegedSecIsrael water facility SCADA system claims (2023)
GhostSecJumpCloud supply chain breach (2023, 1 million+ businesses exposed)
Jade SleetLehigh Valley Health Network patient data leak (2023)
QilinMandiant APT43 disclosure (March 2023)
APT43Microsoft 365, Outlook, Teams DDoS - 30,000+ customers impacted (June 2023)
Anonymous SudanMinneapolis Public Schools breach and data leak (2023)
MedusaMOVEit zero-day exploitation - 2,000+ organizations, 62M+ individuals (2023)
Cl0pNATO unclassified portal data dump (2023)
SiegedSecPost-October-2023 emergence with Israel-focused intrusions
HandalaQlik Sense vulnerability exploitation as initial access (2023)
CactusRapid victim disclosure cadence beginning mid-2023
8BaseRebrand from Royal to BlackSuit (mid-2023)
Royal / BlackSuitRouter firmware backdoor campaign (NSA/CISA advisory 2023)
BlackTechRoyal Mail UK attack (2023)
LockBitTelecom backbone intrusions across 2023-2024 (Trend Micro disclosure)
Earth EstriesToyota Financial Services intrusion (2023)
MedusaUK Conservative Party donors and MPs credential harvest (2023)
Callisto GroupUS DoJ charges against IcedID operators (2023)
IcedID / BokbotUS DoJ indictments of FSB officers (2023)
Callisto GroupUS Treasury and congressional websites targeting (2023)
KillNetYamaha Motor Philippines breach (2023)
INC Ransom2024
$42M+ ransom collected (FBI 2024 advisory)
Akira210+ victims in first 6 months (FBI advisory August 2024)
RansomHub260,000-device SOHO botnet (FBI disruption 2024)
Flax TyphoonAscension Health attack (2024, 140 hospitals disrupted nationwide)
Black BastaAT&T breach (2024, 73 million customer records)
ShinyHuntersBreach of AT&T, Verizon, T-Mobile CALEA wiretap systems (2024)
Salt TyphoonChange Healthcare attack - disrupted US pharmacy systems nationwide (2024)
BlackCat / ALPHVChange Healthcare attack (2024, $22M ransom paid, national prescription disruption)
RansomHubCisco Nexus 0-day exploitation (CVE-2024-20399)
Velvet AntContinued public-sector targeting through 2024-2025
Brain CipherCrowdStrike public disclosure at Fal.Con 2024
Liminal PandaFree decryptor released after public pressure (July 2024)
Brain CipherGroup disbandment announcement (July 2024)
SiegedSecIndonesia National Data Center attack (June 2024) — 282 government services impacted
Brain CipherLurie Children's Hospital Chicago (2024, pediatric care disrupted)
RhysidaLynx rebrand and code reuse (mid-2024)
INC RansomMalicious npm packages deployed via GitHub (2024)
Jade SleetMicrosoft senior leadership email access (2024)
APT29Muleshoe Texas water facility manipulation (2024)
Cyber Army of Russia RebornNHS Scotland (Dumfries and Galloway) breach (2024)
INC RansomOperation Cronos law enforcement takedown (2024)
LockBitPivot to data-extortion-only branding as 'World Leaks' (2024)
Hunters InternationalRe-emergence with refined toolkit (Sygnia tracking 2024)
GhostEmperorSchneider Electric Sustainability Business division breach (January 2024)
CactusSynnovis pathology services attack causing NHS surgery cancellations (June 2024)
QilinTargeting of US 2024 presidential campaigns
APT42Three-year stealth intrusion of large Asian enterprise (Sygnia 2024 disclosure)
Velvet AntTransition to ransomware-as-a-service operations (late 2024)
KillSecUS DoJ indictment of Sudanese national (2024)
Anonymous SudanUS Treasury Department breach (2024, SilkTyphoon)
HafniumUS Treasury sanctions on IRGC Cyberspace Battalion officers (2024)
Cyber Av3ngers2025
CISA #StopRansomware joint advisory (AA25-071A, 2025)
MedusaOperator arrests in Thailand (February 2025)
8BaseTata Technologies breach (early 2025)
Hunters International199 of 199 operations shown