Skip to content

Operations Timeline

138 notable operations across 106 adversaries

19962024

1996
Moonlight Maze (1996-1999, attributed)
Turla
2008
Agent.BTZ (Pentagon USB worm, 2008)
Turla
Persistent POS compromise campaigns across US retail (2008–2017)
FIN5
2009
GhostNet - 1,295 infected computers in 103 countries (2009, linked operations)
TA413
Google breach - source code and Gmail accounts of Chinese dissidents (2009)
Operation Aurora
Natanz centrifuge destruction - 1,000+ centrifuges damaged (2009–2010)
Stuxnet Operators
2010
IE zero-day (CVE-2010-0249) exploitation at scale
Operation Aurora
Operation Payback (RIAA/MPAA DDoS, 2010)
Anonymous
Stuxnet (joint with Unit 8200, 2010)
Equation Group
2011
HBGary Federal breach and email release (2011)
Anonymous
2012
Flame malware (2012)
Equation Group
Japan aerospace and defense sector campaigns (2012–present)
Bronze Butler
2013
Mandiant APT1 report exposure (2013)
APT1
Sustained campaign against Indian armed forces since 2013
Transparent Tribe
Turkish government email leak - corruption documents published (2013)
RedHack
2014
Continuous Ukraine targeting since 2014 annexation of Crimea
Gamaredon
Sony Pictures hack (2014)
Lazarus Group
2015
Anti-ISIS website takedowns and account reporting (2015–2016)
GhostSec
Bundestag breach (2015)
APT28
HDD firmware persistence (2015)
Equation Group
OpISIS following Paris attacks (2015)
Anonymous
SEC charges against alleged operators (2015)
FIN4
Ukraine power grid attacks (2015, 2016)
Sandworm
2016
Bangladesh Bank $81M SWIFT heist (2016)
APT38
Bangladesh Bank SWIFT heist ($81M, 2016)
Lazarus Group
DNC breach (2016, separate from APT28)
APT29
DNC hack and email leak (2016)
APT28
Operation Cloud Hopper - global MSP compromise (2016–2017)
APT10
Operation Daybreak (2016)
APT37
WADA doping agency hack (2016)
APT28
2017
French election interference (2017)
APT28
NotPetya global wiper (2017, $10B+ damage)
Sandworm
Operation Erebus (2017)
APT37
US electric grid intrusions (2017-2018, DHS/FBI alert)
Berserk Bear
WannaCry ransomware (2017)
Lazarus Group
2018
Banco de Chile $10M theft (2018)
APT38
British Airways breach - 380,000 payment cards skimmed (2018)
Magecart
DNSpionage campaign (DNS hijacking, 2018)
APT34
Olympic Destroyer (2018 Winter Olympics)
Sandworm
Olympic Destroyer (2018)
APT28
Operation Parliament - senior government officials across Middle East (2018)
Molerats
Researchers accidentally infected own systems with BADNEWS RAT (2018)
Patchwork
UK, US, Russian government entity targeting (2018)
Gorgon Group
US Navy contractor breach - submarine warfare data theft (2018)
APT40
US, UK, Australia, Canada, Japan advisory (2018)
APT10
2019
Asus Live Update supply chain attack (2019)
APT41
BMW and Toyota network intrusions (2019)
APT32
Georgia election infrastructure (2019)
Sandworm
Hijacking Iranian APT34 infrastructure (2019)
Turla
Leaked toolset published by Lab Dookhtegan (2019)
APT34
Mass VPN exploitation campaign (Pulse Secure, Fortinet, Citrix 2019-2020)
Pioneer Kitten
US Treasury OFAC sanctions (2019) - first ransomware group sanctioned
Evil Corp
2020
Biden and Trump campaign phishing (2020)
APT31
COVID-19 themed lures targeting Tibetan organizations (2020)
TA413
COVID-19 vaccine research targeting (2020)
APT29
COVID-19 vaccine research targeting (2020)
APT41
COVID-19 vaccine research targeting (2020)
APT40
Secondary exploitation of SolarWinds victim networks (2020–2021)
SilverFish
SolarWinds Orion supply chain compromise - SUNBURST backdoor (2020)
UNC2452
SolarWinds SUNBURST (2020)
APT29
Targeting of 2020 US presidential campaigns
APT31
US hospital attacks during COVID-19 pandemic (2020)
TrickBot / Ryuk
Vatican network compromise ahead of China–Holy See negotiations (2020)
Mustang Panda
2021
Accellion FTA zero-day campaign - financial and government sectors (2021)
Cl0p
Chinese nuclear energy organization spearphishing (2021)
Bitter
Claimed access to Israeli defense infrastructure (2021–2022)
Moses Staff
Colonial Pipeline - US East Coast fuel supply disruption (May 2021)
DarkSide
Europol/FBI global takedown operation (January 2021)
Emotet / Mealybug
Iowa-based grain cooperative NEW Cooperative ransomware attack (2021)
BlackMatter
Iranian railway hack - fake delay messages and board disruption (2021)
Predatory Sparrow
JBS Foods $11M ransom (2021)
REvil
Kaseya VSA supply chain attack (1,500+ companies, 2021)
REvil
Log4Shell exploitation campaign (December 2021)
Aquatic Panda
Myanmar government targeting after 2021 coup
Mustang Panda
Pivot to Noberus/ALPHV ransomware affiliate (2021–2022)
FIN8
ProxyLogon - Microsoft Exchange 0-day exploitation (March 2021)
Hafnium
Resurrected by TrickBot operators in late 2021
Emotet / Mealybug
Simultaneous compromise of 13 global telecom providers (CrowdStrike 2021)
LightBasin
US critical infrastructure pre-positioning (2021-present)
Volt Typhoon
US state government systems compromise (2021)
APT41
2022
$625M Ronin Network crypto theft (2022)
Lazarus Group
0ktapus campaign - 130+ orgs via Okta credential phishing (2022)
UNC3944
CISA advisory on Iran MOIS operations (2022)
MuddyWater
CISA advisory specifically warning education sector (2022)
Vice Society
FBI infiltration of Hive - decryption keys provided to 300+ victims (2022)
Hive
Internal chat logs leaked by Ukrainian researcher (2022)
Conti
Iranian steel plant cyberattack causing physical fire (2022)
Predatory Sparrow
Israeli critical infrastructure targeting (2022)
Tortoiseshell
Los Angeles Unified School District attack - student mental health records leaked (2022)
Vice Society
Mexican military leak - 6TB of SEDENA emails (2022)
Guacamaya
Most prolific ransomware group 2022-2024
LockBit
Nvidia source code theft - 1TB including DLSS (2022)
Lapsus$
Post-invasion surge: thousands of phishing attacks per week (2022)
Gamaredon
Romanian and Lithuanian government DDoS (2022)
KillNet
Russia leaks following Ukraine invasion (2022)
Anonymous
Russian banking system DDoS campaigns (2022–present)
IT Army of Ukraine
Twilio and Cloudflare phishing campaign (2022)
Scattered Spider
Ukrainian military credential harvesting operations (2022)
Gamaredon
US airport websites DDoS (2022)
KillNet
WhisperGate wiper attack (January 2022, days before Russian invasion)
Cadet Blizzard
2023
Aliquippa, PA water authority - Unitronics PLC compromise (Nov 2023)
Cyber Av3ngers
Boeing data leak (2023)
LockBit
British Library attack (2023, months-long disruption to national services)
Rhysida
ChatGPT outages (2023)
Anonymous Sudan
CISA emergency alert for water sector (Dec 2023)
Cyber Av3ngers
City of Oakland ransomware attack (2023, state of emergency declared)
Play
DOJ and Europol operation dismantled infrastructure (Jan 2023)
Hive
Five Eyes joint advisory (2023)
Volt Typhoon
Forged Microsoft authentication tokens to access US government email (2023)
Storm-0558
GhostLocker ransomware deployment (2023 pivot)
GhostSec
GoAnywhere MFT zero-day - 130+ organizations (2023)
Cl0p
Israel water facility SCADA system claims (2023)
GhostSec
JumpCloud supply chain breach (2023, 1 million+ businesses exposed)
Jade Sleet
Microsoft 365, Outlook, Teams DDoS - 30,000+ customers impacted (June 2023)
Anonymous Sudan
MOVEit zero-day exploitation - 2,000+ organizations, 62M+ individuals (2023)
Cl0p
Router firmware backdoor campaign (NSA/CISA advisory 2023)
BlackTech
Royal Mail UK attack (2023)
LockBit
UK Conservative Party donors and MPs credential harvest (2023)
Callisto Group
US DoJ charges against IcedID operators (2023)
IcedID / Bokbot
US DoJ indictments of FSB officers (2023)
Callisto Group
US Treasury and congressional websites targeting (2023)
KillNet
2024
$42M+ ransom collected (FBI 2024 advisory)
Akira
210+ victims in first 6 months (FBI advisory August 2024)
RansomHub
260,000-device SOHO botnet (FBI disruption 2024)
Flax Typhoon
Ascension Health attack (2024, 140 hospitals disrupted nationwide)
Black Basta
AT&T breach (2024, 73 million customer records)
ShinyHunters
Breach of AT&T, Verizon, T-Mobile CALEA wiretap systems (2024)
Salt Typhoon
Change Healthcare attack - disrupted US pharmacy systems nationwide (2024)
BlackCat / ALPHV
Change Healthcare attack (2024, $22M ransom paid, national prescription disruption)
RansomHub
Lurie Children's Hospital Chicago (2024, pediatric care disrupted)
Rhysida
Malicious npm packages deployed via GitHub (2024)
Jade Sleet
Microsoft senior leadership email access (2024)
APT29
Muleshoe Texas water facility manipulation (2024)
Cyber Army of Russia Reborn
Operation Cronos law enforcement takedown (2024)
LockBit
Targeting of US 2024 presidential campaigns
APT42
US DoJ indictment of Sudanese national (2024)
Anonymous Sudan
US Treasury Department breach (2024, SilkTyphoon)
Hafnium
US Treasury sanctions on IRGC Cyberspace Battalion officers (2024)
Cyber Av3ngers
138 of 138 operations shown