Skip to content

Operations Timeline

199 notable operations across 143 adversaries

19962025

1996
Moonlight Maze (1996-1999, attributed)
Turla
2008
Agent.BTZ (Pentagon USB worm, 2008)
Turla
Persistent POS compromise campaigns across US retail (2008–2017)
FIN5
2009
GhostNet - 1,295 infected computers in 103 countries (2009, linked operations)
TA413
Google breach - source code and Gmail accounts of Chinese dissidents (2009)
Operation Aurora
Natanz centrifuge destruction - 1,000+ centrifuges damaged (2009–2010)
Stuxnet Operators
2010
IE zero-day (CVE-2010-0249) exploitation at scale
Operation Aurora
Operation Aurora (2010, jointly attributed)
APT17
Operation Payback (RIAA/MPAA DDoS, 2010)
Anonymous
Stuxnet (joint with Unit 8200, 2010)
Equation Group
2011
HBGary Federal breach and email release (2011)
Anonymous
2012
Flame malware (2012)
Equation Group
Japan aerospace and defense sector campaigns (2012–present)
Bronze Butler
New York Times intrusion (2012-2013)
APT12
Sustained CIS-region diplomatic targeting since 2012
Inception
2013
Bit9 trust certificate breach (2013)
APT17
DeputyDog campaign (2013)
APT17
European Ministries of Foreign Affairs intrusions (2013)
Ke3chang
Mandiant APT1 report exposure (2013)
APT1
Sustained campaign against Indian armed forces since 2013
Transparent Tribe
Turkish government email leak - corruption documents published (2013)
RedHack
2014
Continuous Ukraine targeting since 2014 annexation of Crimea
Gamaredon
Forbes.com watering hole (2014)
APT19
Sony Pictures hack (2014)
Lazarus Group
2015
Anti-ISIS website takedowns and account reporting (2015–2016)
GhostSec
Bundestag breach (2015)
APT28
FireEye attribution report (April 2015)
APT30
HDD firmware persistence (2015)
Equation Group
Operation Clandestine Wolf (Internet Explorer 0-day, 2015)
APT3
OpISIS following Paris attacks (2015)
Anonymous
SEC charges against alleged operators (2015)
FIN4
Ukraine power grid attacks (2015, 2016)
Sandworm
2016
Bangladesh Bank $81M SWIFT heist (2016)
APT38
Bangladesh Bank SWIFT heist ($81M, 2016)
Lazarus Group
Citizen Lab disclosure of dissident targeting (2016)
Stealth Falcon
DNC breach (2016, separate from APT28)
APT29
DNC hack and email leak (2016)
APT28
ICAO compromise via supply-chain pivot (2016)
APT27
Operation Cloud Hopper - global MSP compromise (2016–2017)
APT10
Operation Daybreak (2016)
APT37
Repurposed NSA EternalSynergy exploit (2016-2017)
APT3
WADA doping agency hack (2016)
APT28
2017
Boyusec / Wu Yingzhuo / Dong Hao DOJ indictment (2017)
APT3
CVE-2017-11882 Equation Editor exploitation
Inception
French election interference (2017)
APT28
NotPetya global wiper (2017, $10B+ damage)
Sandworm
Operation Erebus (2017)
APT37
UK government service provider supply-chain compromise (2017)
Ke3chang
US electric grid intrusions (2017-2018, DHS/FBI alert)
Berserk Bear
WannaCry ransomware (2017)
Lazarus Group
2018
Banco de Chile $10M theft (2018)
APT38
British Airways breach - 380,000 payment cards skimmed (2018)
Magecart
DNSpionage campaign (DNS hijacking, 2018)
APT34
Olympic Destroyer (2018 Winter Olympics)
Sandworm
Olympic Destroyer (2018)
APT28
Operation Parliament - senior government officials across Middle East (2018)
Molerats
Researchers accidentally infected own systems with BADNEWS RAT (2018)
Patchwork
UK, US, Russian government entity targeting (2018)
Gorgon Group
US Navy contractor breach - submarine warfare data theft (2018)
APT40
US, UK, Australia, Canada, Japan advisory (2018)
APT10
2019
Asus Live Update supply chain attack (2019)
APT41
BMW and Toyota network intrusions (2019)
APT32
Georgia election infrastructure (2019)
Sandworm
Hijacking Iranian APT34 infrastructure (2019)
Turla
Leaked toolset published by Lab Dookhtegan (2019)
APT34
Mass VPN exploitation campaign (Pulse Secure, Fortinet, Citrix 2019-2020)
Pioneer Kitten
Reuters Project Raven investigative reporting (2019)
Stealth Falcon
Targeting of Hong Kong universities and political organizations (2019-2020)
APT27
US Treasury OFAC sanctions (2019) - first ransomware group sanctioned
Evil Corp
2020
Aria-body loader campaigns (Check Point disclosure 2020)
Naikon
Biden and Trump campaign phishing (2020)
APT31
COVID-19 themed lures targeting Tibetan organizations (2020)
TA413
COVID-19 vaccine research targeting (2020)
APT29
COVID-19 vaccine research targeting (2020)
APT41
COVID-19 vaccine research targeting (2020)
APT40
Secondary exploitation of SolarWinds victim networks (2020–2021)
SilverFish
SolarWinds Orion supply chain compromise - SUNBURST backdoor (2020)
UNC2452
SolarWinds SUNBURST (2020)
APT29
Targeting of 2020 US presidential campaigns
APT31
Trend Micro Earth Akhlut attribution report (2020)
Tonto Team
US hospital attacks during COVID-19 pandemic (2020)
TrickBot / Ryuk
Vatican network compromise ahead of China–Holy See negotiations (2020)
Mustang Panda
2021
Accellion FTA zero-day campaign - financial and government sectors (2021)
Cl0p
Chinese nuclear energy organization spearphishing (2021)
Bitter
Claimed access to Israeli defense infrastructure (2021–2022)
Moses Staff
Colonial Pipeline - US East Coast fuel supply disruption (May 2021)
DarkSide
Demodex Windows kernel-mode rootkit (Kaspersky disclosure 2021)
GhostEmperor
Europol/FBI global takedown operation (January 2021)
Emotet / Mealybug
Iowa-based grain cooperative NEW Cooperative ransomware attack (2021)
BlackMatter
Iranian railway hack - fake delay messages and board disruption (2021)
Predatory Sparrow
JBS Foods $11M ransom (2021)
REvil
Kaseya VSA supply chain attack (1,500+ companies, 2021)
REvil
Log4Shell exploitation campaign (December 2021)
Aquatic Panda
Microsoft DCU domain seizure operation (December 2021)
Ke3chang
Myanmar government targeting after 2021 coup
Mustang Panda
Pivot to Noberus/ALPHV ransomware affiliate (2021–2022)
FIN8
ProxyLogon - Microsoft Exchange 0-day exploitation (March 2021)
Hafnium
ProxyLogon Exchange exploitation against Eastern European targets (2021)
Tonto Team
Resurrected by TrickBot operators in late 2021
Emotet / Mealybug
Simultaneous compromise of 13 global telecom providers (CrowdStrike 2021)
LightBasin
Transportation and healthcare campaigns (Trend Micro disclosure 2021)
Tropic Trooper
US critical infrastructure pre-positioning (2021-present)
Volt Typhoon
US state government systems compromise (2021)
APT41
2022
$625M Ronin Network crypto theft (2022)
Lazarus Group
0ktapus campaign - 130+ orgs via Okta credential phishing (2022)
UNC3944
CISA advisory on Iran MOIS operations (2022)
MuddyWater
CISA advisory specifically warning education sector (2022)
Vice Society
Decade-long surveillance of Southeast Asian governments (SentinelOne disclosure 2022)
Aoqin Dragon
F5 BIG-IP exploitation including CVE-2022-1388
Velvet Ant
FBI infiltration of Hive - decryption keys provided to 300+ victims (2022)
Hive
Internal chat logs leaked by Ukrainian researcher (2022)
Conti
Iranian steel plant cyberattack causing physical fire (2022)
Predatory Sparrow
Israeli critical infrastructure targeting (2022)
Tortoiseshell
Log4Shell exploitation against US municipalities (2022)
Cobalt Mirage
Los Angeles Unified School District attack - student mental health records leaked (2022)
Vice Society
Mexican military leak - 6TB of SEDENA emails (2022)
Guacamaya
Most prolific ransomware group 2022-2024
LockBit
Nvidia source code theft - 1TB including DLSS (2022)
Lapsus$
Post-invasion surge: thousands of phishing attacks per week (2022)
Gamaredon
Romanian and Lithuanian government DDoS (2022)
KillNet
Ronin bridge $625M theft (March 2022, attributed)
BlueNoroff
Russia leaks following Ukraine invasion (2022)
Anonymous
Russian banking system DDoS campaigns (2022–present)
IT Army of Ukraine
Secureworks and Microsoft public attribution (2022)
Cobalt Mirage
Twilio and Cloudflare phishing campaign (2022)
Scattered Spider
Ukrainian military credential harvesting operations (2022)
Gamaredon
US airport websites DDoS (2022)
KillNet
WhisperGate wiper attack (January 2022, days before Russian invasion)
Cadet Blizzard
WhisperGate wiper deployment against Ukraine (January 2022)
Ember Bear
2023
Aliquippa, PA water authority - Unitronics PLC compromise (Nov 2023)
Cyber Av3ngers
Boeing data leak (2023)
LockBit
British Library attack (2023, months-long disruption to national services)
Rhysida
ChatGPT outages (2023)
Anonymous Sudan
CISA emergency alert for water sector (Dec 2023)
Cyber Av3ngers
Citrix Bleed (CVE-2023-4966) opportunistic exploitation
INC Ransom
City of Dallas attack disrupting municipal services (May 2023)
Royal / BlackSuit
City of Oakland ransomware attack (2023, state of emergency declared)
Play
DOJ and Europol operation dismantled infrastructure (Jan 2023)
Hive
ESET public disclosure (August 2023)
MoustachedBouncer
Five Eyes joint advisory (2023)
Volt Typhoon
Forged Microsoft authentication tokens to access US government email (2023)
Storm-0558
GhostLocker ransomware deployment (2023 pivot)
GhostSec
GoAnywhere MFT zero-day - 130+ organizations (2023)
Cl0p
Idaho National Laboratory employee data leak (November 2023)
SiegedSec
Israel water facility SCADA system claims (2023)
GhostSec
JumpCloud supply chain breach (2023, 1 million+ businesses exposed)
Jade Sleet
Lehigh Valley Health Network patient data leak (2023)
Qilin
Mandiant APT43 disclosure (March 2023)
APT43
Microsoft 365, Outlook, Teams DDoS - 30,000+ customers impacted (June 2023)
Anonymous Sudan
Minneapolis Public Schools breach and data leak (2023)
Medusa
MOVEit zero-day exploitation - 2,000+ organizations, 62M+ individuals (2023)
Cl0p
NATO unclassified portal data dump (2023)
SiegedSec
Post-October-2023 emergence with Israel-focused intrusions
Handala
Qlik Sense vulnerability exploitation as initial access (2023)
Cactus
Rapid victim disclosure cadence beginning mid-2023
8Base
Rebrand from Royal to BlackSuit (mid-2023)
Royal / BlackSuit
Router firmware backdoor campaign (NSA/CISA advisory 2023)
BlackTech
Royal Mail UK attack (2023)
LockBit
Telecom backbone intrusions across 2023-2024 (Trend Micro disclosure)
Earth Estries
Toyota Financial Services intrusion (2023)
Medusa
UK Conservative Party donors and MPs credential harvest (2023)
Callisto Group
US DoJ charges against IcedID operators (2023)
IcedID / Bokbot
US DoJ indictments of FSB officers (2023)
Callisto Group
US Treasury and congressional websites targeting (2023)
KillNet
Yamaha Motor Philippines breach (2023)
INC Ransom
2024
$42M+ ransom collected (FBI 2024 advisory)
Akira
210+ victims in first 6 months (FBI advisory August 2024)
RansomHub
260,000-device SOHO botnet (FBI disruption 2024)
Flax Typhoon
Ascension Health attack (2024, 140 hospitals disrupted nationwide)
Black Basta
AT&T breach (2024, 73 million customer records)
ShinyHunters
Breach of AT&T, Verizon, T-Mobile CALEA wiretap systems (2024)
Salt Typhoon
Change Healthcare attack - disrupted US pharmacy systems nationwide (2024)
BlackCat / ALPHV
Change Healthcare attack (2024, $22M ransom paid, national prescription disruption)
RansomHub
Cisco Nexus 0-day exploitation (CVE-2024-20399)
Velvet Ant
Continued public-sector targeting through 2024-2025
Brain Cipher
CrowdStrike public disclosure at Fal.Con 2024
Liminal Panda
Free decryptor released after public pressure (July 2024)
Brain Cipher
Group disbandment announcement (July 2024)
SiegedSec
Indonesia National Data Center attack (June 2024) — 282 government services impacted
Brain Cipher
Lurie Children's Hospital Chicago (2024, pediatric care disrupted)
Rhysida
Lynx rebrand and code reuse (mid-2024)
INC Ransom
Malicious npm packages deployed via GitHub (2024)
Jade Sleet
Microsoft senior leadership email access (2024)
APT29
Muleshoe Texas water facility manipulation (2024)
Cyber Army of Russia Reborn
NHS Scotland (Dumfries and Galloway) breach (2024)
INC Ransom
Operation Cronos law enforcement takedown (2024)
LockBit
Pivot to data-extortion-only branding as 'World Leaks' (2024)
Hunters International
Re-emergence with refined toolkit (Sygnia tracking 2024)
GhostEmperor
Schneider Electric Sustainability Business division breach (January 2024)
Cactus
Synnovis pathology services attack causing NHS surgery cancellations (June 2024)
Qilin
Targeting of US 2024 presidential campaigns
APT42
Three-year stealth intrusion of large Asian enterprise (Sygnia 2024 disclosure)
Velvet Ant
Transition to ransomware-as-a-service operations (late 2024)
KillSec
US DoJ indictment of Sudanese national (2024)
Anonymous Sudan
US Treasury Department breach (2024, SilkTyphoon)
Hafnium
US Treasury sanctions on IRGC Cyberspace Battalion officers (2024)
Cyber Av3ngers
2025
CISA #StopRansomware joint advisory (AA25-071A, 2025)
Medusa
Operator arrests in Thailand (February 2025)
8Base
Tata Technologies breach (early 2025)
Hunters International
199 of 199 operations shown