Note: Attribution is hard and each entity may only see part of a group's activity. These groupings may change as more information becomes available but are listed to the best of my knowledge at the time of creation.
Democratic People's Republic of Korea | |
---|---|
APT-37 | |
Zscaler | The Unintentional Leak: A glimpse into the attack vectors of APT37 |
APT-38 | |
CISA | Hidden Cobra – North Korea’s DDoS Botnet Infrastructure |
FireEye | APT38: Un-usual Suspects |
Recorded Future | North Korea-Aligned TAG-71 Spoofs Financial Institutions in Asia and US |
APT-43 | |
Mandiant | APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations |
Islamic Republic of Iran | |
---|---|
APT-42 | |
Mandiant | APT42: Crooked Charms, Cons and Compromises |
Russian Federation | |
---|---|
APT-28 | |
FireEye | APT28: At the Center of the Storm |
APT-29 | |
FireEye | HammerToss: Stealthy Tactics Define a Russian Cyber Threat Group |
Financially Motivated Groups | |
---|---|
FIN10 | |
FireEye | FIN10: Anatomy of a Cyber Extortion Operation |