Threat Intelligence · Updated daily from MITRE ATT&CK & OSINT

Threat actor catalog

The named groups behind today's intrusions. Filter by motivation, search by name or alias, and click through to exploited CVEs and attributed campaigns. Curated from MITRE ATT&CK Groups plus open-source threat intelligence.

--
Actors tracked
--
Nation-state
--
Ransomware
--
Active · last 2y
Loading…

Methodology

The catalog combines MITRE ATT&CK Groups with ransomware source records and cited open-source intelligence. It includes active, dormant, and historical groups. Per-CVE, indicator, malware, victim, campaign, and ATT&CK technique relationships retain their originating source so an analyst can inspect the evidence behind each connection.

Automated jobs refresh the catalog daily. MITRE records supply documented group aliases and technique relationships. Ransomware records are promoted from monitored source groups and linked to their victim and leak-site activity. Sector coverage is derived from classified victim records and normalized into stable filter values. A relationship may currently have one source or several; the interface does not imply independent corroboration where the data does not contain it.

Attribution is not identity proof. Publishers may use different names for the same activity, reuse a name for overlapping activity, or disagree. The catalog keeps exact names and tracking identifiers in a source-backed name map. Suspected rebrands, affiliates, overlapping clusters, and disputes remain separate relationships with confidence and citations. Country badges remain limited to reviewed nexus mappings.

Read the full SecurityAlert threat intelligence methodology.

How to use the catalog

Security teams use the actor catalog in four common ways:

The catalog is read-only and indexable. There is no login wall on actor profiles, CVE links, or the index itself. The intended use is reference material that a security analyst can land on from a Google search and use immediately.

Frequently asked questions

What is a threat actor?

A named group (or individual) that conducts intrusions, espionage, fraud, or extortion. Naming lets defenders cluster intrusions that share infrastructure, tooling, or tradecraft, so a CVE alert tied to APT29 carries different urgency than the same CVE tied to a low-skill commodity crew.

How is this different from MITRE ATT&CK Groups?

MITRE ATT&CK Groups supplies documented group identities and technique relationships. SecurityAlert adds ransomware operators, victim activity, indicators, malware, campaigns, and cited CVE relationships from monitored public sources.

Why do you list ransomware groups under "Threat actors" too?

Because they are. Operationally, LockBit and Cl0p run intrusions that look a lot like espionage groups: initial access via known CVEs, lateral movement, data theft. Listing them here lets defenders treat the actor list as one surface. The dedicated ransomware tracker still exists for leak-site activity.

How often is it updated?

Daily. Automated jobs sync MITRE ATT&CK group records, ransomware source records, victim activity, techniques, malware, indicators, and cited CVE relationships. Each relationship retains its named source so analysts can judge the evidence.

How do you handle attribution disputes?

Threat-actor names and attributions can overlap or conflict across publishers. Exact aliases and vendor tracking identifiers are mapped with sources. Rebrands, affiliations, overlaps, and disputes stay as separate confidence-rated relationships so an uncertain assessment cannot silently merge two actor records.

Can I export this data?

The actor catalog is available in the browser, through the search_threat_actors MCP tool, and as a public read-only STIX 2.1 collection through the SecurityAlert TAXII 2.1 API.

See which actors target your sector

SecurityAlert maps active threat actors to your industry and brand so you know who to watch. The free plan covers 1 brand monitor, no credit card.