Threat actor catalog
The named groups behind today's intrusions. Filter by motivation, search by name or alias, and click through to exploited CVEs and attributed campaigns. Curated from MITRE ATT&CK Groups plus open-source threat intelligence.
Methodology
The catalog combines MITRE ATT&CK Groups with ransomware source records and cited open-source intelligence. It includes active, dormant, and historical groups. Per-CVE, indicator, malware, victim, campaign, and ATT&CK technique relationships retain their originating source so an analyst can inspect the evidence behind each connection.
Automated jobs refresh the catalog daily. MITRE records supply documented group aliases and technique relationships. Ransomware records are promoted from monitored source groups and linked to their victim and leak-site activity. Sector coverage is derived from classified victim records and normalized into stable filter values. A relationship may currently have one source or several; the interface does not imply independent corroboration where the data does not contain it.
Attribution is not identity proof. Publishers may use different names for the same activity, reuse a name for overlapping activity, or disagree. The catalog keeps exact names and tracking identifiers in a source-backed name map. Suspected rebrands, affiliates, overlapping clusters, and disputes remain separate relationships with confidence and citations. Country badges remain limited to reviewed nexus mappings.
Read the full SecurityAlert threat intelligence methodology.
How to use the catalog
Security teams use the actor catalog in four common ways:
- Sector targeting research. Filter by motivation, then read group profiles to see which industries each actor has historically hit. Useful for sector-level threat models and board reporting.
- CVE-to-actor mapping for patch prioritisation. If your scanner flags a CVE, click through to see which actors have used it. A KEV CVE attached to three nation-state groups gets a different SLA than one with no attributed exploitation.
- Tactic clustering by motivation. The motivation facet (nation-state, ransomware, cybercrime, hacktivism) groups actors who share goals and therefore tradecraft. Helpful for tabletop exercises and red-team scoping.
- Pivot to the ransomware tracker. Groups with active leak sites link to /ransomware, where you can see victim posts, sector concentration, and 30-day momentum without leaving the site.
The catalog is read-only and indexable. There is no login wall on actor profiles, CVE links, or the index itself. The intended use is reference material that a security analyst can land on from a Google search and use immediately.
Frequently asked questions
What is a threat actor?
A named group (or individual) that conducts intrusions, espionage, fraud, or extortion. Naming lets defenders cluster intrusions that share infrastructure, tooling, or tradecraft, so a CVE alert tied to APT29 carries different urgency than the same CVE tied to a low-skill commodity crew.
How is this different from MITRE ATT&CK Groups?
MITRE ATT&CK Groups supplies documented group identities and technique relationships. SecurityAlert adds ransomware operators, victim activity, indicators, malware, campaigns, and cited CVE relationships from monitored public sources.
Why do you list ransomware groups under "Threat actors" too?
Because they are. Operationally, LockBit and Cl0p run intrusions that look a lot like espionage groups: initial access via known CVEs, lateral movement, data theft. Listing them here lets defenders treat the actor list as one surface. The dedicated ransomware tracker still exists for leak-site activity.
How often is it updated?
Daily. Automated jobs sync MITRE ATT&CK group records, ransomware source records, victim activity, techniques, malware, indicators, and cited CVE relationships. Each relationship retains its named source so analysts can judge the evidence.
How do you handle attribution disputes?
Threat-actor names and attributions can overlap or conflict across publishers. Exact aliases and vendor tracking identifiers are mapped with sources. Rebrands, affiliations, overlaps, and disputes stay as separate confidence-rated relationships so an uncertain assessment cannot silently merge two actor records.
Can I export this data?
The actor catalog is available in the browser, through the search_threat_actors MCP tool, and as a public read-only STIX 2.1 collection through the SecurityAlert TAXII 2.1 API.