Kyber: A Threat Profile

Aliases  No other known aliases at this time.  Related Historical Identifiers  Kyber1024 — post-quantum cryptographic algorithm name adopted as group branding  Get Threat Intel and Security Updates Delivered to Your Inbox.   Profiling  Threat Actor Type: Kyber is a...

The Gentlemen: A Threat Profile

Aliases  Storm-2697 — tracking designation assigned by Microsoft Threat Intelligence to the operators of the RaaS platform. The group continues to brand exclusively as “The Gentlemen” across its leak site, X/Twitter, and underground forums. Its...

Qilin: A Threat Profile

Aliases  Agenda (original name, 2022)  Gold Feather (Secureworks)  Water Galura (Trend Micro)  Get Threat Intel and Security Updates Delivered to Your Inbox.   Profiling  Threat Actor Type: Ransomware-as-a-Service (RaaS) with global affiliate network. ...

Dark Angels: A Threat Profile

Aliases  Dark Angels Dark Angels Team White Rabbit Related Historical Identifiers  MARIO (ESXi) – Babuk-derived ESXi encryptor assessed as part of the Dark Angels lineage  Dunghill – data leak and extortion site branding used in Dark Angels campaign Get...

DarkBit: A Threat Profile

Aliases  DarkBit Ransomware  esxi.darkbit (Linux/ESXi payload name observed in incident response)    Get Threat Intel and Security Updates Delivered to Your Inbox. Profiling  Threat Actor Type: Ransomware operation assessed to function as a politically motivated...

Akira: A Threat Profile

Aliases Akira is the only known alias. Associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara Get Threat Intel and Security Updates Delivered to Your Inbox. Profiling Threat Actor Type: Ransomware-as-a-Service (RaaS) targeting...