The Gentlemen: A Threat Profile

Aliases  No confirmed aliases at this time. The group operates exclusively under “The Gentlemen” branding across underground forums, its dark web leak site, and a public X/Twitter account.  Get Threat Intel and Security Updates Delivered to Your Inbox.  ...

Qilin: A Threat Profile

Aliases  Agenda (original name, 2022)  Gold Feather (Secureworks)  Water Galura (Trend Micro)  Get Threat Intel and Security Updates Delivered to Your Inbox.   Profiling  Threat Actor Type: Ransomware-as-a-Service (RaaS) with global affiliate network. ...

Dark Angels: A Threat Profile

Aliases  Dark Angels Dark Angels Team White Rabbit Related Historical Identifiers  MARIO (ESXi) – Babuk-derived ESXi encryptor assessed as part of the Dark Angels lineage  Dunghill – data leak and extortion site branding used in Dark Angels campaign Get...

DarkBit: A Threat Profile

Aliases  DarkBit Ransomware  esxi.darkbit (Linux/ESXi payload name observed in incident response)    Get Threat Intel and Security Updates Delivered to Your Inbox. Profiling  Threat Actor Type: Ransomware operation assessed to function as a politically motivated...

Akira: A Threat Profile

Aliases Akira is the only known alias. Associated with other groups known as Storm-1567, Howling Scorpius, Punk Spider, and Gold Sahara Get Threat Intel and Security Updates Delivered to Your Inbox. Profiling Threat Actor Type: Ransomware-as-a-Service (RaaS) targeting...

Fire Ant: A Threat Profile

Aliases Fire Ant China‑nexus infrastructure espionage actor (media shorthand) UNC3886‑overlap (tooling/TTP overlap; not a formal attribution) Listed by MITRE as an alias for Mustang Panda (G0129)   Profiling Threat Actor Type: Suspected state aligned...