Aurora: A Threat Profile

Aliases  Tracked as Aurora or Aur0ra; no confirmed MITRE group designation or stable alternate operator name at the time of writing. Get Threat Intel and Security Updates Delivered to Your Inbox.   Profiling  Threat Actor Type: Financially motivated ransomware...

Anubis: A Threat Profile

Aliases  Sphinx — original codename under which early ransomware samples and initial victims were recorded in late 2024, before formal rebranding  Anubis__media — operator persona used on the XSS underground forum  superSonic — operator persona used on the RAMP...

INC Ransom: A Threat Profile

Aliases GOLD IONIC — Secureworks / Counter Threat Unit tracking name G1032 — MITRE ATT&CK group identifier   Profiling Threat Actor Type: Ransomware-as-a-Service (RaaS) operation with double extortion. Whether INC Ransom operates as a fully open affiliate...

Kyber: A Threat Profile

Aliases  No other known aliases at this time.  Related Historical Identifiers  Kyber1024 — post-quantum cryptographic algorithm name adopted as group branding  Get Threat Intel and Security Updates Delivered to Your Inbox.   Profiling  Threat Actor Type: Kyber is a...

The Gentlemen: A Threat Profile

Aliases  Storm-2697 — tracking designation assigned by Microsoft Threat Intelligence to the operators of the RaaS platform. The group continues to brand exclusively as “The Gentlemen” across its leak site, X/Twitter, and underground forums. Its...