Skip to threat actors

Cyber threat intelligence

Resolve the actor before trusting the name.

Vendor names describe overlapping activity, not identical groups. Each dossier keeps designations, confidence and evidence attached to every claim.

Published profiles
5
Latest review
2026-07-19
Distribution
TLP:CLEAR

Actor directory

Curated profiles

Search the dossiers or filter by state alignment.

5 profiles

Microsoft familySandstormIran
activeTLP:CLEAR

State-aligned OT threat group

BAUXITE

A Dragos-designated, state-aligned OT threat group linked by substantial technical overlap to the IRGC-affiliated CyberAv3ngers persona.

Dragos · BAUXITEMITRE ATT&CK · CyberAv3ngers · G1027CISA and partner agencies · IRGC-affiliated cyber actors using the CyberAv3ngers persona · AA23-335A
Open intelligence dossier
Microsoft familySandstormIran
activeTLP:CLEAR

State-sponsored OT threat group

CyberAv3ngers

An IRGC-affiliated threat persona associated with disruptive targeting of exposed operational technology, most visibly the 2023 Unitronics PLC/HMI campaign.

MITRE ATT&CK · CyberAv3ngers · G1027CISA and partner agencies · IRGC-affiliated cyber actors using the CyberAv3ngers persona · AA23-335ADragos · BAUXITE
Open intelligence dossier
Microsoft familyBlizzardRussia
activeTLP:CLEAR

State-aligned OT espionage group

GRAPHITE

A Dragos-designated Stage 1 OT threat group conducting credential theft and espionage against energy, logistics and industrial organisations, with reported overlap to APT28.

Dragos · GRAPHITEMITRE ATT&CK · APT28 · G0007Microsoft · Forest Blizzard
Open intelligence dossier
Microsoft familyBlizzardRussia
activeTLP:CLEAR

State-aligned OT access group

KAMACITE

A Dragos-designated access-development group that penetrates industrial organisations, steals and replays credentials, and enables follow-on ICS operations by teams such as ELECTRUM.

Dragos · KAMACITEDragos · ELECTRUMMITRE ATT&CK · Sandworm Team · G0034
Open intelligence dossier
Microsoft familyBlizzardRussia
activeTLP:CLEAR

State-sponsored destructive threat group

Sandworm Team

A Russian GRU Unit 74455 threat group responsible for destructive global operations and multiple attacks that produced or attempted operational effects in Ukraine's electric grid.

MITRE ATT&CK · Sandworm Team · G0034Google Threat Intelligence · APT44 / FROZENBARENTSMicrosoft · Seashell Blizzard
Open intelligence dossier