One group, forty-six names.
Vendors each name the same threat actor differently. APT Explorer lines up five public datasets, shows which source uses which name, and links every fact to the report it came from.
APT28, as five sources name it. A filled square means that source lists the name. The rows sample the 46 names, most widely listed first.
| Name used in reports | ATT&CK | MISP | ETDA | Malpedia | Microsoft |
|---|---|---|---|---|---|
| APT28 | Lists this name | Lists this name | Does not list this name | Lists this name | Lists this name |
| Sednit | Lists this name | Lists this name | Lists this name | Lists this name | Lists this name |
| Swallowtail | Lists this name | Lists this name | Lists this name | Lists this name | Does not list this name |
| STRONTIUM | Lists this name | Lists this name | Does not list this name | Lists this name | Lists this name |
| IRON TWILIGHT | Lists this name | Lists this name | Does not list this name | Lists this name | Does not list this name |
| ITG05 | Does not list this name | Lists this name | Lists this name | Lists this name | Does not list this name |
| Fighting Ursa | Does not list this name | Lists this name | Lists this name | Lists this name | Does not list this name |
| Grey-Cloud | Does not list this name | Does not list this name | Lists this name | Lists this name | Does not list this name |
| LAKE RELIC | Does not list this name | Lists this name | Does not list this name | Lists this name | Does not list this name |
| HELLFIRE | Does not list this name | Does not list this name | Does not list this name | Lists this name | Lists this name |
| Iron Twilight | Does not list this name | Does not list this name | Lists this name | Does not list this name | Does not list this name |
| Group-4127 | Does not list this name | Does not list this name | Does not list this name | Lists this name | Does not list this name |
and 34 more names for this group
Ways in
- Explore reports
Every report and campaign in one table you can filter by actor, source, date or CVE.
29,483 reports - Actors
One page per group: names, malware, techniques, CVEs, and the reports behind them.
1,096 actors - Trends
Which groups and techniques show up in the last two years of reporting.
Since 1 October 2024 - Name guesses
Names from the paper's reports that match no known group. A program labels each one and gives a score and the evidence.
95 guesses - Sources
Where every fact comes from, what we may publish from it, and when it was last fetched.
13 sources
Where the data comes from
| Source | What we publish |
|---|---|
| MITRE ATT&CK Current , 1,192 records | Full |
| MISP galaxy threat-actor cluster Current , 1,058 records | Full |
| ETDA Threat Group Cards Current , 503 records | Derived facts only |
| Malpedia Current , 4,876 records | Derived facts only |
| ORKL Current , 29,542 records | Links only |
| CISA Known Exploited Vulnerabilities Catalog Current , 1,734 records | Full |
| The DFIR Report Current , 97 records | Links only |
| Yuldoshkhujaev et al., CCS '25 dataset Current , 1,509 records | Full |
| Microsoft threat actor naming table Current , 170 records | Full |
| EPSS exploit prediction scores Current , 382,621 records | Full |
| Cisco Talos blog Current , 18 records | Derived facts only |
| ESET WeLiveSecurity blog Current , 24 records | Derived facts only |
| Microsoft Security blog Current , 14 records | Derived facts only |
Sources are fetched weekly. A failed fetch keeps the last good snapshot and marks the source stale. Full license table and fetch dates
Built on the dataset of Yuldoshkhujaev et al. (CCS '25). About has the full credit.