About APT Explorer
APT Explorer tracks advanced persistent threat (APT) actors, the reports written about them and current reporting trends. It is a personal, non-commercial research project built only from open sources.
Different sources give the same actor different names: one vendor's APT28 is another's Fancy Bear, Sofacy or Sednit. The site merges actor records from MITRE ATT&CK®, the MISP galaxy, ETDA's Threat Group Cards and Malpedia, and records the evidence behind each merge. Where sources disagree, such as on an actor's origin, the site shows every value with its source. The Methodology page reports how well the merge works.
Reports belong to their authors. The site publishes derived facts, metadata and links, and it never re-hosts a report's text or PDF.
Built on Yuldoshkhujaev et al. (CCS '25)
This project builds on Yuldoshkhujaev, Jeon, Kim, Nikiforakis and Koo, A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends, published at the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). The preprint is on arXiv (2509.07457).
The authors released their data as Zenodo record 16869733 under CC BY 4.0. The dataset covers reports from 2014 to 2023 and appears here as a separate, labeled layer. No view reproduces a figure from the paper.
Dataset attribution
Data from Yuldoshkhujaev, S., Jeon, M., Kim, D., Nikiforakis, N., Koo, H. A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends. Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Dataset: https://doi.org/10.5281/zenodo.16869733, licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Modified: rows were parsed, split and filtered by apt-explorer.
Sources and Licenses
Each source's license decides what the site may publish from it. The project's SOURCES.md file quotes every license and records the decision.
-
Attribution
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.
-
Attribution
Threat actor data from the MISP galaxy threat-actor cluster (MISP Project; authors Alexandre Dulaunoy, Florian Roth, Thomas Schreck, Timo Steffens and others), https://github.com/MISP/misp-galaxy, used under CC0 1.0.
-
Attribution
Threat Group Cards: A Threat Actor Encyclopedia. Copyright © Electronic Transactions Development Agency, 2019-2026. https://apt.etda.or.th/. Licensed under CC BY-NC-SA 4.0, https://creativecommons.org/licenses/by-nc-sa/4.0/. Provided by ETDA on an 'As Is' basis with no warranty. Modified: names and values were normalized and merged with other sources by apt-explorer.
-
Attribution
Malpedia, a free service offered by Fraunhofer FKIE. https://malpedia.caad.fkie.fraunhofer.de/. Licensed under CC BY-NC-SA 3.0, https://creativecommons.org/licenses/by-nc-sa/3.0/. Modified: actor, family and library data were normalized and merged with other sources by apt-explorer. Plohmann, D., Clauss, M., Enders, S., Padilla, E. Malpedia: A Collaborative Effort to Inventorize the Malware Landscape. The Journal on Cybercrime & Digital Investigations, [S.l.], v. 3, n. 1, apr. 2018.
-
Attribution
Report metadata from ORKL, the community cyber threat intelligence library, https://orkl.eu.
-
Attribution
CISA Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, CC0 1.0.
-
Attribution
Report titles and links from The DFIR Report, https://thedfirreport.com/. © The DFIR Report. All rights reserved; report content is not reproduced here.
-
Attribution
Data from Yuldoshkhujaev, S., Jeon, M., Kim, D., Nikiforakis, N., Koo, H. A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends. Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Dataset: https://doi.org/10.5281/zenodo.16869733, licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Modified: rows were parsed, split and filtered by apt-explorer.
-
Attribution
Threat actor naming data from Microsoft Threat Intelligence, Microsoft Corporation, https://github.com/microsoft/mstic (PublicFeeds/ThreatActorNaming), licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Modified: names and origin values were normalized and merged with other sources by apt-explorer. This project is not endorsed by or affiliated with Microsoft.
-
Attribution
Exploit Prediction Scoring System (EPSS) scores from FIRST, https://www.first.org/epss, scores generated by Empirical Security. Jay Jacobs, Sasha Romanosky, Benjamin Edwards, Michael Roytman, Idris Adjerid, (2021), Exploit Prediction Scoring System, Digital Threats Research and Practice, 2(3). Scores are shown unchanged. This project is not endorsed by FIRST.
-
Attribution
Post titles and links from the Cisco Talos blog, https://blog.talosintelligence.com/. © Cisco and/or its affiliates. All rights reserved; post content is not reproduced here. Where a post states that two names are one actor, those two names are kept as an alias. This project is not endorsed by Cisco.
-
Attribution
Post titles and links from the ESET WeLiveSecurity blog, https://www.welivesecurity.com/. © ESET. All rights reserved; post content is not reproduced here. Where a post states that two names are one actor, those two names are kept as an alias. This project is not endorsed by ESET.
-
Attribution
Post titles and links from the Microsoft Security blog, https://www.microsoft.com/en-us/security/blog/. © Microsoft. All rights reserved; post content is not reproduced here. Where a post states that two names are one actor, those two names are kept as an alias. This project is not endorsed by or affiliated with Microsoft.
What Each Publish Value Means
A source's publish value limits what the site may show from it. It never reduces what the license requires: attribution, NonCommercial and ShareAlike terms apply in full.
fullEvery field the pipeline takes from the source may appear, with a source badge and its provenance.
Used by ATT&CK, MISP, CISA KEV, CCS '25 data, Microsoft and EPSS.
derived-onlyShort factual values may appear with a source badge: names, aliases, country and sector values, motivation, dates and identifiers. The source's own text is never copied. The license duties still apply in full.
Used by ETDA, Malpedia, Talos, ESET and MS Security.
link-onlyOnly each item's title, publisher, publication date and link appear, plus identifiers this project computes itself, such as a content hash.
Used by ORKL and DFIR Report.
evidence-onlyNothing from the source appears in the published data. The source only adds evidence when the registry decides whether two actor names belong to the same actor, and the site reports that evidence as a count.
No source uses this value in this build.
Original, Archive and Mirror Links
A report can have two links: the publisher's own page and a copy held by someone else. The site labels each link by where it goes, so a copy is never passed off as the original. The Methodology page explains how and where the label can be wrong.
- Original publisher
- The address the source records as the place the report was published.
- Link, publisher not confirmed
- A link on a site that serves other people’s pages, such as a link shortener, a reference page, a file host or a cache. The site cannot tell whether it is the publisher’s page or a copy.
- Archived copy on ORKL
- A saved copy of the report held by ORKL, a threat report library. It is not the publisher’s page.
- Mirror on VX-Underground
- A copy in the VX-Underground paper collection, a third-party site. It is not the publisher’s page.
- CyberMonitor archive on GitHub
- A copy in the CyberMonitor collection of threat reports on GitHub. It is not the publisher’s page.
- Mirror on Box
- A copy in a shared Box folder. It is not the publisher’s page.
- Wayback Machine
- A snapshot saved by the Internet Archive. It shows the page as it was on the snapshot date, which may differ from the page today.
- archive.today
- A snapshot saved by archive.today. It shows the page as it was on the snapshot date, which may differ from the page today.
Some reports have no known original. Their records point only to a mirror or to a link whose publisher the site cannot confirm, and the panel says no original publisher link is known or confirmed. The site does not guess one.
Data License
The published data is offered under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License (CC BY-NC-SA 4.0).
It carries this license because it adapts two share-alike sources: values from ETDA's Threat Group Cards and from Malpedia are normalized and merged with the other sources. Anyone who reuses the data receives the same NonCommercial and ShareAlike terms and must credit the sources listed above.
No additional terms apply to the data, and the license of the APT Explorer code does not cover it. The same notice ships with the data as NOTICE.md.
MITRE ATT&CK
Values from MITRE ATT&CK stay under MITRE's license, which requires its copyright designation and license in every copy:
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.
APT Explorer is not affiliated with, sponsored by or endorsed by MITRE, CISA or the US Department of Homeland Security (DHS), and it does not use the CISA logo or the DHS seal.