About APT Explorer

APT Explorer tracks advanced persistent threat (APT) actors, the reports written about them and current reporting trends. It is a personal, non-commercial research project built only from open sources.

Different sources give the same actor different names: one vendor's APT28 is another's Fancy Bear, Sofacy or Sednit. The site merges actor records from MITRE ATT&CK®, the MISP galaxy, ETDA's Threat Group Cards and Malpedia, and records the evidence behind each merge. Where sources disagree, such as on an actor's origin, the site shows every value with its source. The Methodology page reports how well the merge works.

Reports belong to their authors. The site publishes derived facts, metadata and links, and it never re-hosts a report's text or PDF.

Built on Yuldoshkhujaev et al. (CCS '25)

This project builds on Yuldoshkhujaev, Jeon, Kim, Nikiforakis and Koo, A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends, published at the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). The preprint is on arXiv (2509.07457).

The authors released their data as Zenodo record 16869733 under CC BY 4.0. The dataset covers reports from 2014 to 2023 and appears here as a separate, labeled layer. No view reproduces a figure from the paper.

Dataset attribution

Data from Yuldoshkhujaev, S., Jeon, M., Kim, D., Nikiforakis, N., Koo, H. A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends. Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Dataset: https://doi.org/10.5281/zenodo.16869733, licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Modified: rows were parsed, split and filtered by apt-explorer.

Sources and Licenses

Each source's license decides what the site may publish from it. The project's SOURCES.md file quotes every license and records the decision.

  • MITRE ATT&CK

    Groups, aliases, campaigns, techniques and software.

    Publish
    full
    Last good fetch
    Records
    1,192

    Attribution

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.

  • MISP galaxy threat-actor cluster

    Actors, synonyms, origin, motive and claimed sectors.

    Publish
    full
    License
    CC0 1.0
    Last good fetch
    Records
    1,058

    Attribution

    Threat actor data from the MISP galaxy threat-actor cluster (MISP Project; authors Alexandre Dulaunoy, Florian Roth, Thomas Schreck, Timo Steffens and others), https://github.com/MISP/misp-galaxy, used under CC0 1.0.

  • ETDA Threat Group Cards

    Actor names, aliases and short values such as origin.

    Publish
    derived-only
    Last good fetch
    Records
    503

    Attribution

    Threat Group Cards: A Threat Actor Encyclopedia. Copyright © Electronic Transactions Development Agency, 2019-2026. https://apt.etda.or.th/. Licensed under CC BY-NC-SA 4.0, https://creativecommons.org/licenses/by-nc-sa/4.0/. Provided by ETDA on an 'As Is' basis with no warranty. Modified: names and values were normalized and merged with other sources by apt-explorer.

  • Malpedia

    Links from actors to malware families and reports, and report dates.

    Publish
    derived-only
    Last good fetch
    Records
    4,876

    Attribution

    Malpedia, a free service offered by Fraunhofer FKIE. https://malpedia.caad.fkie.fraunhofer.de/. Licensed under CC BY-NC-SA 3.0, https://creativecommons.org/licenses/by-nc-sa/3.0/. Modified: actor, family and library data were normalized and merged with other sources by apt-explorer. Plohmann, D., Clauss, M., Enders, S., Padilla, E. Malpedia: A Collaborative Effort to Inventorize the Malware Landscape. The Journal on Cybercrime & Digital Investigations, [S.l.], v. 3, n. 1, apr. 2018.

  • ORKL

    Report titles, dates and links. Its actor tags are used only as matching evidence.

    Publish
    link-only
    Last good fetch
    Records
    29,542

    Attribution

    Report metadata from ORKL, the community cyber threat intelligence library, https://orkl.eu.

  • CISA Known Exploited Vulnerabilities Catalog

    Exploited CVEs, the date each was added and the ransomware flag.

    Publish
    full
    License
    CC0 1.0
    Last good fetch
    Records
    1,734

    Attribution

    CISA Known Exploited Vulnerabilities Catalog, https://www.cisa.gov/known-exploited-vulnerabilities-catalog, CC0 1.0.

  • The DFIR Report

    Titles, dates and links for intrusion write-ups.

    Publish
    link-only
    Last good fetch
    Records
    97

    Attribution

    Report titles and links from The DFIR Report, https://thedfirreport.com/. © The DFIR Report. All rights reserved; report content is not reproduced here.

  • Yuldoshkhujaev et al., CCS '25 dataset

    Reports from 2014 to 2023, shown as a labeled layer.

    Publish
    full
    License
    CC BY 4.0
    Last good fetch
    Records
    1,509

    Attribution

    Data from Yuldoshkhujaev, S., Jeon, M., Kim, D., Nikiforakis, N., Koo, H. A Decade-long Landscape of Advanced Persistent Threats: Longitudinal Analysis and Global Trends. Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS '25). Dataset: https://doi.org/10.5281/zenodo.16869733, licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Modified: rows were parsed, split and filtered by apt-explorer.

  • Microsoft threat actor naming table

    Microsoft's names for actors, with the aliases other vendors use and the origin it gives.

    Publish
    full
    License
    CC BY 4.0
    Last good fetch
    Records
    170

    Attribution

    Threat actor naming data from Microsoft Threat Intelligence, Microsoft Corporation, https://github.com/microsoft/mstic (PublicFeeds/ThreatActorNaming), licensed under CC BY 4.0, https://creativecommons.org/licenses/by/4.0/. Modified: names and origin values were normalized and merged with other sources by apt-explorer. This project is not endorsed by or affiliated with Microsoft.

  • EPSS exploit prediction scores

    The modeled chance that each listed CVE is exploited in the next 30 days.

    Publish
    full
    Last good fetch
    Records
    382,621

    Attribution

    Exploit Prediction Scoring System (EPSS) scores from FIRST, https://www.first.org/epss, scores generated by Empirical Security. Jay Jacobs, Sasha Romanosky, Benjamin Edwards, Michael Roytman, Idris Adjerid, (2021), Exploit Prediction Scoring System, Digital Threats Research and Practice, 2(3). Scores are shown unchanged. This project is not endorsed by FIRST.

  • Cisco Talos blog

    Titles, dates and links for Talos research posts, and the names a post says are one actor.

    Publish
    derived-only
    Last good fetch
    Records
    18

    Attribution

    Post titles and links from the Cisco Talos blog, https://blog.talosintelligence.com/. © Cisco and/or its affiliates. All rights reserved; post content is not reproduced here. Where a post states that two names are one actor, those two names are kept as an alias. This project is not endorsed by Cisco.

  • ESET WeLiveSecurity blog

    Titles, dates and links for ESET blog posts, and the names a post says are one actor.

    Publish
    derived-only
    Last good fetch
    Records
    24

    Attribution

    Post titles and links from the ESET WeLiveSecurity blog, https://www.welivesecurity.com/. © ESET. All rights reserved; post content is not reproduced here. Where a post states that two names are one actor, those two names are kept as an alias. This project is not endorsed by ESET.

  • Microsoft Security blog

    Titles, dates and links for Microsoft Security blog posts, and the names a post says are one actor.

    Publish
    derived-only
    Last good fetch
    Records
    14

    Attribution

    Post titles and links from the Microsoft Security blog, https://www.microsoft.com/en-us/security/blog/. © Microsoft. All rights reserved; post content is not reproduced here. Where a post states that two names are one actor, those two names are kept as an alias. This project is not endorsed by or affiliated with Microsoft.

What Each Publish Value Means

A source's publish value limits what the site may show from it. It never reduces what the license requires: attribution, NonCommercial and ShareAlike terms apply in full.

full

Every field the pipeline takes from the source may appear, with a source badge and its provenance.

Used by ATT&CK, MISP, CISA KEV, CCS '25 data, Microsoft and EPSS.

derived-only

Short factual values may appear with a source badge: names, aliases, country and sector values, motivation, dates and identifiers. The source's own text is never copied. The license duties still apply in full.

Used by ETDA, Malpedia, Talos, ESET and MS Security.

evidence-only

Nothing from the source appears in the published data. The source only adds evidence when the registry decides whether two actor names belong to the same actor, and the site reports that evidence as a count.

No source uses this value in this build.

Data License

The published data is offered under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License (CC BY-NC-SA 4.0).

It carries this license because it adapts two share-alike sources: values from ETDA's Threat Group Cards and from Malpedia are normalized and merged with the other sources. Anyone who reuses the data receives the same NonCommercial and ShareAlike terms and must credit the sources listed above.

No additional terms apply to the data, and the license of the APT Explorer code does not cover it. The same notice ships with the data as NOTICE.md.

MITRE ATT&CK

Values from MITRE ATT&CK stay under MITRE's license, which requires its copyright designation and license in every copy:

© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy. MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation.

APT Explorer is not affiliated with, sponsored by or endorsed by MITRE, CISA or the US Department of Homeland Security (DHS), and it does not use the CISA logo or the DHS seal.