All actors

Axiom

Also reported as Group 72.

Reports
42
Last reported
Known CVEs
24
Techniques in ATT&CK
16
ID
G0001
Sources
ATT&CK
Merge evidence
0 alias matches

Reports per quarter

  1. 2013 Q2: 1 report
  2. 2013 Q3: no reports
  3. 2013 Q4: no reports
  4. 2014 Q1: no reports
  5. 2014 Q2: no reports
  6. 2014 Q3: no reports
  7. 2014 Q4: 5 reports
  8. 2015 Q1: 3 reports
  9. 2015 Q2: 5 reports
  10. 2015 Q3: no reports
  11. 2015 Q4: no reports
  12. 2016 Q1: 2 reports
  13. 2016 Q2: no reports
  14. 2016 Q3: 2 reports
  15. 2016 Q4: no reports
  16. 2017 Q1: no reports
  17. 2017 Q2: no reports
  18. 2017 Q3: 1 report
  19. 2017 Q4: 3 reports
  20. 2018 Q1: 2 reports
  21. 2018 Q2: 2 reports
  22. 2018 Q3: 1 report
  23. 2018 Q4: no reports
  24. 2019 Q1: no reports
  25. 2019 Q2: no reports
  26. 2019 Q3: 1 report
  27. 2019 Q4: 2 reports
  28. 2020 Q1: no reports
  29. 2020 Q2: 1 report
  30. 2020 Q3: 2 reports
  31. 2020 Q4: no reports
  32. 2021 Q1: no reports
  33. 2021 Q2: no reports
  34. 2021 Q3: no reports
  35. 2021 Q4: no reports
  36. 2022 Q1: no reports
  37. 2022 Q2: no reports
  38. 2022 Q3: no reports
  39. 2022 Q4: 1 report
  40. 2023 Q1: no reports
  41. 2023 Q2: no reports
  42. 2023 Q3: no reports
  43. 2023 Q4: no reports
  44. 2024 Q1: no reports
  45. 2024 Q2: no reports
  46. 2024 Q3: no reports
  47. 2024 Q4: no reports
  48. 2025 Q1: no reports
  49. 2025 Q2: no reports
  50. 2025 Q3: no reports
  51. 2025 Q4: no reports
  52. 2026 Q1: no reports
  53. 2026 Q2: 8 reports
Dated reports, 2013 Q2 to 2026 Q2.

Techniques in ATT&CK

Listed by ATT&CK

Show all 16 techniques Show fewer

No report from the last two years names a technique ID.

CVEs named in reports

Show all 24 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. ZXShell (Malware Family)

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  4. Operation-Blockbuster-Report

    date ORKL added it fromORKL

Show all 42 reports Show fewer
  1. What even is Winnti-

    date in the title fromORKL

  2. T1055 Process Injection

    date in the title fromORKL

  3. ESET_Winnti

    Malpedia library date fromORKL

  4. HELO Winnti_ Attack or Scan

    file creation date fromORKL

  5. HELO Winnti- Attack or Scan-

    date in the title fromORKL

  6. CN_APT-C-01

    file creation date fromORKL

  7. Burning Umbrella

    date in the CCS '25 data 401TRG fromORKLCCS '25 data

  8. Aurora_Operation_CCleaner_II

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  9. ICIT-Brief-China-Espionage-Dynasty

    date in the CCS '25 data Debra Obyrne fromORKLCCS '25 data

  10. Please Read

    date in the CCS '25 data FireEye and Microsoft fromORKLCCS '25 data

  11. Operation Blockbuster

    date in the CCS '25 data Novetta fromORKLCCS '25 data

  12. Games are over - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  13. WINNTI Analysis

    date in the CCS '25 data Novetta fromCCS '25 data

  14. WINNTI Analysis

    Malpedia library date Novetta fromORKL

  15. Anthem Breach May Have Started in April 2014

    date in the title fromORKL

  16. Cisco - Annual Security Report - 2015.pdf

    file creation date fromORKL

  17. Threat Spotlight: Group 72, Opening the ZxShell

    date in the CCS '25 data Cisco fromORKLCCS '25 data

  18. Operation SMN

    date in the CCS '25 data Novetta fromCCS '25 data

  19. Threat Spotlight: Group 72

    date in the CCS '25 data Cisco fromORKLCCS '25 data

Newest first. Details opens the report in Explore.