Methodology

This page reports how the actor registry is built and how well it matches the actor names in the data released with the CCS '25 paper.

The Registry

The registry merges actor records from MITRE ATT&CK®, the MISP galaxy, ETDA's Threat Group Cards and Malpedia into one actor per group and keeps the evidence for each merge.

Source records
2,971
Actors
1,096
Merges
1,875
Evidence links
4,440
Ambiguous aliases
133
Typed as software
5,253

Merges is the number of records folded into another record, which is source records minus actors. An evidence link is one shared name that joined two records. An ambiguous alias is a name that two ATT&CK groups both carry. Typed as software counts the names that belong to malware or a tool and to no actor.

How Records Are Merged

  1. Names are normalized. The registry lowercases each name, folds full-width characters to plain ones, drops spaces and punctuation, and removes a trailing “Group” or “Team”. Digits stay, so APT28 and APT2 remain separate actors.
  2. Shared names make candidates. Two records are candidates for a merge when they share a normalized name or alias. Each shared name is kept as an evidence link.
  3. Some names are left alone. A shared name never merges two groups that ATT&CK lists under different IDs. The name is recorded as an ambiguity.
  4. Software is not an actor. A name that matches a Malpedia malware family or an ATT&CK software entry, and no actor, is typed as malware or a tool and is not shown as an actor.

Match Against the Paper's Names

75.4% of the paper's names resolve to an actor

The CCS '25 dataset labels its reports with 443 actor names. The registry resolves 334 of them to an actor. Another 23 are typed as malware or a tool. The remaining 86 match neither.

Software names do not raise the match rate. It measures agreement with the paper's labels, not how many resolved names are correct, because a resolved name is only as reliable as the aliases behind it.

Ambiguous Aliases

Each alias below is carried by more than one ATT&CK group. The registry cannot tell which group another source meant by it, so it does not merge the groups and does not use the alias to link a report to either one.

AliasGroups that carry it
actinium
appleworm
apt34
apt36
apt38
aptc26
aquablizzard
armageddon
atk3
atk32
atk6
axiom
backdoordiplomacy
beagleboyz
beijing
berserkbear
blackfly
blackvine
bluekraken
bluenoroff
bromine
bronzeexport
bronzegeneva
bronzesterling
calcium
carbonspider
cerium
charcoaltyphoon
chromium
citrinesleet
cobaltgypsy
controlx
copernicium
crambus
crouchingyeti
deeppanda
dev0139
dev0157
dev0206
diamondsleet
dragonfly
dymalloy
earthkasha
earthlusca
elbrus
elderwood
elderwoodgang
energeticbear
europium
fin7
fireant
g0011
g0013
g0032
g0035
g0046
g0093
gamaredon
ghostblizzard
goldniagara
grizzlysteppe
group24
group72
group77
group83
guardiansofpeace
hastati
hazelsandstorm
helixkitten
hiddencobra
higaisa
hippo
iron
ironliberty
irontilden
itg15
kaos
koala
kungfukittens
labyrinthchollima
lazarus
lorec53
lotusblossom
lotuspanda
luminousmoth
moafee
moonstonesleet
mustardtempest
mythicleopard
newromaniccyberarmy
newsbeef
newscaster
nickelacademy
nickelgladstone
oilrig
opalsleet
osmium
overridepanda
parastoo
pinkpanther
pittypanda
primitivebear
radium
raspberrytyphoon
rubysleet
saintbear
sangriatempest
sapphiresleet
shellcrew
shuckworm
sneakypanda
stardustchollima
storm0156
storm0587
ta404
ta471
tag22
tarhandishan
tempavengers
tempbeanie
tg2754
tg4192
thrip
timberworm
transparenttribe
uac0056
unc788
webmasters
whitefly
whoishacking
wickedspider
winnti
zinc

Names That Did Not Resolve

These names appear in reports and resolve to no actor, most frequent first. A name typed as malware or a tool is software, not a missing actor. A name with no type may be an actor that none of the sources lists. The Name Guesses page gives a program's label for each one and the method's measured accuracy, with every label pending confirmation.

NameTimes seenTyped as
Winnti Umbrella592not typed
Operation Armageddon24not typed
COBALT GIPSY19not typed
Kimsuki19not typed
Timberworm19not typed
nso group5not typed
LOTUS PANDA4not typed
Oktropys3not typed
grand theft auto panda3not typed
uac-00563not typed
Sphinx (APT-C-15)2not typed
Stealth Mango2malware
chessmaster2not typed
kovcoreg2not typed
newsbeef2not typed
outlaw2not typed
shadow force2not typed
3ve1not typed
85th gtsss1not typed
DePriMon1malware
DustySky1malware
Iron Group1not typed
Thrip1not typed
TopHat1not typed
a 공격 그룹1not typed
a41apt1not typed
aleksandr1not typed
appin security group1not typed
apt sidewinder1not typed
apt-c-011not typed
apt-c-471not typed
apt-c-591not typed
black mafia1not typed
black peace1not typed
blackenergy gang1not typed
blue termit1not typed
c-231not typed
c.rufus security team1not typed
cadelspy1malware
cetarat1malware
china chopper1malware
clouddragon1not typed
comfoo1malware
conti1malware
cosmic banker1not typed
destover1malware
dustysky1malware
edbitss1not typed
emotet gang1not typed
fhappi1not typed
french intelligence1not typed
gholee1malware
gholee61not typed
ghost dragon1not typed
goldenspy1malware
great1not typed
hafnuim1not typed
hussarini1malware
inception attackers1not typed
iron group1not typed
isis-linked hackers1not typed
jolly roger’s patrons1not typed
kelvinsecurityteam1not typed
keyboys1not typed
king kong elephant1not typed
leery turtle1not typed
lucky elephant1not typed
luminousmoth1not typed
miniduke1malware
mirrorthief1not typed
mykings1not typed
negg1not typed
nilephish1not typed
operation falcon1not typed
operation kingphish1not typed
operation oceansalt1not typed
operation transparent tribe1not typed
ozie team1not typed
praying mantis1not typed
punchbuggy1malware
puzzlemaker1malware
quantum ransomware1not typed
rana1malware
raqqah1not typed
reconhellcat1not typed
red hacker alliance1not typed
redoctober1not typed
regin1malware
remexi1malware
right sector1not typed
romcom threat actor1not typed
russian gru1not typed
sakula1malware
sectora051not typed
sectorb061not typed
shadow chaser1not typed
shiqiang1not typed
shun wang technologies1not typed
silverhawk1not typed
solar marker1malware
soraj bear1not typed
sourface1malware
sun team folder1not typed
sunorcal1malware
sunshop digital quartermaster1not typed
tag-261not typed
tarh andishan1not typed
teleport crew1not typed
thrip1not typed
trickbot1malware
uac-00981not typed
ucid9021not typed
unc27271not typed
unclassified1not typed
urlzone1malware
valkyrie-x security research group1not typed
water kappa1not typed
water pamola1not typed
zebra21041not typed
zebrocy1malware
عقارب ليبيا1not typed
伪猎者apt组织1not typed
海莲花1not typed

Report Dates

Each report has one date and a label for where the date came from. The first rule that gives a usable date wins.

  1. The Malpedia library date recorded for the report's URL (malpedia-library).
  2. The date at the start of the report's title (title-date). Some collections file a paper as "2014-11-14 - Title". The site uses that date when it is not later than the day ORKL added the report, and it removes the date from the title it shows.
  3. The file creation date stored in the report itself (file-metadata).
  4. The date ORKL added the report to its collection (orkl-ingest). This is when ORKL saw the report, not when it was published, so it can be later than the true date.

A date before 1990 or a placeholder such as 0001-01-01 counts as missing, and the next rule applies. A report that passes none of the rules is undated, and it is never in a timeline or a trend.

What Is Published

Each source has a publish value that limits what the site may show from it. The About page gives each source's value and license.

evidence-only

Nothing from the source appears in the published data. The source only adds evidence when the registry decides whether two actor names belong to the same actor, and the site reports that evidence as a count.

No source is evidence-only in this build.

ORKL tags its reports with actor names. While ORKL is link-only, the site never shows those tags and never links a report to an actor on the strength of a tag alone. A report is linked to an actor only through Malpedia, ATT&CK references or the paper's data.

The actors, CVEs and techniques listed for an ORKL report were added by this project, and the table can filter and search on them. Actors come from the sources named above, or from a title or text that names them, and CVE and technique IDs are matched in the report text. The link-only rule allows this because the project works out those identifiers itself.

Actors named in a title

The site keeps no post text from the Microsoft, Talos and ESET blogs, The DFIR Report or ORKL. It can still read the title it shows. When that title contains the name of an actor that has a page here, the report is linked to that actor, and the report panel lists it under "Named in the title", apart from the actors a source tags. The paper's own report titles are read the same way. ORKL's actor tags are still never shown or used for these links.

The match reads whole words and uses only the names this site already publishes. It skips a name that belongs to two actors, a name that is also an ordinary word, and the names of malware that a title can mention without being about the actor. A title is the publisher's own statement, but it is weaker than a tag, and it can name an actor in passing.

Actors named in the text

The pipeline reads ORKL's report text once, at fetch, and keeps only which actors with a page here it names, how often, and where the name first appears. The text is never stored or published. The panel lists these actors under "Named in the text", apart from tagged actors and those named in the title.

The match is stricter than for titles, since a report mentions actors in passing. A name must appear twice, or once in the opening 300 words if it has several words or a digit, such as Fancy Bear or APT29. The same names are skipped. Only actors published when a report was read can be found in it.

Names a vendor post states

A post titled with a vendor's own label, such as Storm-3168, can miss the report that uses the actor's usual name. The Microsoft, Talos and ESET blogs often say outright that two names are one actor, as in "JadePuffer, tracked by Microsoft as Storm-3168". The pipeline reads each post's text in memory for phrases that equate two names, such as "also known as", "tracked as" and "a.k.a.", then keeps the two names and drops the sentence. Phrases such as "overlaps with" and "similar to" are not read, because they say the two are different.

A stated pair is used in two cases. When one name is an actor this site already publishes, the other becomes an alias of that actor. When neither name is known, the pair adds a new actor only if one name is a vendor cluster label such as Storm-3168 or UNC2452 and the name guesser calls both names an actor. The guesser alone is not enough, because it calls almost any capitalized name an actor, malware families included. A pair is never used to join two actors the sources keep apart, or to turn a malware family into an actor. The rule is provisional, and every alias it adds carries the blog's source badge.

A cluster ID in a post title can also add an actor. When a Talos title carries a UAT- ID, or a Microsoft title carries a Storm- or DEV- ID, and no source lists that ID, it becomes an actor labeled "unconfirmed vendor cluster" with that post as its report. Only the vendor that issues the format counts, and other shapes such as UNC and TA are left out because they match unrelated labels. The label drops once a source or a stated pair names the cluster.

Known Limitations

  • Sources update on different schedules. The home page shows the last good fetch for each one, and a source that fails keeps its last good data until it recovers.
  • A report that no source connects to an actor appears on no profile, even when its text names one. Actor names found in report text are not extracted in this version.
  • Two sources can disagree on a value such as origin. The profile shows every value with its source and does not pick one.