Intel

Profiles of threat actors and the malware families behind their campaigns.

Threat Actor Nation-State 2026

Sandworm Team

Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.

Read profile →
Threat Actor Nation-State 2026

Xenotime

Group behind TRISIS/TRITON, the first malware built to target a safety instrumented system rather than the process it protects.

Read profile →
Threat Actor Nation-State 2026

Chernovite

Assessed state-sponsored group behind PIPEDREAM, the most capable publicly documented ICS attack toolkit found before it was ever deployed.

Read profile →
Threat Actor Financially Motivated 2025

TamperedChef

Operation behind AceLauncher and the AppSuite PDF Editor backdoor — trojanized, code-signed apps distributed via convincing malvertising.

Read profile →
Malware ICS Protocol Abuse 2026

Industroyer

The first malware framework built to speak grid-control protocols directly — used against a Kyiv transmission substation in 2016.

Read profile →
Malware Safety System Sabotage 2026

TRISIS (TRITON)

The first malware to target a safety instrumented system directly — deployed against Triconex controllers at a Saudi petrochemical plant in 2017.

Read profile →
Malware ICS Protocol Abuse 2026

PIPEDREAM

A modular toolkit built to scan, access, and disable PLCs across multiple vendors — discovered and disclosed before it was ever used.

Read profile →
Malware Infostealer 2025

AceLauncher

A fake browser productivity tool tied to TamperedChef/EvilAI — from AI-generated landing page to .NET binary teardown.

Read profile →