Profiles of threat actors and the malware families behind their campaigns.
Sandworm Team
Russian GRU unit (APT44) behind the 2015 and 2016 Ukraine power grid attacks, NotPetya, and Olympic Destroyer.
Read profile →Xenotime
Group behind TRISIS/TRITON, the first malware built to target a safety instrumented system rather than the process it protects.
Read profile →Chernovite
Assessed state-sponsored group behind PIPEDREAM, the most capable publicly documented ICS attack toolkit found before it was ever deployed.
Read profile →TamperedChef
Operation behind AceLauncher and the AppSuite PDF Editor backdoor — trojanized, code-signed apps distributed via convincing malvertising.
Read profile →Industroyer
The first malware framework built to speak grid-control protocols directly — used against a Kyiv transmission substation in 2016.
Read profile →TRISIS (TRITON)
The first malware to target a safety instrumented system directly — deployed against Triconex controllers at a Saudi petrochemical plant in 2017.
Read profile →PIPEDREAM
A modular toolkit built to scan, access, and disable PLCs across multiple vendors — discovered and disclosed before it was ever used.
Read profile →AceLauncher
A fake browser productivity tool tied to TamperedChef/EvilAI — from AI-generated landing page to .NET binary teardown.
Read profile →