Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Threat-Informed Defense

Browse groups through a defensive analytic lens.

Use activity-cluster profiles to study evidence, naming overlap, behavior relationships, and calibrated attribution.

G0001

Axiom (G0001)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0001, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Chinese espionage cluster reported against aerospace, defense, government, manufacturing, and media sectors.

Open profile →
G0009

Deep Panda (G0009)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0009, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Chinese cluster reported against government, defense, financial, healthcare, and telecommunications targets, with overlap ambiguity in public reporting.

Open profile →
G0012

Darkhotel (G0012)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0012, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected South Korean cluster reported in East Asian espionage operations involving hotel networks, spearphishing, and file-sharing networks.

Open profile →
G0018

admin@338 (G0018)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0018, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a China-based activity cluster reported against organizations involved in financial, economic, and trade policy, often using publicly available remote-access tools.

Open profile →
G0035

Dragonfly (G0035)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0035, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a cyber-espionage cluster attributed to Russia’s FSB Center 16 and reported against industrial-control and critical-infrastructure sectors.

Open profile →
G0047

Gamaredon Group (G0047)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0047, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Russian and FSB-linked cluster reported in persistent operations focused on Ukraine.

Open profile →
G0070

Dark Caracal (G0070)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0070, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an activity cluster attributed in public reporting to the Lebanese General Directorate of General Security and active since at least 2012.

Open profile →
G0079

DarkHydrus (G0079)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0079, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a cluster reported against government agencies and educational institutions in the Middle East using open-source tools and custom payloads.

Open profile →
G0087

APT39 (G0087)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0087, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing Iranian Ministry of Intelligence and Security-linked espionage activity reported across travel, hospitality, academia, and telecommunications.

Open profile →
G0093

GALLIUM (G0093)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0093, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a likely China-based cyber-espionage cluster reported against telecommunications, finance, and government organizations.

Open profile →
G0096

APT41 (G0096)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0096, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a China-sponsored espionage cluster also reported conducting financially motivated operations across many sectors.

Open profile →
G0105

DarkVishnya (G0105)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0105, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a financially motivated cluster reported against financial institutions in Eastern Europe.

Open profile →
G0117

Fox Kitten (G0117)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0117, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Iranian-nexus cluster reported across multiple sectors and regions.

Open profile →
G0125

HAFNIUM (G0125)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0125, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a likely China state-sponsored cluster reported against a broad range of United States sectors.

Open profile →
G0130

Ajax Security Team (G0130)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0130, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an Iran-linked cluster active since at least 2010 that shifted from website defacement toward malware-based espionage.

Open profile →
G0135

BackdoorDiplomacy (G0135)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0135, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an espionage cluster active since at least 2017 and reported against foreign ministries and telecommunications companies.

Open profile →
G0138

Andariel (G0138)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0138, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a North Korean state-sponsored cluster associated with destructive and financially motivated activity, with acknowledged overlap in public naming.

Open profile →
G0143

Aquatic Panda (G0143)

A defensive guide to the Enterprise ATT&CK activity-cluster record G0143, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected China-based cluster with intelligence-collection and industrial-espionage missions against telecommunications, technology, and government entities.

Open profile →
G1000

ALLANITE (G1000)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1000, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Russian espionage cluster reported against electric utilities in the United States and United Kingdom.

Open profile →
G1002

BITTER (G1002)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1002, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected South Asian espionage cluster reported against government, energy, and engineering organizations.

Open profile →
G1007

Aoqin Dragon (G1007)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1007, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected China-based espionage cluster reported against government, education, and telecommunications organizations in Southeast Asia and nearby regions.

Open profile →
G1015

Scattered Spider (G1015)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1015, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an English-speaking cybercriminal cluster reported to rely heavily on social engineering, identity compromise, and cloud access.

Open profile →
G1023

APT5 (G1023)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1023, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a China-based espionage actor reported against telecommunications, aerospace, and defense organizations, including networking devices.

Open profile →
G1027

CyberAv3ngers (G1027)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1027, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Iranian IRGC-affiliated cluster reported in PLC and HMI targeting and device-interface defacement.

Open profile →
G1028

APT-C-23 (G1028)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1028, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a cluster active since at least 2014 with a Middle East focus and reported development of Android and iOS spyware.

Open profile →
G1030

Agrius (G1030)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1030, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an Iranian activity cluster reported in ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.

Open profile →
G1034

Daggerfly (G1034)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1034, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a PRC-linked advanced persistent threat cluster reported against individuals, governments, NGOs, and telecommunications companies.

Open profile →
G1043

BlackByte (G1043)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1043, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a ransomware activity cluster operating since at least 2021 and associated with multiple BlackByte ransomware versions.

Open profile →
G1044

APT42 (G1044)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1044, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an Iranian-sponsored espionage and surveillance cluster reported to use spearphishing, mobile malware, native features, and open-source tools.

Open profile →
G1049

AppleJeus (G1049)

A defensive guide to the Enterprise ATT&CK activity-cluster record G1049, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a DPRK-linked revenue-generating cluster reported against the cryptocurrency sector and associated with the 3CX supply-chain campaign.

Open profile →

Framework metadata remains source-controlled by MITRE.

Bare Metal Cyber profiles add original educational and defensive context. Verify current object status, relationships, and underlying references on the official ATT&CK site before using a profile for operational or attribution decisions.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.