Structured threat intelligence

Threat actor intelligence,
structured for research.

A curated collection of deeply sourced threat-actor dossiers and their related campaigns, malware, targeting and attribution.

APT NOTES · BY HECAVEX · 76 PUBLIC REFERENCES

20Actors
68Aliases
35Campaigns
23Software
32Techniques
59Relationships

Coverage: selected deep profiles, not an exhaustive actor directory. Actor dossiers are the editorial product; Knowledge records support them, and only procedure-backed links enter Relationships. Review the methodology and publication boundaries.

Recently reviewed profiles

All actors →

Black Basta

A ransomware-as-a-service operation active since 2022 that affected more than 500 organisations across North America, Europe and Australia by May 2024.

OriginEastern Europe
Statusuncertain
Confidencehigh
Reviewed27 Aug 2026

CL0P

A financially motivated extortion and ransomware brand associated with repeated mass exploitation of managed file-transfer and enterprise applications affecting organisations across Europe and beyond.

OriginEastern Europe
Statusactive
Confidencehigh
Reviewed27 Aug 2026

Evil Corp

A Russian financially motivated cybercriminal organisation linked by UK and US authorities to Dridex-enabled theft, ransomware operations and extensive harm in the United Kingdom and Europe.

OriginRussia
Statusintermittently-active
Confidencehigh
Reviewed27 Aug 2026

UAC-0010 / Gamaredon

A Russian state-sponsored espionage actor associated with FSB Centre 18 and sustained, high-volume targeting of Ukrainian government and defence organisations.

OriginRussia
Statusactive
Confidencehigh
Reviewed27 Aug 2026

LockBit

A ransomware-as-a-service ecosystem whose administrators supplied malware and infrastructure to affiliates responsible for thousands of intrusions, including extensive European targeting.

OriginRussia
Statusdisrupted
Confidencehigh
Reviewed27 Aug 2026

Choose the depth you need

Latest substantive changes

Complete revision record →
  1. Black Basta profile published

    Published the initial dossier, service campaign and remote-access relationship.

  2. CL0P profile published

    Published the initial dossier, campaign, vulnerability record and exploitation relationship.

  3. Evil Corp profile published

    Published the initial dossier, Dridex campaign and spearphishing relationship.

  4. UAC-0010 / Gamaredon profile published

    Published the initial actor dossier, campaign record and one campaign-scoped procedure relationship.

  5. LockBit profile published

    Published the initial service dossier, mass-operation campaign and exploitation relationship.

APT Notes / contextual record