Threat Library
The Attackers Behind Your Score
Compliance frameworks tell you which controls to implement. The threat library tells you who is actually attacking organizations like yours — and which of your controls move the needle against them.
How It Works
Three Inputs, One Threat-Informed Score
Your Attack Surface Coverage Score (ASCS) combines real attacker behaviors with your sector's specific risk profile and your assessment results.
Real attacker behaviors
The MITRE ATT&CK® technique catalog (~700 techniques) is the structured record of how real adversaries break in, move laterally, and achieve their objectives. Every threat actor we track is mapped to the specific ATT&CK techniques they use.
Your sector's risk profile
Some techniques target K-12 schools heavily, others target water utilities, others target SaaS providers. Per-sector amplifiers from CISA advisories, MS-ISAC reporting, and the Verizon DBIR weight techniques by how likely they actually are to be used against your kind of organization.
Your control implementation
Your framework assessment tells us how well each control is actually in place. Map each control to the techniques it defends against, weight by sector exposure, and the result is a single 0–100 score that means something — and a per-phase breakdown showing where to invest next.
34 Profiles
Threat Actor Library
Every actor below is sourced from a CISA advisory or recognized CERT/threat-intel report. Each carries the specific ATT&CK techniques observed in their operations, weighted by how often they appear in incident response data.
Akira
RansomwareActive since March 2023. Hits SLTT, K-12, manufacturing. Heavy use of VPN appliance vulnerabilities for initial access; double-extortion.
CISA AA24-109A
BianLian
RansomwareActive since mid-2022. Pivoted to exfiltration-only extortion after Avast released a decryptor. Critical infrastructure, healthcare, professional services.
CISA AA23-136A
Black Basta
RansomwareActive since April 2022. Targets SLTT, K-12, healthcare, manufacturing. Initial access often from Qakbot/Pikabot brokers; double-extortion.
CISA AA24-131A
Cl0p
RansomwareActive since 2019. Mass exfiltration via zero-day exploitation of file-transfer software (MOVEit, GoAnywhere). Often skips encryption — exfil-only extortion.
CISA AA23-158A
LockBit
RansomwareMost prolific ransomware operation from 2022 through early 2024. Disrupted by Operation Cronos in February 2024 but affiliates continued under variant brands.
CISA AA23-165A / AA24-060A
Medusa
RansomwareActive since June 2021. Significantly increased K-12 and local-government targeting in 2023-2024. Known for live-streamed extortion presentations.
CISA AA25-071A
Play
RansomwareActive since June 2022. Targets SLTT, SMB, critical infrastructure. Custom tooling, intermittent encryption to evade detection, double-extortion.
CISA AA23-352A
RansomHub
RansomwareRaaS launched February 2024. Rapidly became one of the most active groups following ALPHV/BlackCat and Cl0p disruptions. Broad sector targeting.
CISA AA24-242A
Rhysida
RansomwareActive since May 2023. Heavy K-12 and healthcare focus. Known for opportunistic targeting via external-facing services and phishing.
CISA AA23-319A
Royal / BlackSuit
RansomwareConti splinter active since September 2022, rebranded to BlackSuit in mid-2023. Heavy K-12 (LAUSD 2022), healthcare, SLTT targeting.
CISA AA23-061A / AA24-181A
Scattered Spider
Social EngineeringEnglish-speaking crew specializing in SIM swap, helpdesk impersonation, and MFA-fatigue prompts. High-profile victims include MGM Resorts and Caesars (2023).
CISA AA23-320A
Qilin (Agenda)
RansomwareRansomware-as-a-service (formerly Agenda), active since 2022. Behind the June 2024 Synnovis attack that disrupted multiple London NHS hospitals. Heavy healthcare and manufacturing targeting via affiliates.
MITRE ATT&CK — Qilin / Agenda
Phobos
RansomwareLong-running RaaS active since 2019, frequently deployed against SLTT, K-12, small business, and healthcare. Primary access is brute-forced or phished RDP.
CISA AA24-060A
Hunters International
RansomwareRaaS that emerged in late 2023 reusing code lineage associated with Hive. Double-extortion targeting healthcare and mid-market organizations across sectors.
MITRE ATT&CK; public CERT reporting
INC Ransom / Lynx
RansomwareDouble-extortion operation active since mid-2023 hitting healthcare, education, and government. The Lynx family is widely assessed as a successor using shared code.
MITRE ATT&CK; public CERT reporting
Cactus
RansomwareActive since early 2023; known for exploiting VPN and remote-access appliance vulnerabilities and encrypting its own binary to evade detection. Mid-market and enterprise targeting.
MITRE ATT&CK; public CERT reporting
Vice Society
DormantActive 2021-2023, especially heavy K-12 / Higher Ed targeting. Currently dormant; included for historical reference and because TTPs propagate to other groups.
CISA AA22-249A
ALPHV / BlackCat
DisruptedProlific Rust-based RaaS (2021-2024) behind the February 2024 Change Healthcare breach. Conducted an apparent exit scam in March 2024; affiliates dispersed to other brands.
CISA AA23-353A
Hive
DisruptedRaaS active 2021 to early 2023 with heavy healthcare and education targeting. FBI infiltrated and disrupted the operation in January 2023; its codebase influenced later strains.
CISA AA22-321A
Conti
RetiredHighly organized syndicate (2020-2022) in the Wizard Spider ecosystem. Large-scale double-extortion against healthcare and government; its members and code seeded Black Basta, Royal, and BlackSuit.
CISA AA21-265A
APT29 / Midnight Blizzard
Russia SVRLong-running cyber-espionage. SolarWinds supply-chain attack (2020, ~18,000 affected organizations including SLTT and federal). 2024 OAuth-token theft against Microsoft corporate email.
CISA AA20-352A
APT38 / Lazarus
DPRKDual-purpose: revenue-generating cyber-financial crime (cryptocurrency-exchange theft totalling billions) and espionage. 3CX supply-chain compromise (2023) cascaded across thousands of orgs.
CISA AA22-187A / AA20-239A
CyberAv3ngers
Iran IRGCAttacked the Aliquippa, PA water authority in November 2023 by defacing an internet-exposed Unitronics PLC. Opportunistic ICS attacks against US SLTT water/wastewater systems.
CISA AA23-335A
Salt Typhoon
PRCConducted a mass 2024 breach of US telecommunications providers (Verizon, AT&T, T-Mobile, Lumen). Accessed CALEA lawful-intercept systems and metadata of senior officials.
CISA/FBI/NSA Joint Guidance (2024-12)
Sandworm
Russia GRUThe most persistent and destructive state-sponsored actor on record. 2015 / 2016 Ukraine electric-grid attacks, NotPetya (2017, ~$10B in global damages), Olympic Destroyer.
CISA AA22-110A
Volt Typhoon
PRCPre-positioning operations against US critical infrastructure — communications, energy, transportation, water. Heavy use of living-off-the-land binaries and compromised SOHO routers.
CISA AA24-038A
APT28 / Fancy Bear
Russia GRURussian military-intelligence (GRU) espionage group active since the mid-2000s. Targets government, defense, political organizations, and research via spearphishing and credential harvesting. Also tracked as Fancy Bear and Forest Blizzard.
MITRE ATT&CK G0007; NSA/FBI Drovorub (2020)
Kimsuky
DPRKNorth Korean espionage group active since 2012 targeting think tanks, universities, research institutions, NGOs, and government. Relies on tailored spearphishing and credential theft. Also tracked as APT43 / Emerald Sleet.
CISA AA20-301A
Andariel
DPRKNorth Korean group in the Lazarus ecosystem conducting espionage against defense, aerospace, nuclear, and healthcare research — increasingly funding operations with ransomware. Also tracked as Onyx Sleet / APT45.
CISA AA24-207A
APT41 / Double Dragon
PRCChinese state-linked group blending espionage with financially motivated intrusion. Exploits public-facing applications at scale; victims span healthcare, government (including US state networks), telecom, and manufacturing. Also tracked as Winnti / Brass Typhoon.
MITRE ATT&CK G0096; US DOJ indictments (2020)
Insider threats account for a substantial share of incidents reported in the Verizon DBIR. These are pattern archetypes rather than named groups — sourced from the CERT Insider Threat Center's incident corpus.
Departing Employee with Privileged Access
InsiderEmployee leaving the organization who retains active credentials during the offboarding window. Common pattern: bulk download of customer lists, source code, or design documents in the final two weeks.
Compromised Third-Party Contractor
InsiderExternal adversary using legitimate vendor, contractor, or MSP credentials. Disproportionately affects K-12, SMB, and nonprofits that rely on managed services with persistent vendor access.
Disgruntled Current Employee
InsiderCurrent employee acting maliciously while still holding active credentials. Motivations: retaliation, sabotage, theft of trade secrets prior to a move to a competitor. Slower-paced and harder to detect than the departing case.
Inadvertent / Negligent Insider
InsiderCurrent employee or volunteer who causes data exposure unintentionally — clicking phishing, losing a device, misconfiguring a cloud share, mis-addressing email. Accounts for a substantial share of Verizon DBIR's "Miscellaneous Errors" pattern.
The 7 Phases
The Lockheed Martin Cyber Kill Chain®
Sophisticated attacks unfold in stages. Defending well at any one stage can derail the whole attack — which is why coverage is reported per-phase in your assessment.
Where the Data Comes From
Sourced from Authoritative Threat Intelligence
Every threat actor profile, technique mapping, and sector amplifier in FrameworkMapper is sourced from named, public, and reviewable references. We do not invent threat data.
See How You Stand Up
Explore your industry's exposure in the Threat-Gap Visualizer — free to explore, with the threat-actor filter available on subscription accounts — or run a full framework assessment to get a Threat-Informed Executive Report tailored to your environment.