Skip to main content
FrameworkMapper

Threat Library

The Attackers Behind Your Score

Compliance frameworks tell you which controls to implement. The threat library tells you who is actually attacking organizations like yours — and which of your controls move the needle against them.

How It Works

Three Inputs, One Threat-Informed Score

Your Attack Surface Coverage Score (ASCS) combines real attacker behaviors with your sector's specific risk profile and your assessment results.

1

Real attacker behaviors

The MITRE ATT&CK® technique catalog (~700 techniques) is the structured record of how real adversaries break in, move laterally, and achieve their objectives. Every threat actor we track is mapped to the specific ATT&CK techniques they use.

2

Your sector's risk profile

Some techniques target K-12 schools heavily, others target water utilities, others target SaaS providers. Per-sector amplifiers from CISA advisories, MS-ISAC reporting, and the Verizon DBIR weight techniques by how likely they actually are to be used against your kind of organization.

3

Your control implementation

Your framework assessment tells us how well each control is actually in place. Map each control to the techniques it defends against, weight by sector exposure, and the result is a single 0–100 score that means something — and a per-phase breakdown showing where to invest next.

34 Profiles

Threat Actor Library

Every actor below is sourced from a CISA advisory or recognized CERT/threat-intel report. Each carries the specific ATT&CK techniques observed in their operations, weighted by how often they appear in incident response data.

Ransomware Operators
20 profiles · incl. disrupted & retired

Akira

Ransomware

Active since March 2023. Hits SLTT, K-12, manufacturing. Heavy use of VPN appliance vulnerabilities for initial access; double-extortion.

CISA AA24-109A

BianLian

Ransomware

Active since mid-2022. Pivoted to exfiltration-only extortion after Avast released a decryptor. Critical infrastructure, healthcare, professional services.

CISA AA23-136A

Black Basta

Ransomware

Active since April 2022. Targets SLTT, K-12, healthcare, manufacturing. Initial access often from Qakbot/Pikabot brokers; double-extortion.

CISA AA24-131A

Cl0p

Ransomware

Active since 2019. Mass exfiltration via zero-day exploitation of file-transfer software (MOVEit, GoAnywhere). Often skips encryption — exfil-only extortion.

CISA AA23-158A

LockBit

Ransomware

Most prolific ransomware operation from 2022 through early 2024. Disrupted by Operation Cronos in February 2024 but affiliates continued under variant brands.

CISA AA23-165A / AA24-060A

Medusa

Ransomware

Active since June 2021. Significantly increased K-12 and local-government targeting in 2023-2024. Known for live-streamed extortion presentations.

CISA AA25-071A

Play

Ransomware

Active since June 2022. Targets SLTT, SMB, critical infrastructure. Custom tooling, intermittent encryption to evade detection, double-extortion.

CISA AA23-352A

RansomHub

Ransomware

RaaS launched February 2024. Rapidly became one of the most active groups following ALPHV/BlackCat and Cl0p disruptions. Broad sector targeting.

CISA AA24-242A

Rhysida

Ransomware

Active since May 2023. Heavy K-12 and healthcare focus. Known for opportunistic targeting via external-facing services and phishing.

CISA AA23-319A

Royal / BlackSuit

Ransomware

Conti splinter active since September 2022, rebranded to BlackSuit in mid-2023. Heavy K-12 (LAUSD 2022), healthcare, SLTT targeting.

CISA AA23-061A / AA24-181A

Scattered Spider

Social Engineering

English-speaking crew specializing in SIM swap, helpdesk impersonation, and MFA-fatigue prompts. High-profile victims include MGM Resorts and Caesars (2023).

CISA AA23-320A

Qilin (Agenda)

Ransomware

Ransomware-as-a-service (formerly Agenda), active since 2022. Behind the June 2024 Synnovis attack that disrupted multiple London NHS hospitals. Heavy healthcare and manufacturing targeting via affiliates.

MITRE ATT&CK — Qilin / Agenda

Phobos

Ransomware

Long-running RaaS active since 2019, frequently deployed against SLTT, K-12, small business, and healthcare. Primary access is brute-forced or phished RDP.

CISA AA24-060A

Hunters International

Ransomware

RaaS that emerged in late 2023 reusing code lineage associated with Hive. Double-extortion targeting healthcare and mid-market organizations across sectors.

MITRE ATT&CK; public CERT reporting

INC Ransom / Lynx

Ransomware

Double-extortion operation active since mid-2023 hitting healthcare, education, and government. The Lynx family is widely assessed as a successor using shared code.

MITRE ATT&CK; public CERT reporting

Cactus

Ransomware

Active since early 2023; known for exploiting VPN and remote-access appliance vulnerabilities and encrypting its own binary to evade detection. Mid-market and enterprise targeting.

MITRE ATT&CK; public CERT reporting

Vice Society

Dormant

Active 2021-2023, especially heavy K-12 / Higher Ed targeting. Currently dormant; included for historical reference and because TTPs propagate to other groups.

CISA AA22-249A

ALPHV / BlackCat

Disrupted

Prolific Rust-based RaaS (2021-2024) behind the February 2024 Change Healthcare breach. Conducted an apparent exit scam in March 2024; affiliates dispersed to other brands.

CISA AA23-353A

Hive

Disrupted

RaaS active 2021 to early 2023 with heavy healthcare and education targeting. FBI infiltrated and disrupted the operation in January 2023; its codebase influenced later strains.

CISA AA22-321A

Conti

Retired

Highly organized syndicate (2020-2022) in the Wizard Spider ecosystem. Large-scale double-extortion against healthcare and government; its members and code seeded Black Basta, Royal, and BlackSuit.

CISA AA21-265A

Nation-State APTs
10 profiles

APT29 / Midnight Blizzard

Russia SVR

Long-running cyber-espionage. SolarWinds supply-chain attack (2020, ~18,000 affected organizations including SLTT and federal). 2024 OAuth-token theft against Microsoft corporate email.

CISA AA20-352A

APT38 / Lazarus

DPRK

Dual-purpose: revenue-generating cyber-financial crime (cryptocurrency-exchange theft totalling billions) and espionage. 3CX supply-chain compromise (2023) cascaded across thousands of orgs.

CISA AA22-187A / AA20-239A

CyberAv3ngers

Iran IRGC

Attacked the Aliquippa, PA water authority in November 2023 by defacing an internet-exposed Unitronics PLC. Opportunistic ICS attacks against US SLTT water/wastewater systems.

CISA AA23-335A

Salt Typhoon

PRC

Conducted a mass 2024 breach of US telecommunications providers (Verizon, AT&T, T-Mobile, Lumen). Accessed CALEA lawful-intercept systems and metadata of senior officials.

CISA/FBI/NSA Joint Guidance (2024-12)

Sandworm

Russia GRU

The most persistent and destructive state-sponsored actor on record. 2015 / 2016 Ukraine electric-grid attacks, NotPetya (2017, ~$10B in global damages), Olympic Destroyer.

CISA AA22-110A

Volt Typhoon

PRC

Pre-positioning operations against US critical infrastructure — communications, energy, transportation, water. Heavy use of living-off-the-land binaries and compromised SOHO routers.

CISA AA24-038A

APT28 / Fancy Bear

Russia GRU

Russian military-intelligence (GRU) espionage group active since the mid-2000s. Targets government, defense, political organizations, and research via spearphishing and credential harvesting. Also tracked as Fancy Bear and Forest Blizzard.

MITRE ATT&CK G0007; NSA/FBI Drovorub (2020)

Kimsuky

DPRK

North Korean espionage group active since 2012 targeting think tanks, universities, research institutions, NGOs, and government. Relies on tailored spearphishing and credential theft. Also tracked as APT43 / Emerald Sleet.

CISA AA20-301A

Andariel

DPRK

North Korean group in the Lazarus ecosystem conducting espionage against defense, aerospace, nuclear, and healthcare research — increasingly funding operations with ransomware. Also tracked as Onyx Sleet / APT45.

CISA AA24-207A

APT41 / Double Dragon

PRC

Chinese state-linked group blending espionage with financially motivated intrusion. Exploits public-facing applications at scale; victims span healthcare, government (including US state networks), telecom, and manufacturing. Also tracked as Winnti / Brass Typhoon.

MITRE ATT&CK G0096; US DOJ indictments (2020)

Insider Archetypes
4 profiles

Insider threats account for a substantial share of incidents reported in the Verizon DBIR. These are pattern archetypes rather than named groups — sourced from the CERT Insider Threat Center's incident corpus.

Departing Employee with Privileged Access

Insider

Employee leaving the organization who retains active credentials during the offboarding window. Common pattern: bulk download of customer lists, source code, or design documents in the final two weeks.

Compromised Third-Party Contractor

Insider

External adversary using legitimate vendor, contractor, or MSP credentials. Disproportionately affects K-12, SMB, and nonprofits that rely on managed services with persistent vendor access.

Disgruntled Current Employee

Insider

Current employee acting maliciously while still holding active credentials. Motivations: retaliation, sabotage, theft of trade secrets prior to a move to a competitor. Slower-paced and harder to detect than the departing case.

Inadvertent / Negligent Insider

Insider

Current employee or volunteer who causes data exposure unintentionally — clicking phishing, losing a device, misconfiguring a cloud share, mis-addressing email. Accounts for a substantial share of Verizon DBIR's "Miscellaneous Errors" pattern.

The 7 Phases

The Lockheed Martin Cyber Kill Chain®

Sophisticated attacks unfold in stages. Defending well at any one stage can derail the whole attack — which is why coverage is reported per-phase in your assessment.

1
Reconnaissance
Passive and active research about your organization, employees, and public systems.
2
Weaponization
Building the attack tool. Happens on the attacker side, so defensive frameworks rarely cover it directly.
3
Delivery
Getting the malicious payload to you — phishing email, drive-by download, USB drop, or supply-chain compromise.
4
Exploitation
The initial compromise — triggering a vulnerability or convincing a user to run something they should not.
5
Installation
Establishing a foothold — implants, persistence mechanisms, scheduled tasks, or new accounts.
6
Command & Control
Remote operation — the attacker steering the foothold from outside your network.
7
Actions on Objectives
What the attacker came to do — data theft, ransomware deployment, lateral movement, or financial fraud.

Where the Data Comes From

Sourced from Authoritative Threat Intelligence

Every threat actor profile, technique mapping, and sector amplifier in FrameworkMapper is sourced from named, public, and reviewable references. We do not invent threat data.

CISA Advisories
#StopRansomware joint advisories from CISA, FBI, NSA, and international partners
MITRE ATT&CK
The structured catalog of adversary tactics and techniques (~700 entries)
MITRE CTID
Center for Threat-Informed Defense control-framework mappings (NIST 800-53 & more)
MS-ISAC
SLTT-focused threat reporting and the K12 SIX program
Verizon DBIR
Annual Data Breach Investigations Report — sector-by-sector incident patterns
CERT/CC
Carnegie Mellon's Insider Threat Center incident corpus and pattern archetypes

See How You Stand Up

Explore your industry's exposure in the Threat-Gap Visualizer — free to explore, with the threat-actor filter available on subscription accounts — or run a full framework assessment to get a Threat-Informed Executive Report tailored to your environment.