HomeAtlasDashboardChartsReal valueResearchPersonsCatalogsBlockchainBubble MapGlobeQuantumAILeadershipLensesMethodologyGlossarySource ↗
Independent research & opinion. Gradings are automated / LLM-assisted and may contain errors or hallucinations; nothing here is a statement of fact, financial advice, or an accusation of wrongdoing by any party. Claims about identifiable people or organizations reflect public records + good-faith interpretation; intent is not inferred from association. Methodology & disclaimer.

State APT catalog: the major nation-state hacking groups and their sponsors

The first batch of the threat-actor catalog - the principal state-sponsored APT groups, each wired to its sponsoring service, the vendor/government that attributed it, and its signature operations. This is the espionage/sabotage branch of the malware lineage (distinct from criminal ransomware and commercial spyware).

China

Russia

North Korea

Iran

United States

Honest limits

Attribution is probabilistic: naming differs per vendor (Fancy Bear = APT28 = Sofacy = Forest Blizzard), and a "group" is a cluster of activity, not a fixed roster. This block records the widely-accepted consensus attributions with their sources (indictments, sanctions, CISA advisories, vendor reports); it does not assert individual identities beyond public indictments, and consolidates aliases to one node each.

Sources: Mandiant APT1 (2013); DOJ indictments (PLA 2014; GRU 2018/2020); CrowdStrike Bear/Panda/Chollima/Kitten taxonomy; CISA advisories (Volt/Salt Typhoon); Kaspersky (Equation 2015); UN Panel of Experts (DPRK); OFAC. Cross-refs: NSA, MSS, PLA, GRU, SVR, China, Russia, North_Korea, Iran, Sandworm, Lazarus_Group, SaltTyphoon, Equation_Group, Power_Grid, TMobile, Malware_Lineage.

← Research index · structured data: spec-state-apt-catalog.json · spec-state-apt-catalog.md