About aptZoo

aptZoo maps between threat actor names and their aliases. For each actor it shows the other names it's known by, descriptions from several sources, and a list of reference reports. It currently holds 4,297 threat actor names and aliases; the data was last updated 2026-09-26 22:00Z.

How to search

Pick a search type above the search box:

Name / alias
Enter a threat actor name; suggestions appear as you type. Use * as a basic wildcard, e.g. MUSTANG*. Tick Regex pattern for regular expressions, e.g. UNC39\d+ matches UNC3944 and UNC3973. Tick Include Malpedia bibliography to add Malpedia's references for the actor.
Alias lookup
Type a few characters of any name and see every alias, grouped by actor, straight away. Pick one to open it.
Descriptions
Lists threat actors whose description mentions your term, e.g. new zealand.
References
Lists threat actors that have reference reports whose URL contains your term, e.g. silentpush lists actors with Silent Push reports.

Every search has its own link, so you can bookmark results or share them. On a result, click any alias to look it up, and sort or filter the references by date or publisher.

Data sources

Data is merged and scraped from:

See the full list of threat actors and aliases.

Motivation

aptZoo grew out of frustration with the very large number of threat actor names used in cyber threat intelligence reporting - there are well over 3,000 different threat actors and aliases.

There has been much discussion about threat actor naming conventions. It's important to understand that vendors see different data, for example:

Because vendors have different views of threat actor activity, attribution is hard to make precise. aptZoo doesn't aim to be a true Rosetta Stone; it aims to help you understand a threat actor's nature when you come across one in a publication. More features are planned - stay tuned!

Disclaimer

Use at your own risk 😁. For suggestions, bugs, flames etc, contact me and I'll try to help.