About aptZoo
aptZoo maps between threat actor names and their aliases. For each actor it shows the other names it's known by, descriptions from several sources, and a list of reference reports. It currently holds 4,297 threat actor names and aliases; the data was last updated 2026-09-26 22:00Z.
How to search
Pick a search type above the search box:
- Name / alias
-
Enter a threat actor name; suggestions appear as you type. Use
*as a basic wildcard, e.g.MUSTANG*. Tick Regex pattern for regular expressions, e.g.UNC39\d+matches UNC3944 and UNC3973. Tick Include Malpedia bibliography to add Malpedia's references for the actor. - Alias lookup
- Type a few characters of any name and see every alias, grouped by actor, straight away. Pick one to open it.
- Descriptions
- Lists threat actors whose description mentions your term, e.g. new zealand.
- References
- Lists threat actors that have reference reports whose URL contains your term, e.g. silentpush lists actors with Silent Push reports.
Every search has its own link, so you can bookmark results or share them. On a result, click any alias to look it up, and sort or filter the references by date or publisher.
Data sources
Data is merged and scraped from:
- ETDA (Thai Electronic Transactions Development Agency) - Threat Group Cards
- Malpedia
- Microsoft MSTIC - Threat Actor Naming
- MISP - Ransomware Galaxy and Threat Actor Galaxy
- MITRE ATT&CK - Groups
- Palo Alto Networks Unit 42 - Groups
- RANSOMWARE.LIVE - ransomware monitoring site
- Wiz - Threat Actors
- Thrunter.org - Threat Actor Naming
See the full list of threat actors and aliases.
Motivation
aptZoo grew out of frustration with the very large number of threat actor names used in cyber threat intelligence reporting - there are well over 3,000 different threat actors and aliases.
There has been much discussion about threat actor naming conventions. It's important to understand that vendors see different data, for example:
- EDR providers like CrowdStrike see telemetry from their mainly enterprise customers.
- Antivirus providers like Avast see malware detections from home users.
- Microsoft sees both consumer and enterprise activity, plus operating system diagnostics.
- Google gains insight from its SaaS services, its web browser and its services arm, Mandiant.
Because vendors have different views of threat actor activity, attribution is hard to make precise. aptZoo doesn't aim to be a true Rosetta Stone; it aims to help you understand a threat actor's nature when you come across one in a publication. More features are planned - stay tuned!
Disclaimer
Use at your own risk 😁. For suggestions, bugs, flames etc, contact me and I'll try to help.