Threat Actors
Unattributed Threat Actors
The operators behind the reports. A UTA is a tracking label this publication assigns to an actor it has observed but cannot yet link to a publicly named group, so that the same operator can be recognised across reports. Each profile summarises what the reports already say and points back to them.
No actors match that filter.
UTA-2026-024
Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
UTA-2026-023
Telecom-focused operator reaching a carrier's credential plane through a customer's managed router
UTA-2026-021
Assembler-model intrusion operator staging other actors' tooling against one German victim forest
UTA-2026-020
Self-branded commodity cryptojacking operator mass-exploiting exposed Chinese enterprise software
UTA-2026-019
Grey-market personal-data harvester running scores of LLM-assisted attack scripts against Chinese consumer platforms
UTA-2026-018
Hands-on-keyboard operator exploiting four Southeast Asian governments with a bespoke edge-device toolkit
UTA-2026-017
GHOST cryptojacker kit customer (operator B) using public mining pools, host abandoned
UTA-2026-016
GHOST cryptojacker kit customer (operator A) with self-hosted mining pool proxies
UTA-2026-015
Operator running Claude Code and OpenClaw side by side, observed at capsule depth only
UTA-2026-014
DDoS-for-hire operator running an AI co-authored C2 framework over a Pandora-Mirai botnet
UTA-2026-013
Espionage-flavoured operator harvesting a state-affiliated insurer's observability stack through an AI agent platform
UTA-2026-012 bandcampro (Trend Micro)
AI-augmented credential-mill operator using an LLM for per-target password mutation
UTA-2026-011
Financially motivated operator weaponising a cPanel authentication bypass with a custom harvesting toolkit
UTA-2026-010
Rhadamanthys MaaS customer with a self-built loader (customer side only, never the vendor)
UTA-2026-009
Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
UTA-2026-008
Developer and operator of the BellaMain Turkish phishing-as-a-service panel
UTA-2026-007
HijackLoader customer running a 15-month multi-vector phishing campaign into an AsyncRAT-class RAT
UTA-2026-006
Stock AdaptixC2 operator with an operator-written PowerShell and .NET injection chain
UTA-2026-005
Chaos ransomware builder user with a private five-stage crypter
UTA-2026-004
Developer of the OpenStrike multi-implant C2 toolkit, with a cracked Cobalt Strike arsenal
UTA-2026-003
Commodity MaaS consumer running Shadow RAT and XWorm from one Windows VPS
UTA-2026-002
XiebroC2 and Covenant operator working from a Chinese-language build environment
UTA-2026-001
Sliver C2 operator with an automated ScareCrow, Donut and SysWhispers3 build pipeline
Designations are numbered in the order they were created and are never reused. A designation whose report is published preview-style is listed once the report goes live. Confidence is the published report's figure for "one trackable operator"; named-actor attribution is INSUFFICIENT for every designation here, which is what the label means.