[
  {
    "id": "actor-apt28",
    "slug": "apt28",
    "name": "APT28",
    "attack_group_id": "G0007",
    "aliases": [
      "Fancy Bear",
      "Sofacy",
      "Sednit",
      "STRONTIUM",
      "Unit 26165"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "U.S. Department of Justice Indictment (D.D.C.)",
    "case_count": 2,
    "case_slugs": [
      "us-v-netyksho-apt28-dnc",
      "us-v-badin-german-bundestag-apt28"
    ],
    "techniques": [
      "T1566.002",
      "T1059.001",
      "T1583.001",
      "T1071.004",
      "T1546.003",
      "T1566.001"
    ]
  },
  {
    "id": "actor-revil",
    "slug": "revil-sodinokibi",
    "name": "REvil / Sodinokibi",
    "attack_group_id": "G0115",
    "aliases": [
      "Sodinokibi",
      "Gold Southfield"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "U.S. Department of Justice (N.D. Tex.) & Europol Operation GoldDust",
    "case_count": 2,
    "case_slugs": [
      "us-v-vasinskyi-kaseya-revil",
      "us-v-sikerin-polyanin-revil-affiliates"
    ],
    "techniques": [
      "T1190",
      "T1574.002",
      "T1486",
      "T1569.002",
      "T1082"
    ]
  },
  {
    "id": "actor-sandworm",
    "slug": "sandworm-team",
    "name": "Sandworm Team",
    "attack_group_id": "G0034",
    "aliases": [
      "Telebots",
      "Voodoo Bear",
      "Iron Viking",
      "Unit 74455",
      "BlackEnergy Group"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "U.S. Department of Justice Indictment (W.D. Pa.) & CISA",
    "case_count": 1,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer"
    ],
    "techniques": [
      "T1485",
      "T1190",
      "T1021.002",
      "T1003",
      "T1566.001",
      "T1055.012",
      "T1036.005",
      "T1543.003",
      "T1499",
      "T1124"
    ]
  },
  {
    "id": "actor-apt29",
    "slug": "apt29",
    "name": "APT29",
    "attack_group_id": "G0016",
    "aliases": [
      "Cozy Bear",
      "Nobelium",
      "Midnight Blizzard",
      "The Dukes",
      "SVR"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "CISA Advisory AA20-352A & White House Statement",
    "case_count": 1,
    "case_slugs": [
      "solarwinds-orion-supply-chain-compromise"
    ],
    "techniques": [
      "T1190",
      "T1071.001",
      "T1078",
      "T1132",
      "T1036"
    ]
  },
  {
    "id": "actor-lockbit",
    "slug": "lockbit-group",
    "name": "LockBit Ransomware Group",
    "attack_group_id": "G1020",
    "aliases": [
      "LockBit 2.0",
      "LockBit 3.0",
      "LockBit Black",
      "LockBit Green"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "U.S. Department of Justice (D.N.J.) & NCA Operation Cronos",
    "case_count": 1,
    "case_slugs": [
      "lockbit-ransomware-takedown"
    ],
    "techniques": [
      "T1486",
      "T1567",
      "T1490",
      "T1190",
      "T1078",
      "T1047",
      "T1562.001",
      "T1558.003",
      "T1573"
    ]
  },
  {
    "id": "actor-volt-typhoon",
    "slug": "volt-typhoon",
    "name": "Volt Typhoon",
    "attack_group_id": "G1017",
    "aliases": [
      "BRONZE SILHOUETTE",
      "Vanguard Panda",
      "Insidious Taurus"
    ],
    "country_attribution": "People's Republic of China",
    "attribution_source": "CISA, FBI, NSA Joint Cybersecurity Advisory",
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ],
    "techniques": [
      "T1078",
      "T1190",
      "T1584",
      "T1059.003",
      "T1016",
      "T1018",
      "T1033",
      "T1057",
      "T1570"
    ]
  },
  {
    "id": "actor-lazarus-group",
    "slug": "lazarus-group",
    "name": "Lazarus Group",
    "attack_group_id": "G0032",
    "aliases": [
      "HIDDEN COBRA",
      "Guardians of Peace",
      "Zinc",
      "APT38",
      "Labyrinth Chollima"
    ],
    "country_attribution": "Democratic People's Republic of Korea",
    "attribution_source": "U.S. Department of Justice Indictment (C.D. Cal.)",
    "case_count": 1,
    "case_slugs": [
      "us-v-park-jin-hyok-lazarus"
    ],
    "techniques": [
      "T1485",
      "T1486",
      "T1021.002",
      "T1566.002",
      "T1027",
      "T1001.002",
      "T1068"
    ]
  },
  {
    "id": "actor-evil-corp",
    "slug": "evil-corp",
    "name": "Evil Corp",
    "attack_group_id": "G0095",
    "aliases": [
      "Indiktor",
      "Dridex Gang"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "U.S. Department of Justice (W.D. Pa.) & OFAC Sanctions",
    "case_count": 1,
    "case_slugs": [
      "us-v-yakubets-evil-corp-dridex"
    ],
    "techniques": [
      "T1566.001",
      "T1555",
      "T1486",
      "T1055",
      "T1547.001",
      "T1053.005",
      "T1102"
    ]
  },
  {
    "id": "actor-fin7",
    "slug": "fin7",
    "name": "FIN7",
    "attack_group_id": "G0046",
    "aliases": [
      "Carbanak Group",
      "Navigator Group",
      "ELBRUS"
    ],
    "country_attribution": "Transnational / Eastern Europe",
    "attribution_source": "U.S. Department of Justice Indictments (W.D. Wash.)",
    "case_count": 1,
    "case_slugs": [
      "us-v-hladyr-fin7-carbanak"
    ],
    "techniques": [
      "T1566.001",
      "T1059.001",
      "T1041",
      "T1056.001",
      "T1113",
      "T1074.001",
      "T1020"
    ]
  },
  {
    "id": "actor-darkside",
    "slug": "darkside",
    "name": "DarkSide",
    "attack_group_id": "G0128",
    "aliases": [
      "BlackMatter",
      "ALPHV Affiliate"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "CISA Advisory AA21-131A & DOJ Forfeiture Actions",
    "case_count": 1,
    "case_slugs": [
      "colonial-pipeline-ransomware"
    ],
    "techniques": [
      "T1078",
      "T1486",
      "T1041",
      "T1021.001"
    ]
  },
  {
    "id": "actor-alphv",
    "slug": "alphv-blackcat",
    "name": "ALPHV / BlackCat",
    "attack_group_id": "G1014",
    "aliases": [
      "BlackCat",
      "Noberus"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "DOJ Takedown & CISA Joint Advisory AA23-353A",
    "case_count": 1,
    "case_slugs": [
      "alphv-blackcat-change-healthcare"
    ],
    "techniques": [
      "T1078",
      "T1486",
      "T1567",
      "T1041",
      "T1133",
      "T1087"
    ]
  },
  {
    "id": "actor-wizard-spider",
    "slug": "wizard-spider",
    "name": "Wizard Spider",
    "attack_group_id": "G0102",
    "aliases": [
      "Trickbot Group",
      "Conti",
      "UNC1878",
      "Grim Spider"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "U.S. Department of Justice Indictment (N.D. Ohio)",
    "case_count": 1,
    "case_slugs": [
      "us-v-witte-dunaev-trickbot"
    ],
    "techniques": [
      "T1566.001",
      "T1003",
      "T1486"
    ]
  },
  {
    "id": "actor-pla-unit-61398",
    "slug": "pla-unit-61398",
    "name": "PLA Unit 61398",
    "attack_group_id": "G0006",
    "aliases": [
      "APT1",
      "Comment Crew",
      "TG-8223"
    ],
    "country_attribution": "People's Republic of China",
    "attribution_source": "U.S. Department of Justice Indictment (W.D. Pa., May 2014)",
    "case_count": 1,
    "case_slugs": [
      "us-v-sun-kailiang-pla-unit-61398"
    ],
    "techniques": [
      "T1566.001",
      "T1041"
    ]
  },
  {
    "id": "actor-irgc-cyber",
    "slug": "irgc-cyber-electronic-command",
    "name": "IRGC Cyber-Electronic Command",
    "attack_group_id": "G1028",
    "aliases": [
      "CyberAv3ngers",
      "Shahid Shoushtari",
      "Cotton Sandstorm"
    ],
    "country_attribution": "Islamic Republic of Iran",
    "attribution_source": "U.S. Department of Justice (W.D. Pa.) & CISA Advisory AA23-335A",
    "case_count": 1,
    "case_slugs": [
      "us-v-irgc-cyberav3ngers-water"
    ],
    "techniques": [
      "T1078",
      "T1485"
    ]
  },
  {
    "id": "actor-salt-typhoon",
    "slug": "salt-typhoon",
    "name": "Salt Typhoon",
    "attack_group_id": "G1032",
    "aliases": [
      "GhostEmperor",
      "FamousSparrow"
    ],
    "country_attribution": "People's Republic of China",
    "attribution_source": "CISA & FBI Joint Statement on Telecommunications Infiltration",
    "case_count": 0,
    "case_slugs": [],
    "techniques": []
  },
  {
    "id": "actor-cl0p",
    "slug": "cl0p",
    "name": "CL0P",
    "attack_group_id": "G0088",
    "aliases": [
      "TA505",
      "FIN11",
      "Lace Tempest"
    ],
    "country_attribution": "Russian Federation",
    "attribution_source": "CISA Advisory AA23-158A (MOVEit Campaign)",
    "case_count": 0,
    "case_slugs": [],
    "techniques": []
  }
]