The Gentlemen ➜ Ransomware-as-a-Service (RaaS)
Scattered Spider ➜ Social Engineering & Identity Attacks
ShinyHunters ➜ Data Extortion & Cloud Intrusions
FIN7 ➜ Financial Cybercrime & Enterprise Intrusions
UNC6040 ➜ Cloud Identity & Voice Phishing (Vishing)
Lazarus Group ➜ Nation-State Cyber Operations & Financial Theft
Volt Typhoon ➜ Critical Infrastructure & Living-off-the-Land
TraderTraitor ➜ Cryptocurrency Theft & Supply Chain Attacks
Luna Moth ➜ Callback Phishing & Data Extortion
| Reconnaissance — TA0043 | ➜ Find information about the target. |
| Resource Development — TA0042 | ➜ Prepare infrastructure, malware, accounts, or credentials. |
| Initial Access — TA0001 | ➜ Get into the victim's system. |
| Execution — TA0002 | ➜ Run malicious code or commands. |
| Persistence — TA0003 | ➜ Stay in the system after gaining access. |
| Privilege Escalation — TA0004 | ➜ Gain higher-level permissions. |
| Defense Evasion — TA0005 | ➜ Hide activity and avoid detection. |
| Credential Access — TA0006 | ➜ Steal passwords, tokens, or other credentials. |
| Discovery — TA0007 | ➜ Find systems, users, networks, and valuable data. |
| Lateral Movement — TA0008 | ➜ Move from one compromised system to another. |
| Command and Control — TA0011 | ➜ Communicate with attacker-controlled infrastructure. |
| Collection — TA0009 | ➜ Gather valuable information from the victim. |
| Exfiltration — TA0010 | ➜ Move stolen data outside the victim's network. |
| Impact — TA0040 | ➜ Disrupt, destroy, encrypt, or expose systems and data. |

