Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| 2023 State of The Threat – A Year in Reviewreport | Related to | Cl0pactor | — | ORKL | 2023-09-29 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2023-09-29 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2024-02-15 |
| TLP-CLEAR-From-espionage-to-PsyOps-Tracking-operations-and-infrastructure-of-UACs-in-2025-EN-1.pdfreport | Related to | RansomHubactor | — | ORKL | 2025-03-28 |
| Chinese APT: A Master of Exploiting Edge Devicesreport | Related to | Cleaveractor | — | ORKL | 2024-04-12 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Nemesis Kittenactor | — | ORKL | 2024-02-08 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | HEXANE (Lyceum)actor | — | ORKL | 2024-02-08 |
| Mandiant M-Trends 2025 Reportreport | Related to | MuddyWateractor | — | ORKL | 2025-04-24 |
| Mandiant M-Trends 2025 Reportreport | Related to | UNC1860actor | — | ORKL | 2025-04-24 |
| Kinsing Demystified A Comprehensive Technical Guidereport | Related to | Cleaveractor | — | ORKL | 2024-05-03 |
| Arid Viper poisons Android apps with AridSpyreport | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2024-07-25 |
| eset-apt-activity-report-q4-2025-q1-2026.pdfreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2026-05-22 |
| rapid7-threat-landscape-report-2026.pdfreport | Related to | RansomHubactor | — | ORKL | 2026-03-17 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-02-08 |
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | CyberAv3ngersactor | — | ORKL | 2026-03-25 |
| eset-apt-activity-report-q4-2025-q1-2026.pdfreport | Related to | MuddyWateractor | — | ORKL | 2026-05-22 |
| ESET APT Activity Report Q4 2024-Q1 2025report | Related to | HEXANE (Lyceum)actor | — | ORKL | 2025-05-12 |
| Iranian Cyber Actors May Target Vulnerable US Networks and Entities of Interestreport | Related to | CyberAv3ngersactor | — | ORKL | 2025-06-27 |
| Mandiant M-Trends 2025 Reportreport | Related to | Cyber Toufan (Al-Aqsa)actor | — | ORKL | 2025-04-24 |
| ShadowSyndicate infrastructure illuminationreport | Related to | RansomHubactor | — | ORKL | 2025-08-01 |
| From Albania To The Middle East: The Scarred Manticore Is Listeningreport | Related to | Scarred Manticore (Storm-0861)actor | — | ORKL | 2023-12-12 |
| Operation 99 North Korean State Sponsored Supply Chain Attack on Tech Innovationreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-01-14 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-02-15 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Anonymous Sudanactor | — | ORKL | 2023-09-29 |
| Down the Grayrabbit Hole – Exposing UNC3569 and its Modus Operandireport | Related to | Cleaveractor | — | ORKL | 2024-09-24 |
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | UNC1549 / TA455actor | — | ORKL | 2026-03-25 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | SideWinderactor | — | ORKL | 2024-02-15 |
| Botnet Command and Control Infrastructure Report January to June 2024report | Related to | Cleaveractor | — | ORKL | 2024-07-08 |
| 100DaysofYARA - SpectralBlur | A Clever Blog Name by Greg Lesnewichreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-06-26 |
| Untitledreport | Related to | RansomHubactor | — | ORKL | 2025-08-28 |
| ESET APT Activity Report Q2 2024-Q3 2024report | Related to | BladedFelineactor | — | ORKL | 2024-11-07 |
| Mandiant M-Trends 2025 Reportreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2025-04-24 |
| eset-apt-activity-report-q2-2025-q3-2025.pdfreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-10-30 |
| Threat Horizons Reportreport | Related to | Cl0pactor | — | ORKL | 2023-07-26 |
| From Albania To The Middle East: The Scarred Manticore Is Listeningreport | Related to | OilRig (APT34)actor | — | ORKL | 2023-12-12 |
| New BugSleep Backdoor Deployed in Recent MuddyWater Campaigns - Check Point Researchreport | Related to | MuddyWateractor | — | ORKL | 2024-07-25 |
| RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scalereport | Related to | UNC215actor | — | ORKL | 2023-08-07 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | Cleaveractor | — | ORKL | 2025-06-24 |
| How North Korea-Backed Lazarus Group Is Weaponizing Open Source to Target Developersreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-07-29 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | DragonForceactor | — | ORKL | 2025-06-24 |
| ESET APT Activity Report Q4 2024-Q1 2025report | Related to | BladedFelineactor | — | ORKL | 2025-05-12 |
| 2023 Adversary Infrastructure Reportreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-01-08 |
| Iran steps into US election 2024 with cyber-enabled influence operationsreport | Related to | Fox Kittenactor | — | ORKL | 2024-08-06 |
| Botnet Command and Control Infrastructure Report Q4 2023report | Related to | Cleaveractor | — | ORKL | 2024-01-11 |
| New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implantsreport | Related to | MuddyWateractor | — | ORKL | 2024-01-16 |
| eset-apt-activity-report-q2-2025-q3-2025.pdfreport | Related to | UNC1549 / TA455actor | — | ORKL | 2025-10-30 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | ALPHV / BlackCatactor | — | ORKL | 2024-02-15 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Emennet Pasargadactor | — | ORKL | 2023-09-29 |
| Botnet Command & Control Infrastructure Report Q2 2023report | Related to | Cleaveractor | — | ORKL | 2023-07-12 |
| 2023 Adversary Infrastructure Reportreport | Related to | MuddyWateractor | — | ORKL | 2024-01-08 |