Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2026-03-25 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Sea Turtleactor | — | ORKL | 2024-02-15 |
| 2023-05-23 - Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350report | Related to | MuddyWateractor | — | ORKL | 2023-06-04 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Handalaactor | — | ORKL | 2024-02-08 |
| Operation Marstech Mayhem Lazarus Group's Open-Source Trap: North Korea's New Malware Tactic Targeting Developers and Crypto Walletsreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-02-10 |
| Smoking Out an Affiliatereport | Related to | RansomHubactor | — | ORKL | 2026-04-13 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2023-09-29 |
| Iranian "Dream Job" campaignreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-11-12 |
| 日本を狙うサイバーエスピオナージ(標的型攻撃)の動向2023年度report | Related to | Tropic Trooperactor | — | ORKL | 2024-06-28 |
| Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africareport | Related to | MuddyWateractor | — | ORKL | 2023-12-20 |
| 2025_IC3Report.pdfreport | Related to | Sinobiactor | — | ORKL | 2026-04-16 |
| Staying ahead of threat actors in the age of AIreport | Related to | UNC1549 / TA455actor | — | ORKL | 2024-02-20 |
| ShadowSyndicate infrastructure illuminationreport | Related to | Cl0pactor | — | ORKL | 2025-08-01 |
| Iran steps into US election 2024 with cyber-enabled influence operationsreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-08-06 |
| 2025 THREAT DETECTION REPORTreport | Related to | RansomHubactor | — | ORKL | 2025-03-12 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | MuddyWateractor | — | ORKL | 2024-05-13 |
| eset-apt-activity-report-q2-2025-q3-2025.pdfreport | Related to | BladedFelineactor | — | ORKL | 2025-10-30 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Nemesis Kittenactor | — | ORKL | 2023-09-29 |
| Smoking Out an Affiliatereport | Related to | Qilin (fka Agenda)actor | — | ORKL | 2026-04-13 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Agrius (Agonizing Serpens / BlackShadow)actor | — | ORKL | 2024-05-13 |
| THE MASK HAS BEEN UNMASKED AGAINreport | Related to | MuddyWateractor | — | ORKL | 2024-09-24 |
| Dark Pink APT unleashes malware for deeper and more sinister intrusions in the Asia-Pacific and Europereport | Related to | Cleaveractor | — | ORKL | 2024-01-12 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Poloniumactor | — | ORKL | 2024-02-08 |
| New Zero-Day Vulnerability Detected: CVE-2024-43451report | Related to | Handalaactor | — | ORKL | 2024-11-13 |
| 2025_IC3Report.pdfreport | Related to | RansomHubactor | — | ORKL | 2026-04-16 |
| RALord: Novo grupo de Ransomware-as-a-Servicereport | Related to | FunkSecactor | — | ORKL | 2025-04-01 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2025-06-24 |
| Iranian "Dream Job" campaignreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-11-12 |
| 2023-05-30 - Void Rabisu’s Use of RomCom Backdoor Shows a Growing Shift in Threat Actors’ Goalsreport | Related to | Killnetactor | — | ORKL | 2023-06-04 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | BladedFelineactor | — | ORKL | 2024-05-13 |
| Investigating Iranian Intrusion into Strategic Middle East Critical Infrastructurereport | Related to | UNC1549 / TA455actor | — | ORKL | 2025-03-07 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-06-24 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-09-29 |
| CROWDSTRIKE 2023 THREAT HUNTING REPORTreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-08-07 |
| ShadowSyndicate infrastructure illuminationreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2025-08-01 |
| Microsoft Word - JCSA-20241030-001report | Related to | Emennet Pasargadactor | — | ORKL | 2024-10-30 |
| Mandiant M-Trends 2025 Reportreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2025-04-24 |
| M-Trends 2024 Special Reportreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-04-22 |
| New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implantsreport | Related to | Volatile Cedaractor | — | ORKL | 2024-01-16 |
| THE MASK HAS BEEN UNMASKED AGAINreport | Related to | Careto / Maskactor | — | ORKL | 2024-09-24 |
| Lazarus supply-chain attack in South Koreareport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-01-04 |
| Mandiant M-Trends 2025 Reportreport | Related to | OilRig (APT34)actor | — | ORKL | 2025-04-24 |
| ESET APT Activity Report Q4 2024-Q1 2025report | Related to | MuddyWateractor | — | ORKL | 2025-05-12 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | RansomHubactor | — | ORKL | 2025-06-24 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Emennet Pasargadactor | — | ORKL | 2024-02-08 |
| Mandiant M-Trends 2025 Reportreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-04-24 |
| Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections | Trend Micro (US)report | Related to | ALPHV / BlackCatactor | — | ORKL | 2024-06-27 |
| Mandiant M-Trends 2025 Reportreport | Related to | RansomHubactor | — | ORKL | 2025-04-24 |
| Investigating Iranian Intrusion into Strategic Middle East Critical Infrastructurereport | Related to | MuddyWateractor | — | ORKL | 2025-03-07 |
| Botnet Command & Control Infrastructure Reportreport | Related to | Cleaveractor | — | ORKL | 2025-01-10 |