Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| #StopRansomware: RansomHub Ransomwarereport | Related to | ALPHV / BlackCatactor | — | ORKL | 2024-09-06 |
| China Panda attacks supply chain against Vietnam Government Certification Authority - Part1report | Related to | Careto / Maskactor | — | ORKL | 2024-01-04 |
| ShadowSyndicate infrastructure illuminationreport | Related to | Killnetactor | — | ORKL | 2025-08-01 |
| Operation Dream Magicreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-10-13 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2024-02-15 |
| Mandiant M-Trends 2025 Reportreport | Related to | UNC1549 / TA455actor | — | ORKL | 2025-04-24 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | FunkSecactor | — | ORKL | 2025-06-24 |
| 202309181700_ManageEngine Vulnerability Sector Alert_TLPCLEARreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-09-18 |
| ShadowSyndicate infrastructure illuminationreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-08-01 |
| Threat Horizons H1 2025report | Related to | RansomHubactor | — | ORKL | 2025-01-16 |
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | MuddyWateractor | — | ORKL | 2026-03-25 |
| ESET APT Activity Report Q2 2024-Q3 2024report | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-11-07 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Moses Staffactor | — | ORKL | 2023-09-29 |
| 2025 THREAT DETECTION REPORTreport | Related to | FunkSecactor | — | ORKL | 2025-03-12 |
| ESET APT Activity Report Q4 2024-Q1 2025report | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-05-12 |
| 2025 Cyber Threat Intelligence Reportreport | Related to | MuddyWateractor | — | ORKL | 2025-06-24 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Killnetactor | — | ORKL | 2023-09-29 |
| Iran steps into US election 2024 with cyber-enabled influence operationsreport | Related to | Emennet Pasargadactor | — | ORKL | 2024-08-06 |
| 2025 November GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Toolsreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-11-05 |
| Pawn Storm Uses Brute Force and Stealth Against High-Value Targets | Trend Micro (US)report | Related to | ALPHV / BlackCatactor | — | ORKL | 2024-06-27 |
| OilRig's persistent attacks using cloud service-powered downloadersreport | Related to | OilRig (APT34)actor | — | ORKL | 2023-12-18 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-02-15 |
| 2025_IC3Report.pdfreport | Related to | DragonForceactor | — | ORKL | 2026-04-16 |
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2026-03-25 |
| Understanding Ransomware Threat Actorsreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2023-06-14 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-11-03 |
| Warning of North Korean cyber threats targeting the Defense Sectorreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-02-17 |
| 2025 November GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Toolsreport | Related to | MuddyWateractor | — | ORKL | 2025-11-05 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | MuddyWateractor | — | ORKL | 2023-11-03 |
| GreenCharlie Infrastructure Linked to US Political Campaign Targetingreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-08-19 |
| 2023 Adversary Infrastructure Reportreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-01-08 |
| 2025 Global Threat Reportreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-02-27 |
| Scattered Spiderreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2023-11-15 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2023-12-18 |
| #StopRansomware: RansomHub Ransomwarereport | Related to | RansomHubactor | — | ORKL | 2024-09-06 |
| Hamas Application Infrastructure Reveals Possible Overlap With TAG-63 and Iranian Threat Activityreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2023-10-23 |
| Inside BlackBasta: Actor Profiles, Extortion Tactics & Financesreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2025-04-02 |
| Multi-year Chinese APT Campaign Targets South Korean Academic, Government, and Political Entitiesreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2023-09-19 |
| From Albania to the Middle East: The Scarred Manticore is Listeningreport | Related to | Scarred Manticore (Storm-0861)actor | — | ORKL | 2024-01-16 |
| Iranian "Dream Job" campaignreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-11-12 |
| Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targetsreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2026-03-20 |
| RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scalereport | Related to | Flying Kittenactor | — | ORKL | 2023-08-07 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2024-02-08 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2023-12-18 |
| ShadowSyndicate infrastructure illuminationreport | Related to | Spacebearsactor | — | ORKL | 2025-08-01 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | WIRTEactor | — | ORKL | 2023-12-18 |
| 2023-05-23 - Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350report | Related to | Cl0pactor | — | ORKL | 2023-06-04 |
| Israel-Hamas War Spotlight: Shaking the Rust Off SysJokerreport | Related to | Gaza Cybergang / Moleratsactor | — | ORKL | 2024-01-16 |
| Pirates of The Nang Hai: Follow the Artifacts No One Knowsreport | Related to | Tropic Trooperactor | — | ORKL | 2024-09-04 |
| Operation Phantom Circuit North Korea's Global Data Exfiltration Campaignreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-01-27 |