Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| 2023-05-23 - Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350report | Related to | Nemesis Kittenactor | — | ORKL | 2023-06-04 |
| Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectorsreport | Related to | Agrius (Agonizing Serpens / BlackShadow)actor | — | ORKL | 2024-01-16 |
| Mandiant M-Trends 2025 Reportreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2025-04-24 |
| Lazarus campaigns and backdoors in 2022-23report | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-10-19 |
| Investigating Iranian Intrusion into Strategic Middle East Critical Infrastructurereport | Related to | Fox Kittenactor | — | ORKL | 2025-03-07 |
| Staying ahead of threat actors in the age of AIreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-02-20 |
| OilRig's persistent attacks using cloud service-powered downloadersreport | Related to | HEXANE (Lyceum)actor | — | ORKL | 2023-12-18 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | UNC1549 / TA455actor | — | ORKL | 2024-02-08 |
| M-Trends 2024 Special Reportreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2024-04-22 |
| Threat Horizons Reportreport | Related to | MuddyWateractor | — | ORKL | 2023-07-26 |
| Iranian Cyber Actors May Target Vulnerable US Networks and Entities of Interestreport | Related to | Emennet Pasargadactor | — | ORKL | 2025-06-27 |
| Objective-See's Blogreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-06-26 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Fox Kittenactor | — | ORKL | 2023-09-29 |
| Arid Viper poisons Android apps with AridSpyreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2024-07-25 |
| Hamas Application Infrastructure Reveals Possible Overlap With TAG-63 and Iranian Threat Activityreport | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2023-10-23 |
| Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africareport | Related to | MuddyWateractor | — | ORKL | 2024-01-16 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Predatory Sparrowactor | — | ORKL | 2023-09-29 |
| MuddyWater eN-Able spear-phishing with new TTPsreport | Related to | MuddyWateractor | — | ORKL | 2023-12-12 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Predatory Sparrowactor | — | ORKL | 2024-02-08 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2024-02-08 |
| M-Trends 2024 Special Reportreport | Related to | Cl0pactor | — | ORKL | 2024-04-22 |
| ESET APT Activity Report Q2 2024-Q3 2024report | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-11-07 |
| Inside a New Cyber Weapon: IOCONTROLreport | Related to | CyberAv3ngersactor | — | ORKL | 2024-12-18 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2023-09-29 |
| Iran steps into US election 2024 with cyber-enabled influence operationsreport | Related to | APT33actor | — | ORKL | 2024-08-06 |
| 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=enreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2026-03-25 |
| SentinelOne WatchTower Intelligence-Driven Threat Hunting End of Year 2023report | Related to | Sea Turtleactor | — | ORKL | 2024-02-15 |
| 2023-05-23 - Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350report | Related to | MuddyWateractor | — | ORKL | 2023-06-04 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Handalaactor | — | ORKL | 2024-02-08 |
| Operation Marstech Mayhem Lazarus Group's Open-Source Trap: North Korea's New Malware Tactic Targeting Developers and Crypto Walletsreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-02-10 |
| Smoking Out an Affiliatereport | Related to | RansomHubactor | — | ORKL | 2026-04-13 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2023-09-29 |
| Iranian "Dream Job" campaignreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2024-11-12 |
| 日本を狙うサイバーエスピオナージ(標的型攻撃)の動向2023年度report | Related to | Tropic Trooperactor | — | ORKL | 2024-06-28 |
| Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africareport | Related to | MuddyWateractor | — | ORKL | 2023-12-20 |
| 2025_IC3Report.pdfreport | Related to | Sinobiactor | — | ORKL | 2026-04-16 |
| Staying ahead of threat actors in the age of AIreport | Related to | UNC1549 / TA455actor | — | ORKL | 2024-02-20 |
| ShadowSyndicate infrastructure illuminationreport | Related to | Cl0pactor | — | ORKL | 2025-08-01 |
| Iran steps into US election 2024 with cyber-enabled influence operationsreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-08-06 |
| 2025 THREAT DETECTION REPORTreport | Related to | RansomHubactor | — | ORKL | 2025-03-12 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | MuddyWateractor | — | ORKL | 2024-05-13 |
| eset-apt-activity-report-q2-2025-q3-2025.pdfreport | Related to | BladedFelineactor | — | ORKL | 2025-10-30 |
| 2023 State of The Threat – A Year in Reviewreport | Related to | Nemesis Kittenactor | — | ORKL | 2023-09-29 |
| Smoking Out an Affiliatereport | Related to | Qilin (fka Agenda)actor | — | ORKL | 2026-04-13 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Agrius (Agonizing Serpens / BlackShadow)actor | — | ORKL | 2024-05-13 |
| THE MASK HAS BEEN UNMASKED AGAINreport | Related to | MuddyWateractor | — | ORKL | 2024-09-24 |
| Dark Pink APT unleashes malware for deeper and more sinister intrusions in the Asia-Pacific and Europereport | Related to | Cleaveractor | — | ORKL | 2024-01-12 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Poloniumactor | — | ORKL | 2024-02-08 |
| New Zero-Day Vulnerability Detected: CVE-2024-43451report | Related to | Handalaactor | — | ORKL | 2024-11-13 |
| 2025_IC3Report.pdfreport | Related to | RansomHubactor | — | ORKL | 2026-04-16 |