Every asserted link across the corpus, materialized once with its source. Each edge names its two independent confidence axes where the source carries them — Evidence (is it real?) kept separate from Attribution (whose is it?). Indicators are defanged.
| From | Relationship | To | Confidence | Source | As of |
|---|---|---|---|---|---|
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-11-03 |
| Warning of North Korean cyber threats targeting the Defense Sectorreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-02-17 |
| 2025 November GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Toolsreport | Related to | MuddyWateractor | — | ORKL | 2025-11-05 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | MuddyWateractor | — | ORKL | 2023-11-03 |
| GreenCharlie Infrastructure Linked to US Political Campaign Targetingreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-08-19 |
| 2023 Adversary Infrastructure Reportreport | Related to | Charming Kitten / APT42actor | — | ORKL | 2024-01-08 |
| 2025 Global Threat Reportreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-02-27 |
| Scattered Spiderreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2023-11-15 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2023-12-18 |
| #StopRansomware: RansomHub Ransomwarereport | Related to | RansomHubactor | — | ORKL | 2024-09-06 |
| Hamas Application Infrastructure Reveals Possible Overlap With TAG-63 and Iranian Threat Activityreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2023-10-23 |
| Inside BlackBasta: Actor Profiles, Extortion Tactics & Financesreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2025-04-02 |
| Multi-year Chinese APT Campaign Targets South Korean Academic, Government, and Political Entitiesreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2023-09-19 |
| From Albania to the Middle East: The Scarred Manticore is Listeningreport | Related to | Scarred Manticore (Storm-0861)actor | — | ORKL | 2024-01-16 |
| Iranian "Dream Job" campaignreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-11-12 |
| Government of Iran Cyber Actors Deploy Telegram C2 to Push Malware to Identified Targetsreport | Related to | Void Manticore (Storm-0842)actor | — | ORKL | 2026-03-20 |
| RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scalereport | Related to | Flying Kittenactor | — | ORKL | 2023-08-07 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Desert Falcons (original 2015 cluster)actor | — | ORKL | 2024-02-08 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2023-12-18 |
| ShadowSyndicate infrastructure illuminationreport | Related to | Spacebearsactor | — | ORKL | 2025-08-01 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | WIRTEactor | — | ORKL | 2023-12-18 |
| 2023-05-23 - Taming the Storm- Understanding and Mitigating the Consequences of CVE-2023-27350report | Related to | Cl0pactor | — | ORKL | 2023-06-04 |
| Israel-Hamas War Spotlight: Shaking the Rust Off SysJokerreport | Related to | Gaza Cybergang / Moleratsactor | — | ORKL | 2024-01-16 |
| Pirates of The Nang Hai: Follow the Artifacts No One Knowsreport | Related to | Tropic Trooperactor | — | ORKL | 2024-09-04 |
| Operation Phantom Circuit North Korea's Global Data Exfiltration Campaignreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-01-27 |
| From Albania to the Middle East: The Scarred Manticore is Listeningreport | Related to | OilRig (APT34)actor | — | ORKL | 2024-01-16 |
| Scattered Spider Threat Group Analysisreport | Related to | ALPHV / BlackCatactor | — | ORKL | 2024-04-22 |
| The Human Factor 2023report | Related to | Sea Turtleactor | — | ORKL | 2023-06-07 |
| Gaza Cybergang Unified Front Targeting Hamas Oppositionreport | Related to | Gaza Cybergang / Moleratsactor | — | ORKL | 2023-12-18 |
| 2023 Adversary Infrastructure Reportreport | Related to | APT33actor | — | ORKL | 2024-01-08 |
| Updated MATA attacks industrial companies in Eastern Europereport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-10-18 |
| New ShroudedSnooper actor targets telecommunications firms in the Middle East with novel Implantsreport | Related to | Scarred Manticore (Storm-0861)actor | — | ORKL | 2024-01-16 |
| Scattered Spiderreport | Related to | DragonForceactor | — | ORKL | 2025-08-01 |
| Crypto Country: North Korea's Targeting of Cryptocurrencyreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-11-29 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2024-05-13 |
| eset-apt-activity-report-q2-2025-q3-2025.pdfreport | Related to | Imperial Kitten (CURIUM)actor | — | ORKL | 2025-10-30 |
| 2025 Global Threat Reportreport | Related to | Cleaveractor | — | ORKL | 2025-02-27 |
| Iranian "Dream Job" campaignreport | Related to | UNC1549 / TA455actor | — | ORKL | 2024-11-12 |
| When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectorsreport | Related to | UNC1549 / TA455actor | — | ORKL | 2024-03-13 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Poloniumactor | — | ORKL | 2024-05-13 |
| Mandiant M-Trends 2025 Reportreport | Related to | Handalaactor | — | ORKL | 2025-04-24 |
| Threat Horizons H1 2025report | Related to | ALPHV / BlackCatactor | — | ORKL | 2025-01-16 |
| 2023-05-22 - Bluenoroff’s RustBucket campaignreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-06-04 |
| Israel-Hamas War in Cyber February 2024 Tool of First Resortreport | Related to | Arid Viper (APT-C-23 / Desert Falcon)actor | — | ORKL | 2024-02-08 |
| To the past and beyond: Andariel's latest arsenal and cyberattacksreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2026-01-16 |
| Modern Asia APT groups TTPsreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2023-11-09 |
| Mandiant M-Trends 2025 Reportreport | Related to | Agrius (Agonizing Serpens / BlackShadow)actor | — | ORKL | 2025-04-24 |
| Exposing DPRK's Cyber Syndicate and Hidden IT Workforcereport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-05-14 |
| ESET APT Activity Report Q2 2023-Q3 2023: Government espionage and unpatched vulnerabilitiesreport | Related to | Poloniumactor | — | ORKL | 2023-11-03 |
| DECEPTIVEDEVELOPMENT: FROM PRIMITIVE CRYPTO THEFT TO SOPHISTICATED AI-BASED DECEPTIONreport | Related to | Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroffactor | — | ORKL | 2025-09-16 |