Skip to main content
QUIETLYTIC
Analysis

7 Most Dangerous State-Sponsored Hacker Groups Targeting the U.S.

Seven state-sponsored hacker groups U.S. government advisories most frequently name as active threats — with DOJ, CISA, and Treasury attribution for each.

7 Most Dangerous State-Sponsored Hacker Groups Targeting the U.S. — Analysis research

These seven groups recur most frequently across DOJ indictments, CISA cybersecurity advisories, and Treasury sanctions actions naming active threats to U.S. government, defense, and critical infrastructure targets. Each entry below links to this site’s full profile, which traces the group’s tactics back to MITRE ATT&CK’s own data.

1. APT28 (Fancy Bear)

Attributed to Russia’s GRU Military Unit 26165, APT28 has been active since at least 2004 and is one of the most extensively documented Russian state-sponsored groups, per MITRE ATT&CK’s group profile. Its operations span political espionage and credential-theft campaigns against government, military, and defense targets, including a 2022–2024 operation that reached Ukraine-focused targets by daisy-chaining through nearby Wi-Fi networks, documented in the APT28 Nearest Neighbor Campaign. Full profile: APT28.

2. APT29 (Cozy Bear)

Also Russian state-sponsored, APT29 is best known for the 2020 compromise of SolarWinds’ Orion software supply chain, which gave it access to numerous downstream U.S. federal agencies and enterprises — documented in our research on the SolarWinds compromise. Its tradecraft prioritizes long-term, low-noise intelligence gathering over disruption. Full profile: APT29.

3. Lazarus Group

North Korea’s Lazarus Group, tied by a 2021 DOJ indictment to the Reconnaissance General Bureau (RGB), blends espionage with financially motivated operations — a joint CISA, FBI, and Treasury advisory documented the group’s cryptocurrency theft activity, and OFAC first sanctioned the group and its sub-groups in 2019. Its 2016 spearphishing campaign against Sony Pictures employees and defense-sector targets is documented in Operation Dream Job. Full profile: Lazarus Group.

4. APT41

A Chinese threat group DOJ describes as conducting both state-directed espionage and financially motivated intrusions “potentially outside of state control” — a 2020 DOJ indictment charged members with compromising more than 100 companies globally, while noting the group received “tacit” rather than confirmed direct state support. Its supply chain and software-compromise techniques are documented in Operation CuckooBees. Full profile: APT41.

5. Volt Typhoon

A Chinese state-sponsored group CISA has specifically flagged for pre-positioning inside U.S. critical infrastructure — energy, water, and transportation networks — using “living off the land” techniques that rely on legitimate administrative tools instead of custom malware, making detection significantly harder. CISA’s advisories describe this activity as establishing persistent access for potential future disruption rather than immediate theft or espionage, documented in KV Botnet Activity. Full profile: Volt Typhoon.

6. Sandworm Team

Attributed to Russia’s GRU Unit 74455, Sandworm Team is documented by CISA as one of the most destructively focused state-sponsored groups, with a history of attacks against Ukraine’s power grid and other critical infrastructure targets dating back to at least 2009, per MITRE ATT&CK’s group profile. Unlike primarily espionage-focused groups, its operations have repeatedly aimed at physical disruption — including the 2015 and 2016 attacks on Ukraine’s power grid, the first and second publicly documented cyberattacks to disrupt electric grid infrastructure. Full profile: Sandworm Team.

7. Kimsuky

A North Korean state-sponsored group CISA has documented targeting government, academic, and think-tank organizations focused on North Korean policy, geopolitical events, and nuclear policy issues — reflecting an intelligence-gathering objective distinct from Lazarus Group’s more financially driven operations, per MITRE ATT&CK’s group profile. Full profile: Kimsuky.

Why these seven, specifically

This list isn’t a ranking by damage caused — it’s the set of groups that appear most consistently across current DOJ indictments, CISA advisories, and Treasury sanctions as active, ongoing threats rather than historical footnotes. Notably, it spans three of the four countries U.S. advisories most frequently name (Russia, China, North Korea) and covers every major motivation this site’s complete guide to state-sponsored hackers describes: espionage (APT28, APT29, Kimsuky), destructive disruption (Sandworm Team), pre-positioning (Volt Typhoon), and blended espionage-and-financial operations (Lazarus Group, APT41). For the tactics these groups share and how to defend against them, see our tactics and defense guide, and for the full set of groups this site tracks in detail, visit our threat actors hub.

Frequently Asked Questions

Which state-sponsored hacker group is considered the most active against the U.S. right now? CISA’s most recent advisories place particular emphasis on Volt Typhoon because of its pre-positioning inside U.S. critical infrastructure — a pattern distinct from traditional espionage that CISA has flagged as a specific ongoing concern.

Is APT41 confirmed to work directly for the Chinese government? Not with full certainty. DOJ’s 2020 indictment describes “tacit” state support rather than direct employment, and notes the group conducts financially motivated operations described as potentially outside state control — a more ambiguous attribution than groups like APT28, which is tied to a specific GRU military unit.

What’s the difference between Lazarus Group and Kimsuky, since both are North Korean? Lazarus Group has increasingly blended espionage with financially motivated cryptocurrency theft, per joint CISA/FBI/Treasury advisories, while Kimsuky’s documented targeting centers on intelligence gathering around North Korean policy and nuclear issues — a narrower, more traditional espionage focus.


Grounded in DOJ indictments, CISA cybersecurity advisories, Treasury (OFAC) sanctions actions, and MITRE ATT&CK. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 MITRE ATT&CK
02 U.S. Department of Justice (DOJ)
03 Cybersecurity and Infrastructure Security Agency (CISA)
04 U.S. Department of the Treasury (OFAC)

Related intelligence


Cross-referenced intelligence


Analyst tools