Uptime Hamster: 10d 23h 1mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza againstthewest

againstthewest

2 incidentes 1 paises 0 sectores ransomware US Ultimo: 2026-06-29
Aliases: BlueHornet, APT49, ATW, para disfrazar su origen, AgainstTheWest, referencias a organizaciones, APTs provenientes de Rusia, China, Irán, Corea del Norte, otros países, conexiones a organizaciones gubernamentales en Rusia
Ver en IntelTracker → APTTrail →
AgainstTheWest (ATW) is a hacktivist group that first emerged on October 14, 2021, on RaidForums as a data leak group. The group comprises individuals assessed to be primarily from Switzerland, France, Poland, and Canada, and identifies as pro-Western. Its primary motivation is ideological opposition to authoritarian and corrupt governments, particularly targeting the Chinese Communist Party over issues such as the Uighur genocide, aggression against Taiwan, and actions in Hong Kong. ATW distinguishes itself by frequently releasing stolen data, including source code, for free, often demonstrating a lack of financial motivation by accepting easily traceable cryptocurrencies and indicating disinterest in sales if data does not attract buyers. While initially focused on China, the group expanded its operations to include Russia, Belarus, Iran, and North Korea. The group has also been associated with the alias BlueHornet.

Aliases del actor

BlueHornetAPT49ATWpara disfrazar su origenAgainstTheWestreferencias a organizacionesAPTs provenientes de RusiaChinaIránCorea del Norteotros paísesconexiones a organizaciones gubernamentales en Rusia

Actores similares

apt-glassesactor · 1apt-modifiedelephantactor · 1APT-C-36apt · 1APT 28apt · 0APT 29apt · 0APT 41apt · 0APT-C-34apt · 0APT-C-27apt · 0APT-C-12apt · 0APT-C-60apt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionupgiphvoitymatg4cv7bxqh5dz6sn6bfscywoat4qtslztkomf5lavrayd.onionagainstthewest
DLS / leak siteupransomware.anggipradana.comRansomware Group: againstthewest
Tecnicas MITRE
TA0001, TA0002, TA0003, TA0004, TA0005, TA0007
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

BelarusChinaIran, Islamic Republic ofKorea, Democratic People's Republic ofKorea, Republic ofPolandRussian Federation

Sectores objetivo (SOCRadar)

Other Information ServicesMonetary Authorities-Central BankRail TransportationSoftware PublishersEnterprises & HoldingAir TransportationManufacturingConstructionPublic AdministrationEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com