> For the complete documentation index, see [llms.txt](https://blog.r00t-hunter.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://blog.r00t-hunter.com/threat-actor-files.md).

# Threat Actor Files

**Overview**

This section documents my write-ups on state-sponsored and highly organized threat actors involved in cyberwarfare, espionage, and critical-infrastructure intrusions, along with major cyberwarfare news and campaign disclosures as they break. Research is compiled from public advisories, vendor threat intel, and verified reporting cross-referenced wherever possible.

Each write-up follows a consistent structure:

* **Profile**: known aliases, attribution confidence, and first-observed activity
* **Initial Access**: how the group gets in exploited CVEs, protocols, or edge devices
* **Tradecraft**: tooling, C2 infrastructure, and persistence techniques
* **Objectives & Impact**: what data or access the group is after, and documented real-world consequences
* **Detection & Defense**: IOCs, hunting guidance, and mitigations for defenders

Only publicly attributed, sourced activity is documented here — no speculative attribution, and no operational detail that would function as a how-to for replicating an intrusion.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://blog.r00t-hunter.com/threat-actor-files.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
