> ## Documentation Index
> Fetch the complete documentation index at: https://docs.reyhford.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Threat Actor Profiles

> Publicly documented actors relevant to ICS/OT and regional critical infrastructure.

Profiles below use **public naming**. Reyhford does not assert that every honeypot source IP belongs to a named group — we provide protocol and technique context so analysts can hypothesize and hunt.

## Strategic (nation-state / APT)

| Profile                | Relevance to ICS/OT                            |
| ---------------------- | ---------------------------------------------- |
| **Sandworm**           | Grid-oriented; Industroyer lineage             |
| **XENOTIME**           | Safety systems (Triton)                        |
| **Volt Typhoon**       | Living-off-the-land in critical infrastructure |
| **APT33**              | Energy / petrochemical targeting               |
| **APT41**              | Espionage + crime; SEA manufacturing/energy    |
| **APT32 / OceanLotus** | Regional political + commercial intel          |
| **Lazarus**            | Financial ops; energy-sector intersections     |

## Criminal / opportunistic

* Ransomware affiliates targeting industrial verticals
* Commodity botnet scanners hitting 502/102/10001
* Hacktivist campaigns against energy and government portals

## How to use profiles with Reyhford data

1. Pull high-confidence ICS-protocol indicators via TAXII/API
2. Enrich in your TIP with public APT reporting
3. Ask: does this source also appear on your OT DMZ or VPN?

See [Who attacks](/threat-landscape/who-attacks) and [Southeast Asia](/regional/southeast-asia).
