The APT Dossier - Threat Landscape 2026
An Intelligence Briefing on Top APTs and Hacker Groups by the Institute for Critical Infrastructure Cybersecurity (ICIC), founded by James Scott.
About the APT Dossier
The definitive intelligence briefing on the Top 50 Advanced Persistent Threat and hacker groups, ranked by ARCS (Adversary Risk Classification System) composite risk scores. Audit-ready, provenance-chained analysis for Congressional stakeholders, national security advisors, and critical infrastructure defenders.
Key Statistics
- 50 Top Threat Actors profiled and ranked
- 68% of threat actors are state-sponsored
- 96% of attacks utilize phishing vectors
- 21 days average dwell time before detection
Intelligence Modules
Top 10 Threat Actors by ARCS Score
- APT29 (Cozy Bear) - ARCS Score: 98
- Lazarus Group - ARCS Score: 98
- APT41 (Wicked Panda) - ARCS Score: 96
- Sandworm - ARCS Score: 95
- APT28 (Fancy Bear) - ARCS Score: 94
- Volt Typhoon - ARCS Score: 93
- DarkSide / BlackCat - ARCS Score: 92
- LockBit - ARCS Score: 91
- UNC1151 (Ghostwriter) - ARCS Score: 90
- Charming Kitten - ARCS Score: 89
About James Scott
James Scott is the founder of the Institute for Critical Infrastructure Cybersecurity (ICIC) and a recognized authority in cyber adversary research. His work focuses on adversary profiling, APT ecosystem analysis, supply-chain threat modeling, and critical-infrastructure cyber risk.
About ICIC
The Institute for Critical Infrastructure Cybersecurity (ICIC) is an independent research center dedicated to adversary profiling, APT ecosystem analysis, and critical-infrastructure cyber risk. ICIC operates without commercial clients or donors, ensuring unbiased intelligence focused on capability transfer to government and critical infrastructure operators.