Cyber Resilience

Threat Actor SpotlightWeekly

Threat actor spotlight: PROMETHIUM

Updated 12 August 2026 · Timeframe: All tracked history to date

PROMETHIUM12NEODYMIUM12Lazarus Group12Storm-053011Maui ransomware11Andariel11
Most CVE-linked threat actors we track · security-resilience.ai

PROMETHIUM (state) is linked to 12 CVEs in our corpus, and targets Government Activity, Telecommunications Services (TRBC); Public Administration, Telecommunications (NAICS).

Why it matters

Defending against an adversary is more actionable than defending against a CVE list. Knowing who is active and who they hunt lets teams prioritize by likelihood, not just severity.

What to do

Our take

Adversary-centric storytelling — who, why, and how to defend — is far stickier than another vulnerability roundup.

Earlier issues

Past states of this signal, most recent first.

06 August 2026 Threat actor spotlight: PROMETHIUM

Timeframe: All tracked history to date

PROMETHIUM12NEODYMIUM12Lazarus Group12Storm-053011Andariel11Maui ransomware11

PROMETHIUM (state) is linked to 12 CVEs in our corpus, and targets Government Activity, Telecommunications Services (TRBC); Public Administration, Telecommunications (NAICS).

31 July 2026 Threat actor spotlight: Lazarus Group

Timeframe: All tracked history to date

Lazarus Group12NEODYMIUM12PROMETHIUM12Maui ransomware11Storm-053011Andariel11

Lazarus Group (state) is linked to 12 CVEs in our corpus, 2 named victims, and targets Cyclical Consumer Services, Banking & Investment Services (TRBC); Arts, Entertainment & Recreation, Credit Intermediation & Related Activities (Banking), Securities, Commodity Contracts & Other Financial Investments (NAICS).

25 July 2026 Threat actor spotlight: NEODYMIUM

Timeframe: All tracked history to date

NEODYMIUM12PROMETHIUM12Lazarus Group12Andariel11Maui ransomware11Storm-053011

NEODYMIUM (unknown) is linked to 12 CVEs in our corpus.