Google Threat Analysis Group (TAG) is Google’s security and intelligence team focused on identifying, tracking, and disrupting advanced cyber threats, including state-backed intrusion activity, commercial spyware operations, and in-the-wild exploitation of zero-day vulnerabilities. TAG is widely recognized for discovering and reporting highly targeted attacks affecting major technology ecosystems, including Android, Chrome, Apple platforms, and mobile chipsets. The group has been publicly associated with the discovery or observation of multiple zero-day vulnerabilities exploited in targeted attacks, including flaws in Qualcomm components, Samsung mobile processors, WebKit, and the Angle graphics library used by Chromium- and Apple-related software stacks. Its reporting has highlighted exploit chains enabling arbitrary code execution and privilege escalation, particularly against specific individuals in sophisticated surveillance-oriented operations. TAG has also coordinated vulnerability disclosure and patching with major vendors including Apple. Google Threat Analysis Group is not a malicious threat actor. It is a defensive security organization that conducts threat research, incident investigation, and vulnerability discovery. Its work frequently attributes activity to advanced persistent threat groups and commercial spyware vendors, but the high-confidence facts available here support TAG’s role as a reporting and research entity rather than an offensive intrusion operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TAG is known for tracking and reporting on advanced exploitation of zero-day vulnerabilities, including those used in privilege escalation chains on mobile devices.
Google Threat Analysis Group (TAG) is monitoring and reporting on the exploitation of zero-day vulnerabilities in Qualcomm components, which have been used in targeted attacks, potentially linked to spyware campaigns.
Google Threat Analysis Group is involved in the discovery and analysis of zero-day vulnerabilities exploited in highly targeted attacks, often linked to commercial spyware vendors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.