2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 51–100 of 204 in CN · page 2 of 5

IDTitleSummary
CL-STA-0048CL-STA-0048
CN
CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunications entities, with a focus o…
CL-STA-1087CL-STA-1087
CN
CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia. The actor has demonst…
Curious GorgeCurious Gorge
CN
Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in Ukraine, Russia, Kazakhstan,…
DAGGER PANDADAGGER PANDA
CN
Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets…
DalbitDalbit
CN
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of…
DEV-0147DEV-0147
CN
DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra…
DiceyFDiceyF
CN
DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended period. They have exhi…
DragonbridgeDragonbridge
CN
DRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political interests of the People's Republic…
DragonOKDragonOK
CN
Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to hav…
DragonSparkDragonSpark
CN
DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the open-source tool SparkRAT, whic…
DriftingCloudDriftingCloud
CN
DriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or acquiring zero-day exploits …
Earth AluxEarth Alux
CN
Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, technology, and telecommunicat…
Earth BaxiaEarth Baxia
CN
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing…
Earth BerberokaEarth Berberoka
CN
According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign use…
Earth FreybugEarth Freybug
CN
Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities a…
Earth KrahangEarth Krahang
CN
Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
Earth LamiaEarth Lamia
CN
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
Earth LuscaEarth Lusca
CN
Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication c…
Earth NagaEarth Naga
CN
Earth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and military-related man…
Earth WendigoEarth Wendigo
CN
Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and unive…
ELECTRIC PANDAELECTRIC PANDA
CN
ELECTRIC PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: ELECTRIC PANDA is a Chinese-attributed threa…
ELOQUENT PANDAELOQUENT PANDA
CN
ELOQUENT PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: ELOQUENT PANDA is a Chinese-attributed threa…
Evasive PandaEvasive Panda
CN
Evasive Panda is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as BRONZE HIGHLAND. Operational targ…
Flax TyphoonFlax Typhoon
CN
Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining an…
FOXY PANDAFOXY PANDA
CN
FOXY PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: FOXY PANDA is a Chinese-attributed threat actor …
GALLIUMGALLIUM
CN
GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target…
GhostEmperorGhostEmperor
CN
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo…
GhostRedirectorGhostRedirector
CN
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie…
GIBBERISH PANDAGIBBERISH PANDA
CN
GIBBERISH PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: GIBBERISH PANDA is a Chinese-attributed thr…
GOBLIN PANDAGOBLIN PANDA
CN
GOBLIN PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Conimes, Cycldek. Operational targ…
GoldFactoryGoldFactory
CN
GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the Asia-Pacific region, speci…
GopherWhisperGopherWhisper
CN
GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Microsoft 365 Outlook to evade det…
GraylingGrayling
CN
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling app…
GREFGREF
CN
GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loaders, and ancillary tools in th…
GTG-1002GTG-1002
CN
GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately 30 global organizations acro…
HAFNIUMHAFNIUM
CN
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher educat…
HellsingHellsing
CN
This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States. It also seems to have target…
HenBoxHenBox
CN
HenBox is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Civil society sector. Documented…
HoukenHouken
CN
Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to cr…
HummingBadHummingBad
CN
This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arse…
HURRICANE PANDAHURRICANE PANDA
CN
We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large telecommunications and technology comp…
IcePeonyIcePeony
CN
IcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and political organizations…
IMPERSONATING PANDAIMPERSONATING PANDA
CN
IMPERSONATING PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: IMPERSONATING PANDA is a Chinese-attrib…
IndigoZebraIndigoZebra
CN
IndigoZebra is a Chinese state-sponsored actor mentioned for the first time by Kaspersky in its APT Trends report Q2 2017, targeting, at the time of its discov…
IronHuskyIronHusky
CN
IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research…
Lilac TyphoonLilac Typhoon
CN
Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a…
LIMINAL PANDALIMINAL PANDA
CN
LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d…
LongNosedGoblinLongNosedGoblin
CN
LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for…
LOTUS PANDALOTUS PANDA
CN
LOTUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spring Dragon, ST Group, DRAGONFISH…
Mana TeamMana Team
CN
Mana Team is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Mana Team is a Chinese-attributed threat actor ca…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base