2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1–50 of 1,546 in Other · page 1 of 31

IDTitleSummary
STEALTH-MANGO-AND-TANGELO Stealth Mango and Tangelo This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and S…
[Unnamed group][Unnamed group]Over the last few weeks, several significant leaks regarding a number of Iranian APTs took place. After analyzing and investigating the documents we conclude t…
UNNAMED-GROUP[Unnamed group]Over the last few weeks, several significant leaks regarding a number of Iranian APTs took place. After analyzing and investigating the documents we conclude t…
[Vault 7/8][Vault 7/8]An unnamed source leaked almost 10,000 documents describing a large number of 0-day vulnerabilities, methodologies and tools that had been collected by the CIA…
VAULT-7-8[Vault 7/8]An unnamed source leaked almost 10,000 documents describing a large number of 0-day vulnerabilities, methodologies and tools that had been collected by the CIA…
1937CN1937CN1937CN is a Chinese hacking group that has been active since at least 2013. The group is known for targeting Vietnamese organizations, including government age…
313-TEAM313 Team313 Team is an Iraq-based threat actor that has conducted coordinated DDoS campaigns targeting multiple government servers in the UAE, Kuwait, and Romania, oft…
ABABIL-OF-MINABAbabil of MinabAbabil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in threat intelligence reporting…
Actor240524Actor240524Actor240524 is a newly identified APT group that targeted Azerbaijani and Israeli diplomats through spear-phishing emails to steal sensitive data. The group em…
ACTOR240524Actor240524Actor240524 is a newly identified APT group that targeted Azerbaijani and Israeli diplomats through spear-phishing emails to steal sensitive data. The group em…
AdrasteaAdrasteaAdrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen data for sale. They …
ADRASTEAAdrasteaAdrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen data for sale. They …
AeroBladeAeroBladeAeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States. Their objective appears to be conducting…
AEROBLADEAeroBladeAeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States. Their objective appears to be conducting…
Aggressive Inventory ZombiesAggressive Inventory ZombiesAggressive Inventory Zombies is a threat actor involved in a large-scale phishing and pig-butchering network targeting retail brands and cryptocurrency users. …
AGGRESSIVE-INVENTORY-ZOMBIESAggressive Inventory ZombiesAggressive Inventory Zombies is a threat actor involved in a large-scale phishing and pig-butchering network targeting retail brands and cryptocurrency users. …
ALLANITEALLANITEAdversaries abusing ICS (based on Dragos Inc adversary list). ALLANITE accesses business and industrial control (ICS) networks, conducts reconnaissance, and ga…
ALLANITEALLANITEAdversaries abusing ICS (based on Dragos Inc adversary list). ALLANITE accesses business and industrial control (ICS) networks, conducts reconnaissance, and ga…
Alpha SpiderAlpha SpiderALPHA SPIDER is a threat actor known for developing and operating the Alphv ransomware as a service. They have been observed using novel offensive techniques, …
ALPHA-SPIDERAlpha SpiderALPHA SPIDER is a threat actor known for developing and operating the Alphv ransomware as a service. They have been observed using novel offensive techniques, …
ALTAHREA-TEAMAltahrea TeamAltahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for a number of cyberattacks, inclu…
ALTDOSALTDOSALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia. They have been involved in data breac…
ALTDOSALTDOSALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia. They have been involved in data breac…
Altoufan TeamAltoufan TeamALTOUFAN TEAM is a politically motivated hacktivist group with anti-Zionism, anti-monarchy, and pro-14-February movement sentiments. They have targeted governm…
ALTOUFAN-TEAMAltoufan TeamALTOUFAN TEAM is a politically motivated hacktivist group with anti-Zionism, anti-monarchy, and pro-14-February movement sentiments. They have targeted governm…
AMARANTH-DRAGONAmaranth-DragonAmaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exhibiting similar tooling and o…
ANDROMEDA SPIDERANDROMEDA SPIDER
ANDROMEDA-SPIDERANDROMEDA SPIDER
ANGRY-LIKHOAngry LikhoAngry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Russia and Belarus. Their attac…
Anonymous KSAAnonymous KSAAnonymous KSA is a Saudi hacking group that has executed cyber attacks targeting Indian institutions, including a significant breach of UIDAI's data storage un…
ANONYMOUS-KSAAnonymous KSAAnonymous KSA is a Saudi hacking group that has executed cyber attacks targeting Indian institutions, including a significant breach of UIDAI's data storage un…
Anonymous SudanAnonymous SudanSince January 23, 2023, a threat actor identifying as "Anonymous Sudan" has been conducting denial of service (DDoS) attacks against multiple organizations in …
ANONYMOUS-SUDANAnonymous SudanSince January 23, 2023, a threat actor identifying as "Anonymous Sudan" has been conducting denial of service (DDoS) attacks against multiple organizations in …
ANONYMOUS64Anonymous64Anonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electronic screens, and network tel…
ANTHROPOID SPIDERANTHROPOID SPIDERPublicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial …
ANTHROPOID-SPIDERANTHROPOID SPIDERPublicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial …
ANTLIONAntlionAntlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan. This persistent campaign has…
AOQIN-DRAGONAoqin DragonSentinelLabs has uncovered a cluster of activity beginning at least as far back as 2013 and continuing to the present day, primarily targeting organizations in…
APPMILADAppMiladAppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad. This spyware is designed to silently infiltr…
APT-C-12APT-C-12According to 360 TIC the actor has carried out continuous cyber espionage activities since 2011 on key units and departments of the Chinese government, militar…
APT-C-12APT-C-12According to 360 TIC the actor has carried out continuous cyber espionage activities since 2011 on key units and departments of the Chinese government, militar…
APT-C-27APT-C-27A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the Syrian region using Android a…
APT-C-34APT-C-34As reported by ZDNet, Chinese cyber-security vendor Qihoo 360 published a report on 2019-11-29 exposing an extensive hacking operation targeting the country of…
APT-C-34APT-C-34As reported by ZDNet, Chinese cyber-security vendor Qihoo 360 published a report on 2019-11-29 exposing an extensive hacking operation targeting the country of…
APT-C-36APT-C-36Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government…
APT-C-36APT-C-36Since April 2018, an APT group (Blind Eagle, APT-C-36) suspected coming from South America carried out continuous targeted attacks against Colombian government…
APT-C-60APT-C-60APT-C-60 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as APT-Q-12. Original record: APT-C-60 is a threat actor cat…
APT-C-60APT-C-60APT-C-60
APT-3102APT.3102
APT1APT1PLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Army advanced persistent threat…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.