2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 451–500 of 1,546 in Other · page 10 of 31

IDTitleSummary
Ghost JackalGhost Jackal
GHOST-JACKALGhost Jackal
GHOST-STADIUMGHOST STADIUMGHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom…
GHOSTEMPERORGhostEmperorGhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo…
GhostNetGhostNetCyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio…
GHOSTNETGhostNetCyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio…
GhostRGhostRGhostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about…
GHOSTRGhostRGhostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about…
GHOSTREDIRECTORGhostRedirectorGhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie…
GhostSecGhostSecGhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as…
GHOSTSECGhostSecGhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as…
GHOSTWRITERGhostwriterGhostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas, rather than as an ac…
GIBBERISH-PANDAGIBBERISH PANDA
GitlokerGitlokerGitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com…
GITLOKERGitlokerGitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com…
GnosticplayersGnosticplayersThe hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. …
GNOSTICPLAYERSGnosticplayersThe hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. …
GOBLIN-PANDAGOBLIN PANDAGoblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups. Most Chinese APTs target the United States and NATO, but Goblin Pand…
GOFFEEGOFFEEGOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with malicious attachments, inc…
GOFFEEGOFFEEGOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with malicious attachments, inc…
GOLD BURLAPGOLD BURLAPGOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cros…
GOLD-BURLAPGOLD BURLAPGOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cros…
GOLD CABINGOLD CABINGOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABI…
GOLD-CABINGOLD CABINGOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABI…
GOLD DUPONTGOLD DUPONTGOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) …
GOLD-DUPONTGOLD DUPONTGOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) …
GOLD EVERGREENGOLD EVERGREENGOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompass…
GOLD-EVERGREENGOLD EVERGREENGOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompass…
GOLD FAIRFAXGOLD FAIRFAXGOLD FAIRFAX is a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit botnet. Ramnit, the …
GOLD-FAIRFAXGOLD FAIRFAXGOLD FAIRFAX is a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit botnet. Ramnit, the …
GOLD FLANDERSGOLD FLANDERSGOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails demanding between 5 and …
GOLD-FLANDERSGOLD FLANDERSGOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails demanding between 5 and …
GOLD GALLEONGOLD GALLEONGOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry out business email comp…
GOLD-GALLEONGOLD GALLEONGOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry out business email comp…
GOLD GARDENGOLD GARDENGOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018 through May 2019. GandC…
GOLD-GARDENGOLD GARDENGOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018 through May 2019. GandC…
GOLD MANSARDGOLD MANSARDGOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019. The threat actor behind Nemty is known …
GOLD-MANSARDGOLD MANSARDGOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019. The threat actor behind Nemty is known …
GOLD NORTHFIELDGOLD NORTHFIELDOperational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomwar…
GOLD-NORTHFIELDGOLD NORTHFIELDOperational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomwar…
GOLD PRELUDEGOLD PRELUDEGOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE op…
GOLD-PRELUDEGOLD PRELUDEGOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE op…
GOLD REBELLIONGOLD REBELLIONGOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware. The group posted its first victim…
GOLD-REBELLIONGOLD REBELLIONGOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware. The group posted its first victim…
GOLD RIVERVIEWGOLD RIVERVIEWGOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on behalf of its custome…
GOLD-RIVERVIEWGOLD RIVERVIEWGOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on behalf of its custome…
GOLD SKYLINEGOLD SKYLINEGOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by business email compro…
GOLD-SKYLINEGOLD SKYLINEGOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by business email compro…
GOLD SOUTHFIELDGOLD SOUTHFIELDGOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various affi…
GOLD-SOUTHFIELDGOLD SOUTHFIELDGOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various affi…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base