2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 551–600 of 1,596 in Other · page 12 of 32
| ID | Title | Summary |
|---|---|---|
| GTG-1002 | GTG-1002 | GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately 30 global organizations acro… |
| GTG-20006 | GTG-20006 | GTG-20006 is a Russian espionage operator that has targeted over 20 organizations in Ukrainian and European government, defense, and diplomatic sectors, exfilt… |
| Guacamaya | Guacamaya | Guacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America, which they believe hav… |
| GUACAMAYA | Guacamaya | Guacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America, which they believe hav… |
| GURU SPIDER | GURU SPIDER | GURU SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Early in 2018, CrowdStrike Intelligence observed GURU SPIDER suppo… |
| GURU-SPIDER | GURU SPIDER | Early in 2018, CrowdStrike Intelligence observed GURU SPIDER supporting the distribution of multiple crimeware families through its flagship malware loader, Qu… |
| Hacking Team | Hacking Team | The many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in 2015, have been used by … |
| HACKING-TEAM | Hacking Team | The many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in 2015, have been used by … |
| HAFNIUM | HAFNIUM | HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher educat… |
| Hagga | Hagga | Hagga is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Aggah, TH-157. Original record: Hagga is believed to have be… |
| HAGGA | Hagga | Hagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims since the latter part of… |
| HANDALA | Handala | Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive at… |
| HAZY-TIGER | HAZY TIGER | The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the Andr… |
| Head Mare | Head Mare | Head Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called PhantomRAT. They have… |
| HEAD-MARE | Head Mare | Head Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called PhantomRAT. They have… |
| HellHounds | HellHounds | Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerabl… |
| HELLHOUNDS | HellHounds | Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerabl… |
| HELLSING | Hellsing | This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States. It also seems to have target… |
| HENBOX | HenBox | This threat actor targets Uighurs—a minority ethnic group located primarily in northwestern China—and devices from Chinese mobile phone manufacturer Xiaomi, fo… |
| HexagonalRodent | HexagonalRodent | HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like BeaverT… |
| HEXAGONALRODENT | HexagonalRodent | HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like BeaverT… |
| Hezb | Hezb | Hezb is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Mimo. Original record: Hezb is a group deploying cryptominers… |
| HEZB | Hezb | Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities. The name is after the miner process they deploy. |
| HIDDENART | HiddenArt | It was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the personal devices of targeted i… |
| HIGAISA | Higaisa | The organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The bait includes New Year blessi… |
| HikkI-Chan | HikkI-Chan | Hikki-Chan has claimed responsibility for multiple significant data breaches, including the theft of data from 390.4 million users of VKontakte, which included… |
| HIKKI-CHAN | HikkI-Chan | Hikki-Chan has claimed responsibility for multiple significant data breaches, including the theft of data from 390.4 million users of VKontakte, which included… |
| HIVE-0145 | HIVE-0145 | Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware to target email cred… |
| HIVE-0145 | HIVE-0145 | Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware to target email cred… |
| Hive0117 | Hive0117 | Hive0117 is a financially motivated cybercriminal group that conducts phishing campaigns to deliver the fileless malware DarkWatchman, which is capable of keyl… |
| HIVE0117 | Hive0117 | Hive0117 is a financially motivated cybercriminal group that conducts phishing campaigns to deliver the fileless malware DarkWatchman, which is capable of keyl… |
| Hive0137 | Hive0137 | Being one of the most active malware distributors, Hive0137 demonstrates a willingness to explore new payloads and technologies such as GenAI. They have quickl… |
| HIVE0137 | Hive0137 | Being one of the most active malware distributors, Hive0137 demonstrates a willingness to explore new payloads and technologies such as GenAI. They have quickl… |
| Hive0163 | Hive0163 | Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. … |
| HIVE0163 | Hive0163 | Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. … |
| HollowQuill | HollowQuill | SEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known institution for various defe… |
| HOLLOWQUILL | HollowQuill | SEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known institution for various defe… |
| HOMELAND-JUSTICE | HomeLand Justice | HomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021. They have targeted various organizations, inclu… |
| Honeybee | Honeybee | McAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as ba… |
| HONEYBEE | Honeybee | McAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as ba… |
| HookAds | HookAds | HookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online games, or blackhat seo sit… |
| HOOKADS | HookAds | HookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online games, or blackhat seo sit… |
| HOUKEN | Houken | Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to cr… |
| HOUND SPIDER | HOUND SPIDER | HOUND SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: HOUND SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga… |
| HOUND-SPIDER | HOUND SPIDER | According to Crowdstrike, HOUND SPIDER affiliates arrested in Romania on December,2017 |
| HOUNDSTOOTH-TYPHOON | Houndstooth Typhoon | Microsoft threat actor profile. Origin/Threat: China. |
| HUMMINGBAD | HummingBad | This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arse… |
| HUNT3R-KILL3RS | Hunt3r Kill3rs | Hunt3r Kill3rs is a newly emerged threat group claiming expertise in cyber operations, including ICS breaches and web application vulnerabilities exploitation.… |
| HURRICANE-PANDA | HURRICANE PANDA | We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large telecommunications and technology comp… |
| HYADINA | Hyadina | Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows systems while avoiding … |