2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 601–650 of 1,546 in Other · page 13 of 31

IDTitleSummary
IRON-GROUPIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
IronErn440IronErn440IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV…
IRONERN440IronErn440IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV…
IRONHUSKYIronHuskyIronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research…
ItaDukeItaDukeItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive…
ITADUKEItaDukeItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive…
JABAROOTJabarootJabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl…
JavaGhostJavaGhostJavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. …
JAVAGHOSTJavaGhostJavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. …
JINX-0126JINX-0126Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed …
JINX-0126JINX-0126Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed …
JINX-0164JINX-0164JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering …
JuiceLedgerJuiceLedgerJuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond…
JUICELEDGERJuiceLedgerJuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond…
KairosKairosKairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare…
KAIROSKairosKairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare…
KarakurtKarakurtKarakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic…
KARAKURTKarakurtKarakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic…
KarkadannKarkadannKarkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i…
KARKADANNKarkadannKarkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i…
KASABLANKAKasablankaThe Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver…
KAX17KAX17KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar…
KAX17KAX17KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar…
KazuKazuKazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h…
KAZUKazuKazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h…
KeksecKeksecKeksec is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The threat group behind EnemyBot, Keksec, is well-resourced and has the…
KEKSECKeksecThe threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of malware on a daily basis (…
KELVINSECURITYKelvinSecurityKelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and p…
Keymous+Keymous+Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur…
KEYMOUSKeymous+Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur…
KillnetKillnetKillnet is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisations…
KILLNETKillnetA group targeting various countries using Denial of Services attacked.
KIMSUKYKimsukyThis threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
KinsingKinsingThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
KINSINGKinsingThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
Kiss-a-DogKiss-a-DogCrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and…
KISS-A-DOGKiss-a-DogCrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and…
KromSecKromSecKromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi…
KROMSECKromSecKromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi…
KrybitKrybitKrybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support …
KRYBITKrybitKrybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support …
LabHostLabHostLabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re…
LABHOSTLabHostLabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re…
LamashtuLamashtuLamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun…
LAMASHTULamashtuLamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun…
LanceflyLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LANCEFLYLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LAPSUSLAPSUSLAPSUS is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LAPSUS$, DEV-0537, SLIPPY SPIDER (and 3 more). Original rec…
LAPSUSLAPSUSAn actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive element…
Larva-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base