2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 601–650 of 1,596 in Other · page 13 of 32

IDTitleSummary
IAMNOTAVILLAINIAmNotAVillainIAmNotAVillain is a threat actor that claimed responsibility for a data breach at Revolut, threatening to sell confidential customer records unless a ransom of…
ICEPEONYIcePeonyIcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and political organizations…
IMPERSONATING-PANDAIMPERSONATING PANDA
INCEPTION-FRAMEWORKInception FrameworkThis threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa…
INDIGOZEBRAIndigoZebraIndigoZebra is a Chinese state-sponsored actor mentioned for the first time by Kaspersky in its APT Trends report Q2 2017, targeting, at the time of its discov…
INDOHAXSEC-TEAMINDOHAXSEC TEAMINDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt websites and demand Bitc…
INDRIK-SPIDERINDRIK SPIDERINDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank…
INFRASTRUCTURE-DESTRUCTION-SQUADInfrastructure Destruction SquadDark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.…
INFYInfyInfy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based …
INJ3CTOR3INJ3CTOR3INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei…
INJ3CTOR3INJ3CTOR3INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei…
INTEIDInteidInteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Den…
IntelBrokerIntelBrokerIntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a…
INTELBROKERIntelBrokerIntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a…
InvisiMoleInvisiMoleInvisiMole is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati…
INVISIMOLEInvisiMoleAdversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine.
IRIDIUMIRIDIUMResecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar…
IRLeaksIRLeaksIRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB…
IRLEAKSIRLeaksIRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB…
Iron GroupIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
IRON-GROUPIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
IronErn440IronErn440IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV…
IRONERN440IronErn440IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV…
IRONHUSKYIronHuskyIronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research…
ItaDukeItaDukeItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive…
ITADUKEItaDukeItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive…
JABAROOTJabarootJabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl…
JACKPOT-PANDAJACKPOT PANDAJackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online g…
JADEPUFFERJadePufferJADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack ch…
JavaGhostJavaGhostJavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. …
JAVAGHOSTJavaGhostJavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. …
JINX-0126JINX-0126Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed …
JINX-0126JINX-0126Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed …
JINX-0164JINX-0164JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering …
JuiceLedgerJuiceLedgerJuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond…
JUICELEDGERJuiceLedgerJuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond…
KairosKairosKairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare…
KAIROSKairosKairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare…
KarakurtKarakurtKarakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic…
KARAKURTKarakurtKarakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic…
KarkadannKarkadannKarkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i…
KARKADANNKarkadannKarkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i…
KASABLANKAKasablankaThe Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver…
KAX17KAX17KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar…
KAX17KAX17KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar…
KazuKazuKazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h…
KAZUKazuKazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h…
KeksecKeksecKeksec is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The threat group behind EnemyBot, Keksec, is well-resourced and has the…
KEKSECKeksecThe threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of malware on a daily basis (…
KELVINSECURITYKelvinSecurityKelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and p…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.