2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 601–650 of 1,596 in Other · page 13 of 32
| ID | Title | Summary |
|---|---|---|
| IAMNOTAVILLAIN | IAmNotAVillain | IAmNotAVillain is a threat actor that claimed responsibility for a data breach at Revolut, threatening to sell confidential customer records unless a ransom of… |
| ICEPEONY | IcePeony | IcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and political organizations… |
| IMPERSONATING-PANDA | IMPERSONATING PANDA | |
| INCEPTION-FRAMEWORK | Inception Framework | This threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa… |
| INDIGOZEBRA | IndigoZebra | IndigoZebra is a Chinese state-sponsored actor mentioned for the first time by Kaspersky in its APT Trends report Q2 2017, targeting, at the time of its discov… |
| INDOHAXSEC-TEAM | INDOHAXSEC TEAM | INDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt websites and demand Bitc… |
| INDRIK-SPIDER | INDRIK SPIDER | INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank… |
| INFRASTRUCTURE-DESTRUCTION-SQUAD | Infrastructure Destruction Squad | Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.… |
| INFY | Infy | Infy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based … |
| INJ3CTOR3 | INJ3CTOR3 | INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei… |
| INJ3CTOR3 | INJ3CTOR3 | INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei… |
| INTEID | Inteid | Inteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Den… |
| IntelBroker | IntelBroker | IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a… |
| INTELBROKER | IntelBroker | IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a… |
| InvisiMole | InvisiMole | InvisiMole is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati… |
| INVISIMOLE | InvisiMole | Adversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine. |
| IRIDIUM | IRIDIUM | Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar… |
| IRLeaks | IRLeaks | IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB… |
| IRLEAKS | IRLeaks | IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB… |
| Iron Group | Iron Group | Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma… |
| IRON-GROUP | Iron Group | Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma… |
| IronErn440 | IronErn440 | IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV… |
| IRONERN440 | IronErn440 | IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV… |
| IRONHUSKY | IronHusky | IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research… |
| ItaDuke | ItaDuke | ItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive… |
| ITADUKE | ItaDuke | ItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive… |
| JABAROOT | Jabaroot | JabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl… |
| JACKPOT-PANDA | JACKPOT PANDA | Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online g… |
| JADEPUFFER | JadePuffer | JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack ch… |
| JavaGhost | JavaGhost | JavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. … |
| JAVAGHOST | JavaGhost | JavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. … |
| JINX-0126 | JINX-0126 | Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed … |
| JINX-0126 | JINX-0126 | Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed … |
| JINX-0164 | JINX-0164 | JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering … |
| JuiceLedger | JuiceLedger | JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond… |
| JUICELEDGER | JuiceLedger | JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond… |
| Kairos | Kairos | Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare… |
| KAIROS | Kairos | Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare… |
| Karakurt | Karakurt | Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic… |
| KARAKURT | Karakurt | Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic… |
| Karkadann | Karkadann | Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i… |
| KARKADANN | Karkadann | Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i… |
| KASABLANKA | Kasablanka | The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver… |
| KAX17 | KAX17 | KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar… |
| KAX17 | KAX17 | KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar… |
| Kazu | Kazu | Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h… |
| KAZU | Kazu | Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h… |
| Keksec | Keksec | Keksec is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The threat group behind EnemyBot, Keksec, is well-resourced and has the… |
| KEKSEC | Keksec | The threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of malware on a daily basis (… |
| KELVINSECURITY | KelvinSecurity | KelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and p… |