2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 651–700 of 1,596 in Other · page 14 of 32
| ID | Title | Summary |
|---|---|---|
| Keymous+ | Keymous+ | Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur… |
| KEYMOUS | Keymous+ | Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur… |
| Killnet | Killnet | Killnet is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisations… |
| KILLNET | Killnet | A group targeting various countries using Denial of Services attacked. |
| KIMSUKY | Kimsuky | This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes. |
| Kinsing | Kinsing | This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear… |
| KINSING | Kinsing | This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear… |
| Kiss-a-Dog | Kiss-a-Dog | CrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and… |
| KISS-A-DOG | Kiss-a-Dog | CrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and… |
| KromSec | KromSec | KromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi… |
| KROMSEC | KromSec | KromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi… |
| Krybit | Krybit | Krybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support … |
| KRYBIT | Krybit | Krybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support … |
| LabHost | LabHost | LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re… |
| LABHOST | LabHost | LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re… |
| Lamashtu | Lamashtu | Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun… |
| LAMASHTU | Lamashtu | Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun… |
| Lancefly | Lancefly | Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a… |
| LANCEFLY | Lancefly | Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a… |
| LAPSUS | LAPSUS | LAPSUS is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LAPSUS$, DEV-0537, SLIPPY SPIDER (and 3 more). Original rec… |
| LAPSUS | LAPSUS | An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive element… |
| Larva-208 | Larva-208 | LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi… |
| LARVA-208 | Larva-208 | LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi… |
| LARVA-24005 | Larva-24005 | Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individual… |
| LARVA-24009 | Larva-24009 | Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The acto… |
| Larva-24010 | Larva-24010 | The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst… |
| LARVA-24010 | Larva-24010 | The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst… |
| Larva-26002 | Larva-26002 | Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona… |
| LARVA-26002 | Larva-26002 | Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona… |
| LARVA-26005 | Larva-26005 | Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found d… |
| LARVA-26009 | Larva-26009 | Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner. |
| LARVA-26010 | Larva-26010 | Larva-26010 targets web servers and MS-SQL servers in Korea to install SoftEther VPN, using the systems as VPN servers. After the initial breach, the actor ins… |
| Larva‑25012 | Larva‑25012 | Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows… |
| LARVA-25012 | Larva‑25012 | Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows… |
| LAZARUS-GROUP | Lazarus Group | Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltratio… |
| LIBYAN-SCORPIONS | Libyan Scorpions | Libyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is intelligence gatherin… |
| Lifting Zmiy | Lifting Zmiy | Rostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t… |
| LIFTING-ZMIY | Lifting Zmiy | Rostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t… |
| LightBasin | LightBasin | UNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise… |
| LIGHTBASIN | LightBasin | UNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise… |
| LILAC-TYPHOON | Lilac Typhoon | Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a… |
| LilacSquid | LilacSquid | LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised… |
| LILACSQUID | LilacSquid | LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised… |
| LIMINAL-PANDA | LIMINAL PANDA | LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d… |
| LinkC Pub | LinkC Pub | Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H… |
| LINKC-PUB | LinkC Pub | Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H… |
| LofyGang | LofyGang | LofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope… |
| LOFYGANG | LofyGang | LofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope… |
| LONGHORN | Longhorn | Longhorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh… |
| LONGNOSEDGOBLIN | LongNosedGoblin | LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for… |