2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 651–700 of 1,596 in Other · page 14 of 32

IDTitleSummary
Keymous+Keymous+Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur…
KEYMOUSKeymous+Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur…
KillnetKillnetKillnet is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisations…
KILLNETKillnetA group targeting various countries using Denial of Services attacked.
KIMSUKYKimsukyThis threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
KinsingKinsingThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
KINSINGKinsingThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
Kiss-a-DogKiss-a-DogCrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and…
KISS-A-DOGKiss-a-DogCrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and…
KromSecKromSecKromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi…
KROMSECKromSecKromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi…
KrybitKrybitKrybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support …
KRYBITKrybitKrybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support …
LabHostLabHostLabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re…
LABHOSTLabHostLabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re…
LamashtuLamashtuLamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun…
LAMASHTULamashtuLamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun…
LanceflyLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LANCEFLYLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LAPSUSLAPSUSLAPSUS is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LAPSUS$, DEV-0537, SLIPPY SPIDER (and 3 more). Original rec…
LAPSUSLAPSUSAn actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive element…
Larva-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
LARVA-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
LARVA-24005Larva-24005Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individual…
LARVA-24009Larva-24009Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The acto…
Larva-24010Larva-24010The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst…
LARVA-24010Larva-24010The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst…
Larva-26002Larva-26002Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona…
LARVA-26002Larva-26002Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona…
LARVA-26005Larva-26005Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found d…
LARVA-26009Larva-26009Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
LARVA-26010Larva-26010Larva-26010 targets web servers and MS-SQL servers in Korea to install SoftEther VPN, using the systems as VPN servers. After the initial breach, the actor ins…
Larva‑25012Larva‑25012Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows…
LARVA-25012Larva‑25012Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows…
LAZARUS-GROUPLazarus GroupSince 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltratio…
LIBYAN-SCORPIONSLibyan ScorpionsLibyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is intelligence gatherin…
Lifting ZmiyLifting ZmiyRostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t…
LIFTING-ZMIYLifting ZmiyRostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t…
LightBasinLightBasinUNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise…
LIGHTBASINLightBasinUNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise…
LILAC-TYPHOONLilac TyphoonLilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a…
LilacSquidLilacSquidLilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised…
LILACSQUIDLilacSquidLilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised…
LIMINAL-PANDALIMINAL PANDALIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d…
LinkC PubLinkC PubLinkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H…
LINKC-PUBLinkC PubLinkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H…
LofyGangLofyGangLofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope…
LOFYGANGLofyGangLofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope…
LONGHORNLonghornLonghorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh…
LONGNOSEDGOBLINLongNosedGoblinLongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.