2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 751–800 of 1,546 in Other · page 16 of 31

IDTitleSummary
NARWHAL SPIDERNARWHAL SPIDERNARWHAL SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as GOLD ESSEX, TA544, Storm-0302. Original record: NAR…
NARWHAL-SPIDERNARWHAL SPIDERNARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by brin…
NatohubNatohubNatohub is a hacker who claimed to have stolen 42,000 documents from the UN’s International Civil Aviation Organization and is offering the data for sale on un…
NATOHUBNatohubNatohub is a hacker who claimed to have stolen 42,000 documents from the UN’s International Civil Aviation Organization and is offering the data for sale on un…
NazarNazarThis actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation' leak. Earliest known si…
NAZARNazarThis actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation' leak. Earliest known si…
NB65NB65NB65 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Network Battalion 65. Original record: Network Battalion 65 i…
NB65NB65Network Battalion 65 is an hactivist group with ties to Anonymous, known for attacking Russian companies and performing hack-and-leak operations.
NEODYMIUMNEODYMIUMNEODYMIUM is an activity group that is known to use a backdoor malware detected by Microsoft as Wingbird. This backdoor’s characteristics closely match FinFish…
NEODYMIUMNEODYMIUMNEODYMIUM is an activity group that is known to use a backdoor malware detected by Microsoft as Wingbird. This backdoor’s characteristics closely match FinFish…
NetRunnerPRNetRunnerPRNetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan, exfiltrating patient PII and me…
NETRUNNERPRNetRunnerPRNetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan, exfiltrating patient PII and me…
NewsPenguinNewsPenguinNewsPenguin is threat actor that has been targeting organizations in Pakistan. They use a complex payload delivery mechanism and exploit the upcoming Pakistan …
NEWSPENGUINNewsPenguinNewsPenguin is threat actor that has been targeting organizations in Pakistan. They use a complex payload delivery mechanism and exploit the upcoming Pakistan …
Nexus ZetaNexus ZetaNexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP …
NEXUS-ZETANexus ZetaNexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP …
NICKEL-ALLEYNickel AlleyNICKEL ALLEY is a North Korean threat group that targets technology professionals through fake job opportunities, employing social engineering tactics such as …
NIGHT-DRAGONNight Dragon
NIGHTEAGLENightEagleNightEagle is an advanced Threat Actor that targeted China's High-Tech Industry and Military Organisation, leveraging sophisticated techniques, 0 days, and spe…
NITRONitroThese attackers were the subject of an extensive report by Symantec in 2011, which termed the attackers Nitro and stated: 'The goal of the attackers appears to…
NOCTURNAL SPIDERNOCTURNAL SPIDERNOCTURNAL SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: NOCTURNAL SPIDER is a threat actor catalogued by MISP-Galaxy …
NOCTURNAL-SPIDERNOCTURNAL SPIDERMentioned as MaaS operator in CrowdStrike's 2020 Report.
NOMAD PANDANOMAD PANDANOMAD PANDA is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: In the first quarter of 2018, CrowdStrike Intelligence identified …
NOMAD-PANDANOMAD PANDAIn the first quarter of 2018, CrowdStrike Intelligence identified NOMAD PANDA activity targeting Central Asian nations with exploit documents built with the 8.…
NoName057(16)NoName057(16)NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications companies, transportation a…
NONAME057-16NoName057(16)NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications companies, transportation a…
NOTROBINNOTROBINResearchers at FireEye report finding a hacking group (dubbed NOTROBIN) that has been bundling mitigation code for NetScaler servers with its exploits. In effe…
NOTROBINNOTROBINResearchers at FireEye report finding a hacking group (dubbed NOTROBIN) that has been bundling mitigation code for NetScaler servers with its exploits. In effe…
NullbulgeNullbulgeNullBulge is a cybercriminal threat group targeting AI and gaming focused entities. They weaponize code in publicly available repositories to distribute malwar…
NULLBULGENullbulgeNullBulge is a cybercriminal threat group targeting AI and gaming focused entities. They weaponize code in publicly available repositories to distribute malwar…
NyxarGroupNyxarGroupNyxarGroup is a threat actor involved in a coordinated data brokerage ecosystem across Latin America, primarily targeting government infrastructure. They have …
NYXARGROUPNyxarGroupNyxarGroup is a threat actor involved in a coordinated data brokerage ecosystem across Latin America, primarily targeting government infrastructure. They have …
OilAlphaOilAlphaOilAlpha has almost exclusively relied on infrastructure associated with the Public Telecommunication Corporation (PTC), a Yemeni government-owned enterprise r…
OILALPHAOilAlphaOilAlpha has almost exclusively relied on infrastructure associated with the Public Telecommunication Corporation (PTC), a Yemeni government-owned enterprise r…
OILRIGOilRigOilRig is an Iranian threat group operating primarily in the Middle East by targeting organizations in this region that are in a variety of different industrie…
OLDGREMLINOldGremlinOldGremlin is a Russian-speaking ransomware group that has been active for several years. They primarily target organizations in Russia, including banks, logis…
ONIONDOGOnionDogThis threat actor targets the South Korean government, transportation, and energy sectors.
OPAL-SLEETOpal SleetKonni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activ…
OPERATION-BUGDROPOperation BugDropThis threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine. The threat actors deploy the BugDrop malware to rem…
OPERATION-C-MAJOROperation C-MajorGroup targeting Indian Army or related assets in India, as well as activists and civil society in Pakistan. Attribution to a Pakistani connection has been made…
Operation Cobalt WhisperOperation Cobalt Whisper
OPERATION-COBALT-WHISPEROperation Cobalt Whisper
Operation ComandoOperation ComandoOperation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves h…
OPERATION-COMANDOOperation ComandoOperation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves h…
OPERATION-DRBCONTROLOperation DRBControlOperation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of H…
OPERATION-EMMENTALOperation EmmentalOperation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks i…
Operation ForumTrollOperation ForumTrollOperation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Go…
OPERATION-FORUMTROLLOperation ForumTrollOperation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Go…
Operation GhoulOperation GhoulOperation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and engineering sectors. They…
OPERATION-GHOULOperation GhoulOperation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and engineering sectors. They…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.