2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 851–900 of 1,596 in Other · page 18 of 32
| ID | Title | Summary |
|---|---|---|
| OROVA | Orova | Orova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple companies in Hong Kong, such … |
| OurMine | OurMine | OurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r… |
| OURMINE | OurMine | OurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r… |
| OUTLAW SPIDER | OUTLAW SPIDER | On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi… |
| OUTLAW-SPIDER | OUTLAW SPIDER | On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi… |
| OverFlame | OverFlame | OverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ… |
| OVERFLAME | OverFlame | OverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ… |
| OVERLORD SPIDER | OVERLORD SPIDER | OVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun… |
| OVERLORD-SPIDER | OVERLORD SPIDER | OVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun… |
| Pacha Group | Pacha Group | Antd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a … |
| PACHA-GROUP | Pacha Group | Antd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a … |
| Packrat | Packrat | A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician… |
| PACKRAT | Packrat | A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician… |
| PALE-PANDA | PALE PANDA | |
| PARINACOTA | PARINACOTA | One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i… |
| PARINACOTA | PARINACOTA | One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i… |
| PASSCV | PassCV | The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. S… |
| Patched Lightning | Patched Lightning | Patched Lightning is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Storm-0113. Original record: Patched Lightning i… |
| PATCHED-LIGHTNING | Patched Lightning | |
| PayTool | PayTool | PayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e… |
| PAYTOOL | PayTool | PayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e… |
| PEARL-SLEET | Pearl Sleet | Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, m… |
| People's Cyber Army of Russia | People's Cyber Army of Russia | People's Cyber Army of Russia is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as People's Cyber Army of Russia. |
| PEOPLE-S-CYBER-ARMY-OF-RUSSIA | People's Cyber Army of Russia | |
| PERSWAYSION | PerSwaysion | PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are… |
| PhantomControl | PhantomControl | PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree… |
| PHANTOMCONTROL | PhantomControl | PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree… |
| Phlox Tempest | Phlox Tempest | Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL… |
| PHLOX-TEMPEST | Phlox Tempest | Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL… |
| Pickaxe | Pickaxe | Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t… |
| PICKAXE | Pickaxe | Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t… |
| PINCHY SPIDER | PINCHY SPIDER | First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the … |
| PINCHY-SPIDER | PINCHY SPIDER | First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the … |
| PINK-SANDSTORM | Pink Sandstorm | Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima… |
| PINSTRIPE-LIGHTNING | Pinstripe Lightning | Microsoft threat actor profile from the public naming mapping feed. |
| PIZZO-SPIDER | PIZZO SPIDER | |
| PLATINUM | PLATINUM | PLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ… |
| PLATINUM | PLATINUM | PLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ… |
| PLUSHDAEMON | PlushDaemon | PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat… |
| POISON CARP | POISON CARP | Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p… |
| POISON-CARP | POISON CARP | Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p… |
| PoisonSeed | PoisonSeed | PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra… |
| POISONSEED | PoisonSeed | PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra… |
| POISONUS-PANDA | POISONUS PANDA | |
| POLONIUM | POLONIUM | Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell… |
| POSEIDON-GROUP | Poseidon Group | Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi… |
| PowerPool | PowerPool | Malware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability… |
| POWERPOOL | PowerPool | Malware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability… |
| PREDATOR-PANDA | PREDATOR PANDA | |
| Predatory Sparrow | Predatory Sparrow | Predatory Sparrow is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Indra, Gonjeshke Darande. Operational targeting … |