2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 851–900 of 1,596 in Other · page 18 of 32

IDTitleSummary
OROVAOrovaOrova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple companies in Hong Kong, such …
OurMineOurMineOurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r…
OURMINEOurMineOurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r…
OUTLAW SPIDEROUTLAW SPIDEROn May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi…
OUTLAW-SPIDEROUTLAW SPIDEROn May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi…
OverFlameOverFlameOverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ…
OVERFLAMEOverFlameOverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ…
OVERLORD SPIDEROVERLORD SPIDEROVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun…
OVERLORD-SPIDEROVERLORD SPIDEROVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun…
Pacha GroupPacha GroupAntd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a …
PACHA-GROUPPacha GroupAntd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a …
PackratPackratA threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician…
PACKRATPackratA threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician…
PALE-PANDAPALE PANDA
PARINACOTAPARINACOTAOne actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i…
PARINACOTAPARINACOTAOne actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i…
PASSCVPassCVThe PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. S…
Patched LightningPatched LightningPatched Lightning is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Storm-0113. Original record: Patched Lightning i…
PATCHED-LIGHTNINGPatched Lightning
PayToolPayToolPayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e…
PAYTOOLPayToolPayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e…
PEARL-SLEETPearl SleetPearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, m…
People's Cyber Army of RussiaPeople's Cyber Army of RussiaPeople's Cyber Army of Russia is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as People's Cyber Army of Russia.
PEOPLE-S-CYBER-ARMY-OF-RUSSIAPeople's Cyber Army of Russia
PERSWAYSIONPerSwaysionPerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are…
PhantomControlPhantomControlPhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree…
PHANTOMCONTROLPhantomControlPhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree…
Phlox TempestPhlox TempestPhlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL…
PHLOX-TEMPESTPhlox TempestPhlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL…
PickaxePickaxePrying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t…
PICKAXEPickaxePrying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t…
PINCHY SPIDERPINCHY SPIDERFirst observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the …
PINCHY-SPIDERPINCHY SPIDERFirst observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the …
PINK-SANDSTORMPink SandstormAgonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima…
PINSTRIPE-LIGHTNINGPinstripe LightningMicrosoft threat actor profile from the public naming mapping feed.
PIZZO-SPIDERPIZZO SPIDER
PLATINUMPLATINUMPLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ…
PLATINUMPLATINUMPLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ…
PLUSHDAEMONPlushDaemonPlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat…
POISON CARPPOISON CARPBetween November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p…
POISON-CARPPOISON CARPBetween November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p…
PoisonSeedPoisonSeedPoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra…
POISONSEEDPoisonSeedPoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra…
POISONUS-PANDAPOISONUS PANDA
POLONIUMPOLONIUMMicrosoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell…
POSEIDON-GROUPPoseidon GroupPoseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi…
PowerPoolPowerPoolMalware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability…
POWERPOOLPowerPoolMalware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability…
PREDATOR-PANDAPREDATOR PANDA
Predatory SparrowPredatory SparrowPredatory Sparrow is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Indra, Gonjeshke Darande. Operational targeting …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.