2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 901–950 of 1,596 in Other · page 19 of 32

IDTitleSummary
PREDATORY-SPARROWPredatory SparrowA self-proclaimed hacktivist group that carried out attacks against Iranian railway systems and against Iranian steel plants.
ProCCProCCProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017…
PROCCProCCProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017…
PROJECTSAURONProjectSauronProjectSauron is the name for a top level modular cyber-espionage platform, designed to enable and manage long-term campaigns through stealthy survival mechani…
Prolific PumaProlific PumaProlific Puma provides an underground link shortening service to criminals. Infoblox states that during analysis, no legitimate content was observed being serv…
PROLIFIC-PUMAProlific PumaProlific Puma provides an underground link shortening service to criminals. Infoblox states that during analysis, no legitimate content was observed being serv…
PROMETHIUMPROMETHIUMPROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation fo…
Prophet SpiderProphet SpiderPROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonl…
PROPHET-SPIDERProphet SpiderPROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonl…
PUNK-003puNK-003puNK-003 is a North Korean APT group known for deploying the Lilith RAT, a sophisticated C++ remote access trojan, and its AutoIt variant, CURKON, which functi…
PURPLEHAZEPurpleHazePurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors such as telecommunicatio…
QTFYQTFYQTFY is a state-sponsored group from the People's Republic of China, operating as an infrastructure quartermaster that provides reconnaissance, access, and obf…
QUILTED-TIGERQUILTED TIGERDropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and eco…
R00TK1TR00tK1TR00TK1T is a hacking group known for sophisticated cyber attacks targeting governmental agencies in Malaysia, including data exfiltration from the National Pop…
RADIO-PANDARADIO PANDA
RAHDITRaHDitRaHDit is a pro-Kremlin hacktivist group known for orchestrating hack-and-leak operations, including the publication of personal information about Ukrainian mi…
RANCORRANCORThe Rancor group’s attacks use two primary malware families which are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears t…
RansomHouseRansomHouseThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
RANSOMHOUSERansomHouseThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
RansomHubRansomHubRansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware. They have been linked to attacks exploiting t…
RANSOMHUBRansomHubRansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware. They have been linked to attacks exploiting t…
RansomVCRansomVCRansomed.VC burst onto the scene with a well-orchestrated PR campaign, encompassing a clearnet site and multiple communication channels including Telegram and …
RANSOMVCRansomVCRansomed.VC burst onto the scene with a well-orchestrated PR campaign, encompassing a clearnet site and multiple communication channels including Telegram and …
RASPBERRY-TYPHOONRaspberry TyphoonMicrosoft has tracked Raspberry Typhoon (RADIUM) as the primary threat group targeting nations that ring the South China Sea. Raspberry Typhoon consistently ta…
RASPITERASPITEDragos has identified a new activity group targeting access operations in the electric utility sector. We call this activity group RASPITE. Analysis of RASPIT…
RASPITERASPITEDragos has identified a new activity group targeting access operations in the electric utility sector. We call this activity group RASPITE. Analysis of RASPIT…
RATPAK SPIDERRATPAK SPIDERIn July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s …
RATPAK-SPIDERRATPAK SPIDERIn July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s …
RAZOR-TIGERRAZOR TIGERAn actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian compan…
REBEL-JACKALRebel JackalThis is a pro-Islamist organization that generally conducts attacks motivated by real world events in which its members believe that members of the Muslim fait…
Reckless RabbitReckless RabbitReckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with embedded web forms for perso…
RECKLESS-RABBITReckless RabbitReckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with embedded web forms for perso…
Red CharonRed CharonThroughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks havi…
RED-CHARONRed CharonThroughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks havi…
RED-DEV-17Red Dev 17In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat acto…
RED-MENSHENRed MenshenSince 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East and Asia, as well as…
RED-NUERed NueRed Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows…
Red-LiliRed-LiliRED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platfo…
RED-LILIRed-LiliRED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platfo…
RedAlphaRedAlphaRecorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we…
REDALPHARedAlphaRecorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we…
RedDeltaRedDeltaLikely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX …
REDDELTARedDeltaLikely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX …
RedEchoRedEchoRedEcho is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: RedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we us…
REDECHORedEchoRedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we use to track infrastructure that comprises ShadowPad C2s, which is shared between several C…
RedflyRedflyRedfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evi…
REDFLYRedflyRedfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evi…
REDGOLFRedGolfRecorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KE…
REDJULIETTRedJuliettRedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in Taiwan. They exploit vu…
RedKittenRedKittenRedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The mal…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base