2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 901–950 of 1,546 in Other · page 19 of 31

IDTitleSummary
RECKLESS-RABBITReckless RabbitReckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with embedded web forms for perso…
Red CharonRed CharonThroughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks havi…
RED-CHARONRed CharonThroughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks havi…
RED-DEV-17Red Dev 17In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat acto…
RED-MENSHENRed MenshenSince 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East and Asia, as well as…
RED-NUERed NueRed Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows…
Red-LiliRed-LiliRED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platfo…
RED-LILIRed-LiliRED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platfo…
RedAlphaRedAlphaRecorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we…
REDALPHARedAlphaRecorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we…
RedDeltaRedDeltaLikely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX …
REDDELTARedDeltaLikely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX …
RedEchoRedEchoRedEcho is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: RedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we us…
REDECHORedEchoRedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we use to track infrastructure that comprises ShadowPad C2s, which is shared between several C…
RedflyRedflyRedfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evi…
REDFLYRedflyRedfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evi…
REDGOLFRedGolfRecorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KE…
REDJULIETTRedJuliettRedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in Taiwan. They exploit vu…
RedKittenRedKittenRedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The mal…
REDKITTENRedKittenRedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The mal…
RedStingerRedStingerIn October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crim…
REDSTINGERRedStingerIn October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crim…
REF2924REF2924A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the resear…
REF5961REF5961Elastic's security team has published a report on REF5961, a cyber-espionage group they found on the network of a Foreign Affairs Ministry from a member of the…
REF5961REF5961Elastic's security team has published a report on REF5961, a cyber-espionage group they found on the network of a Foreign Affairs Ministry from a member of the…
REF7707REF7707REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families such as FinalDraft, Gui…
ResumeLootersResumeLootersSince the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites. The group employs a variety of simple techniques, including SQL i…
RESUMELOOTERSResumeLootersSince the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites. The group employs a variety of simple techniques, including SQL i…
Returned LibraReturned LibraReturned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017. Tools commonly employed during their o…
RETURNED-LIBRAReturned LibraReturned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017. Tools commonly employed during their o…
RevengeHotelsRevengeHotelsRevengeHotels is a targeted cybercrime campaign that has been active since 2015, primarily targeting hotels, hostels, and tourism companies. The threat actor u…
REVENGEHOTELSRevengeHotelsRevengeHotels is a targeted cybercrime campaign that has been active since 2015, primarily targeting hotels, hostels, and tourism companies. The threat actor u…
RGB-TEAMRGB-TEAMRGB-TEAM is a previously unknown Russian-speaking threat actor. They describe themselves as “a community of anonymous hacktivists fighting for freedom.” The gr…
RGB-TEAMRGB-TEAMRGB-TEAM is a previously unknown Russian-speaking threat actor. They describe themselves as “a community of anonymous hacktivists fighting for freedom.” The gr…
RIDDLE SPIDERRIDDLE SPIDERRIDDLE SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: RIDDLE SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-…
RIDDLE-SPIDERRIDDLE SPIDERAccording to Crowdstrike, RIDDLE SPIDER is the operator behind the avaddon ransomware
RIPPERSECRipperSecRipperSec is a pro-Palestinian, likely Malaysian hacktivist group created in June 2023, known for conducting DDoS attacks, data breaches, and defacements prima…
Roaming MantisRoaming MantisAccording to new research by Kaspersky's GReAT team, the online criminal activities of the Roaming Mantis Group have continued to evolve since they were first …
ROAMING-MANTISRoaming MantisAccording to new research by Kaspersky's GReAT team, the online criminal activities of the Roaming Mantis Group have continued to evolve since they were first …
Roaming TigerRoaming TigerRoaming Tiger is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as BRONZE WOODLAND, Rotten Tomato. Original record: Roa…
ROAMING-TIGERRoaming Tiger
RockeRockeThis threat actor initially came to our attention in April 2018, leveraging both Western and Chinese Git repositories to deliver malware to honeypot systems vu…
ROCKERockeThis threat actor initially came to our attention in April 2018, leveraging both Western and Chinese Git repositories to deliver malware to honeypot systems vu…
ROCKET-KITTENRocket KittenTargets Saudi Arabia, Israel, US, Iran, high ranking defense officials, embassies of various target countries, notable Iran researchers, human rights activists…
ROMCOMRomComROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially motivated attacks. They ha…
RTMRTMThere are several groups actively and profitably targeting businesses in Russia. A trend that we have seen unfold before our eyes lately is these cybercriminal…
RTMRTMThere are several groups actively and profitably targeting businesses in Russia. A trend that we have seen unfold before our eyes lately is these cybercriminal…
RUBY-SLEETRuby SleetRuby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, an…
RUBYCARPRUBYCARPRUBYCARP is a financially-motivated threat actor group likely based in Romania, with a history of at least 10 years of activity. They operate a botnet using pu…
RUSKINETRuskiNetRuskiNet is a pro-Russian hacktivist collective associated with disruptive operations including DDoS attacks, website defacements, phishing, and data leaks aga…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base