2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 51–100 of 1,546 in Other · page 2 of 31

IDTitleSummary
APT10APT10menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Min…
APT12APT12A group of China-based attackers, who conducted a number of spear phishing attacks in 2013.
APT14APT14PLA Navy Anchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and military maritime operations in t…
APT15APT15This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
APT16APT16Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and Taiw…
APT17APT17FireEye described APT17 in a 2015 report as: 'APT17, also known as DeputyDog, is a China based threat group that FireEye Intelligence has observed conducting n…
APT18APT18Wekby was described by Palo Alto Networks in a 2015 report as: 'Wekby is a group that has been active for a number of years, targeting various industries such …
APT19APT19Adversary group targeting financial, technology, non-profit organisations.
APT2APT2Putter Panda were the subject of an extensive report by CrowdStrike, which stated: 'The CrowdStrike Intelligence team has been tracking this particular unit si…
APT20APT20We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer. Watering hole attacks are an increasingl…
APT21APT21
APT22APT22Suckfly is a China-based threat group that has been active since at least 2014
APT23APT23TrendMicro described Tropic Trooper in a 2015 report as: 'Taiwan and the Philippines have become the targets of an ongoing campaign called Operation TropicTroo…
APT24APT24The Pitty Tiger group has been active since at least 2011. They have been seen using HeartBleed vulnerability in order to directly get valid credentials
APT26APT26
APT27APT27A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.
APT28APT28The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely op…
APT29APT29A 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been work…
APT3APT3Symantec described UPS in 2016 report as: 'Buckeye (also known as APT3, Gothic Panda, UPS Team, and TG-0110) is a cyberespionage group that is believed to hav…
APT30APT30APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appe…
APT31APT31FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competeti…
APT32APT32Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple indust…
APT33APT33Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of …
APT35APT35FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government th…
APT37APT37APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its …
APT39APT39APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a group publicly referred to as "…
APT4APT4
APT40APT40Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-stand…
APT41APT41APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially ou…
APT42APT42Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against individuals and organizations o…
APT43APT43• APT43 is a prolific cyber operator that supports the interests of the North Korean regime. The group combines moderately-sophisticated technical capabilities…
APT43APT43• APT43 is a prolific cyber operator that supports the interests of the North Korean regime. The group combines moderately-sophisticated technical capabilities…
APT45APT45APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and …
APT5APT5We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than half of the organizations we…
APT6APT6The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems as far back as 2011 …
APT73APT73APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that…
APT73APT73APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that…
APT9APT9APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within…
APTIRANAPTIranAPTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of government ministries, hospi…
ArcaneDoorArcaneDoorArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these actor…
ARCANEDOORArcaneDoorArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these actor…
ARIDVIPERAridViperAridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a focus on Israel and Palestine…
ASLAN-NEFERLER-TIMAslan Neferler TimTurkish nationalist hacktivist group that has been active for roughly one year. According to Domaintools, the group’s site has been registered since December 2…
AsnarökAsnarökAsnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asna…
ASNAR-KAsnarökAsnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asna…
AtlasCrossAtlasCrossNSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this f…
ATLASCROSSAtlasCrossNSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this f…
AttorAttorAttor is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private sector and Government sectors. Original reco…
ATTORAttorAdversary group targeting diplomatic missions and governmental organisations.
AVIVOREAvivoreThe group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that compromise smaller engineering…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.