2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,001–1,050 of 1,596 in Other · page 21 of 32

IDTitleSummary
SCARLET-MIMICScarlet MimicScarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group’s mo…
SCARLETEELSCARLETEELSCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and …
SCARLETEELSCARLETEELSCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and …
SCARRED-MANTICOREScarred ManticoreScarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety…
SCATTERED-CANARYScattered CanaryWhen the first member of Scattered Canary, who, for the purposes of this report, we call Alpha, began his operations, he was a lone wolf—working mostly Craigsl…
SCATTERED-LAPSUS-HUNTERSScattered Lapsus HuntersLaunched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on today’s cybercriminal…
Scattered SpiderScattered SpiderScattered Spider is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC3944, Muddled Libra, Oktapus (and 7 more). Ori…
SCATTERED-SPIDERScattered SpiderScattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing.
ScreamedJungleScreamedJungleScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablo…
SCREAMEDJUNGLEScreamedJungleScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablo…
Scripted SparrowScripted SparrowScripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating professional services…
SCRIPTED-SPARROWScripted SparrowScripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating professional services…
SCULLY SPIDERSCULLY SPIDERSCULLY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SCULLY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-…
SCULLY-SPIDERSCULLY SPIDERMentioned as operator of DanaBot in CrowdStrike's 2020 Report.
SEA-TURTLESea TurtleThis blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily nati…
SEXiSEXiSEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines…
SEXISEXiSEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines…
Shadow NetworkShadow NetworkShadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer networ…
SHADOW-NETWORKShadow NetworkShadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer networ…
SHADOW-AETHER-015SHADOW-AETHER-015SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management s…
SHADOW-AETHER-015SHADOW-AETHER-015SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management s…
SHADOW-EARTH-053Shadow-Earth-053SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cybere…
SHADOW-VOID-042SHADOW-VOID-042SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing campaigns against energy, def…
SHADOW-VOID-042SHADOW-VOID-042SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing campaigns against energy, def…
SHADOW-WATER-063SHADOW-WATER-063SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian financial accounts. Analysi…
SHADOWBYT3ShadowByt3$ShadowByt3$ is a ransomware group known for exfiltrating sensitive data from various organizations, including John Engel Team, Abbott Laboratories, and Nintend…
ShadowSyndicateShadowSyndicateShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple servers. They have bee…
SHADOWSYNDICATEShadowSyndicateShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple servers. They have bee…
ShadyPandaShadyPandaShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioni…
SHADYPANDAShadyPandaShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioni…
SHAGGYPANTHERShaggyPantherShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia. They have been active since 2008 and utilize hidden encrypte…
SHAHID-HEMMATShahid HemmatShahid Hemmat is an IRGC-CEC affiliated hacking group linked to cyberattacks targeting U.S. critical infrastructure, including the defense industry and interna…
SHAMOON-GROUPShamoon GroupShamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle East, especially in the…
SHARK-SPIDERSHARK SPIDERThis group's activity was first observed in November 2013. It leverages a banking Trojan more commonly known as Shylock which aims to compromise online banking…
SHARPPANDASharpPandaSharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018. The APT group utilizes spear-phish…
ShinyHuntersShinyHuntersShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra…
SHINYHUNTERSShinyHuntersShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra…
ShroudedSnooperShroudedSnooperIn September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East…
SHROUDEDSNOOPERShroudedSnooperIn September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East…
SIDECOPYSideCopyThe SideCopy APT is a Pakistani threat actor that has been operating since at least 2019, mainly targeting South Asian countries and more specifically India an…
SiegedSecSiegedSecSiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your…
SIEGEDSECSiegedSecSiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your…
SiestaSiestaFireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure…
SIESTASiestaFireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure…
Silence groupSilence groupa relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha…
SILENCE-GROUPSilence groupa relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha…
SILENT-CHOLLIMASilent ChollimaAndariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary …
SILENT-LIBRARIANSilent LibrarianLast Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. Accordi…
SilitNetworkSilitNetworkSilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach …
SILITNETWORKSilitNetworkSilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base