2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,001–1,050 of 1,596 in Other · page 21 of 32
| ID | Title | Summary |
|---|---|---|
| SCARLET-MIMIC | Scarlet Mimic | Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group’s mo… |
| SCARLETEEL | SCARLETEEL | SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and … |
| SCARLETEEL | SCARLETEEL | SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and … |
| SCARRED-MANTICORE | Scarred Manticore | Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety… |
| SCATTERED-CANARY | Scattered Canary | When the first member of Scattered Canary, who, for the purposes of this report, we call Alpha, began his operations, he was a lone wolf—working mostly Craigsl… |
| SCATTERED-LAPSUS-HUNTERS | Scattered Lapsus Hunters | Launched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on today’s cybercriminal… |
| Scattered Spider | Scattered Spider | Scattered Spider is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC3944, Muddled Libra, Oktapus (and 7 more). Ori… |
| SCATTERED-SPIDER | Scattered Spider | Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing. |
| ScreamedJungle | ScreamedJungle | ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablo… |
| SCREAMEDJUNGLE | ScreamedJungle | ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablo… |
| Scripted Sparrow | Scripted Sparrow | Scripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating professional services… |
| SCRIPTED-SPARROW | Scripted Sparrow | Scripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating professional services… |
| SCULLY SPIDER | SCULLY SPIDER | SCULLY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SCULLY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-… |
| SCULLY-SPIDER | SCULLY SPIDER | Mentioned as operator of DanaBot in CrowdStrike's 2020 Report. |
| SEA-TURTLE | Sea Turtle | This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily nati… |
| SEXi | SEXi | SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines… |
| SEXI | SEXi | SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines… |
| Shadow Network | Shadow Network | Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer networ… |
| SHADOW-NETWORK | Shadow Network | Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer networ… |
| SHADOW-AETHER-015 | SHADOW-AETHER-015 | SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management s… |
| SHADOW-AETHER-015 | SHADOW-AETHER-015 | SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management s… |
| SHADOW-EARTH-053 | Shadow-Earth-053 | SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cybere… |
| SHADOW-VOID-042 | SHADOW-VOID-042 | SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing campaigns against energy, def… |
| SHADOW-VOID-042 | SHADOW-VOID-042 | SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing campaigns against energy, def… |
| SHADOW-WATER-063 | SHADOW-WATER-063 | SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian financial accounts. Analysi… |
| SHADOWBYT3 | ShadowByt3$ | ShadowByt3$ is a ransomware group known for exfiltrating sensitive data from various organizations, including John Engel Team, Abbott Laboratories, and Nintend… |
| ShadowSyndicate | ShadowSyndicate | ShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple servers. They have bee… |
| SHADOWSYNDICATE | ShadowSyndicate | ShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple servers. They have bee… |
| ShadyPanda | ShadyPanda | ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioni… |
| SHADYPANDA | ShadyPanda | ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioni… |
| SHAGGYPANTHER | ShaggyPanther | ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia. They have been active since 2008 and utilize hidden encrypte… |
| SHAHID-HEMMAT | Shahid Hemmat | Shahid Hemmat is an IRGC-CEC affiliated hacking group linked to cyberattacks targeting U.S. critical infrastructure, including the defense industry and interna… |
| SHAMOON-GROUP | Shamoon Group | Shamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle East, especially in the… |
| SHARK-SPIDER | SHARK SPIDER | This group's activity was first observed in November 2013. It leverages a banking Trojan more commonly known as Shylock which aims to compromise online banking… |
| SHARPPANDA | SharpPanda | SharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018. The APT group utilizes spear-phish… |
| ShinyHunters | ShinyHunters | ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra… |
| SHINYHUNTERS | ShinyHunters | ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra… |
| ShroudedSnooper | ShroudedSnooper | In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East… |
| SHROUDEDSNOOPER | ShroudedSnooper | In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East… |
| SIDECOPY | SideCopy | The SideCopy APT is a Pakistani threat actor that has been operating since at least 2019, mainly targeting South Asian countries and more specifically India an… |
| SiegedSec | SiegedSec | SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your… |
| SIEGEDSEC | SiegedSec | SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your… |
| Siesta | Siesta | FireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure… |
| SIESTA | Siesta | FireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure… |
| Silence group | Silence group | a relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha… |
| SILENCE-GROUP | Silence group | a relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha… |
| SILENT-CHOLLIMA | Silent Chollima | Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary … |
| SILENT-LIBRARIAN | Silent Librarian | Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. Accordi… |
| SilitNetwork | SilitNetwork | SilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach … |
| SILITNETWORK | SilitNetwork | SilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach … |