2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,251–1,300 of 1,596 in Other · page 26 of 32
| ID | Title | Summary |
|---|---|---|
| TAG-124 | TAG-124 | TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting various sectors through p… |
| TAG-124 | TAG-124 | TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting various sectors through p… |
| TAG-140 | TAG-140 | TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and malware campaigns. Th… |
| TAG-28 | TAG-28 | TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have… |
| TAG-56 | TAG-56 | TAG-56 is a threat actor group that shares similarities with the APT42 group. They use tactics such as fake registration pages and spearphishing to target vict… |
| Taidoor | Taidoor | The Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Ta… |
| TAIDOOR | Taidoor | The Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Ta… |
| TASKMASTERS | TaskMasters | TaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia… |
| Team-Xecuter | Team-Xecuter | Team-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA. They were involved in a piracy conspiracy against Nintendo, creating and selling ill… |
| TEAM-XECUTER | Team-Xecuter | Team-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA. They were involved in a piracy conspiracy against Nintendo, creating and selling ill… |
| Team46 | Team46 | Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations through spearphishing emai… |
| TEAM46 | Team46 | Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations through spearphishing emai… |
| TeamPCP | TeamPCP | TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and L… |
| TEAMPCP | TeamPCP | TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and L… |
| TEAMSPY-CREW | TeamSpy Crew | Researchers have uncovered a long-term cyber-espionage campaign that used a combination of legitimate software packages and commodity malware tools to target a… |
| TeamTNT | TeamTNT | In early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Do… |
| TEAMTNT | TeamTNT | In early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Do… |
| TeamXRat | TeamXRat | TeamXRat is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as CorporacaoXRat, CorporationXRat. |
| TEAMXRAT | TeamXRat | |
| TELEBOYI | Teleboyi | Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a si… |
| TEMP-HERETIC | TEMP_Heretic | TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Z… |
| TEMP-HERMIT | TEMP.Hermit | |
| TEMP.Veles | TEMP.Veles | TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed… |
| TEMP-VELES | TEMP.Veles | TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed… |
| TEMPER-PANDA | TEMPER PANDA | China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in finan… |
| TEMPTICK | TempTick | This threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media organizations in East Asi… |
| TERBIUM | TERBIUM | Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to … |
| TERBIUM | TERBIUM | Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to … |
| TEST-PANDA | TEST PANDA | |
| TetrisPhantom | TetrisPhantom | TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh… |
| TETRISPHANTOM | TetrisPhantom | TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh… |
| The Big Bang | The Big Bang | While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona… |
| THE-BIG-BANG | The Big Bang | While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona… |
| The Gentlemen | The Gentlemen | The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi… |
| THE-GENTLEMEN | The Gentlemen | The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi… |
| The Gorgon Group | The Gorgon Group | Unit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon… |
| THE-GORGON-GROUP | The Gorgon Group | Unit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon… |
| The Shadow Brokers | The Shadow Brokers | The Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se… |
| THE-SHADOW-BROKERS | The Shadow Brokers | The Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se… |
| TheDarkOverlord | TheDarkOverlord | TheDarkOverlord is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The Dark Overlord is a financially motivated ransomware group … |
| THEDARKOVERLORD | TheDarkOverlord | The Dark Overlord is a financially motivated ransomware group that has been active since 2016. The group is known for targeting large organizations, including … |
| THEHATMAN | TheHatman | TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, includi… |
| TheWizards | TheWizards | TheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti… |
| THEWIZARDS | TheWizards | TheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti… |
| Threat Actor 888 | Threat Actor 888 | Threat Actor 888 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Threat actor 888 is a hacker active in 2024, targeting compan… |
| THREAT-ACTOR-888 | Threat Actor 888 | Threat actor 888 is a hacker active in 2024, targeting companies for data breaches. They've hit Microsoft, BMW (Hong Kong), and others in tech, freight, and oi… |
| Threatsec | Threatsec | ThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f… |
| THREATSEC | Threatsec | ThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f… |
| Thrip | Thrip | Thrip is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0076, ATK78. Operational targeting focuses on the Private s… |
| THRIP | Thrip | This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and S… |