2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,251–1,300 of 1,596 in Other · page 26 of 32

IDTitleSummary
TAG-124TAG-124TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting various sectors through p…
TAG-124TAG-124TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting various sectors through p…
TAG-140TAG-140TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and malware campaigns. Th…
TAG-28TAG-28TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have…
TAG-56TAG-56TAG-56 is a threat actor group that shares similarities with the APT42 group. They use tactics such as fake registration pages and spearphishing to target vict…
TaidoorTaidoorThe Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Ta…
TAIDOORTaidoorThe Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Ta…
TASKMASTERSTaskMastersTaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia…
Team-XecuterTeam-XecuterTeam-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA. They were involved in a piracy conspiracy against Nintendo, creating and selling ill…
TEAM-XECUTERTeam-XecuterTeam-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA. They were involved in a piracy conspiracy against Nintendo, creating and selling ill…
Team46Team46Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations through spearphishing emai…
TEAM46Team46Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations through spearphishing emai…
TeamPCPTeamPCPTeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and L…
TEAMPCPTeamPCPTeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and L…
TEAMSPY-CREWTeamSpy CrewResearchers have uncovered a long-term cyber-espionage campaign that used a combination of legitimate software packages and commodity malware tools to target a…
TeamTNTTeamTNTIn early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Do…
TEAMTNTTeamTNTIn early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Do…
TeamXRatTeamXRatTeamXRat is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as CorporacaoXRat, CorporationXRat.
TEAMXRATTeamXRat
TELEBOYITeleboyiTeleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a si…
TEMP-HERETICTEMP_HereticTEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Z…
TEMP-HERMITTEMP.Hermit
TEMP.VelesTEMP.VelesTEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed…
TEMP-VELESTEMP.VelesTEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed…
TEMPER-PANDATEMPER PANDAChina-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in finan…
TEMPTICKTempTickThis threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media organizations in East Asi…
TERBIUMTERBIUMMicrosoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to …
TERBIUMTERBIUMMicrosoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to …
TEST-PANDATEST PANDA
TetrisPhantomTetrisPhantomTetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh…
TETRISPHANTOMTetrisPhantomTetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh…
The Big BangThe Big BangWhile it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona…
THE-BIG-BANGThe Big BangWhile it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona…
The GentlemenThe GentlemenThe Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi…
THE-GENTLEMENThe GentlemenThe Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi…
The Gorgon GroupThe Gorgon GroupUnit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon…
THE-GORGON-GROUPThe Gorgon GroupUnit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon…
The Shadow BrokersThe Shadow BrokersThe Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se…
THE-SHADOW-BROKERSThe Shadow BrokersThe Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se…
TheDarkOverlordTheDarkOverlordTheDarkOverlord is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The Dark Overlord is a financially motivated ransomware group …
THEDARKOVERLORDTheDarkOverlordThe Dark Overlord is a financially motivated ransomware group that has been active since 2016. The group is known for targeting large organizations, including …
THEHATMANTheHatmanTheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, includi…
TheWizardsTheWizardsTheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti…
THEWIZARDSTheWizardsTheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti…
Threat Actor 888Threat Actor 888Threat Actor 888 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Threat actor 888 is a hacker active in 2024, targeting compan…
THREAT-ACTOR-888Threat Actor 888Threat actor 888 is a hacker active in 2024, targeting companies for data breaches. They've hit Microsoft, BMW (Hong Kong), and others in tech, freight, and oi…
ThreatsecThreatsecThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f…
THREATSECThreatsecThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f…
ThripThripThrip is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0076, ATK78. Operational targeting focuses on the Private s…
THRIPThripThis threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and S…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base