2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,301–1,350 of 1,596 in Other · page 27 of 32

IDTitleSummary
TIANWUTianWu
TICKTickTick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese Natio…
TIDRONETIDRONETIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers i…
TILTEDTEMPLETiltedTempleOne of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activ…
TINY SPIDERTINY SPIDERTINY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: According to CrowdStrike, this actor is using TinyLoader and TinyP…
TINY-SPIDERTINY SPIDERAccording to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
ToddyCatToddyCatToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little infor…
TODDYCATToddyCatToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little infor…
TONTO-TEAMTonto TeamTonto Team is a Chinese-speaking APT group that has been active since at least 2013. They primarily target military, diplomatic, and infrastructure organizatio…
TORTOISESHELLTortoiseshellA previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain …
TOXCAR CYBER TEAMTOXCAR CYBER TEAMThe Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing screensho…
TOXCAR-CYBER-TEAMTOXCAR CYBER TEAMThe Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing screensho…
TOXIC-PANDATOXIC PANDAA group targeting dissident groups in China and at the boundaries.
TRACER-KITTENTRACER KITTENIn April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a …
TRADERTRAITORTraderTraitorTraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administr…
TRAVELING SPIDERTRAVELING SPIDERCrowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authenticatio…
TRAVELING-SPIDERTRAVELING SPIDERCrowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authenticatio…
TridentLockerTridentLockerTridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services …
TRIDENTLOCKERTridentLockerTridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services …
TRIPLESTRENGTHTRIPLESTRENGTHTRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking, ransomware, and extortio…
TRIPLESTRENGTHTRIPLESTRENGTHTRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking, ransomware, and extortio…
TSTARKTstarkTStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit targeting CVE-2020-15069 …
TUNNELSNAKETunnelSnakeThe TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive toolset and infiltrating…
TURKHACKTEAMTurkHackTeamFounded in 2004, Turkhackteam is one of Turkey’s oldest and most high-profile hacking collectives. According to a list compiled on Turkhackteam’s forum, the gr…
TURLATurlaA 2014 Guardian article described Turla as: 'Dubbed the Turla hackers, initial intelligence had indicated western powers were key targets, but it was later det…
TwoSail JunkTwoSail JunkTwoSail Junk directs visitors to its exploit site by posting links within the threads of forum discussions, or creating new topic threads of their own. To date…
TWOSAIL-JUNKTwoSail JunkTwoSail Junk directs visitors to its exploit site by posting links within the threads of forum discussions, or creating new topic threads of their own. To date…
UAC-0006UAC-0006UAC-0006 is a financially motivated threat actor that has been active since at least 2013. They primarily target Ukrainian organizations, particularly accounta…
UAC-0006UAC-0006UAC-0006 is a financially motivated threat actor that has been active since at least 2013. They primarily target Ukrainian organizations, particularly accounta…
UAC-0020UAC-0020Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin. They have targeted Ukrainian governm…
UAC-0050UAC-0050UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine. They have been distributing the Remcos RAT malware throug…
UAC-0050UAC-0050UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine. They have been distributing the Remcos RAT malware throug…
UAC-0063UAC-0063UAC-0063 is a threat actor linked to Russian APT28, known for targeting government entities in Ukraine and Central Asia for cyber espionage operations. They ut…
UAC-0063UAC-0063UAC-0063 is a threat actor linked to Russian APT28, known for targeting government entities in Ukraine and Central Asia for cyber espionage operations. They ut…
UAC-0094UAC-0094State Service of Special Communication and Information Protection of Ukraine spotted a new wave of cyber attacks aimed at gaining access to users’ Telegram acc…
UAC-0099UAC-0099UAC-0099 is a threat actor that has been active since at least May 2023, targeting Ukrainian entities. They have been observed using a known WinRAR vulnerabili…
UAC-0099UAC-0099UAC-0099 is a threat actor that has been active since at least May 2023, targeting Ukrainian entities. They have been observed using a known WinRAR vulnerabili…
UAC-0102UAC-0102UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks. They distribute emails with HTML file attachments that redirect users to a f…
UAC-0102UAC-0102UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks. They distribute emails with HTML file attachments that redirect users to a f…
UAC-0118UAC-0118From Russia with Love, is a threat actor group that emerged during the Russia-Ukraine war in 2022. They primarily engage in DDoS attacks and have targeted crit…
UAC-0118UAC-0118From Russia with Love, is a threat actor group that emerged during the Russia-Ukraine war in 2022. They primarily engage in DDoS attacks and have targeted crit…
UAC-0149UAC-0149UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware. They use obfuscation techniques like character encoding and base64 encod…
UAC-0149UAC-0149UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware. They use obfuscation techniques like character encoding and base64 encod…
UAC-0154UAC-0154UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military. They employ a Microsoft Help file conta…
UAC-0154UAC-0154UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military. They employ a Microsoft Help file conta…
UAC-0184UAC-0184UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks. They have been observed utiliz…
UAC-0184UAC-0184UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks. They have been observed utiliz…
UAC-0185UAC-0185UAC-0185 has been active since at least 2022, primarily targeting Ukrainian defense organizations through credential theft via messaging apps like Signal, Tele…
UAC-0185UAC-0185UAC-0185 has been active since at least 2022, primarily targeting Ukrainian defense organizations through credential theft via messaging apps like Signal, Tele…
UAC-0194UAC-0194UAC-0194 is a Russian threat actor linked to the exploitation of the Windows zero-day CVE-2024-43451, which was used in attacks against Ukrainian organizations…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base