2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 101–150 of 1,546 in Other · page 3 of 31

IDTitleSummary
Awaken LikhoAwaken LikhoAwaken Likho is an APT group that has targeted Russian government agencies and industrial enterprises, employing techniques such as information gathering via s…
AWAKEN-LIKHOAwaken LikhoAwaken Likho is an APT group that has targeted Russian government agencies and industrial enterprises, employing techniques such as information gathering via s…
AYY-LD-Z-TIMAyyıldız TimAyyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002. It performs defacements and DDoS attacks against the websites of governments t…
AZZASECAzzaSecAzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various cyberattacks targeting Israel …
BackdoorDiplomacyBackdoorDiplomacyAn APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunica…
BACKDOORDIPLOMACYBackdoorDiplomacyAn APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunica…
BadRoryBadRoryKaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The cam…
BADRORYBadRoryKaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The cam…
BahamutBahamutBahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They wer…
BAHAMUTBahamutBahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They wer…
BAMBOO SPIDERBAMBOO SPIDERBAMBOO SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: BAMBOO SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-…
BAMBOO-SPIDERBAMBOO SPIDERCrowdstrike tracks the developer of Panda Zeus as BAMBOO SPIDER
BANISHED-KITTENBANISHED KITTENBANISHED KITTEN is an Iranian state-nexus adversary active since at least 2008. While the adversary’s most prominent activity is the July and September 2022 di…
BATSHADOWBatShadowBatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering campaigns, deploying the Go-base…
BazarCallBazarCallBazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into calling. It’s a technique …
BAZARCALLBazarCallBazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into calling. It’s a technique …
BEARLYFYBearlyfyBearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware st…
BEIJING-GROUPBeijing Group
BelialDemonBelialDemonBelialDemon is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Matanbuchus. Original record: BelialDemon is a threat …
BELIALDEMONBelialDemonMentioned as operator of TriumphLoader and Matanbuchus
Belsen GroupBelsen GroupThe Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configura…
BELSEN-GROUPBelsen GroupThe Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configura…
BIBIGUNBiBiGunA pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operate…
BIG-PANDABIG PANDA
BIGNOSABignosaBignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla atta…
BITWISE SPIDERBITWISE SPIDERBITWISE SPIDER has recently and quickly become a significant player in the big game hunting (BGH) landscape. Their dedicated leak site (DLS) has received the h…
BITWISE-SPIDERBITWISE SPIDERBITWISE SPIDER has recently and quickly become a significant player in the big game hunting (BGH) landscape. Their dedicated leak site (DLS) has received the h…
BLACKATOMBlackatomRecent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted to appeal to a niche g…
BLACKGEARBlackgearBLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years. Multiple papers and talks have been released covering this campaign, whic…
BLACKJACKBlackJackBlackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. …
BLACKMASKERSBlackMaskersBlackMaskers Team has emerged as a significant threat actor, particularly targeting Jordan amid the Israel-Iran conflict. They have claimed responsibility for …
BLACKMETABlackmetaBLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches targeting organizations perceive…
BlackOasisBlackOasisBlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United N…
BLACKOASISBlackOasisBlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United N…
BlacktailBlacktailBlacktail is a cybercrime group that has gained attention for its ransomware campaigns, particularly the Buhti ransomware. They are known for using custom-buil…
BLACKTAILBlacktailBlacktail is a cybercrime group that has gained attention for its ransomware campaigns, particularly the Buhti ransomware. They are known for using custom-buil…
BLACKTECHBlackTechBlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes a…
BLACKWOODBlackwoodBlackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and c…
BLADEDFELINEBladedFelineBladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The gr…
BladeHawkBladeHawkBladeHawk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisatio…
BLADEHAWKBladeHawk
BLUE-TERMITEBlue TermiteBlue Termite is a group of suspected Chinese origin active in Japan.
BLUE-TSUNAMIBlue TsunamiBlue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube. They target individuals in various…
BlueBottleBlueBottleBluebottle, a cyber-crime group that specializes in targeted attacks against the financial sector, is continuing to mount attacks on banks in Francophone count…
BLUEBOTTLEBlueBottleBluebottle, a cyber-crime group that specializes in targeted attacks against the financial sector, is continuing to mount attacks on banks in Francophone count…
BlueHornetBlueHornetBlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked …
BLUEHORNETBlueHornetBlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked …
BOHRIUMBohriumBohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India. They often cr…
BondnetBondnetBondnet is a threat actor that deploys backdoors and cryptocurrency miners. They use high-performance bots as C2 servers and configure reverse RDP environments…
BONDNETBondnetBondnet is a threat actor that deploys backdoors and cryptocurrency miners. They use high-performance bots as C2 servers and configure reverse RDP environments…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.