2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,451–1,500 of 1,596 in Other · page 30 of 32

IDTitleSummary
UNC6485UNC6485UNC6485 is a cyber-espionage group exploiting CVE-2025-12480 in Gladinet’s Triofox file-sharing platform to gain initial network access and establish long-term…
UNC6485UNC6485UNC6485 is a cyber-espionage group exploiting CVE-2025-12480 in Gladinet’s Triofox file-sharing platform to gain initial network access and establish long-term…
UNC6508UNC6508UNC6508 is a PRC-nexus threat actor targeting North American academic, medical, and military research institutions, employing tactics such as exploiting REDCap…
UNC6619UNC6619TGR-STA-1030 is a state-aligned cyberespionage group operating out of Asia, known for compromising government and critical infrastructure organizations across …
UNC6619UNC6619TGR-STA-1030 is a state-aligned cyberespionage group operating out of Asia, known for compromising government and critical infrastructure organizations across …
UNC6671UNC6671UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a vict…
UNC6671UNC6671UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a vict…
UNC6691UNC6691UNC6691 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: UNC6691 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341)…
UNC6691UNC6691financially motivated threat actor operating from China
UNC6692UNC6692UNC6692 is a threat actor that employs social engineering tactics, such as impersonating IT helpdesk personnel, to gain initial access to victim environments. …
UNC6692UNC6692UNC6692 is a threat actor that employs social engineering tactics, such as impersonating IT helpdesk personnel, to gain initial access to victim environments. …
UNC6748UNC6748UNC6748 targets users in Saudi Arabia through a fake Snapchat website, employing a backdoor known as GHOSTKNIFE for data exfiltration. Their exploitation proce…
UNFADING-SEA-HAZEUnfading Sea HazeUnfading Sea Haze is a threat actor focused on espionage, targeting government and military organizations in the South China Sea region since 2018. They employ…
UNG0002UNG0002UNG0002 is a technically adept APT conducting large-scale cyber espionage campaigns targeting strategic sectors in China, Hong Kong, and Pakistan, including de…
UNG0002UNG0002UNG0002 is a technically adept APT conducting large-scale cyber espionage campaigns targeting strategic sectors in China, Hong Kong, and Pakistan, including de…
UNG0901UNG0901UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing spear-phishing tactics. They…
UNG0901UNG0901UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing spear-phishing tactics. They…
UNION-PANDAUNION PANDA
UNION-SPIDERUNION SPIDERAdversary targeting manufacturing and industrial organizations.
UNIT-8200Unit 8200
UNK-ACADEMICFLAREUNK_AcademicFlareUNK_AcademicFlare is a suspected Russia-aligned threat actor that conducts device code phishing campaigns by leveraging compromised email addresses from govern…
UNK_DropPitchUNK_DropPitchBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNK-DROPPITCHUNK_DropPitchBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNK_FistBumpUNK_FistBumpBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNK-FISTBUMPUNK_FistBumpBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNK-REMOTEROGUEUNK_RemoteRogueUNK_RemoteRogue is a suspected Russian threat actor that has been observed utilizing ClickFix in its infection chains, although this technique is not revolutio…
UNK_SparkyCarpUNK_SparkyCarpBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNK-SPARKYCARPUNK_SparkyCarpBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNNAMED-ACTORUnnamed ActorThis threat actor compromises civil society groups the Chinese Communist Party views as hostile to its interests, such as Tibetan, Uyghur, Hong Kong, and Taiwa…
UNSOLICITEDBOOKERUnsolicitedBookerUnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi Arabia, employing a backdoo…
UrpageUrpageWhat sets Urpage attacks apart is its targeting of InPage, a word processor for Urdu and Arabic languages. However, its Delphi backdoor component, which it has…
URPAGEUrpageWhat sets Urpage attacks apart is its targeting of InPage, a word processor for Urdu and Arabic languages. However, its Delphi backdoor component, which it has…
USDoDUSDoDUSDoD is a threat actor known for leaking large databases of personal information, including from companies like Airbus and the U.S. Environmental Protection A…
USDODUSDoDUSDoD is a threat actor known for leaking large databases of personal information, including from companies like Airbus and the U.S. Environmental Protection A…
USERSECUserSecUserSec is a pro-Russian hacking group that has been active since at least 2022. The group is known for its DDoS attacks and has collaborated with other pro-Ru…
UTA0178UTA0178While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the…
UTA0218UTA0218UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data. They exploit vulne…
UTA0218UTA0218UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data. They exploit vulne…
UTA0352UTA0352UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government of…
UTA0355UTA0355UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine. The actor initiates contact…
UTA0388UTA0388UTA0388 is a China-aligned APT known for spear-phishing campaigns targeting organizations in North America, Asia, and Europe, primarily to deliver a Go-based i…
UTA0533UTA0533UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and …
UTG-Q-008UTG-Q-008UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network…
UTG-Q-008UTG-Q-008UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network…
UTG-Q-010UTG-Q-010UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical industry and cryptoc…
UTG-Q-010UTG-Q-010UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical industry and cryptoc…
V0IDIXV0idixV0idix is a threat actor known for distributing leaked data for free on leak forums, with some files requiring a reply-to-unlock to access.
Vanilla TempestVanilla TempestVice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also bee…
VANILLA-TEMPESTVanilla TempestVice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also bee…
VANTACOREVantaCoreVantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom dema…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base