2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,501–1,546 of 1,546 in Other · page 31 of 31

IDTitleSummary
WATER-SACIWater SaciWater Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to …
WATER-SIGBINWater SigbinThe 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Ora…
WEBWORMWebwormSpace Pirates is a cybercrime group that has been active since at least 2017. They primarily target Russian companies and have been observed using various malw…
WeedSecWeedSecWeedSec is a threat actor group that recently targeted the online learning and course management platform Moodle. They posted sample databases of Moodle on the…
WEEDSECWeedSecWeedSec is a threat actor group that recently targeted the online learning and course management platform Moodle. They posted sample databases of Moodle on the…
WEREDEVILSWeRedEvilsWeRedEvils is a hacking group that has claimed responsibility for multiple cyber attacks. They targeted the Iranian Electric Grid and the Tasnimnews website, c…
WET-PANDAWET PANDA
WHITE-BEARWhite BearAs a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting APT activity that we …
WhiteCobraWhiteCobraWhiteCobra is a threat actor that has infiltrated the Visual Studio Code marketplace and Open VSX registry, deploying 24 malicious extensions targeting cryptoc…
WHITECOBRAWhiteCobraWhiteCobra is a threat actor that has infiltrated the Visual Studio Code marketplace and Open VSX registry, deploying 24 malicious extensions targeting cryptoc…
WhiteflyWhiteflyIn July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until n…
WHITEFLYWhiteflyIn July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until n…
WildCardWildCardWildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware. They have since expanded their operations and develop…
WILDCARDWildCardWildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware. They have since expanded their operations and develop…
WildNeutronWildNeutronA corporate espionage group has compromised a string of major corporations over the past three years in order to steal confidential information and intellectua…
WILDNEUTRONWildNeutronA corporate espionage group has compromised a string of major corporations over the past three years in order to steal confidential information and intellectua…
WildPressureWildPressureWildPressure is a threat actor that targets industrial-related entities in the Middle East. They use a variety of programming languages, including C++, VBScrip…
WILDPRESSUREWildPressureWildPressure is a threat actor that targets industrial-related entities in the Middle East. They use a variety of programming languages, including C++, VBScrip…
WindShiftWindShiftIn August of 2018, DarkMatter released a report entitled “In the Trails of WINDSHIFT APT”, which unveiled a threat actor with TTPs very similar to those of Bah…
WINDSHIFTWindShiftIn August of 2018, DarkMatter released a report entitled “In the Trails of WINDSHIFT APT”, which unveiled a threat actor with TTPs very similar to those of Bah…
WINTER-VIVERNWinter VivernWinter Vivern is a cyberespionage group first revealed by DomainTools in 2021. It is thought to have been active since at least 2020 and it targets governments…
WIP19WIP19WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia. They utilize a stolen certificate to sign their malware, inc…
WIRTEWIRTEWIRTE is a threat actor group that was first discovered in 2018. They are suspected to be part of the Gaza Cybergang, an Arabic politically motivated cyber cri…
WITCHETTYWitchettyWitchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some l…
WIZARD-SPIDERWIZARD SPIDERWizard Spider is reportedly associated with Grim Spider and Lunar Spider. The WIZARD SPIDER threat group is the Russia-based operator of the TrickBot banking m…
WOLF-SPIDERWOLF SPIDERFIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthca…
WOROKWorokWorok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBea…
XAKNETXakNetXakNet is a self-proclaimed hacktivist group that has targeted Ukraine. They claim to be comprised of Russian patriotic volunteers and have conducted various t…
XcatzeXcatzeCloud security company Lacework says it discovered a threat actor group named Xcatze that uses a Python named AndroxGh0st to take over AWS servers and send out…
XCATZEXcatzeCloud security company Lacework says it discovered a threat actor group named Xcatze that uses a Python named AndroxGh0st to take over AWS servers and send out…
XDSpyXDSpyRare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since…
XDSPYXDSpyRare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since…
XIAOQIYINGXiaoqiyingXiaoqiying is a primarily Chinese-speaking threat group that is most well known for conducting website defacement and data exfiltration attacks on more than a …
XINXINXinXinXinXin is a Chinese-speaking threat actor known for its phishing-as-a-service platform, Lucid, which targets global organizations to steal credit card details …
Yanbian GangYanbian GangRiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious Android apps purporting …
YANBIAN-GANGYanbian GangRiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious Android apps purporting …
YOROTROOPERYoroTrooperYoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on …
Z-PENTEST-ALLIANCEZ-Pentest AllianceZ-Pentest Alliance is a pro-Russian hacktivist group known for targeting industrial control systems and operational technology systems, particularly in Italy a…
ZARYAZaryaZarya is a pro-Russian hacktivist group that emerged in March 2022. Initially operating as a special forces unit under the command of Killnet, Zarya has since …
ZEFFSECZeffSecZeffSec is a hacktivist collective focused on infrastructure-level disruption and exposing vulnerabilities in centralized digital networks. In March 2026, the …
ZeroSevenGroupZeroSevenGroupZeroSevenGroup is a threat actor that claims to have breached a U.S. branch of Toyota, stealing 240GB of sensitive data, including employee and customer inform…
ZEROSEVENGROUPZeroSevenGroupZeroSevenGroup is a threat actor that claims to have breached a U.S. branch of Toyota, stealing 240GB of sensitive data, including employee and customer inform…
ZOMBIE SPIDERZOMBIE SPIDEROn April 7, 2017, Pytor Levashov — who predominantly used the alias Severa or Peter Severa and whom Falcon Intelligence tracks as ZOMBIE SPIDER — was arrested …
ZOMBIE-SPIDERZOMBIE SPIDEROn April 7, 2017, Pytor Levashov — who predominantly used the alias Severa or Peter Severa and whom Falcon Intelligence tracks as ZOMBIE SPIDER — was arrested …
ZooParkZooParkZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind ZooPark infect Androi…
ZOOPARKZooParkZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind ZooPark infect Androi…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.