2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 151–200 of 1,546 in Other · page 4 of 31

IDTitleSummary
BoolkaBoolkaBoolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL in…
BOOLKABoolkaBoolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL in…
BOSON SPIDERBOSON SPIDERBOSON SPIDER is a cyber criminal group, which was first identified in 2015, recently and inexplicably went dark in the spring of 2016, appears to be a tightly …
BOSON-SPIDERBOSON SPIDERBOSON SPIDER is a cyber criminal group, which was first identified in 2015, recently and inexplicably went dark in the spring of 2016, appears to be a tightly …
BOSS SPIDERBOSS SPIDERThroughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. …
BOSS-SPIDERBOSS SPIDERThroughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. …
BOULDER-BEARBoulder BearFirst observed activity in December 2013.
BRAZENBAMBOOBrazenBambooBrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families. Their infrastructure includ…
BreachLaboratoryBreachLaboratoryBreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from various organizations. The…
BREACHLABORATORYBreachLaboratoryBreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from various organizations. The…
BRONZE-EDGEWOODBRONZE EDGEWOODIn early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed…
BRONZE-HIGHLANDBRONZE HIGHLANDBRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Thi…
BRONZE-SPIRALBRONZE SPIRALIn December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platf…
BRONZE-SPRINGBRONZE SPRINGBRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense…
BRONZE-STARLIGHTBRONZE STARLIGHTBRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group leverages HUI Loader to load…
BRONZE-VAPORBRONZE VAPORBRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated with this group and open sou…
BUDMINERBudminerBased on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group. While we have not …
BUHTRAPBuhTrapBuhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015. Earlier, the group had only f…
ByteToBreachByteToBreachByteToBreach is a prolific cybercriminal who operates across multiple platforms, including DarkForums and Telegram, and has been active since at least June 202…
BYTETOBREACHByteToBreachByteToBreach is a prolific cybercriminal who operates across multiple platforms, including DarkForums and Telegram, and has been active since at least June 202…
CADELLECadelleSymantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity began well before this date.…
Caliente BanditsCaliente BanditsCaliente Bandits is a highly active threat group that targets multiple industries, including finance and entertainment. They distribute the Bandook remote acce…
CALIENTE-BANDITSCaliente BanditsCaliente Bandits is a highly active threat group that targets multiple industries, including finance and entertainment. They distribute the Bandook remote acce…
CALLISTOCallistoThe Callisto Group is an advanced threat actor whose known targets include military personnel, government officials, think tanks, and journalists in Europe and…
CalypsoCalypsoFor the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, during the work to detect cyber t…
CALYPSOCalypsoFor the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, during the work to detect cyber t…
CAMARO-DRAGONCamaro DragonIn early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of tool…
Caracal KittenCaracal KittenCaracal Kitten is an APT group that has been targeting activists associated with the Kurdistan Democratic Party. They employ a mobile remote access Trojan to g…
CARACAL-KITTENCaracal KittenCaracal Kitten is an APT group that has been targeting activists associated with the Kurdistan Democratic Party. They employ a mobile remote access Trojan to g…
Caramel TsunamiCaramel TsunamiCaramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting s…
CARAMEL-TSUNAMICaramel TsunamiCaramel Tsunami is a threat actor that specializes in spyware attacks. They have recently resurfaced with an updated toolset and zero-day exploits, targeting s…
CarderbeeCarderbeeSymantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and…
CARDERBEECarderbeeSymantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and…
CARDINALLIZARDCardinalLizardCardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018. Their methods include spear-phishing, custom malware with anti-…
CARETOCaretoThis threat actor targets governments, diplomatic missions, private companies in the energy sector, and academics for espionage purposes. The Mask is an advanc…
CARMINE-TSUNAMICarmine TsunamiCarmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream. QuaDream sells a platform called REIGN to governmen…
CashRewindoCashRewindoCashRewindo is a sophisticated threat actor leveraging aged domains in global malvertising campaigns to direct victims to investment scam sites. The group empl…
CASHREWINDOCashRewindoCashRewindo is a sophisticated threat actor leveraging aged domains in global malvertising campaigns to direct victims to investment scam sites. The group empl…
CERANAKEEPERCeranaKeeperCeranaKeeper is a China-aligned APT that has been active since at least early 2022, primarily targeting governmental institutions in Asian countries. The group…
ChainedSharkChainedSharkChainedShark is an APT group targeting China's scientific research sector, particularly professionals in international relations and marine technology, with th…
CHAINEDSHARKChainedSharkChainedShark is an APT group targeting China's scientific research sector, particularly professionals in international relations and marine technology, with th…
ChamelgangChamelgangIn Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company. The investigation revealed that the company's…
CHAMELGANGChamelgangIn Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company. The investigation revealed that the company's…
CHARMING-KITTENCharming KittenCharming Kitten (aka Parastoo, aka Newscaster) is an group with a suspected nexus to Iran that targets organizations involved in government, defense technology…
CHAYA-004Chaya_004Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell backdoors and various pen te…
CHERNOVITEChernoviteChernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM. They are known for tar…
CHRONUS-GROUPChronus GroupChronus Team is a hacktivist group known for defacement attacks and data leaks, primarily targeting public-sector organizations in Mexico. They have been linke…
CHRYSENECHRYSENEAdversaries abusing ICS (based on Dragos Inc adversary list). This threat actor targets organizations involved in oil, gas, and electricity production, primari…
CHRYSENECHRYSENEAdversaries abusing ICS (based on Dragos Inc adversary list). This threat actor targets organizations involved in oil, gas, and electricity production, primari…
CiberInteligenciaSVCiberInteligenciaSVCiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums. They have also compromised El Salvador's state Bitcoin walle…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base