2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 201–250 of 1,546 in Other · page 5 of 31

IDTitleSummary
CIBERINTELIGENCIASVCiberInteligenciaSVCiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums. They have also compromised El Salvador's state Bitcoin walle…
CIRCUS-SPIDERCIRCUS SPIDERAccording to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIRCUS SPIDER. Initially discove…
CL-STA-0043CL-STA-0043CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the Middle East and Africa. T…
CL-STA-0043CL-STA-0043CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the Middle East and Africa. T…
CL-STA-0048CL-STA-0048CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunications entities, with a focus o…
CL-STA-1009CL-STA-1009CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell a…
CL-STA-1009CL-STA-1009CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell a…
CL-STA-1020CL-STA-1020CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control com…
CL-STA-1087CL-STA-1087CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia. The actor has demonst…
CL-UNK-1068CL-UNK-1068CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage. They utilize cross-platform tool…
CLEAVERCleaverA group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. or…
CLEVER-KITTENClever Kitten
CLOCKWORK SPIDERCLOCKWORK SPIDERCLOCKWORK SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Opportunistic actor that installs custom root certificate on …
CLOCKWORK-SPIDERCLOCKWORK SPIDEROpportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
CloudSorcererCloudSorcererCloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The ma…
CLOUDSORCERERCloudSorcererCloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The ma…
CobaltCobaltA criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided s…
COBALTCobaltA criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided s…
COBALT JUNOCOBALT JUNOCOBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyw…
COBALT-JUNOCOBALT JUNOCOBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyw…
COBALT KATANACOBALT KATANACOBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group h…
COBALT-KATANACOBALT KATANACOBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group h…
CodefingerCodefingerCodefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. …
CODEFINGERCodefingerCodefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. …
Coinbase CartelCoinbase CartelCoinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 vict…
COINBASE-CARTELCoinbase CartelCoinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 vict…
Cold RiverCold RiverIn short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control t…
COLD-RIVERCold RiverIn short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control t…
ComicFormComicFormComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian co…
COMICFORMComicFormComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian co…
Common RavenCommon RavenCommon Raven is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as OPERA1ER, NXSMS, DESKTOP-GROUP. Original record: Thre…
COMMON-RAVENCommon RavenThreat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent pay…
CONFUCIOUSConfuciousConfucius is an APT organization funded by India. It has been carrying out cyber attacks since 2013. Its main targets are India's neighbouring countries such a…
Conquerors Electronic ArmyConquerors Electronic ArmyConquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including civil emergency alert…
CONQUERORS-ELECTRONIC-ARMYConquerors Electronic ArmyConquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including civil emergency alert…
Contagious InterviewContagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, incl…
CONTAGIOUS-INTERVIEWContagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, incl…
Copy-PasteCopy-PasteCopy-Paste is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati…
COPY-PASTECopy-PasteThe title ‘Copy-paste compromises’ is derived from the actor’s heavy use of tools copied almost identically from open source given by The Australian Government.
COPYKITTENSCopyKittens
CORALRAIDERCoralRaiderCoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They us…
CORSAIR-JACKALCorsair Jackal
Cosmic LynxCosmic LynxCosmic Lynx is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Cosmic Lynx is a Russia-based BEC cybercriminal organization that …
COSMIC-LYNXCosmic LynxCosmic Lynx is a Russia-based BEC cybercriminal organization that has significantly impacted the email threat landscape with sophisticated, high-dollar phishin…
CosmicBeetleCosmicBeetleCosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolse…
COSMICBEETLECosmicBeetleCosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolse…
CostaRictoCostaRictoCostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware to…
COSTARICTOCostaRictoCostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware to…
COTTON-SANDSTORMCotton SandstormCotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical maga…
CoughingDownCoughingDownCoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes service manipulation an…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base