2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 201–250 of 1,596 in Other · page 5 of 32

IDTitleSummary
CHAYA-004Chaya_004Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell backdoors and various pen te…
CHERNOVITEChernoviteChernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM. They are known for tar…
CHRONUS-GROUPChronus GroupChronus Team is a hacktivist group known for defacement attacks and data leaks, primarily targeting public-sector organizations in Mexico. They have been linke…
CHRYSENECHRYSENEAdversaries abusing ICS (based on Dragos Inc adversary list). This threat actor targets organizations involved in oil, gas, and electricity production, primari…
CHRYSENECHRYSENEAdversaries abusing ICS (based on Dragos Inc adversary list). This threat actor targets organizations involved in oil, gas, and electricity production, primari…
CiberInteligenciaSVCiberInteligenciaSVCiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums. They have also compromised El Salvador's state Bitcoin walle…
CIBERINTELIGENCIASVCiberInteligenciaSVCiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums. They have also compromised El Salvador's state Bitcoin walle…
CIKLEAKCikLeakCikLeak is a threat actor that claims to have accessed systems of Russia’s Central Election Commission and companies involved in the Vybory platform, which adm…
CIRCUS-SPIDERCIRCUS SPIDERAccording to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIRCUS SPIDER. Initially discove…
CL-STA-0043CL-STA-0043CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the Middle East and Africa. T…
CL-STA-0043CL-STA-0043CL-STA-0043 is a Chinese state-nexus cyber-espionage actor tracked by Palo Alto Networks Unit 42, which promoted the activity cluster to the named threat actor…
CL-STA-0048CL-STA-0048CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunications entities, with a focus o…
CL-STA-1009CL-STA-1009CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell a…
CL-STA-1009CL-STA-1009CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell a…
CL-STA-1020CL-STA-1020CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control com…
CL-STA-1087CL-STA-1087CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia. The actor has demonst…
CL-UNK-1068CL-UNK-1068CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage. They utilize cross-platform tool…
CLEAVERCleaverA group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. or…
CLEVER-KITTENClever Kitten
CLOCKWORK SPIDERCLOCKWORK SPIDERCLOCKWORK SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Opportunistic actor that installs custom root certificate on …
CLOCKWORK-SPIDERCLOCKWORK SPIDEROpportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
CloudSorcererCloudSorcererCloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The ma…
CLOUDSORCERERCloudSorcererCloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The ma…
CobaltCobaltA criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided s…
COBALTCobaltA criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided s…
COBALT JUNOCOBALT JUNOCOBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyw…
COBALT-JUNOCOBALT JUNOCOBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyw…
COBALT KATANACOBALT KATANACOBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group h…
COBALT-KATANACOBALT KATANACOBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group h…
CodefingerCodefingerCodefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. …
CODEFINGERCodefingerCodefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. …
Coinbase CartelCoinbase CartelCoinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 vict…
COINBASE-CARTELCoinbase CartelCoinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 vict…
Cold RiverCold RiverIn short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control t…
COLD-RIVERCold RiverIn short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control t…
ComicFormComicFormComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian co…
COMICFORMComicFormComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian co…
Common RavenCommon RavenCommon Raven is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as OPERA1ER, NXSMS, DESKTOP-GROUP. Original record: Thre…
COMMON-RAVENCommon RavenThreat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent pay…
CONFERENCE-CREWConference CrewConference Crew is a China-nexus threat cluster renamed CONFERENCE CASTLE under Google Threat Intelligence's updated naming system.
CONFUCIOUSConfuciousConfucius is an APT organization funded by India. It has been carrying out cyber attacks since 2013. Its main targets are India's neighbouring countries such a…
Conquerors Electronic ArmyConquerors Electronic ArmyConquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including civil emergency alert…
CONQUERORS-ELECTRONIC-ARMYConquerors Electronic ArmyConquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including civil emergency alert…
Contagious InterviewContagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, incl…
CONTAGIOUS-INTERVIEWContagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, incl…
Copy-PasteCopy-PasteCopy-Paste is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati…
COPY-PASTECopy-PasteThe title ‘Copy-paste compromises’ is derived from the actor’s heavy use of tools copied almost identically from open source given by The Australian Government.
COPYKITTENSCopyKittens
CORALRAIDERCoralRaiderCoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They us…
CORSAIR-JACKALCorsair Jackal
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base