2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 251–300 of 1,596 in Other · page 6 of 32

IDTitleSummary
Cosmic LynxCosmic LynxCosmic Lynx is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Cosmic Lynx is a Russia-based BEC cybercriminal organization that …
COSMIC-LYNXCosmic LynxCosmic Lynx is a Russia-based BEC cybercriminal organization that has significantly impacted the email threat landscape with sophisticated, high-dollar phishin…
CosmicBeetleCosmicBeetleCosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolse…
COSMICBEETLECosmicBeetleCosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolse…
CostaRictoCostaRictoCostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware to…
COSTARICTOCostaRictoCostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware to…
COTTON-SANDSTORMCotton SandstormCotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical maga…
CoughingDownCoughingDownCoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes service manipulation an…
COUGHINGDOWNCoughingDownCoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes service manipulation an…
Crimson CollectiveCrimson CollectiveThe Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025. The group asserted it ha…
CRIMSON-COLLECTIVECrimson CollectiveThe Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025. The group asserted it ha…
CRPXOCRPxOCRPxO is a ransomware group that has claimed responsibility for attacks on various organizations, including Encore Enterprises, Inc., KUVEYT TURK, and Johnson …
CryptoChameleonCryptoChameleonCryptoChameleon is a cybercriminal group known for targeting cryptocurrency exchanges and users to steal digital assets, employing tactics such as VIP spear ph…
CRYPTOCHAMELEONCryptoChameleonCryptoChameleon is a cybercriminal group known for targeting cryptocurrency exchanges and users to steal digital assets, employing tactics such as VIP spear ph…
CRYSTALRAYCRYSTALRAYCRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They…
CRYSTALRAYCRYSTALRAYCRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They…
CUBOID-SANDSTORMCuboid SandstormCuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the company's network and used it to c…
CURIOUS-GORGECurious GorgeCurious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in Ukraine, Russia, Kazakhstan,…
CURLY-COMRADESCurly COMradesCurly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ tec…
CUTTING-KITTENCutting KittenOne of the threat actors responsible for the denial of service attacks against U.S in 2012–2013. Three individuals associated with the group—believed to be hav…
CYBER-ALLIANCECyber AllianceThe Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of Ukraine in 2022. They…
Cyber Army of Russia RebornCyber Army of Russia RebornCyber Army of Russia Reborn is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Cyber Army of Russia Reborn.
CYBER-ARMY-OF-RUSSIA-REBORNCyber Army of Russia Reborn
CYBER-AV3NGERSCyber Av3ngersCyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational technology and industrial control …
CYBER-BERKUTCyber Berkut
Cyber Caliphate ArmyCyber Caliphate ArmyCyber Caliphate Army is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Islamic State Hacking Division, CCA, United C…
CYBER-CALIPHATE-ARMYCyber Caliphate Army
CYBER-FIGHTERS-OF-IZZ-AD-DIN-AL-QASSAMCyber fighters of Izz Ad-Din Al Qassam
CYBER-ISLAMIC-RESISTANCECyber Islamic ResistanceCyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website defacements, DDoS attacks, and data…
CYBER-PARTISANSCyber PartisansThe Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and infrastructure in Belarus and …
CYBER-SERPCyber SerpUAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting organizations in Ukraine's publi…
CYBER-TOUFANCyber ToufanCyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations. The group's tactics suggest potential nat…
CYBER-ANARCHY-SQUADCyber.Anarchy.SquadCyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure. They have carried out cyberattacks on Russian…
CyberNiggersCyberNiggersCyberNiggers is a threat group known for breaching various organizations, including the US military, federal contractors, and multinational corporations like G…
CYBERNIGGERSCyberNiggersCyberNiggers is a threat group known for breaching various organizations, including the US military, federal contractors, and multinational corporations like G…
DAGGER-PANDADAGGER PANDAOperate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets…
Daixin TeamDaixin TeamDaixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att…
DAIXIN-TEAMDaixin TeamDaixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att…
DALBITDalbitThe group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of…
Dancing SalomeDancing SalomeDancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S…
DANCING-SALOMEDancing SalomeDancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S…
DangerousSavannaDangerousSavannaMalicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr…
DANGEROUSSAVANNADangerousSavannaMalicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr…
DantiDantiDanti is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Danti.
DANTIDanti
DAONLYSPARKDaOnlySparkDaOnlySpark is a forum actor claiming to have leaked sensitive data from AdvaCare, including internal financial details, and from Jinko, comprising 3.7 GB of p…
Dark BasinDark BasinDark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups …
DARK-BASINDark BasinDark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups …
DARK-CARACALDark CaracalLookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad…
DarkCasinoDarkCasinoDarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base