2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 301–350 of 1,546 in Other · page 7 of 31

IDTitleSummary
DarkSpectreDarkSpectre
DARKSPECTREDarkSpectre
DarkVishnyaDarkVishnyaDubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers…
DARKVISHNYADarkVishnyaDubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers…
DEADEYE-JACKALDeadeye JackalThe Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass…
DefrayXDefrayXDefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W…
DEFRAYXDefrayXDefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W…
DENIM-TSUNAMIDenim TsunamiDenim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using…
Desorden GroupDesorden GroupDesorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se…
DESORDEN-GROUPDesorden GroupDesorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se…
DEV-0147DEV-0147DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra…
DEV-0270DEV-0270Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s…
DEV-0569DEV-0569DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech…
DEV-0569DEV-0569DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech…
DEV-0586DEV-0586MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw…
DEV-0928DEV-0928DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi…
DEV-0928DEV-0928DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi…
DEV-0950DEV-0950Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to s…
DEV-0950DEV-0950Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to s…
DEV-1028DEV-1028DEV-1028 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Microsoft reported on MCCrash, an IoT botnet operated by the DEV-1028…
DEV-1028DEV-1028Microsoft reported on MCCrash, an IoT botnet operated by the DEV-1028 threat actor and used to launch DDoS attacks against private Minecraft servers.
DEXTOROUS SPIDERDEXTOROUS SPIDER
DEXTOROUS-SPIDERDEXTOROUS SPIDER
DICEYFDiceyFDiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended period. They have exhi…
DieNetDieNetDieNet is a hacktivist group that emerged in March 2025, known for conducting DDoS attacks targeting entities associated with political figures, such as Trump …
DIENETDieNetDieNet is a hacktivist group that emerged in March 2025, known for conducting DDoS attacks targeting entities associated with political figures, such as Trump …
DIZZY PANDADIZZY PANDADIZZY PANDA is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LadyBoyle. Original record: DIZZY PANDA is a threat ac…
DIZZY-PANDADIZZY PANDA
DNSpionageDNSpionageCisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airli…
DNSPIONAGEDNSpionageCisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airli…
DOMESTIC-KITTENDomestic KittenAn extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along wi…
DOPPEL SPIDERDOPPEL SPIDERIn June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical…
DOPPEL-SPIDERDOPPEL SPIDERIn June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical…
DragonBreathDragonBreathGolden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. Th…
DRAGONBREATHDragonBreathGolden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. Th…
DRAGONBRIDGEDragonbridgeDRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political interests of the People's Republic…
DRAGONFORCEDragonForceDragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in In…
DRAGONOKDragonOKThreat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to hav…
DragonRankDragonRankDragonRank is a threat actor primarily targeting web application services in Asia and Europe, utilizing TTPs associated with Simplified Chinese-speaking hackin…
DRAGONRANKDragonRankDragonRank is a threat actor primarily targeting web application services in Asia and Europe, utilizing TTPs associated with Simplified Chinese-speaking hackin…
DRAGONSPARKDragonSparkDragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the open-source tool SparkRAT, whic…
DRIFTINGCLOUDDriftingCloudDriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or acquiring zero-day exploits …
DRIVESURGEDriveSurgeDriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and ClickFix-style prompts.…
DUNGEON SPIDERDUNGEON SPIDERDUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in la…
DUNGEON-SPIDERDUNGEON SPIDERDUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in la…
Dust StormDust StormDust Storm is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0031. Original record: Threat actors behind the Operat…
DUST-STORMDust StormThreat actors behind the Operation Dust Storm have been active since at least 2010, the hackers targeted several organizations in Japan, South Korea, the US, E…
DUSTSQUADDustSquadProdaft researchers have published a report on Paperbug, a cyber-espionage campaign carried out by suspected Russian-speaking group Nomadic Octopus and which t…
EARTH-ALUXEarth AluxEarth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, technology, and telecommunicat…
EARTH-BAXIAEarth BaxiaEarth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base