2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 351–400 of 1,546 in Other · page 8 of 31

IDTitleSummary
EARTH-BERBEROKAEarth BerberokaAccording to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign use…
Earth EstriesEarth EstriesTrend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned,…
EARTH-ESTRIESEarth EstriesTrend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned,…
EARTH-FREYBUGEarth FreybugEarth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities a…
Earth KapreEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
EARTH-KAPREEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
Earth KitsuneEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
EARTH-KITSUNEEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
EARTH-KRAHANGEarth KrahangEarth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
Earth KurmaEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
EARTH-KURMAEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
EARTH-LAMIAEarth LamiaEarth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
Earth LongzhiEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
EARTH-LONGZHIEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
EARTH-LUSCAEarth LuscaEarth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication c…
EARTH-NAGAEarth NagaEarth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and military-related man…
EARTH-WENDIGOEarth WendigoEarth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and unive…
Earth YakoEarth YakoEarth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails wit…
EARTH-YAKOEarth YakoEarth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails wit…
EC2 GrouperEC2 GrouperEC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments. They typically utilize…
EC2-GROUPEREC2 GrouperEC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments. They typically utilize…
EDALAT-E-ALIEdalat-e AliEdalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as the Revolution Day cere…
EDUCATED-MANTICOREEducated ManticoreEducated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting government, military, a…
El MacheteEl MacheteEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successf…
EL-MACHETEEl MacheteEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successf…
ELECTRIC-PANDAELECTRIC PANDA
ELOQUENT-PANDAELOQUENT PANDA
ELUSIVE-COMETELUSIVE COMETELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks, particularly leveraging Zoom…
ENERGETIC-BEARENERGETIC BEARA Russian group that collects intelligence on the energy industry.
EQUATION-GROUPEquation GroupThe Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups i…
EVASIVE-PANDAEvasive PandaEvasive Panda is an APT group that has been active since at least 2012, conducting cyberespionage targeting individuals, government institutions and organizati…
Evil CorpEvil CorpEvil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and…
EVIL-CORPEvil CorpEvil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and…
EvilbyteEvilbyteEvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation ag…
EVILBYTEEvilbyteEvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation ag…
EvilnumEvilnumESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While …
EVILNUMEvilnumESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While …
EvilPostEvilPost
EVILPOSTEvilPost
EvilTrafficEvilTrafficMalware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised websites. Crooks exploited …
EVILTRAFFICEvilTrafficMalware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised websites. Crooks exploited …
EVILWEBEvilWebEvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak method alongside DDoS attacks…
ExCobaltExCobaltExCobalt is an APT group that has been active since at least 2016 and is believed to be linked to the notorious Cobalt Gang. The group primarily targets Russia…
EXCOBALTExCobaltExCobalt is an APT group that has been active since at least 2016 and is believed to be linked to the notorious Cobalt Gang. The group primarily targets Russia…
EXOTIC LILYEXOTIC LILYEXOTIC LILY is a resourceful, financially motivated group whose activities appear to be closely linked with data exfiltration and deployment of human-operated …
EXOTIC-LILYEXOTIC LILYEXOTIC LILY is a resourceful, financially motivated group whose activities appear to be closely linked with data exfiltration and deployment of human-operated …
Fail0verflowFail0verflowFail0verflow is a hacking group known for exploiting vulnerabilities in gaming consoles, notably the Nintendo Wii and PlayStation 3. They utilized techniques s…
FAIL0VERFLOWFail0verflowFail0verflow is a hacking group known for exploiting vulnerabilities in gaming consoles, notably the Nintendo Wii and PlayStation 3. They utilized techniques s…
FASTCashFASTCashTreasury has identified a sophisticated cyber-enabled ATM cash out campaign we are calling FASTCash. FASTCash has been active since late 2016 targeting banks i…
FASTCASHFASTCashTreasury has identified a sophisticated cyber-enabled ATM cash out campaign we are calling FASTCash. FASTCash has been active since late 2016 targeting banks i…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base