2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 351–400 of 1,596 in Other · page 8 of 32

IDTitleSummary
DRAGONSPARKDragonSparkDragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the open-source tool SparkRAT, whic…
DRIFTINGCLOUDDriftingCloudDriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or acquiring zero-day exploits …
DRIVESURGEDriveSurgeDriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and ClickFix-style prompts.…
DUNGEON SPIDERDUNGEON SPIDERDUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in la…
DUNGEON-SPIDERDUNGEON SPIDERDUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in la…
Dust StormDust StormDust Storm is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0031. Original record: Threat actors behind the Operat…
DUST-STORMDust StormThreat actors behind the Operation Dust Storm have been active since at least 2010, the hackers targeted several organizations in Japan, South Korea, the US, E…
DUSTSQUADDustSquadProdaft researchers have published a report on Paperbug, a cyber-espionage campaign carried out by suspected Russian-speaking group Nomadic Octopus and which t…
EARTH-ALUXEarth AluxEarth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, technology, and telecommunicat…
EARTH-BAXIAEarth BaxiaEarth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing…
EARTH-BERBEROKAEarth BerberokaAccording to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign use…
Earth EstriesEarth EstriesTrend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned,…
EARTH-ESTRIESEarth EstriesTrend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned,…
EARTH-FREYBUGEarth FreybugEarth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities a…
Earth KapreEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
EARTH-KAPREEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
Earth KitsuneEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
EARTH-KITSUNEEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
EARTH-KRAHANGEarth KrahangEarth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
Earth KurmaEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
EARTH-KURMAEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
EARTH-LAMIAEarth LamiaEarth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
Earth LongzhiEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
EARTH-LONGZHIEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
EARTH-LUSCAEarth LuscaEarth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication c…
EARTH-NAGAEarth NagaEarth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and military-related man…
EARTH-WENDIGOEarth WendigoEarth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and unive…
Earth YakoEarth YakoEarth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails wit…
EARTH-YAKOEarth YakoEarth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails wit…
EC2 GrouperEC2 GrouperEC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments. They typically utilize…
EC2-GROUPEREC2 GrouperEC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments. They typically utilize…
EDALAT-E-ALIEdalat-e AliEdalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as the Revolution Day cere…
EDUCATED-MANTICOREEducated ManticoreEducated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting government, military, a…
El MacheteEl MacheteEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successf…
EL-MACHETEEl MacheteEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successf…
ELECTRIC-PANDAELECTRIC PANDA
ELOQUENT-PANDAELOQUENT PANDA
ELUSIVE-COMETELUSIVE COMETELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks, particularly leveraging Zoom…
ENERGETIC-BEARENERGETIC BEARA Russian group that collects intelligence on the energy industry.
EQUATION-GROUPEquation GroupThe Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups i…
EVASIVE-PANDAEvasive PandaEvasive Panda is an APT group that has been active since at least 2012, conducting cyberespionage targeting individuals, government institutions and organizati…
Evil CorpEvil CorpEvil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and…
EVIL-CORPEvil CorpEvil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and…
EvilbyteEvilbyteEvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation ag…
EVILBYTEEvilbyteEvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation ag…
EvilnumEvilnumESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While …
EVILNUMEvilnumESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While …
EvilPostEvilPostEvilPost is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as EvilPost.
EVILPOSTEvilPost
EvilTrafficEvilTrafficMalware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised websites. Crooks exploited …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base