2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

6 in UA · 2,004 total

IDTitleSummary
BearlyfyBearlyfy
UA
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware st…
BlackJackBlackJack
UA
Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. …
Cyber AllianceCyber Alliance
UA
The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of Ukraine in 2022. They…
Cyber.Anarchy.SquadCyber.Anarchy.Squad
UA
Cyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure. They have carried out cyberattacks on Russian…
GroundbaitGroundbait
UA
Groundbait is a Ukrainian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Groundbait is a group targeting anti-governmen…
Ukrainian Cyber AllianceUkrainian Cyber Alliance
UA
Cyber Alliance is a hacktivist group that has demonstrated capabilities in exploiting vulnerabilities, such as CVE-2023-22515 in Confluence, to escalate privil…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base