2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 451–500 of 2,004 · page 10 of 41

IDTitleSummary
DIZZY PANDADIZZY PANDADIZZY PANDA is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LadyBoyle. Original record: DIZZY PANDA is a threat ac…
DIZZY-PANDADIZZY PANDA
DNSpionageDNSpionageCisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airli…
DNSPIONAGEDNSpionageCisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airli…
Domestic KittenDomestic Kitten
IR
An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along wi…
DOMESTIC-KITTENDomestic KittenAn extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information on the device along wi…
DOPPEL SPIDERDOPPEL SPIDERIn June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical…
DOPPEL-SPIDERDOPPEL SPIDERIn June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as DoppelPaymer. Further technical…
DragonBreathDragonBreathGolden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. Th…
DRAGONBREATHDragonBreathGolden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. Th…
DragonbridgeDragonbridge
CN
DRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political interests of the People's Republic…
DRAGONBRIDGEDragonbridgeDRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political interests of the People's Republic…
DragonForceDragonForce
MY
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in In…
DRAGONFORCEDragonForceDragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in In…
DragonOKDragonOK
CN
Threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to hav…
DRAGONOKDragonOKThreat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to hav…
DragonRankDragonRankDragonRank is a threat actor primarily targeting web application services in Asia and Europe, utilizing TTPs associated with Simplified Chinese-speaking hackin…
DRAGONRANKDragonRankDragonRank is a threat actor primarily targeting web application services in Asia and Europe, utilizing TTPs associated with Simplified Chinese-speaking hackin…
DragonSparkDragonSpark
CN
DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the open-source tool SparkRAT, whic…
DRAGONSPARKDragonSparkDragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia. They utilize the open-source tool SparkRAT, whic…
DriftingCloudDriftingCloud
CN
DriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or acquiring zero-day exploits …
DRIFTINGCLOUDDriftingCloudDriftingCloud is a persistent threat actor known for targeting various industries and locations. They are skilled at developing or acquiring zero-day exploits …
DRIVESURGEDriveSurgeDriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and ClickFix-style prompts.…
DUNGEON SPIDERDUNGEON SPIDERDUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in la…
DUNGEON-SPIDERDUNGEON SPIDERDUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in la…
Dust StormDust StormDust Storm is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0031. Original record: Threat actors behind the Operat…
DUST-STORMDust StormThreat actors behind the Operation Dust Storm have been active since at least 2010, the hackers targeted several organizations in Japan, South Korea, the US, E…
DustSquadDustSquad
RU
Prodaft researchers have published a report on Paperbug, a cyber-espionage campaign carried out by suspected Russian-speaking group Nomadic Octopus and which t…
DUSTSQUADDustSquadProdaft researchers have published a report on Paperbug, a cyber-espionage campaign carried out by suspected Russian-speaking group Nomadic Octopus and which t…
Earth AluxEarth Alux
CN
Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, technology, and telecommunicat…
EARTH-ALUXEarth AluxEarth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, technology, and telecommunicat…
Earth BaxiaEarth Baxia
CN
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing…
EARTH-BAXIAEarth BaxiaEarth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing…
Earth BerberokaEarth Berberoka
CN
According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign use…
EARTH-BERBEROKAEarth BerberokaAccording to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign use…
Earth EstriesEarth EstriesTrend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned,…
EARTH-ESTRIESEarth EstriesTrend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned,…
Earth FreybugEarth Freybug
CN
Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities a…
EARTH-FREYBUGEarth FreybugEarth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities a…
Earth KapreEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
EARTH-KAPREEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
Earth KitsuneEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
EARTH-KITSUNEEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
Earth KrahangEarth Krahang
CN
Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
EARTH-KRAHANGEarth KrahangEarth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
Earth KurmaEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
EARTH-KURMAEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
Earth LamiaEarth Lamia
CN
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
EARTH-LAMIAEarth LamiaEarth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
Earth LongzhiEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base