2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 501–550 of 2,054 · page 11 of 42

IDTitleSummary
EARTH-KAPREEarth KapreEarth Kapre is an APT group specializing in cyberespionage. They target organizations in various countries through phishing campaigns using malicious attachmen…
Earth KitsuneEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
EARTH-KITSUNEEarth KitsuneEarth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and …
Earth KrahangEarth Krahang
CN
Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
EARTH-KRAHANGEarth KrahangEarth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors …
Earth KurmaEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
EARTH-KURMAEarth KurmaEarth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advan…
Earth LamiaEarth Lamia
CN
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
EARTH-LAMIAEarth LamiaEarth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, …
Earth LongzhiEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
EARTH-LONGZHIEarth LongzhiEarth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Ex…
Earth LuscaEarth Lusca
CN
Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication c…
EARTH-LUSCAEarth LuscaEarth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication c…
Earth NagaEarth Naga
CN
Earth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and military-related man…
EARTH-NAGAEarth NagaEarth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and military-related man…
Earth WendigoEarth Wendigo
CN
Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and unive…
EARTH-WENDIGOEarth WendigoEarth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and unive…
Earth YakoEarth YakoEarth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails wit…
EARTH-YAKOEarth YakoEarth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan. They use spearphishing emails wit…
EC2 GrouperEC2 GrouperEC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments. They typically utilize…
EC2-GROUPEREC2 GrouperEC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments. They typically utilize…
Edalat-e AliEdalat-e Ali
IR
Edalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as the Revolution Day cere…
EDALAT-E-ALIEdalat-e AliEdalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as the Revolution Day cere…
Educated ManticoreEducated Manticore
IR
Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting government, military, a…
EDUCATED-MANTICOREEducated ManticoreEducated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting government, military, a…
El MacheteEl MacheteEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successf…
EL-MACHETEEl MacheteEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successf…
ELECTRIC PANDAELECTRIC PANDA
CN
ELECTRIC PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: ELECTRIC PANDA is a Chinese-attributed threa…
ELECTRIC-PANDAELECTRIC PANDA
ELOQUENT PANDAELOQUENT PANDA
CN
ELOQUENT PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: ELOQUENT PANDA is a Chinese-attributed threa…
ELOQUENT-PANDAELOQUENT PANDA
ELUSIVE COMETELUSIVE COMET
KP
ELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks, particularly leveraging Zoom…
ELUSIVE-COMETELUSIVE COMETELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks, particularly leveraging Zoom…
ENERGETIC BEARENERGETIC BEAR
RU
ENERGETIC BEAR is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as BERSERK BEAR, ALLANITE, CASTLE (…
ENERGETIC-BEARENERGETIC BEARA Russian group that collects intelligence on the energy industry.
Equation GroupEquation Group
US
The Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups i…
EQUATION-GROUPEquation GroupThe Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups i…
Evasive PandaEvasive Panda
CN
Evasive Panda is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as BRONZE HIGHLAND. Operational targ…
EVASIVE-PANDAEvasive PandaEvasive Panda is an APT group that has been active since at least 2012, conducting cyberespionage targeting individuals, government institutions and organizati…
Evil CorpEvil CorpEvil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and…
EVIL-CORPEvil CorpEvil Corp is an internaltional cybercrime network. In December of 2019 the US Federal Government offered a $5M bounty for information leading to the arrest and…
EvilbyteEvilbyteEvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation ag…
EVILBYTEEvilbyteEvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation ag…
EvilnumEvilnumESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While …
EVILNUMEvilnumESET has analyzed the operations of Evilnum, the APT group behind the Evilnum malware previously seen in attacks against financial technology companies. While …
EvilPostEvilPostEvilPost is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as EvilPost.
EVILPOSTEvilPost
EvilTrafficEvilTrafficMalware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised websites. Crooks exploited …
EVILTRAFFICEvilTrafficMalware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised websites. Crooks exploited …
EvilWebEvilWeb
RU
EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak method alongside DDoS attacks…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.