2,004 indexed
ACTORSThreat actors
2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 551–600 of 2,004 · page 12 of 41
| ID | Title | Summary |
|---|---|---|
| FEMWAR02 | Femwar02 | Femwar02 is a previously unknown pro-Russian ransomware threat actor that emerged in early 2026, linked to a major cyberattack on Italy's Sapienza University o… |
| Ferocious Kitten | Ferocious Kitten IR | Ferocious Kitten is an APT group that has been active against Persian-speaking individuals since 2015 and appears to be based in Iran. Although it has been act… |
| FEROCIOUS-KITTEN | Ferocious Kitten | Ferocious Kitten is an APT group that has been active against Persian-speaking individuals since 2015 and appears to be based in Iran. Although it has been act… |
| FIN1 | FIN1 RU | FireEye first identified this activity during a recent investigation at an organization in the financial industry. They identified the presence of a financiall… |
| FIN1 | FIN1 | FireEye first identified this activity during a recent investigation at an organization in the financial industry. They identified the presence of a financiall… |
| FIN10 | FIN10 | FireEye has observed multiple targeted intrusions occurring in North America — predominately in Canada — dating back to at least 2013 and continuing through at… |
| FIN10 | FIN10 | FireEye has observed multiple targeted intrusions occurring in North America — predominately in Canada — dating back to at least 2013 and continuing through at… |
| FIN11 | FIN11 | FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion. The group has been active since 2017 an… |
| FIN11 | FIN11 | FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion. The group has been active since 2017 an… |
| FIN13 | FIN13 RU | Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term intrusions in Mexico with an… |
| FIN13 | FIN13 | Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term intrusions in Mexico with an… |
| FIN5 | FIN5 | FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active sinc… |
| FIN5 | FIN5 | FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active sinc… |
| FIN6 | FIN6 | FIN6 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as SKELETON SPIDER, ITG08, MageCart Group 6 (and 7 more). Origin… |
| FIN6 | FIN6 | FIN is a group targeting financial assets including assets able to do financial transaction including PoS. |
| FIN7 | FIN7 RU | FIN7 is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as CARBON SPIDER, GOLD NIAGARA, Calcium (and … |
| FIN7 | FIN7 | Groups targeting financial organizations or people with significant financial assets. |
| FIN8 | FIN8 | FIN8 is a financially motivated group targeting the retail, hospitality and entertainment industries. The actor had previously conducted several tailored spear… |
| FIN8 | FIN8 | FIN8 is a financially motivated group targeting the retail, hospitality and entertainment industries. The actor had previously conducted several tailored spear… |
| Fishing Elephant | Fishing Elephant | Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan. They rely on consistent TTPs, including payload and communication… |
| FISHING-ELEPHANT | Fishing Elephant | Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan. They rely on consistent TTPs, including payload and communication… |
| FishMedley | FishMedley | Verticals targeted during Operation FishMedley include governments, NGOs, and think tanks, across Asia, Europe, and the United States. ; Operators used implant… |
| FISHMEDLEY | FishMedley | Verticals targeted during Operation FishMedley include governments, NGOs, and think tanks, across Asia, Europe, and the United States. ; Operators used implant… |
| Flash Kitten | Flash Kitten | This suspected Iran-based adversary conducted long-running SWC campaigns from December 2016 until public disclosure in July 2018. Like other Iran-based actors,… |
| FLASH-KITTEN | Flash Kitten | This suspected Iran-based adversary conducted long-running SWC campaigns from December 2016 until public disclosure in July 2018. Like other Iran-based actors,… |
| Flax Typhoon | Flax Typhoon CN | Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining an… |
| FLAX-TYPHOON | Flax Typhoon | Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan. They conduct espionage campaigns and focus on gaining an… |
| FlowerStorm | FlowerStorm | FlowerStorm is a phishing-as-a-service platform that mimics legitimate services to bypass multi-factor authentication structure. The majority of its targets ar… |
| FLOWERSTORM | FlowerStorm | FlowerStorm is a phishing-as-a-service platform that mimics legitimate services to bypass multi-factor authentication structure. The majority of its targets ar… |
| Flying Kitten | Flying Kitten IR | Flying Kitten is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as SaffronRose, Saffron Rose, AjaxSe… |
| FLYING-KITTEN | Flying Kitten | Activity: defense and aerospace sectors, also interested in targeting entities in the oil/gas industry. |
| FlyingYeti | FlyingYeti RU | FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using m… |
| FLYINGYETI | FlyingYeti | FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using m… |
| Fox Kitten | Fox Kitten IR | PIONEER KITTEN is an Iran-based adversary that has been active since at least 2017 and has a suspected nexus to the Iranian government. This adversary appears … |
| FOX-KITTEN | Fox Kitten | PIONEER KITTEN is an Iran-based adversary that has been active since at least 2017 and has a suspected nexus to the Iranian government. This adversary appears … |
| FOXY PANDA | FOXY PANDA CN | FOXY PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: FOXY PANDA is a Chinese-attributed threat actor … |
| FOXY-PANDA | FOXY PANDA | Adversary group targeting telecommunication and technology organizations. |
| FrostyNeighbor | FrostyNeighbor BY | FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuani… |
| FROSTYNEIGHBOR | FrostyNeighbor | FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuani… |
| FunkSec | FunkSec | Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS… |
| FUNKSEC | FunkSec | Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS… |
| FusionCore | FusionCore | The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hack… |
| FUSIONCORE | FusionCore | The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hack… |
| Fxmsp | Fxmsp | Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp… |
| FXMSP | Fxmsp | Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp… |
| GALLIUM | GALLIUM CN | GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target… |
| GALLIUM | GALLIUM | GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target… |
| Gallmaker | Gallmaker | Symantec researchers have uncovered a previously unknown attack group that is targeting government and military targets, including several overseas embassies o… |
| GALLMAKER | Gallmaker | Symantec researchers have uncovered a previously unknown attack group that is targeting government and military targets, including several overseas embassies o… |
| GamaCopy | GamaCopy | GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimi… |