2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 601–650 of 2,054 · page 13 of 42
| ID | Title | Summary |
|---|---|---|
| FrostyNeighbor | FrostyNeighbor BY | FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuani… |
| FROSTYNEIGHBOR | FrostyNeighbor | FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuani… |
| FULCRUMSEC | FulcrumSec | FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited v… |
| FunkSec | FunkSec | Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS… |
| FUNKSEC | FunkSec | Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS… |
| FusionCore | FusionCore | The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hack… |
| FUSIONCORE | FusionCore | The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hack… |
| Fxmsp | Fxmsp | Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp… |
| FXMSP | Fxmsp | Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp… |
| GALLIUM | GALLIUM CN | GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target… |
| GALLIUM | GALLIUM | GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target… |
| Gallmaker | Gallmaker | Symantec researchers have uncovered a previously unknown attack group that is targeting government and military targets, including several overseas embassies o… |
| GALLMAKER | Gallmaker | Symantec researchers have uncovered a previously unknown attack group that is targeting government and military targets, including several overseas embassies o… |
| GamaCopy | GamaCopy | GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimi… |
| GAMACOPY | GamaCopy | GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimi… |
| Gamaredon Group | Gamaredon Group RU | Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon G… |
| GAMAREDON-GROUP | Gamaredon Group | Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon G… |
| GambleForce | GambleForce | GambleForce is a threat actor specializing in SQL injection attacks. They have targeted over 20 websites in various sectors across multiple countries, compromi… |
| GAMBLEFORCE | GambleForce | GambleForce is a threat actor specializing in SQL injection attacks. They have targeted over 20 websites in various sectors across multiple countries, compromi… |
| GAMMAX | Gammax | Gammax is a ransomware group that has claimed responsibility for attacks on various organizations, including MTCO in Saudi Arabia, RE/MAX 1st Choice in the USA… |
| GC01 | GC01 | From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered … |
| GC01 | GC01 | From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered … |
| GC02 | GC02 | From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered … |
| GC02 | GC02 | From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered … |
| GCMAN | GCMAN RU | GCMAN is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0036. Original record: GCMAN is a threat… |
| GCMAN | GCMAN | GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. |
| Gelsemium | Gelsemium | The Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible tra… |
| GELSEMIUM | Gelsemium | The Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible tra… |
| Ghost Jackal | Ghost Jackal | Ghost Jackal is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Ghost Jackal. |
| GHOST-JACKAL | Ghost Jackal | |
| GHOST-STADIUM | GHOST STADIUM | GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom… |
| GhostEmperor | GhostEmperor CN | GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo… |
| GHOSTEMPEROR | GhostEmperor | GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo… |
| GhostNet | GhostNet | Cyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio… |
| GHOSTNET | GhostNet | Cyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio… |
| GhostR | GhostR | Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about… |
| GHOSTR | GhostR | Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about… |
| GhostRedirector | GhostRedirector CN | GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie… |
| GHOSTREDIRECTOR | GhostRedirector | GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie… |
| GhostSec | GhostSec | GhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as… |
| GHOSTSEC | GhostSec | GhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as… |
| Ghostwriter | Ghostwriter BY | Ghostwriter is a Belarusian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC1151, TA445, PUSHCHA (and 3 m… |
| GHOSTWRITER | Ghostwriter | Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas, rather than as an ac… |
| GIBBERISH PANDA | GIBBERISH PANDA CN | GIBBERISH PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: GIBBERISH PANDA is a Chinese-attributed thr… |
| GIBBERISH-PANDA | GIBBERISH PANDA | |
| Gitloker | Gitloker | Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com… |
| GITLOKER | Gitloker | Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com… |
| GLOBALSECRETGROUP | GlobalSecretGroup | Global Secret is a ransomware group that has claimed attacks on various organizations across multiple countries, including the USA, India, and Brazil. |
| Gnosticplayers | Gnosticplayers | The hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. … |
| GNOSTICPLAYERS | Gnosticplayers | The hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. … |