2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 601–650 of 2,054 · page 13 of 42

IDTitleSummary
FrostyNeighborFrostyNeighbor
BY
FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuani…
FROSTYNEIGHBORFrostyNeighborFrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuani…
FULCRUMSECFulcrumSecFulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited v…
FunkSecFunkSecFunksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS…
FUNKSECFunkSecFunksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS…
FusionCoreFusionCoreThe CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hack…
FUSIONCOREFusionCoreThe CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore. Running Malware-as-a-service, along with the hack…
FxmspFxmspThroughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp…
FXMSPFxmspThroughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground. Some of the known Fxmsp…
GALLIUMGALLIUM
CN
GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target…
GALLIUMGALLIUMGALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise target…
GallmakerGallmakerSymantec researchers have uncovered a previously unknown attack group that is targeting government and military targets, including several overseas embassies o…
GALLMAKERGallmakerSymantec researchers have uncovered a previously unknown attack group that is targeting government and military targets, including several overseas embassies o…
GamaCopyGamaCopyGamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimi…
GAMACOPYGamaCopyGamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimi…
Gamaredon GroupGamaredon Group
RU
Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon G…
GAMAREDON-GROUPGamaredon GroupUnit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon G…
GambleForceGambleForceGambleForce is a threat actor specializing in SQL injection attacks. They have targeted over 20 websites in various sectors across multiple countries, compromi…
GAMBLEFORCEGambleForceGambleForce is a threat actor specializing in SQL injection attacks. They have targeted over 20 websites in various sectors across multiple countries, compromi…
GAMMAXGammaxGammax is a ransomware group that has claimed responsibility for attacks on various organizations, including MTCO in Saudi Arabia, RE/MAX 1st Choice in the USA…
GC01GC01From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GC01GC01From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GC02GC02From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GC02GC02From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GCMANGCMAN
RU
GCMAN is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0036. Original record: GCMAN is a threat…
GCMANGCMANGCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
GelsemiumGelsemiumThe Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible tra…
GELSEMIUMGelsemiumThe Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible tra…
Ghost JackalGhost JackalGhost Jackal is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Ghost Jackal.
GHOST-JACKALGhost Jackal
GHOST-STADIUMGHOST STADIUMGHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom…
GhostEmperorGhostEmperor
CN
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo…
GHOSTEMPERORGhostEmperorGhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo…
GhostNetGhostNetCyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio…
GHOSTNETGhostNetCyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio…
GhostRGhostRGhostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about…
GHOSTRGhostRGhostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about…
GhostRedirectorGhostRedirector
CN
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie…
GHOSTREDIRECTORGhostRedirectorGhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie…
GhostSecGhostSecGhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as…
GHOSTSECGhostSecGhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as…
GhostwriterGhostwriter
BY
Ghostwriter is a Belarusian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC1151, TA445, PUSHCHA (and 3 m…
GHOSTWRITERGhostwriterGhostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas, rather than as an ac…
GIBBERISH PANDAGIBBERISH PANDA
CN
GIBBERISH PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: GIBBERISH PANDA is a Chinese-attributed thr…
GIBBERISH-PANDAGIBBERISH PANDA
GitlokerGitlokerGitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com…
GITLOKERGitlokerGitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com…
GLOBALSECRETGROUPGlobalSecretGroupGlobal Secret is a ransomware group that has claimed attacks on various organizations across multiple countries, including the USA, India, and Brazil.
GnosticplayersGnosticplayersThe hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. …
GNOSTICPLAYERSGnosticplayersThe hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base