2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 601–650 of 2,004 · page 13 of 41

IDTitleSummary
GAMACOPYGamaCopyGamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical infrastructure sectors by mimi…
Gamaredon GroupGamaredon Group
RU
Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon G…
GAMAREDON-GROUPGamaredon GroupUnit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon G…
GambleForceGambleForceGambleForce is a threat actor specializing in SQL injection attacks. They have targeted over 20 websites in various sectors across multiple countries, compromi…
GAMBLEFORCEGambleForceGambleForce is a threat actor specializing in SQL injection attacks. They have targeted over 20 websites in various sectors across multiple countries, compromi…
GC01GC01From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GC01GC01From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GC02GC02From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GC02GC02From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered …
GCMANGCMAN
RU
GCMAN is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0036. Original record: GCMAN is a threat…
GCMANGCMANGCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
GelsemiumGelsemiumThe Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible tra…
GELSEMIUMGelsemiumThe Gelsemium group has been active since at least 2014 and was described in the past by a few security companies. Gelsemium’s name comes from one possible tra…
Ghost JackalGhost Jackal
GHOST-JACKALGhost Jackal
GHOST-STADIUMGHOST STADIUMGHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom…
GhostEmperorGhostEmperor
CN
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo…
GHOSTEMPERORGhostEmperorGhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode roo…
GhostNetGhostNetCyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio…
GHOSTNETGhostNetCyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigatio…
GhostRGhostRGhostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about…
GHOSTRGhostRGhostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about…
GhostRedirectorGhostRedirector
CN
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie…
GHOSTREDIRECTORGhostRedirectorGhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vie…
GhostSecGhostSecGhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as…
GHOSTSECGhostSecGhostSec is a hacktivist group that emerged as an offshoot of Anonymous. They primarily focused on counterterrorism efforts and monitoring online activities as…
GhostwriterGhostwriter
BY
Ghostwriter is a Belarusian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC1151, TA445, PUSHCHA (and 3 m…
GHOSTWRITERGhostwriterGhostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas, rather than as an ac…
GIBBERISH PANDAGIBBERISH PANDA
CN
GIBBERISH PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: GIBBERISH PANDA is a Chinese-attributed thr…
GIBBERISH-PANDAGIBBERISH PANDA
GitlokerGitlokerGitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com…
GITLOKERGitlokerGitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to com…
GnosticplayersGnosticplayersThe hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. …
GNOSTICPLAYERSGnosticplayersThe hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt. …
GOBLIN PANDAGOBLIN PANDA
CN
GOBLIN PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Conimes, Cycldek. Operational targ…
GOBLIN-PANDAGOBLIN PANDAGoblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups. Most Chinese APTs target the United States and NATO, but Goblin Pand…
GOFFEEGOFFEEGOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with malicious attachments, inc…
GOFFEEGOFFEEGOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with malicious attachments, inc…
GOLD BURLAPGOLD BURLAPGOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cros…
GOLD-BURLAPGOLD BURLAPGOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cros…
GOLD CABINGOLD CABINGOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABI…
GOLD-CABINGOLD CABINGOLD CABIN is a financially motivated cybercriminal threat group operating a malware distribution service on behalf of numerous customers since 2018. GOLD CABI…
GOLD DUPONTGOLD DUPONTGOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) …
GOLD-DUPONTGOLD DUPONTGOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka Defray777 or RansomExx) …
GOLD EVERGREENGOLD EVERGREENGOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompass…
GOLD-EVERGREENGOLD EVERGREENGOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until June 2014. It encompass…
GOLD FAIRFAXGOLD FAIRFAXGOLD FAIRFAX is a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit botnet. Ramnit, the …
GOLD-FAIRFAXGOLD FAIRFAXGOLD FAIRFAX is a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit botnet. Ramnit, the …
GOLD FLANDERSGOLD FLANDERSGOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails demanding between 5 and …
GOLD-FLANDERSGOLD FLANDERSGOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails demanding between 5 and …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base