2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 651–700 of 2,004 · page 14 of 41

IDTitleSummary
GOLD GALLEONGOLD GALLEONGOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry out business email comp…
GOLD-GALLEONGOLD GALLEONGOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry out business email comp…
GOLD GARDENGOLD GARDENGOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018 through May 2019. GandC…
GOLD-GARDENGOLD GARDENGOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018 through May 2019. GandC…
GOLD MANSARDGOLD MANSARDGOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019. The threat actor behind Nemty is known …
GOLD-MANSARDGOLD MANSARDGOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019. The threat actor behind Nemty is known …
GOLD NORTHFIELDGOLD NORTHFIELDOperational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomwar…
GOLD-NORTHFIELDGOLD NORTHFIELDOperational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD SOUTHFIELD's REvil ransomwar…
GOLD PRELUDEGOLD PRELUDEGOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE op…
GOLD-PRELUDEGOLD PRELUDEGOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE op…
GOLD REBELLIONGOLD REBELLIONGOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware. The group posted its first victim…
GOLD-REBELLIONGOLD REBELLIONGOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware. The group posted its first victim…
GOLD RIVERVIEWGOLD RIVERVIEWGOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on behalf of its custome…
GOLD-RIVERVIEWGOLD RIVERVIEWGOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on behalf of its custome…
GOLD SKYLINEGOLD SKYLINEGOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by business email compro…
GOLD-SKYLINEGOLD SKYLINEGOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by business email compro…
GOLD SOUTHFIELDGOLD SOUTHFIELDGOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various affi…
GOLD-SOUTHFIELDGOLD SOUTHFIELDGOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various affi…
GOLD SYMPHONYGOLD SYMPHONYGOLD SYMPHONY is a financially motivated cybercrime group, likely based in Russia, that is responsible for the development and sale on underground forums of th…
GOLD-SYMPHONYGOLD SYMPHONYGOLD SYMPHONY is a financially motivated cybercrime group, likely based in Russia, that is responsible for the development and sale on underground forums of th…
GOLD WATERFALLGOLD WATERFALLGOLD WATERFALL is a group of financially motivated cybercriminals responsible for the creation, distribution, and operation of the Darkside ransomware. Active …
GOLD-WATERFALLGOLD WATERFALLGOLD WATERFALL is a group of financially motivated cybercriminals responsible for the creation, distribution, and operation of the Darkside ransomware. Active …
GOLD WINTERGOLD WINTERGOLD WINTER are a financially motivated group, likely based in Russia, who operate the Hades ransomware. Hades activity was first identified in December 2020 a…
GOLD-WINTERGOLD WINTERGOLD WINTER are a financially motivated group, likely based in Russia, who operate the Hades ransomware. Hades activity was first identified in December 2020 a…
GoldenJackalGoldenJackalGoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers uplo…
GOLDENJACKALGoldenJackalGoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic. Kaspersky believes the attackers uplo…
GoldFactoryGoldFactory
CN
GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the Asia-Pacific region, speci…
GOLDFACTORYGoldFactoryGoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the Asia-Pacific region, speci…
GopherWhisperGopherWhisper
CN
GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Microsoft 365 Outlook to evade det…
GOPHERWHISPERGopherWhisperGopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Microsoft 365 Outlook to evade det…
GorillaGorillaGorilla is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Gorilla is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341)…
GORILLAGorillaGorilla is a threat-actor operating a DoS-as-a-service service controlled on Telegram.
GozNymGozNymIBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware. It appears that the operators of Nymaim have recompiled its sourc…
GOZNYMGozNymIBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware. It appears that the operators of Nymaim have recompiled its sourc…
Gray SandstormGray Sandstorm
IR
Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology companies, maritime transportatio…
GRAY-SANDSTORMGray SandstormGray Sandstorm is an Iran-linked threat actor that has been active since at least 2012. They have targeted defense technology companies, maritime transportatio…
GrayBravoGrayBravoTAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including CastleLoader and Castl…
GRAYBRAVOGrayBravoTAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including CastleLoader and Castl…
GrayCharlieGrayCharlieGrayCharlie is a threat actor that compromises WordPress sites to inject malicious JavaScript, redirecting visitors to NetSupport RAT payloads via fake browser…
GRAYCHARLIEGrayCharlieGrayCharlie is a threat actor that compromises WordPress sites to inject malicious JavaScript, redirecting visitors to NetSupport RAT payloads via fake browser…
GraylingGrayling
CN
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling app…
GRAYLINGGraylingGrayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling app…
GreedyBearGreedyBear
RU
GreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 150 malicious Firefox extension…
GREEDYBEARGreedyBearGreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 150 malicious Firefox extension…
GreenbugGreenbug
IR
Greenbug is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Greenbug was discovered targeting a range of organ…
GREENBUGGreenbugGreenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government, investment, and educatio…
GreenSpotGreenSpot
TW
GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, and military entities in China…
GREENSPOTGreenSpotGreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, and military entities in China…
GREFGREF
CN
GREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loaders, and ancillary tools in th…
GREFGREFGREF is a China-aligned APT group that has been active since at least March 2017. They are known for using custom backdoors, loaders, and ancillary tools in th…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base