2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 701–750 of 2,004 · page 15 of 41

IDTitleSummary
GreyEnergyGreyEnergyGreyEnergy is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: ESET research reveals a successor to the infamous BlackEnergy APT g…
GREYENERGYGreyEnergyESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks
GREYVIBEGreyVibeGREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs c…
GRIM SPIDERGRIM SPIDERGRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom retu…
GRIM-SPIDERGRIM SPIDERGRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom retu…
GroundbaitGroundbait
UA
Groundbait is a Ukrainian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Groundbait is a group targeting anti-governmen…
GROUNDBAITGroundbaitGroundbait is a group targeting anti-government separatists in the self-declared Donetsk and Luhansk People’s Republics.
Group5Group5A threat actor using Iranian-language tools, Iranian hosting companies, operating from the Iranian IP space at times was observed targeting the Syrian oppositi…
GROUP5Group5A threat actor using Iranian-language tools, Iranian hosting companies, operating from the Iranian IP space at times was observed targeting the Syrian oppositi…
GTFireGTFireGTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs, effectively bypassing secur…
GTFIREGTFireGTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs, effectively bypassing secur…
GTG-1002GTG-1002
CN
GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately 30 global organizations acro…
GTG-1002GTG-1002GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately 30 global organizations acro…
GuacamayaGuacamayaGuacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America, which they believe hav…
GUACAMAYAGuacamayaGuacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America, which they believe hav…
GURU SPIDERGURU SPIDERGURU SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Early in 2018, CrowdStrike Intelligence observed GURU SPIDER suppo…
GURU-SPIDERGURU SPIDEREarly in 2018, CrowdStrike Intelligence observed GURU SPIDER supporting the distribution of multiple crimeware families through its flagship malware loader, Qu…
Hacking TeamHacking TeamThe many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in 2015, have been used by …
HACKING-TEAMHacking TeamThe many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in 2015, have been used by …
HAFNIUMHAFNIUM
CN
HAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher educat…
HAFNIUMHAFNIUMHAFNIUM primarily targets entities in the United States across a number of industry sectors, including infectious disease researchers, law firms, higher educat…
HaggaHaggaHagga is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Aggah, TH-157. Original record: Hagga is believed to have be…
HAGGAHaggaHagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims since the latter part of…
HandalaHandala
PS
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive at…
HANDALAHandalaHandala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive at…
HAZY TIGERHAZY TIGER
IN
The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the Andr…
HAZY-TIGERHAZY TIGERThe Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the Andr…
Head MareHead MareHead Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called PhantomRAT. They have…
HEAD-MAREHead MareHead Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called PhantomRAT. They have…
HellHoundsHellHoundsHellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerabl…
HELLHOUNDSHellHoundsHellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog. They gain initial access through vulnerabl…
HellsingHellsing
CN
This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States. It also seems to have target…
HELLSINGHellsingThis threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States. It also seems to have target…
HenBoxHenBox
CN
HenBox is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Civil society sector. Documented…
HENBOXHenBoxThis threat actor targets Uighurs—a minority ethnic group located primarily in northwestern China—and devices from Chinese mobile phone manufacturer Xiaomi, fo…
HexagonalRodentHexagonalRodentHexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like BeaverT…
HEXAGONALRODENTHexagonalRodentHexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like BeaverT…
HezbHezbHezb is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Mimo. Original record: Hezb is a group deploying cryptominers…
HEZBHezbHezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities. The name is after the miner process they deploy.
HiddenArtHiddenArt
RU
It was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the personal devices of targeted i…
HIDDENARTHiddenArtIt was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the personal devices of targeted i…
HigaisaHigaisa
KR
The organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The bait includes New Year blessi…
HIGAISAHigaisaThe organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The bait includes New Year blessi…
HikkI-ChanHikkI-ChanHikki-Chan has claimed responsibility for multiple significant data breaches, including the theft of data from 390.4 million users of VKontakte, which included…
HIKKI-CHANHikkI-ChanHikki-Chan has claimed responsibility for multiple significant data breaches, including the theft of data from 390.4 million users of VKontakte, which included…
HIVE-0145HIVE-0145Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware to target email cred…
HIVE-0145HIVE-0145Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware to target email cred…
Hive0117Hive0117Hive0117 is a financially motivated cybercriminal group that conducts phishing campaigns to deliver the fileless malware DarkWatchman, which is capable of keyl…
HIVE0117Hive0117Hive0117 is a financially motivated cybercriminal group that conducts phishing campaigns to deliver the fileless malware DarkWatchman, which is capable of keyl…
Hive0137Hive0137Being one of the most active malware distributors, Hive0137 demonstrates a willingness to explore new payloads and technologies such as GenAI. They have quickl…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base