2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 751–800 of 2,004 · page 16 of 41

IDTitleSummary
HIVE0137Hive0137Being one of the most active malware distributors, Hive0137 demonstrates a willingness to explore new payloads and technologies such as GenAI. They have quickl…
Hive0163Hive0163Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. …
HIVE0163Hive0163Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. …
HollowQuillHollowQuillSEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known institution for various defe…
HOLLOWQUILLHollowQuillSEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known institution for various defe…
HomeLand JusticeHomeLand Justice
IR
HomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021. They have targeted various organizations, inclu…
HOMELAND-JUSTICEHomeLand JusticeHomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021. They have targeted various organizations, inclu…
HoneybeeHoneybeeMcAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as ba…
HONEYBEEHoneybeeMcAfee Advanced Threat Research analysts have discovered a new operation targeting humanitarian aid organizations and using North Korean political topics as ba…
HookAdsHookAdsHookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online games, or blackhat seo sit…
HOOKADSHookAdsHookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online games, or blackhat seo sit…
HoukenHouken
CN
Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to cr…
HOUKENHoukenHouken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain initial access to cr…
HOUND SPIDERHOUND SPIDERHOUND SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: HOUND SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga…
HOUND-SPIDERHOUND SPIDERAccording to Crowdstrike, HOUND SPIDER affiliates arrested in Romania on December,2017
HummingBadHummingBad
CN
This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arse…
HUMMINGBADHummingBadThis group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue. The group effectively controls an arse…
Hunt3r Kill3rsHunt3r Kill3rs
RU
Hunt3r Kill3rs is a newly emerged threat group claiming expertise in cyber operations, including ICS breaches and web application vulnerabilities exploitation.…
HUNT3R-KILL3RSHunt3r Kill3rsHunt3r Kill3rs is a newly emerged threat group claiming expertise in cyber operations, including ICS breaches and web application vulnerabilities exploitation.…
HURRICANE PANDAHURRICANE PANDA
CN
We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large telecommunications and technology comp…
HURRICANE-PANDAHURRICANE PANDAWe have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large telecommunications and technology comp…
IcePeonyIcePeony
CN
IcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and political organizations…
ICEPEONYIcePeonyIcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and political organizations…
IMPERSONATING PANDAIMPERSONATING PANDA
CN
IMPERSONATING PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: IMPERSONATING PANDA is a Chinese-attrib…
IMPERSONATING-PANDAIMPERSONATING PANDA
Inception FrameworkInception Framework
RU
This threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa…
INCEPTION-FRAMEWORKInception FrameworkThis threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa…
IndigoZebraIndigoZebra
CN
IndigoZebra is a Chinese state-sponsored actor mentioned for the first time by Kaspersky in its APT Trends report Q2 2017, targeting, at the time of its discov…
INDIGOZEBRAIndigoZebraIndigoZebra is a Chinese state-sponsored actor mentioned for the first time by Kaspersky in its APT Trends report Q2 2017, targeting, at the time of its discov…
INDOHAXSEC TEAMINDOHAXSEC TEAM
ID
INDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt websites and demand Bitc…
INDOHAXSEC-TEAMINDOHAXSEC TEAMINDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt websites and demand Bitc…
INDRIK SPIDERINDRIK SPIDER
RU
INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank…
INDRIK-SPIDERINDRIK SPIDERINDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank…
Infrastructure Destruction SquadInfrastructure Destruction Squad
RU
Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.…
INFRASTRUCTURE-DESTRUCTION-SQUADInfrastructure Destruction SquadDark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.…
InfyInfy
IR
Infy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based …
INFYInfyInfy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based …
INJ3CTOR3INJ3CTOR3INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei…
INJ3CTOR3INJ3CTOR3INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei…
INTEIDInteidInteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Den…
IntelBrokerIntelBrokerIntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a…
INTELBROKERIntelBrokerIntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a…
InvisiMoleInvisiMoleInvisiMole is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati…
INVISIMOLEInvisiMoleAdversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine.
IRIDIUMIRIDIUM
IR
Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar…
IRIDIUMIRIDIUMResecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar…
IRLeaksIRLeaksIRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB…
IRLEAKSIRLeaksIRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB…
Iron GroupIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
IRON-GROUPIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.