2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 801–850 of 2,054 · page 17 of 42
| ID | Title | Summary |
|---|---|---|
| INDOHAXSEC-TEAM | INDOHAXSEC TEAM | INDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt websites and demand Bitc… |
| INDRIK SPIDER | INDRIK SPIDER RU | INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank… |
| INDRIK-SPIDER | INDRIK SPIDER | INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank… |
| Infrastructure Destruction Squad | Infrastructure Destruction Squad RU | Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.… |
| INFRASTRUCTURE-DESTRUCTION-SQUAD | Infrastructure Destruction Squad | Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.… |
| Infy | Infy IR | Infy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based … |
| INFY | Infy | Infy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based … |
| INJ3CTOR3 | INJ3CTOR3 | INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei… |
| INJ3CTOR3 | INJ3CTOR3 | INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei… |
| INTEID | Inteid | Inteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Den… |
| IntelBroker | IntelBroker | IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a… |
| INTELBROKER | IntelBroker | IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a… |
| InvisiMole | InvisiMole | InvisiMole is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati… |
| INVISIMOLE | InvisiMole | Adversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine. |
| IRIDIUM | IRIDIUM IR | Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar… |
| IRIDIUM | IRIDIUM | Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar… |
| IRLeaks | IRLeaks | IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB… |
| IRLEAKS | IRLeaks | IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB… |
| Iron Group | Iron Group | Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma… |
| IRON-GROUP | Iron Group | Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma… |
| IronErn440 | IronErn440 | IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV… |
| IRONERN440 | IronErn440 | IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV… |
| IronHusky | IronHusky CN | IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research… |
| IRONHUSKY | IronHusky | IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research… |
| ItaDuke | ItaDuke | ItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive… |
| ITADUKE | ItaDuke | ItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive… |
| Jabaroot | Jabaroot DZ | JabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl… |
| JABAROOT | Jabaroot | JabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl… |
| JACKPOT-PANDA | JACKPOT PANDA | Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online g… |
| JADEPUFFER | JadePuffer | JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack ch… |
| JavaGhost | JavaGhost | JavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. … |
| JAVAGHOST | JavaGhost | JavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. … |
| JINX-0126 | JINX-0126 | Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed … |
| JINX-0126 | JINX-0126 | Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed … |
| JINX-0164 | JINX-0164 | JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering … |
| JuiceLedger | JuiceLedger | JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond… |
| JUICELEDGER | JuiceLedger | JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond… |
| Kairos | Kairos | Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare… |
| KAIROS | Kairos | Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare… |
| Karakurt | Karakurt | Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic… |
| KARAKURT | Karakurt | Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic… |
| Karkadann | Karkadann | Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i… |
| KARKADANN | Karkadann | Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i… |
| Kasablanka | Kasablanka MA | The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver… |
| KASABLANKA | Kasablanka | The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver… |
| KAX17 | KAX17 | KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar… |
| KAX17 | KAX17 | KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar… |
| Kazu | Kazu | Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h… |
| KAZU | Kazu | Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h… |
| Keksec | Keksec | Keksec is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The threat group behind EnemyBot, Keksec, is well-resourced and has the… |