2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 801–850 of 2,054 · page 17 of 42

IDTitleSummary
INDOHAXSEC-TEAMINDOHAXSEC TEAMINDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt websites and demand Bitc…
INDRIK SPIDERINDRIK SPIDER
RU
INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank…
INDRIK-SPIDERINDRIK SPIDERINDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime bank…
Infrastructure Destruction SquadInfrastructure Destruction Squad
RU
Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.…
INFRASTRUCTURE-DESTRUCTION-SQUADInfrastructure Destruction SquadDark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy and food processing.…
InfyInfy
IR
Infy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based …
INFYInfyInfy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based …
INJ3CTOR3INJ3CTOR3INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei…
INJ3CTOR3INJ3CTOR3INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and CVE-2021-45461. Thei…
INTEIDInteidInteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Den…
IntelBrokerIntelBrokerIntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a…
INTELBROKERIntelBrokerIntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook Marketplace. They have a…
InvisiMoleInvisiMoleInvisiMole is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati…
INVISIMOLEInvisiMoleAdversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine.
IRIDIUMIRIDIUM
IR
Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar…
IRIDIUMIRIDIUMResecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a nation-state actor whom we ar…
IRLeaksIRLeaksIRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB…
IRLEAKSIRLeaksIRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where they exfiltrated 3TB…
Iron GroupIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
IRON-GROUPIron GroupIron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms. They have used their ma…
IronErn440IronErn440IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV…
IRONERN440IronErn440IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since September 2023 exploiting CV…
IronHuskyIronHusky
CN
IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research…
IRONHUSKYIronHuskyIronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation companies and research…
ItaDukeItaDukeItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive…
ITADUKEItaDukeItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an actor named DarkUnive…
JabarootJabaroot
DZ
JabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl…
JABAROOTJabarootJabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the Ministry of Economic Incl…
JACKPOT-PANDAJACKPOT PANDAJackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online g…
JADEPUFFERJadePufferJADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack ch…
JavaGhostJavaGhostJavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. …
JAVAGHOSTJavaGhostJavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data theft for extortion. …
JINX-0126JINX-0126Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed …
JINX-0126JINX-0126Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL servers. In the observed …
JINX-0164JINX-0164JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering …
JuiceLedgerJuiceLedgerJuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond…
JUICELEDGERJuiceLedgerJuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly. They have evolved from spreading fraudulent applications to cond…
KairosKairosKairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare…
KAIROSKairosKairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare…
KarakurtKarakurtKarakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic…
KARAKURTKarakurtKarakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt vic…
KarkadannKarkadannKarkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i…
KARKADANNKarkadannKarkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle East. They have been i…
KasablankaKasablanka
MA
The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver…
KASABLANKAKasablankaThe Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using various payloads deliver…
KAX17KAX17KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar…
KAX17KAX17KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primar…
KazuKazuKazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h…
KAZUKazuKazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group h…
KeksecKeksecKeksec is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The threat group behind EnemyBot, Keksec, is well-resourced and has the…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.