2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 851–900 of 2,004 · page 18 of 41

IDTitleSummary
LANCEFLYLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LAPSUSLAPSUSLAPSUS is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LAPSUS$, DEV-0537, SLIPPY SPIDER (and 3 more). Original rec…
LAPSUSLAPSUSAn actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive element…
Larva-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
LARVA-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
Larva-24005Larva-24005
KP
Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individual…
LARVA-24005Larva-24005Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individual…
Larva-24010Larva-24010The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst…
LARVA-24010Larva-24010The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst…
Larva-26002Larva-26002Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona…
LARVA-26002Larva-26002Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona…
Larva‑25012Larva‑25012Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows…
LARVA-25012Larva‑25012Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows…
Lazarus GroupLazarus Group
KP
Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltratio…
LAZARUS-GROUPLazarus GroupSince 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltratio…
Libyan ScorpionsLibyan Scorpions
LY
Libyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is intelligence gatherin…
LIBYAN-SCORPIONSLibyan ScorpionsLibyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is intelligence gatherin…
Lifting ZmiyLifting ZmiyRostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t…
LIFTING-ZMIYLifting ZmiyRostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t…
LightBasinLightBasinUNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise…
LIGHTBASINLightBasinUNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise…
Lilac TyphoonLilac Typhoon
CN
Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a…
LILAC-TYPHOONLilac TyphoonLilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a…
LilacSquidLilacSquidLilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised…
LILACSQUIDLilacSquidLilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised…
LIMINAL PANDALIMINAL PANDA
CN
LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d…
LIMINAL-PANDALIMINAL PANDALIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d…
LinkC PubLinkC PubLinkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H…
LINKC-PUBLinkC PubLinkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H…
LofyGangLofyGangLofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope…
LOFYGANGLofyGangLofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope…
LonghornLonghorn
US
Longhorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh…
LONGHORNLonghornLonghorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh…
LongNosedGoblinLongNosedGoblin
CN
LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for…
LONGNOSEDGOBLINLongNosedGoblinLongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for…
LOTUS PANDALOTUS PANDA
CN
LOTUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spring Dragon, ST Group, DRAGONFISH…
LOTUS-PANDALOTUS PANDALotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.
Lucky CatLucky CatA series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to succes…
LUCKY-CATLucky CatA series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to succes…
LulzIntelLulzIntelThe threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing …
LULZINTELLulzIntelThe threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing …
LulzSec BlackLulzSec BlackLulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical infrastructure in resp…
LULZSEC-BLACKLulzSec BlackLulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical infrastructure in resp…
Luna MothLuna MothLuna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims int…
LUNA-MOTHLuna MothLuna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims int…
LUNAR SPIDERLUNAR SPIDERAccording to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intellig…
LUNAR-SPIDERLUNAR SPIDERAccording to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intellig…
luoxkluoxkluoxk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: luoxk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Or…
LUOXKluoxkLuoxk is a malware campaign targeting web servers throughout Asia, Europe and North America.
LYCEUMLYCEUM
IR
Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and t…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.