2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 851–900 of 2,054 · page 18 of 42

IDTitleSummary
KEKSECKeksecThe threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of malware on a daily basis (…
KelvinSecurityKelvinSecurity
ES
KelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and p…
KELVINSECURITYKelvinSecurityKelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and p…
Keymous+Keymous+Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur…
KEYMOUSKeymous+Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and critical infrastructur…
KillnetKillnetKillnet is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisations…
KILLNETKillnetA group targeting various countries using Denial of Services attacked.
KimsukyKimsuky
KP
Kimsuky is a North Korean-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Velvet Chollima, Black Banshee, Th…
KIMSUKYKimsukyThis threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
KinsingKinsingThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
KINSINGKinsingThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
Kiss-a-DogKiss-a-DogCrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and…
KISS-A-DOGKiss-a-DogCrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure. Called “Kiss-a-dog,” the campaign targets Docker and…
KromSecKromSecKromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi…
KROMSECKromSecKromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists. The group has been involved in a number of high-profi…
KrybitKrybitKrybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support …
KRYBITKrybitKrybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support …
LabHostLabHostLabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re…
LABHOSTLabHostLabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks. They have been observed using tools like LabRat and LabSend for re…
LamashtuLamashtuLamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun…
LAMASHTULamashtuLamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with coun…
LanceflyLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LANCEFLYLanceflyLancefly targets government, aviation, and telecom organizations in South and Southeast Asia. They use a custom backdoor named Merdoor, developed since 2018, a…
LAPSUSLAPSUSLAPSUS is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as LAPSUS$, DEV-0537, SLIPPY SPIDER (and 3 more). Original rec…
LAPSUSLAPSUSAn actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive element…
Larva-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
LARVA-208Larva-208LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware. The actor uses multi…
Larva-24005Larva-24005
KP
Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individual…
LARVA-24005Larva-24005Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individual…
LARVA-24009Larva-24009Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The acto…
Larva-24010Larva-24010The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst…
LARVA-24010Larva-24010The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the inst…
Larva-26002Larva-26002Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona…
LARVA-26002Larva-26002Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks. The actor has distributed Trigona…
LARVA-26005Larva-26005Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea. The malware was initially disclosed in 2024 and was later found d…
LARVA-26009Larva-26009Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
LARVA-26010Larva-26010Larva-26010 targets web servers and MS-SQL servers in Korea to install SoftEther VPN, using the systems as VPN servers. After the initial breach, the actor ins…
Larva‑25012Larva‑25012Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows…
LARVA-25012Larva‑25012Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows…
Lazarus GroupLazarus Group
KP
Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltratio…
LAZARUS-GROUPLazarus GroupSince 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltratio…
Libyan ScorpionsLibyan Scorpions
LY
Libyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is intelligence gatherin…
LIBYAN-SCORPIONSLibyan ScorpionsLibyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is intelligence gatherin…
Lifting ZmiyLifting ZmiyRostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t…
LIFTING-ZMIYLifting ZmiyRostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were t…
LightBasinLightBasinUNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise…
LIGHTBASINLightBasinUNC1945 is an APT group that has been targeting telecommunications companies globally. They use Linux-based implants to maintain long-term access in compromise…
Lilac TyphoonLilac Typhoon
CN
Lilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a…
LILAC-TYPHOONLilac TyphoonLilac Typhoon is a threat actor attributed to China. They have been identified as exploiting the Atlassian Confluence RCE vulnerability CVE-2022-26134, which a…
LilacSquidLilacSquidLilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base