2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 901–950 of 2,004 · page 19 of 41

IDTitleSummary
LYCEUMLYCEUMLyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and t…
MadiMadi
IR
Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified …
MADIMadiKaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified …
MageCartMageCartMageCart is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Digital threat management company RiskIQ tracks the activity of MageC…
MAGECARTMageCartDigital threat management company RiskIQ tracks the activity of MageCart group and reported their use of web-based card skimmers since 2016.
Magic KittenMagic Kitten
IR
Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of…
MAGIC-KITTENMagic KittenEarliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of…
MAGNETIC SPIDERMAGNETIC SPIDER
RU
MAGNETIC SPIDER is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: MAGNETIC SPIDER is a Russian-attributed thr…
MAGNETIC-SPIDERMAGNETIC SPIDER
MalKamakMalKamak
IR
MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against g…
MALKAMAKMalKamakMalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against g…
MALLARD SPIDERMALLARD SPIDERMALLARD SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as GOLD LAGOON. Original record: Crowdstrike tarcks th…
MALLARD-SPIDERMALLARD SPIDERCrowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
MalsmokeMalsmokeMalsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content lures and geographic IP i…
MALSMOKEMalsmokeMalsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content lures and geographic IP i…
MalteiroMalteiroMalteiro is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: This group of cybercriminals is named Malteiroby SCILabs, they operat…
MALTEIROMalteiroThis group of cybercriminals is named Malteiroby SCILabs, they operate and distribute the URSA/Mispadu banking trojan.
Mana TeamMana Team
CN
Mana Team is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Mana Team is a Chinese-attributed threat actor ca…
MANA-TEAMMana Team
MarkopoloMarkopoloMarkopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog…
MARKOPOLOMarkopoloMarkopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog…
MassgraveMassgraveMassgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling permanent activation of vers…
MASSGRAVEMassgraveMassgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling permanent activation of vers…
MetadorMetadorMetador primarily targets telecommunications, internet service providers, and universities in several countries in the Middle East and Africa. Metador’s attack…
METADORMetadorMetador primarily targets telecommunications, internet service providers, and universities in several countries in the Middle East and Africa. Metador’s attack…
MIMIC SPIDERMIMIC SPIDERMIMIC SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: MIMIC SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga…
MIMIC-SPIDERMIMIC SPIDERMIMIC SPIDER is mentioned in two summary reports only
Mirage TigerMirage TigerMirage Tiger is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Documented victim organisations include Germany. Original record: Mirage Tiger is …
MIRAGE-TIGERMirage Tiger
MirrorFaceMirrorFace
CN
MirrorFace is a Chinese-speaking advanced persistent threat group that has been targeting high-value organizations in Japan, including media, government, diplo…
MIRRORFACEMirrorFaceMirrorFace is a Chinese-speaking advanced persistent threat group that has been targeting high-value organizations in Japan, including media, government, diplo…
Mocha ManakinMocha ManakinMocha Manakin is a threat actor that employs the paste and run technique for initial access, tricking users into executing scripts that download various payloa…
MOCHA-MANAKINMocha ManakinMocha Manakin is a threat actor that employs the paste and run technique for initial access, tricking users into executing scripts that download various payloa…
ModifiedElephantModifiedElephantOur research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we now attribute to a prev…
MODIFIEDELEPHANTModifiedElephantOur research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we now attribute to a prev…
MofangMofang
CN
Mofang is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Superman, BRONZE WALKER. Operational tar…
MOFANGMofang
MogilevichMogilevichMogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs, offering stolen data f…
MOGILEVICHMogilevichMogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs, offering stolen data f…
MolatoriMolatoriMolatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on domains like atmolatori.…
MOLATORIMolatoriMolatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on domains like atmolatori.…
MoleratsMolerats
PS
In October 2012, malware attacks against Israeli government targets grabbed media attention as officials temporarily cut off Internet access for its entire pol…
MOLERATSMoleratsIn October 2012, malware attacks against Israeli government targets grabbed media attention as officials temporarily cut off Internet access for its entire pol…
MoneyTakerMoneyTakerIn less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and Russia. The group has …
MONEYTAKERMoneyTakerIn less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and Russia. The group has …
MONTY SPIDERMONTY SPIDERMONTY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spandex Tempest. Original record: Spambots continued …
MONTY-SPIDERMONTY SPIDERSpambots continued to decline in 2019, with MONTY SPIDER’s CraP2P spambot falling silent in April.
Mora_001Mora_001
RU
Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit ecosystem. The actor has be…
MORA-001Mora_001Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit ecosystem. The actor has be…
MORH4xMORH4x
MA
MORH4x is a self-proclaimed Moroccan hacking group that claimed responsibility for a data leak from Algeria's pharmaceutical industry ministry. The group annou…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.