2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 901–950 of 2,054 · page 19 of 42

IDTitleSummary
LILACSQUIDLilacSquidLilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised…
LIMINAL PANDALIMINAL PANDA
CN
LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d…
LIMINAL-PANDALIMINAL PANDALIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d…
LinkC PubLinkC PubLinkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H…
LINKC-PUBLinkC PubLinkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H…
LofyGangLofyGangLofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope…
LOFYGANGLofyGangLofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope…
LonghornLonghorn
US
Longhorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh…
LONGHORNLonghornLonghorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh…
LongNosedGoblinLongNosedGoblin
CN
LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for…
LONGNOSEDGOBLINLongNosedGoblinLongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for…
LOTUS PANDALOTUS PANDA
CN
LOTUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spring Dragon, ST Group, DRAGONFISH…
LOTUS-PANDALOTUS PANDALotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.
Lucky CatLucky CatA series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to succes…
LUCKY-CATLucky CatA series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to succes…
LulzIntelLulzIntelThe threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing …
LULZINTELLulzIntelThe threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing …
LulzSec BlackLulzSec BlackLulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical infrastructure in resp…
LULZSEC-BLACKLulzSec BlackLulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical infrastructure in resp…
Luna MothLuna MothLuna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims int…
LUNA-MOTHLuna MothLuna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims int…
LUNAR SPIDERLUNAR SPIDERAccording to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intellig…
LUNAR-SPIDERLUNAR SPIDERAccording to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intellig…
luoxkluoxkluoxk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: luoxk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Or…
LUOXKluoxkLuoxk is a malware campaign targeting web servers throughout Asia, Europe and North America.
LYCEUMLYCEUM
IR
Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and t…
LYCEUMLYCEUMLyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and t…
MadiMadi
IR
Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified …
MADIMadiKaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified …
MageCartMageCartMageCart is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Digital threat management company RiskIQ tracks the activity of MageC…
MAGECARTMageCartDigital threat management company RiskIQ tracks the activity of MageCart group and reported their use of web-based card skimmers since 2016.
Magic KittenMagic Kitten
IR
Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of…
MAGIC-KITTENMagic KittenEarliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of…
MAGNETIC SPIDERMAGNETIC SPIDER
RU
MAGNETIC SPIDER is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: MAGNETIC SPIDER is a Russian-attributed thr…
MAGNETIC-SPIDERMAGNETIC SPIDER
MalKamakMalKamak
IR
MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against g…
MALKAMAKMalKamakMalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against g…
MALLARD SPIDERMALLARD SPIDERMALLARD SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as GOLD LAGOON. Original record: Crowdstrike tarcks th…
MALLARD-SPIDERMALLARD SPIDERCrowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
MalsmokeMalsmokeMalsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content lures and geographic IP i…
MALSMOKEMalsmokeMalsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content lures and geographic IP i…
MalteiroMalteiroMalteiro is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: This group of cybercriminals is named Malteiroby SCILabs, they operat…
MALTEIROMalteiroThis group of cybercriminals is named Malteiroby SCILabs, they operate and distribute the URSA/Mispadu banking trojan.
Mana TeamMana Team
CN
Mana Team is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Mana Team is a Chinese-attributed threat actor ca…
MANA-TEAMMana Team
MarkopoloMarkopoloMarkopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog…
MARKOPOLOMarkopoloMarkopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog…
MassgraveMassgraveMassgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling permanent activation of vers…
MASSGRAVEMassgraveMassgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling permanent activation of vers…
MetadorMetadorMetador primarily targets telecommunications, internet service providers, and universities in several countries in the Middle East and Africa. Metador’s attack…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.