2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 901–950 of 2,054 · page 19 of 42
| ID | Title | Summary |
|---|---|---|
| LILACSQUID | LilacSquid | LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021. They use tactics such as exploiting vulnerabilities and compromised… |
| LIMINAL PANDA | LIMINAL PANDA CN | LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d… |
| LIMINAL-PANDA | LIMINAL PANDA | LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and d… |
| LinkC Pub | LinkC Pub | Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H… |
| LINKC-PUB | LinkC Pub | Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider, H… |
| LofyGang | LofyGang | LofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope… |
| LOFYGANG | LofyGang | LofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022. The group, believed to have been ope… |
| Longhorn | Longhorn US | Longhorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh… |
| LONGHORN | Longhorn | Longhorn has been active since at least 2011. It has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. Longh… |
| LongNosedGoblin | LongNosedGoblin CN | LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for… |
| LONGNOSEDGOBLIN | LongNosedGoblin | LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for… |
| LOTUS PANDA | LOTUS PANDA CN | LOTUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spring Dragon, ST Group, DRAGONFISH… |
| LOTUS-PANDA | LOTUS PANDA | Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia. |
| Lucky Cat | Lucky Cat | A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to succes… |
| LUCKY-CAT | Lucky Cat | A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to succes… |
| LulzIntel | LulzIntel | The threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing … |
| LULZINTEL | LulzIntel | The threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing … |
| LulzSec Black | LulzSec Black | LulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical infrastructure in resp… |
| LULZSEC-BLACK | LulzSec Black | LulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical infrastructure in resp… |
| Luna Moth | Luna Moth | Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims int… |
| LUNA-MOTH | Luna Moth | Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social engineering to lure victims int… |
| LUNAR SPIDER | LUNAR SPIDER | According to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intellig… |
| LUNAR-SPIDER | LUNAR SPIDER | According to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intellig… |
| luoxk | luoxk | luoxk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: luoxk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Or… |
| LUOXK | luoxk | Luoxk is a malware campaign targeting web servers throughout Asia, Europe and North America. |
| LYCEUM | LYCEUM IR | Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and t… |
| LYCEUM | LYCEUM | Lyceum is an Iranian APT group that has been active since at least 2014. They primarily target Middle Eastern governments and organizations in the energy and t… |
| Madi | Madi IR | Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified … |
| MADI | Madi | Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign. Kaspersky Lab and Seculert identified … |
| MageCart | MageCart | MageCart is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Digital threat management company RiskIQ tracks the activity of MageC… |
| MAGECART | MageCart | Digital threat management company RiskIQ tracks the activity of MageCart group and reported their use of web-based card skimmers since 2016. |
| Magic Kitten | Magic Kitten IR | Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of… |
| MAGIC-KITTEN | Magic Kitten | Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013, including a series of… |
| MAGNETIC SPIDER | MAGNETIC SPIDER RU | MAGNETIC SPIDER is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: MAGNETIC SPIDER is a Russian-attributed thr… |
| MAGNETIC-SPIDER | MAGNETIC SPIDER | |
| MalKamak | MalKamak IR | MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against g… |
| MALKAMAK | MalKamak | MalKamak is an Iranian threat actor that has been operating since at least 2018. They have been involved in highly targeted cyber espionage campaigns against g… |
| MALLARD SPIDER | MALLARD SPIDER | MALLARD SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as GOLD LAGOON. Original record: Crowdstrike tarcks th… |
| MALLARD-SPIDER | MALLARD SPIDER | Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER |
| Malsmoke | Malsmoke | Malsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content lures and geographic IP i… |
| MALSMOKE | Malsmoke | Malsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content lures and geographic IP i… |
| Malteiro | Malteiro | Malteiro is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: This group of cybercriminals is named Malteiroby SCILabs, they operat… |
| MALTEIRO | Malteiro | This group of cybercriminals is named Malteiroby SCILabs, they operate and distribute the URSA/Mispadu banking trojan. |
| Mana Team | Mana Team CN | Mana Team is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Mana Team is a Chinese-attributed threat actor ca… |
| MANA-TEAM | Mana Team | |
| Markopolo | Markopolo | Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog… |
| MARKOPOLO | Markopolo | Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog… |
| Massgrave | Massgrave | Massgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling permanent activation of vers… |
| MASSGRAVE | Massgrave | Massgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling permanent activation of vers… |
| Metador | Metador | Metador primarily targets telecommunications, internet service providers, and universities in several countries in the Middle East and Africa. Metador’s attack… |