2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 951–1,000 of 2,054 · page 20 of 42

IDTitleSummary
METADORMetadorMetador primarily targets telecommunications, internet service providers, and universities in several countries in the Middle East and Africa. Metador’s attack…
MIMIC SPIDERMIMIC SPIDERMIMIC SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: MIMIC SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga…
MIMIC-SPIDERMIMIC SPIDERMIMIC SPIDER is mentioned in two summary reports only
Mirage TigerMirage TigerMirage Tiger is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Documented victim organisations include Germany. Original record: Mirage Tiger is …
MIRAGE-TIGERMirage Tiger
MirrorFaceMirrorFace
CN
MirrorFace is a Chinese-speaking advanced persistent threat group that has been targeting high-value organizations in Japan, including media, government, diplo…
MIRRORFACEMirrorFaceMirrorFace is a Chinese-speaking advanced persistent threat group that has been targeting high-value organizations in Japan, including media, government, diplo…
Mocha ManakinMocha ManakinMocha Manakin is a threat actor that employs the paste and run technique for initial access, tricking users into executing scripts that download various payloa…
MOCHA-MANAKINMocha ManakinMocha Manakin is a threat actor that employs the paste and run technique for initial access, tricking users into executing scripts that download various payloa…
MODERNSTEALERModernStealerModernStealer is linked to underground posts offering sensitive military, government, nuclear, and aerospace material, with connections to a Session contact id…
ModifiedElephantModifiedElephantOur research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we now attribute to a prev…
MODIFIEDELEPHANTModifiedElephantOur research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we now attribute to a prev…
MofangMofang
CN
Mofang is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Superman, BRONZE WALKER. Operational tar…
MOFANGMofang
MogilevichMogilevichMogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs, offering stolen data f…
MOGILEVICHMogilevichMogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs, offering stolen data f…
MolatoriMolatoriMolatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on domains like atmolatori.…
MOLATORIMolatoriMolatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on domains like atmolatori.…
MoleratsMolerats
PS
In October 2012, malware attacks against Israeli government targets grabbed media attention as officials temporarily cut off Internet access for its entire pol…
MOLERATSMoleratsIn October 2012, malware attacks against Israeli government targets grabbed media attention as officials temporarily cut off Internet access for its entire pol…
MoneyTakerMoneyTakerIn less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and Russia. The group has …
MONEYTAKERMoneyTakerIn less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and Russia. The group has …
MONTY SPIDERMONTY SPIDERMONTY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spandex Tempest. Original record: Spambots continued …
MONTY-SPIDERMONTY SPIDERSpambots continued to decline in 2019, with MONTY SPIDER’s CraP2P spambot falling silent in April.
Mora_001Mora_001
RU
Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit ecosystem. The actor has be…
MORA-001Mora_001Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit ecosystem. The actor has be…
MORH4xMORH4x
MA
MORH4x is a self-proclaimed Moroccan hacking group that claimed responsibility for a data leak from Algeria's pharmaceutical industry ministry. The group annou…
MORH4XMORH4xMORH4x is a self-proclaimed Moroccan hacking group that claimed responsibility for a data leak from Algeria's pharmaceutical industry ministry. The group annou…
MosesStaffMosesStaff
IR
MosesStaff is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Moses Staff, Marigold Sandstorm, DEV…
MOSESSTAFFMosesStaffCybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies …
Moshen DragonMoshen Dragon
CN
Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizi…
MOSHEN-DRAGONMoshen DragonMoshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizi…
MoskalvzapoeMoskalvzapoeMoskalvzapoe is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as MAN1, TA511. Original record: Moskalvzapoe is a threa…
MOSKALVZAPOEMoskalvzapoe
MoustachedBouncerMoustachedBouncer
BY
MoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in August 2023. The group has been active since at least 2…
MOUSTACHEDBOUNCERMoustachedBouncerMoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in August 2023. The group has been active since at least 2…
Mr_Rot13Mr_Rot13Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since 2020. They utilize the …
MR-ROT13Mr_Rot13Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since 2020. They utilize the …
MuddyWaterMuddyWater
IR
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including t…
MUDDYWATERMuddyWaterThe MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including t…
MUMMY SPIDERMUMMY SPIDERMUMMY SPIDER is a criminal entity linked to the core development of the malware most commonly known as Emotet or Geodo. First observed in mid-2014, this malwar…
MUMMY-SPIDERMUMMY SPIDERMUMMY SPIDER is a criminal entity linked to the core development of the malware most commonly known as Emotet or Geodo. First observed in mid-2014, this malwar…
MurenSharkMurenSharkMurenShark is an advanced persistent threat group that operates primarily in the Middle East, with a focus on targeting Turkey. They have shown interest in mil…
MURENSHARKMurenSharkMurenShark is an advanced persistent threat group that operates primarily in the Middle East, with a focus on targeting Turkey. They have shown interest in mil…
MUSTANG PANDAMUSTANG PANDA
CN
This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence obs…
MUSTANG-PANDAMUSTANG PANDAThis threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence obs…
Mustard TempestMustard TempestMustard Tempest is a threat actor that primarily uses malvertising as their main technique to gain access to and profile networks. They deploy FakeUpdates, dis…
MUSTARD-TEMPESTMustard TempestMustard Tempest is a threat actor that primarily uses malvertising as their main technique to gain access to and profile networks. They deploy FakeUpdates, dis…
MYSTERIOUS-ELEPHANTMysterious ElephantMysterious Elephant is an APT group active since 2023 that primarily targets government and foreign affairs entities across South Asia, especially Pakistan, Ba…
Mythic LikhoMythic LikhoArcane Werewolf has been observed targeting Russian manufacturing enterprises through phishing emails that lead to malicious links and spoofed websites. The ac…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.