2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 951–1,000 of 2,004 · page 20 of 41

IDTitleSummary
MORH4XMORH4xMORH4x is a self-proclaimed Moroccan hacking group that claimed responsibility for a data leak from Algeria's pharmaceutical industry ministry. The group annou…
MosesStaffMosesStaff
IR
MosesStaff is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Moses Staff, Marigold Sandstorm, DEV…
MOSESSTAFFMosesStaffCybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies …
Moshen DragonMoshen Dragon
CN
Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizi…
MOSHEN-DRAGONMoshen DragonMoshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia. They have been observed deploying multiple malware triads and utilizi…
MoskalvzapoeMoskalvzapoeMoskalvzapoe is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as MAN1, TA511. Original record: Moskalvzapoe is a threa…
MOSKALVZAPOEMoskalvzapoe
MoustachedBouncerMoustachedBouncer
BY
MoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in August 2023. The group has been active since at least 2…
MOUSTACHEDBOUNCERMoustachedBouncerMoustachedBouncer is a cyberespionage group discovered by ESET Research and first publicly disclosed in August 2023. The group has been active since at least 2…
Mr_Rot13Mr_Rot13Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since 2020. They utilize the …
MR-ROT13Mr_Rot13Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since 2020. They utilize the …
MuddyWaterMuddyWater
IR
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including t…
MUDDYWATERMuddyWaterThe MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including t…
MUMMY SPIDERMUMMY SPIDERMUMMY SPIDER is a criminal entity linked to the core development of the malware most commonly known as Emotet or Geodo. First observed in mid-2014, this malwar…
MUMMY-SPIDERMUMMY SPIDERMUMMY SPIDER is a criminal entity linked to the core development of the malware most commonly known as Emotet or Geodo. First observed in mid-2014, this malwar…
MurenSharkMurenSharkMurenShark is an advanced persistent threat group that operates primarily in the Middle East, with a focus on targeting Turkey. They have shown interest in mil…
MURENSHARKMurenSharkMurenShark is an advanced persistent threat group that operates primarily in the Middle East, with a focus on targeting Turkey. They have shown interest in mil…
MUSTANG PANDAMUSTANG PANDA
CN
This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence obs…
MUSTANG-PANDAMUSTANG PANDAThis threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence obs…
Mustard TempestMustard TempestMustard Tempest is a threat actor that primarily uses malvertising as their main technique to gain access to and profile networks. They deploy FakeUpdates, dis…
MUSTARD-TEMPESTMustard TempestMustard Tempest is a threat actor that primarily uses malvertising as their main technique to gain access to and profile networks. They deploy FakeUpdates, dis…
Mythic LikhoMythic LikhoArcane Werewolf has been observed targeting Russian manufacturing enterprises through phishing emails that lead to malicious links and spoofed websites. The ac…
MYTHIC-LIKHOMythic LikhoArcane Werewolf has been observed targeting Russian manufacturing enterprises through phishing emails that lead to malicious links and spoofed websites. The ac…
N4ughtysecTUN4ughtysecTU
BR
In March 2022, a hacking group calling themselves N4ughtySecTU claimed to have breached TransUnion’s systems and threatened to leak four terabytes of data if t…
N4UGHTYSECTUN4ughtysecTUIn March 2022, a hacking group calling themselves N4ughtySecTU claimed to have breached TransUnion’s systems and threatened to leak four terabytes of data if t…
NaikonNaikon
CN
Kaspersky described Naikon in a 2015 report as: 'The Naikon group is mostly active in countries such as the Philippines, Malaysia, Cambodia, Indonesia, Vietnam…
NAIKONNaikonKaspersky described Naikon in a 2015 report as: 'The Naikon group is mostly active in countries such as the Philippines, Malaysia, Cambodia, Indonesia, Vietnam…
Nam3L3ssNam3L3ssNam3L3ss is a threat actor who has leaked data from 25 companies, including over 2.8 million lines of Amazon employee data, which was confirmed to be stolen fr…
NAM3L3SSNam3L3ssNam3L3ss is a threat actor who has leaked data from 25 companies, including over 2.8 million lines of Amazon employee data, which was confirmed to be stolen fr…
NARKETING163Narketing163Narketing163 is a financially motivated threat actor named after one of their frequently used email addresses (narketing163@gmail.com). Active since at least J…
NARWHAL SPIDERNARWHAL SPIDERNARWHAL SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as GOLD ESSEX, TA544, Storm-0302. Original record: NAR…
NARWHAL-SPIDERNARWHAL SPIDERNARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by brin…
NatohubNatohubNatohub is a hacker who claimed to have stolen 42,000 documents from the UN’s International Civil Aviation Organization and is offering the data for sale on un…
NATOHUBNatohubNatohub is a hacker who claimed to have stolen 42,000 documents from the UN’s International Civil Aviation Organization and is offering the data for sale on un…
NazarNazarThis actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation' leak. Earliest known si…
NAZARNazarThis actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation' leak. Earliest known si…
NB65NB65NB65 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Network Battalion 65. Original record: Network Battalion 65 i…
NB65NB65Network Battalion 65 is an hactivist group with ties to Anonymous, known for attacking Russian companies and performing hack-and-leak operations.
NEODYMIUMNEODYMIUMNEODYMIUM is an activity group that is known to use a backdoor malware detected by Microsoft as Wingbird. This backdoor’s characteristics closely match FinFish…
NEODYMIUMNEODYMIUMNEODYMIUM is an activity group that is known to use a backdoor malware detected by Microsoft as Wingbird. This backdoor’s characteristics closely match FinFish…
NetRunnerPRNetRunnerPRNetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan, exfiltrating patient PII and me…
NETRUNNERPRNetRunnerPRNetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan, exfiltrating patient PII and me…
NewsPenguinNewsPenguinNewsPenguin is threat actor that has been targeting organizations in Pakistan. They use a complex payload delivery mechanism and exploit the upcoming Pakistan …
NEWSPENGUINNewsPenguinNewsPenguin is threat actor that has been targeting organizations in Pakistan. They use a complex payload delivery mechanism and exploit the upcoming Pakistan …
Nexus ZetaNexus ZetaNexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP …
NEXUS-ZETANexus ZetaNexus Zeta is no stranger when it comes to implementing SOAP related exploits. The threat actor has already been observed in implementing two other known SOAP …
Nickel AlleyNickel Alley
KP
NICKEL ALLEY is a North Korean threat group that targets technology professionals through fake job opportunities, employing social engineering tactics such as …
NICKEL-ALLEYNickel AlleyNICKEL ALLEY is a North Korean threat group that targets technology professionals through fake job opportunities, employing social engineering tactics such as …
Night DragonNight Dragon
CN
Night Dragon is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0014. Original record: Night Drag…
NIGHT-DRAGONNight Dragon
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.