2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,051–1,100 of 2,054 · page 22 of 42
| ID | Title | Summary |
|---|---|---|
| OnionDog | OnionDog KP | OnionDog is a North Korean-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government and Private se… |
| ONIONDOG | OnionDog | This threat actor targets the South Korean government, transportation, and energy sectors. |
| Opal Sleet | Opal Sleet KP | Konni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activ… |
| OPAL-SLEET | Opal Sleet | Konni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activ… |
| Operation BugDrop | Operation BugDrop RU | This threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine. The threat actors deploy the BugDrop malware to rem… |
| OPERATION-BUGDROP | Operation BugDrop | This threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine. The threat actors deploy the BugDrop malware to rem… |
| Operation C-Major | Operation C-Major PK | Operation C-Major is a Pakistani-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as C-Major, Transparent Tribe,… |
| OPERATION-C-MAJOR | Operation C-Major | Group targeting Indian Army or related assets in India, as well as activists and civil society in Pakistan. Attribution to a Pakistani connection has been made… |
| Operation Cobalt Whisper | Operation Cobalt Whisper | Operation Cobalt Whisper is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Operation Cobalt Whisper. |
| OPERATION-COBALT-WHISPER | Operation Cobalt Whisper | |
| Operation Comando | Operation Comando | Operation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves h… |
| OPERATION-COMANDO | Operation Comando | Operation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves h… |
| Operation DRBControl | Operation DRBControl CN | Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of H… |
| OPERATION-DRBCONTROL | Operation DRBControl | Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of H… |
| Operation Emmental | Operation Emmental RU | Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks i… |
| OPERATION-EMMENTAL | Operation Emmental | Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks i… |
| Operation ForumTroll | Operation ForumTroll | Operation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Go… |
| OPERATION-FORUMTROLL | Operation ForumTroll | Operation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Go… |
| Operation Ghoul | Operation Ghoul | Operation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and engineering sectors. They… |
| OPERATION-GHOUL | Operation Ghoul | Operation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and engineering sectors. They… |
| Operation Kabar Cobra | Operation Kabar Cobra | Operation Kabar Cobra is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Operation Kabar Cobra. |
| OPERATION-KABAR-COBRA | Operation Kabar Cobra | |
| Operation Parliament | Operation Parliament | This threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations, primarily in the Middle East… |
| OPERATION-PARLIAMENT | Operation Parliament | This threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations, primarily in the Middle East… |
| Operation Poison Needles | Operation Poison Needles | What’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution was established in 19… |
| OPERATION-POISON-NEEDLES | Operation Poison Needles | What’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution was established in 19… |
| Operation Red Signature | Operation Red Signature CN | The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of inte… |
| OPERATION-RED-SIGNATURE | Operation Red Signature | The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of inte… |
| Operation Shadow Force | Operation Shadow Force CN | Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity that attacks Korean c… |
| OPERATION-SHADOW-FORCE | Operation Shadow Force | Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity that attacks Korean c… |
| Operation ShadowHammer | Operation ShadowHammer | Newly discovered supply chain attack that leveraged ASUS Live Update software. The goal of the attack was to surgically target an unknown pool of users, which … |
| OPERATION-SHADOWHAMMER | Operation ShadowHammer | Newly discovered supply chain attack that leveraged ASUS Live Update software. The goal of the attack was to surgically target an unknown pool of users, which … |
| Operation Sharpshooter | Operation Sharpshooter | The McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear, defense, energy, and… |
| OPERATION-SHARPSHOOTER | Operation Sharpshooter | The McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear, defense, energy, and… |
| Operation Soft Cell | Operation Soft Cell | In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor us… |
| OPERATION-SOFT-CELL | Operation Soft Cell | In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor us… |
| Operation Triangulation | Operation Triangulation | Operation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits. The threat actor behind the campaign has been activ… |
| OPERATION-TRIANGULATION | Operation Triangulation | Operation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits. The threat actor behind the campaign has been activ… |
| Operation WizardOpium | Operation WizardOpium | We are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain … |
| OPERATION-WIZARDOPIUM | Operation WizardOpium | We are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain … |
| Operation Wocao | Operation Wocao | Operation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group. This… |
| OPERATION-WOCAO | Operation Wocao | Operation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group. This… |
| Orangeworm | Orangeworm | Symantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large in… |
| ORANGEWORM | Orangeworm | Symantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large in… |
| OROVA | Orova | Orova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple companies in Hong Kong, such … |
| OurMine | OurMine | OurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r… |
| OURMINE | OurMine | OurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r… |
| OUTLAW SPIDER | OUTLAW SPIDER | On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi… |
| OUTLAW-SPIDER | OUTLAW SPIDER | On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi… |
| OverFlame | OverFlame | OverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ… |