2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,051–1,100 of 2,054 · page 22 of 42

IDTitleSummary
OnionDogOnionDog
KP
OnionDog is a North Korean-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government and Private se…
ONIONDOGOnionDogThis threat actor targets the South Korean government, transportation, and energy sectors.
Opal SleetOpal Sleet
KP
Konni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activ…
OPAL-SLEETOpal SleetKonni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activ…
Operation BugDropOperation BugDrop
RU
This threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine. The threat actors deploy the BugDrop malware to rem…
OPERATION-BUGDROPOperation BugDropThis threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine. The threat actors deploy the BugDrop malware to rem…
Operation C-MajorOperation C-Major
PK
Operation C-Major is a Pakistani-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as C-Major, Transparent Tribe,…
OPERATION-C-MAJOROperation C-MajorGroup targeting Indian Army or related assets in India, as well as activists and civil society in Pakistan. Attribution to a Pakistani connection has been made…
Operation Cobalt WhisperOperation Cobalt WhisperOperation Cobalt Whisper is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Operation Cobalt Whisper.
OPERATION-COBALT-WHISPEROperation Cobalt Whisper
Operation ComandoOperation ComandoOperation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves h…
OPERATION-COMANDOOperation ComandoOperation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality sector, which proves h…
Operation DRBControlOperation DRBControl
CN
Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of H…
OPERATION-DRBCONTROLOperation DRBControlOperation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of H…
Operation EmmentalOperation Emmental
RU
Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks i…
OPERATION-EMMENTALOperation EmmentalOperation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012. They primarily target customers of banks i…
Operation ForumTrollOperation ForumTrollOperation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Go…
OPERATION-FORUMTROLLOperation ForumTrollOperation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025. The attack exploited a zero-day vulnerability in Go…
Operation GhoulOperation GhoulOperation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and engineering sectors. They…
OPERATION-GHOULOperation GhoulOperation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and engineering sectors. They…
Operation Kabar CobraOperation Kabar CobraOperation Kabar Cobra is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Operation Kabar Cobra.
OPERATION-KABAR-COBRAOperation Kabar Cobra
Operation ParliamentOperation ParliamentThis threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations, primarily in the Middle East…
OPERATION-PARLIAMENTOperation ParliamentThis threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations, primarily in the Middle East…
Operation Poison NeedlesOperation Poison NeedlesWhat’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution was established in 19…
OPERATION-POISON-NEEDLESOperation Poison NeedlesWhat’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution was established in 19…
Operation Red SignatureOperation Red Signature
CN
The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of inte…
OPERATION-RED-SIGNATUREOperation Red SignatureThe threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to their targets of inte…
Operation Shadow ForceOperation Shadow Force
CN
Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity that attacks Korean c…
OPERATION-SHADOW-FORCEOperation Shadow ForceOperation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity that attacks Korean c…
Operation ShadowHammerOperation ShadowHammerNewly discovered supply chain attack that leveraged ASUS Live Update software. The goal of the attack was to surgically target an unknown pool of users, which …
OPERATION-SHADOWHAMMEROperation ShadowHammerNewly discovered supply chain attack that leveraged ASUS Live Update software. The goal of the attack was to surgically target an unknown pool of users, which …
Operation SharpshooterOperation SharpshooterThe McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear, defense, energy, and…
OPERATION-SHARPSHOOTEROperation SharpshooterThe McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear, defense, energy, and…
Operation Soft CellOperation Soft CellIn 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor us…
OPERATION-SOFT-CELLOperation Soft CellIn 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor us…
Operation TriangulationOperation TriangulationOperation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits. The threat actor behind the campaign has been activ…
OPERATION-TRIANGULATIONOperation TriangulationOperation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits. The threat actor behind the campaign has been activ…
Operation WizardOpiumOperation WizardOpiumWe are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain …
OPERATION-WIZARDOPIUMOperation WizardOpiumWe are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain …
Operation WocaoOperation WocaoOperation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group. This…
OPERATION-WOCAOOperation WocaoOperation Wocao (我操, “Wǒ cāo”, used as “shit” or “damn”) is the name that Fox-IT uses to describe the hacking activities of a Chinese based hacking group. This…
OrangewormOrangewormSymantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large in…
ORANGEWORMOrangewormSymantec has identified a previously unknown group called Orangeworm that has been observed installing a custom backdoor called Trojan.Kwampirs within large in…
OROVAOrovaOrova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple companies in Hong Kong, such …
OurMineOurMineOurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r…
OURMINEOurMineOurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services. (Trend Micro) In light of the recent r…
OUTLAW SPIDEROUTLAW SPIDEROn May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi…
OUTLAW-SPIDEROUTLAW SPIDEROn May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S. City of Baltimore (CoB) was infected with ransomware, which was announced vi…
OverFlameOverFlameOverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.