2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,101–1,150 of 2,054 · page 23 of 42

IDTitleSummary
OVERFLAMEOverFlameOverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ…
OVERLORD SPIDEROVERLORD SPIDEROVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun…
OVERLORD-SPIDEROVERLORD SPIDEROVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun…
Pacha GroupPacha GroupAntd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a …
PACHA-GROUPPacha GroupAntd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a …
PackratPackratA threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician…
PACKRATPackratA threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician…
PALE PANDAPALE PANDA
CN
PALE PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: PALE PANDA is a Chinese-attributed threat actor …
PALE-PANDAPALE PANDA
PARINACOTAPARINACOTAOne actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i…
PARINACOTAPARINACOTAOne actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i…
PassCVPassCV
CN
The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. S…
PASSCVPassCVThe PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. S…
Patched LightningPatched LightningPatched Lightning is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Storm-0113. Original record: Patched Lightning i…
PATCHED-LIGHTNINGPatched Lightning
PayToolPayToolPayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e…
PAYTOOLPayToolPayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e…
Pearl SleetPearl Sleet
KP
Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, m…
PEARL-SLEETPearl SleetPearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, m…
People's Cyber Army of RussiaPeople's Cyber Army of RussiaPeople's Cyber Army of Russia is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as People's Cyber Army of Russia.
PEOPLE-S-CYBER-ARMY-OF-RUSSIAPeople's Cyber Army of Russia
PerSwaysionPerSwaysion
VN
PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are…
PERSWAYSIONPerSwaysionPerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are…
PhantomControlPhantomControlPhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree…
PHANTOMCONTROLPhantomControlPhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree…
Phlox TempestPhlox TempestPhlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL…
PHLOX-TEMPESTPhlox TempestPhlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL…
PickaxePickaxePrying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t…
PICKAXEPickaxePrying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t…
PINCHY SPIDERPINCHY SPIDERFirst observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the …
PINCHY-SPIDERPINCHY SPIDERFirst observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the …
Pink SandstormPink Sandstorm
IR
Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima…
PINK-SANDSTORMPink SandstormAgonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima…
PINSTRIPE-LIGHTNINGPinstripe LightningMicrosoft threat actor profile from the public naming mapping feed.
PIZZO SPIDERPIZZO SPIDER
US
PIZZO SPIDER is a American-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DD4BC, Ambiorx. Original record: …
PIZZO-SPIDERPIZZO SPIDER
PLATINUMPLATINUMPLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ…
PLATINUMPLATINUMPLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ…
PlushDaemonPlushDaemon
CN
PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat…
PLUSHDAEMONPlushDaemonPlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat…
POISON CARPPOISON CARPBetween November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p…
POISON-CARPPOISON CARPBetween November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p…
PoisonSeedPoisonSeedPoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra…
POISONSEEDPoisonSeedPoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra…
POISONUS PANDAPOISONUS PANDA
CN
POISONUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: POISONUS PANDA is a Chinese-attributed threa…
POISONUS-PANDAPOISONUS PANDA
POLONIUMPOLONIUM
LB
Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell…
POLONIUMPOLONIUMMicrosoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell…
Poseidon GroupPoseidon Group
BR
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi…
POSEIDON-GROUPPoseidon GroupPoseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.