2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,101–1,150 of 2,054 · page 23 of 42
| ID | Title | Summary |
|---|---|---|
| OVERFLAME | OverFlame | OverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and corporations in Europ… |
| OVERLORD SPIDER | OVERLORD SPIDER | OVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun… |
| OVERLORD-SPIDER | OVERLORD SPIDER | OVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised servers on undergroun… |
| Pacha Group | Pacha Group | Antd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a … |
| PACHA-GROUP | Pacha Group | Antd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a … |
| Packrat | Packrat | A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician… |
| PACKRAT | Packrat | A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists, journalists, politician… |
| PALE PANDA | PALE PANDA CN | PALE PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: PALE PANDA is a Chinese-attributed threat actor … |
| PALE-PANDA | PALE PANDA | |
| PARINACOTA | PARINACOTA | One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i… |
| PARINACOTA | PARINACOTA | One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as payload. PARINACOTA i… |
| PassCV | PassCV CN | The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. S… |
| PASSCV | PassCV | The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen Authenticode-signing certificates. S… |
| Patched Lightning | Patched Lightning | Patched Lightning is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Storm-0113. Original record: Patched Lightning i… |
| PATCHED-LIGHTNING | Patched Lightning | |
| PayTool | PayTool | PayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e… |
| PAYTOOL | PayTool | PayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians through SMS-based social e… |
| Pearl Sleet | Pearl Sleet KP | Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, m… |
| PEARL-SLEET | Pearl Sleet | Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012. They primarily target defectors from North Korea, m… |
| People's Cyber Army of Russia | People's Cyber Army of Russia | People's Cyber Army of Russia is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as People's Cyber Army of Russia. |
| PEOPLE-S-CYBER-ARMY-OF-RUSSIA | People's Cyber Army of Russia | |
| PerSwaysion | PerSwaysion VN | PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are… |
| PERSWAYSION | PerSwaysion | PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are… |
| PhantomControl | PhantomControl | PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree… |
| PHANTOMCONTROL | PhantomControl | PhantomControl is a sophisticated threat actor that emerged in November 2023. They utilize phishing emails as their initial infection vector and employ a Scree… |
| Phlox Tempest | Phlox Tempest | Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL… |
| PHLOX-TEMPEST | Phlox Tempest | Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious ads. They use ChromeL… |
| Pickaxe | Pickaxe | Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t… |
| PICKAXE | Pickaxe | Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day. The adversary's goal is t… |
| PINCHY SPIDER | PINCHY SPIDER | First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the … |
| PINCHY-SPIDER | PINCHY SPIDER | First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the … |
| Pink Sandstorm | Pink Sandstorm IR | Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima… |
| PINK-SANDSTORM | Pink Sandstorm | Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima… |
| PINSTRIPE-LIGHTNING | Pinstripe Lightning | Microsoft threat actor profile from the public naming mapping feed. |
| PIZZO SPIDER | PIZZO SPIDER US | PIZZO SPIDER is a American-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DD4BC, Ambiorx. Original record: … |
| PIZZO-SPIDER | PIZZO SPIDER | |
| PLATINUM | PLATINUM | PLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ… |
| PLATINUM | PLATINUM | PLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ… |
| PlushDaemon | PlushDaemon CN | PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat… |
| PLUSHDAEMON | PlushDaemon | PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat… |
| POISON CARP | POISON CARP | Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p… |
| POISON-CARP | POISON CARP | Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p… |
| PoisonSeed | PoisonSeed | PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra… |
| POISONSEED | PoisonSeed | PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra… |
| POISONUS PANDA | POISONUS PANDA CN | POISONUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: POISONUS PANDA is a Chinese-attributed threa… |
| POISONUS-PANDA | POISONUS PANDA | |
| POLONIUM | POLONIUM LB | Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell… |
| POLONIUM | POLONIUM | Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell… |
| Poseidon Group | Poseidon Group BR | Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi… |
| POSEIDON-GROUP | Poseidon Group | Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi… |