2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,101–1,150 of 2,004 · page 23 of 41

IDTitleSummary
PINCHY SPIDERPINCHY SPIDERFirst observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the …
PINCHY-SPIDERPINCHY SPIDERFirst observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the …
Pink SandstormPink Sandstorm
IR
Agonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima…
PINK-SANDSTORMPink SandstormAgonizing Serpens is an Iranian-linked APT group that has been active since 2020. They are known for their destructive wiper and fake-ransomware attacks, prima…
PIZZO SPIDERPIZZO SPIDER
US
PIZZO SPIDER is a American-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DD4BC, Ambiorx. Original record: …
PIZZO-SPIDERPIZZO SPIDER
PLATINUMPLATINUMPLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ…
PLATINUMPLATINUMPLATINUM has been targeting its victims since at least as early as 2009, and may have been active for several years prior. Its activities are distinctly differ…
PlushDaemonPlushDaemon
CN
PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat…
PLUSHDAEMONPlushDaemonPlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South Korea, the United Stat…
POISON CARPPOISON CARPBetween November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p…
POISON-CARPPOISON CARPBetween November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators p…
PoisonSeedPoisonSeedPoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra…
POISONSEEDPoisonSeedPoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily targeting email infra…
POISONUS PANDAPOISONUS PANDA
CN
POISONUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: POISONUS PANDA is a Chinese-attributed threa…
POISONUS-PANDAPOISONUS PANDA
POLONIUMPOLONIUM
LB
Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell…
POLONIUMPOLONIUMMicrosoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intell…
Poseidon GroupPoseidon Group
BR
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi…
POSEIDON-GROUPPoseidon GroupPoseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from vi…
PowerPoolPowerPoolMalware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability…
POWERPOOLPowerPoolMalware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability…
PREDATOR PANDAPREDATOR PANDA
CN
PREDATOR PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: PREDATOR PANDA is a Chinese-attributed threa…
PREDATOR-PANDAPREDATOR PANDA
Predatory SparrowPredatory SparrowPredatory Sparrow is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Indra, Gonjeshke Darande. Operational targeting …
PREDATORY-SPARROWPredatory SparrowA self-proclaimed hacktivist group that carried out attacks against Iranian railway systems and against Iranian steel plants.
ProCCProCCProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017…
PROCCProCCProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017…
ProjectSauronProjectSauron
US
ProjectSauron is the name for a top level modular cyber-espionage platform, designed to enable and manage long-term campaigns through stealthy survival mechani…
PROJECTSAURONProjectSauronProjectSauron is the name for a top level modular cyber-espionage platform, designed to enable and manage long-term campaigns through stealthy survival mechani…
Prolific PumaProlific PumaProlific Puma provides an underground link shortening service to criminals. Infoblox states that during analysis, no legitimate content was observed being serv…
PROLIFIC-PUMAProlific PumaProlific Puma provides an underground link shortening service to criminals. Infoblox states that during analysis, no legitimate content was observed being serv…
PROMETHIUMPROMETHIUM
TR
PROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation fo…
PROMETHIUMPROMETHIUMPROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation fo…
Prophet SpiderProphet SpiderPROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonl…
PROPHET-SPIDERProphet SpiderPROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonl…
puNK-003puNK-003
KP
puNK-003 is a North Korean APT group known for deploying the Lilith RAT, a sophisticated C++ remote access trojan, and its AutoIt variant, CURKON, which functi…
PUNK-003puNK-003puNK-003 is a North Korean APT group known for deploying the Lilith RAT, a sophisticated C++ remote access trojan, and its AutoIt variant, CURKON, which functi…
PurpleHazePurpleHaze
CN
PurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors such as telecommunicatio…
PURPLEHAZEPurpleHazePurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors such as telecommunicatio…
QUILTED TIGERQUILTED TIGER
IN
Dropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and eco…
QUILTED-TIGERQUILTED TIGERDropping Elephant (also known as “Chinastrats” and “Patchwork“) is a relatively new threat actor that is targeting a variety of high profile diplomatic and eco…
R00tK1TR00tK1T
IL
R00TK1T is a hacking group known for sophisticated cyber attacks targeting governmental agencies in Malaysia, including data exfiltration from the National Pop…
R00TK1TR00tK1TR00TK1T is a hacking group known for sophisticated cyber attacks targeting governmental agencies in Malaysia, including data exfiltration from the National Pop…
RADIO PANDARADIO PANDA
CN
RADIO PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Shrouded Crossbow. Original record:…
RADIO-PANDARADIO PANDA
RaHDitRaHDit
RU
RaHDit is a pro-Kremlin hacktivist group known for orchestrating hack-and-leak operations, including the publication of personal information about Ukrainian mi…
RAHDITRaHDitRaHDit is a pro-Kremlin hacktivist group known for orchestrating hack-and-leak operations, including the publication of personal information about Ukrainian mi…
RANCORRANCOR
CN
The Rancor group’s attacks use two primary malware families which are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears t…
RANCORRANCORThe Rancor group’s attacks use two primary malware families which are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears t…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.