2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,151–1,200 of 2,004 · page 24 of 41

IDTitleSummary
RansomHouseRansomHouseThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
RANSOMHOUSERansomHouseThis group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear…
RansomHubRansomHubRansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware. They have been linked to attacks exploiting t…
RANSOMHUBRansomHubRansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware. They have been linked to attacks exploiting t…
RansomVCRansomVCRansomed.VC burst onto the scene with a well-orchestrated PR campaign, encompassing a clearnet site and multiple communication channels including Telegram and …
RANSOMVCRansomVCRansomed.VC burst onto the scene with a well-orchestrated PR campaign, encompassing a clearnet site and multiple communication channels including Telegram and …
Raspberry TyphoonRaspberry Typhoon
CN
Microsoft has tracked Raspberry Typhoon (RADIUM) as the primary threat group targeting nations that ring the South China Sea. Raspberry Typhoon consistently ta…
RASPBERRY-TYPHOONRaspberry TyphoonMicrosoft has tracked Raspberry Typhoon (RADIUM) as the primary threat group targeting nations that ring the South China Sea. Raspberry Typhoon consistently ta…
RASPITERASPITEDragos has identified a new activity group targeting access operations in the electric utility sector. We call this activity group RASPITE. Analysis of RASPIT…
RASPITERASPITEDragos has identified a new activity group targeting access operations in the electric utility sector. We call this activity group RASPITE. Analysis of RASPIT…
RATPAK SPIDERRATPAK SPIDERIn July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s …
RATPAK-SPIDERRATPAK SPIDERIn July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s …
RAZOR TIGERRAZOR TIGER
IN
An actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian compan…
RAZOR-TIGERRAZOR TIGERAn actor mainly targeting Pakistan military targets, active since at least 2012. We have low confidence that this malware might be authored by an Indian compan…
Rebel JackalRebel Jackal
TN
This is a pro-Islamist organization that generally conducts attacks motivated by real world events in which its members believe that members of the Muslim fait…
REBEL-JACKALRebel JackalThis is a pro-Islamist organization that generally conducts attacks motivated by real world events in which its members believe that members of the Muslim fait…
Reckless RabbitReckless RabbitReckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with embedded web forms for perso…
RECKLESS-RABBITReckless RabbitReckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with embedded web forms for perso…
Red CharonRed CharonThroughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks havi…
RED-CHARONRed CharonThroughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack. Due to these APT attacks havi…
Red Dev 17Red Dev 17
CN
In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat acto…
RED-DEV-17Red Dev 17In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat acto…
Red MenshenRed Menshen
CN
Since 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East and Asia, as well as…
RED-MENSHENRed MenshenSince 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East and Asia, as well as…
Red NueRed Nue
CN
Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows…
RED-NUERed NueRed Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows…
Red-LiliRed-LiliRED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platfo…
RED-LILIRed-LiliRED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platfo…
RedAlphaRedAlphaRecorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we…
REDALPHARedAlphaRecorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we…
RedDeltaRedDeltaLikely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX …
REDDELTARedDeltaLikely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX …
RedEchoRedEchoRedEcho is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: RedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we us…
REDECHORedEchoRedEcho: The group made heavy use of AXIOMATICASYMPTOTE — a term we use to track infrastructure that comprises ShadowPad C2s, which is shared between several C…
RedflyRedflyRedfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evi…
REDFLYRedflyRedfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months. Researchers discovered evi…
RedGolfRedGolf
CN
Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KE…
REDGOLFRedGolfRecorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows and Linux backdoor KE…
RedJuliettRedJuliett
CN
RedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in Taiwan. They exploit vu…
REDJULIETTRedJuliettRedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in Taiwan. They exploit vu…
RedKittenRedKittenRedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The mal…
REDKITTENRedKittenRedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in January 2026. The mal…
RedStingerRedStingerIn October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crim…
REDSTINGERRedStingerIn October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crim…
REF2924REF2924
CN
A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the resear…
REF2924REF2924A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the resear…
REF5961REF5961Elastic's security team has published a report on REF5961, a cyber-espionage group they found on the network of a Foreign Affairs Ministry from a member of the…
REF5961REF5961Elastic's security team has published a report on REF5961, a cyber-espionage group they found on the network of a Foreign Affairs Ministry from a member of the…
REF7707REF7707
CN
REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families such as FinalDraft, Gui…
REF7707REF7707REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families such as FinalDraft, Gui…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.