2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,251–1,300 of 2,054 · page 26 of 42
| ID | Title | Summary |
|---|---|---|
| ROCKET-KITTEN | Rocket Kitten | Targets Saudi Arabia, Israel, US, Iran, high ranking defense officials, embassies of various target countries, notable Iran researchers, human rights activists… |
| RomCom | RomCom RU | ROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially motivated attacks. They ha… |
| ROMCOM | RomCom | ROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially motivated attacks. They ha… |
| RTM | RTM | There are several groups actively and profitably targeting businesses in Russia. A trend that we have seen unfold before our eyes lately is these cybercriminal… |
| RTM | RTM | There are several groups actively and profitably targeting businesses in Russia. A trend that we have seen unfold before our eyes lately is these cybercriminal… |
| Ruby Sleet | Ruby Sleet KP | Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, an… |
| RUBY-SLEET | Ruby Sleet | Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, an… |
| RUBYCARP | RUBYCARP RO | RUBYCARP is a financially-motivated threat actor group likely based in Romania, with a history of at least 10 years of activity. They operate a botnet using pu… |
| RUBYCARP | RUBYCARP | RUBYCARP is a financially-motivated threat actor group likely based in Romania, with a history of at least 10 years of activity. They operate a botnet using pu… |
| RuskiNet | RuskiNet RU | RuskiNet is a pro-Russian hacktivist collective associated with disruptive operations including DDoS attacks, website defacements, phishing, and data leaks aga… |
| RUSKINET | RuskiNet | RuskiNet is a pro-Russian hacktivist collective associated with disruptive operations including DDoS attacks, website defacements, phishing, and data leaks aga… |
| Ruthless Rabbit | Ruthless Rabbit RU | Ruthless Rabbit has been running investment scam campaigns since November 2022, primarily targeting users in Russia, Poland, Romania, and Kazakhstan. The actor… |
| RUTHLESS-RABBIT | Ruthless Rabbit | Ruthless Rabbit has been running investment scam campaigns since November 2022, primarily targeting users in Russia, Poland, Romania, and Kazakhstan. The actor… |
| Saad Tycoon | Saad Tycoon | Saad Tycoon is the operator and alleged developer of the Tycoon 2FA PhaaS, a phishing service that targets users for financial gain. The actor utilizes Bitcoin… |
| SAAD-TYCOON | Saad Tycoon | Saad Tycoon is the operator and alleged developer of the Tycoon 2FA PhaaS, a phishing service that targets users for financial gain. The actor utilizes Bitcoin… |
| SABRE PANDA | SABRE PANDA CN | SABRE PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SABRE PANDA is a Chinese-attributed threat acto… |
| SABRE-PANDA | SABRE PANDA | |
| SaintBear | SaintBear RU | SaintBear is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC2589, TA471, UAC-0056 (and 11 more… |
| SAINTBEAR | SaintBear | A group targeting UA state organizations using the GraphSteel and GrimPlant malware. |
| SALTY SPIDER | SALTY SPIDER | Beginning in January 2018 and persisting through the first half of the year, CrowdStrike Intelligence observed SALTY SPIDER, developer and operator of the long… |
| SALTY-SPIDER | SALTY SPIDER | Beginning in January 2018 and persisting through the first half of the year, CrowdStrike Intelligence observed SALTY SPIDER, developer and operator of the long… |
| SAMBASPIDER | SAMBASPIDER | SAMBASPIDER is a threat actor associated to the Mispadu malware. On July 24, USDoD allegedly scraped and leaked a 100,000-line Indicator of Compromise list fro… |
| SAMBASPIDER | SAMBASPIDER | SAMBASPIDER is a threat actor associated to the Mispadu malware. On July 24, USDoD allegedly scraped and leaked a 100,000-line Indicator of Compromise list fro… |
| SAMURAI PANDA | SAMURAI PANDA CN | SAMURAI PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as PLA Navy, Wisp Team. Operational … |
| SAMURAI-PANDA | SAMURAI PANDA | |
| SandCat | SandCat | SandCat, on the other hand, is a group that was discovered more recently by Kaspersky. One of the Windows vulnerabilities patched by Microsoft in December had … |
| SANDCAT | SandCat | SandCat, on the other hand, is a group that was discovered more recently by Kaspersky. One of the Windows vulnerabilities patched by Microsoft in December had … |
| Sandman APT | Sandman APT CN | First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG backdoor, specifically STO… |
| SANDMAN-APT | Sandman APT | First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG backdoor, specifically STO… |
| Sands Casino | Sands Casino IR | Sands Casino is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Sands Casino is a Iranian-attributed threat ac… |
| SANDS-CASINO | Sands Casino | |
| Sandworm | Sandworm RU | This threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial … |
| SANDWORM | Sandworm | This threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial … |
| Sath-ı Müdafaa | Sath-ı Müdafaa TR | A Turkish hacking group, Sath-ı Müdafaa, is encouraging individuals to join its DDoS-for-Points platform that features points and prizes for carrying out distr… |
| SATH-M-DAFAA | Sath-ı Müdafaa | A Turkish hacking group, Sath-ı Müdafaa, is encouraging individuals to join its DDoS-for-Points platform that features points and prizes for carrying out distr… |
| ScamClub | ScamClub | ScamClub is a threat actor involved in malvertising activities since 2018. They target the Mobile Web market segment, particularly on iOS devices, where securi… |
| SCAMCLUB | ScamClub | ScamClub is a threat actor involved in malvertising activities since 2018. They target the Mobile Web market segment, particularly on iOS devices, where securi… |
| Scarab | Scarab CN | Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small number of individual… |
| SCARAB | Scarab | Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small number of individual… |
| Scarlet Mimic | Scarlet Mimic CN | Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group’s mo… |
| SCARLET-MIMIC | Scarlet Mimic | Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group’s mo… |
| SCARLETEEL | SCARLETEEL | SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and … |
| SCARLETEEL | SCARLETEEL | SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes. They have been observed stealing proprietary data and … |
| Scarred Manticore | Scarred Manticore IR | Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety… |
| SCARRED-MANTICORE | Scarred Manticore | Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety… |
| Scattered Canary | Scattered Canary NG | When the first member of Scattered Canary, who, for the purposes of this report, we call Alpha, began his operations, he was a lone wolf—working mostly Craigsl… |
| SCATTERED-CANARY | Scattered Canary | When the first member of Scattered Canary, who, for the purposes of this report, we call Alpha, began his operations, he was a lone wolf—working mostly Craigsl… |
| SCATTERED-LAPSUS-HUNTERS | Scattered Lapsus Hunters | Launched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on today’s cybercriminal… |
| Scattered Spider | Scattered Spider | Scattered Spider is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as UNC3944, Muddled Libra, Oktapus (and 7 more). Ori… |
| SCATTERED-SPIDER | Scattered Spider | Scattered Spider, a highly active hacking group, has made headlines by targeting more than 130 organizations, with the number of victims steadily increasing. |