2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,301–1,350 of 2,054 · page 27 of 42
| ID | Title | Summary |
|---|---|---|
| ScreamedJungle | ScreamedJungle | ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablo… |
| SCREAMEDJUNGLE | ScreamedJungle | ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript code, specifically Bablo… |
| Scripted Sparrow | Scripted Sparrow | Scripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating professional services… |
| SCRIPTED-SPARROW | Scripted Sparrow | Scripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating professional services… |
| SCULLY SPIDER | SCULLY SPIDER | SCULLY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SCULLY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-… |
| SCULLY-SPIDER | SCULLY SPIDER | Mentioned as operator of DanaBot in CrowdStrike's 2020 Report. |
| Sea Turtle | Sea Turtle TR | This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily nati… |
| SEA-TURTLE | Sea Turtle | This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily nati… |
| SEXi | SEXi | SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines… |
| SEXI | SEXi | SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines… |
| Shadow Network | Shadow Network | Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer networ… |
| SHADOW-NETWORK | Shadow Network | Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and other computer networ… |
| SHADOW-AETHER-015 | SHADOW-AETHER-015 | SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management s… |
| SHADOW-AETHER-015 | SHADOW-AETHER-015 | SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity and access management s… |
| Shadow-Earth-053 | Shadow-Earth-053 CN | SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cybere… |
| SHADOW-EARTH-053 | Shadow-Earth-053 | SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cybere… |
| SHADOW-VOID-042 | SHADOW-VOID-042 | SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing campaigns against energy, def… |
| SHADOW-VOID-042 | SHADOW-VOID-042 | SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing campaigns against energy, def… |
| SHADOW-WATER-063 | SHADOW-WATER-063 | SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian financial accounts. Analysi… |
| SHADOWBYT3 | ShadowByt3$ | ShadowByt3$ is a ransomware group known for exfiltrating sensitive data from various organizations, including John Engel Team, Abbott Laboratories, and Nintend… |
| ShadowSyndicate | ShadowSyndicate | ShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple servers. They have bee… |
| SHADOWSYNDICATE | ShadowSyndicate | ShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple servers. They have bee… |
| ShadyPanda | ShadyPanda | ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioni… |
| SHADYPANDA | ShadyPanda | ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity tools while functioni… |
| ShaggyPanther | ShaggyPanther CN | ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia. They have been active since 2008 and utilize hidden encrypte… |
| SHAGGYPANTHER | ShaggyPanther | ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia. They have been active since 2008 and utilize hidden encrypte… |
| Shahid Hemmat | Shahid Hemmat IR | Shahid Hemmat is an IRGC-CEC affiliated hacking group linked to cyberattacks targeting U.S. critical infrastructure, including the defense industry and interna… |
| SHAHID-HEMMAT | Shahid Hemmat | Shahid Hemmat is an IRGC-CEC affiliated hacking group linked to cyberattacks targeting U.S. critical infrastructure, including the defense industry and interna… |
| Shamoon Group | Shamoon Group IR | Shamoon Group is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Cutting Sword of Justice. Origina… |
| SHAMOON-GROUP | Shamoon Group | Shamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle East, especially in the… |
| SHARK SPIDER | SHARK SPIDER RU | This group's activity was first observed in November 2013. It leverages a banking Trojan more commonly known as Shylock which aims to compromise online banking… |
| SHARK-SPIDER | SHARK SPIDER | This group's activity was first observed in November 2013. It leverages a banking Trojan more commonly known as Shylock which aims to compromise online banking… |
| SharpPanda | SharpPanda CN | SharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018. The APT group utilizes spear-phish… |
| SHARPPANDA | SharpPanda | SharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018. The APT group utilizes spear-phish… |
| ShinyHunters | ShinyHunters | ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra… |
| SHINYHUNTERS | ShinyHunters | ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra… |
| ShroudedSnooper | ShroudedSnooper | In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East… |
| SHROUDEDSNOOPER | ShroudedSnooper | In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East… |
| SideCopy | SideCopy PK | The SideCopy APT is a Pakistani threat actor that has been operating since at least 2019, mainly targeting South Asian countries and more specifically India an… |
| SIDECOPY | SideCopy | The SideCopy APT is a Pakistani threat actor that has been operating since at least 2019, mainly targeting South Asian countries and more specifically India an… |
| SiegedSec | SiegedSec | SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your… |
| SIEGEDSEC | SiegedSec | SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your… |
| Siesta | Siesta | FireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure… |
| SIESTA | Siesta | FireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure… |
| Silence group | Silence group | a relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha… |
| SILENCE-GROUP | Silence group | a relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha… |
| Silent Chollima | Silent Chollima KP | Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary … |
| SILENT-CHOLLIMA | Silent Chollima | Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary … |
| Silent Librarian | Silent Librarian IR | Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. Accordi… |
| SILENT-LIBRARIAN | Silent Librarian | Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. Accordi… |