2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,301–1,350 of 2,004 · page 27 of 41

IDTitleSummary
SHARPPANDASharpPandaSharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018. The APT group utilizes spear-phish…
ShinyHuntersShinyHuntersShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra…
SHINYHUNTERSShinyHuntersShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide ra…
ShroudedSnooperShroudedSnooperIn September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East…
SHROUDEDSNOOPERShroudedSnooperIn September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications providers in the Middle East…
SideCopySideCopy
PK
The SideCopy APT is a Pakistani threat actor that has been operating since at least 2019, mainly targeting South Asian countries and more specifically India an…
SIDECOPYSideCopyThe SideCopy APT is a Pakistani threat actor that has been operating since at least 2019, mainly targeting South Asian countries and more specifically India an…
SiegedSecSiegedSecSiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your…
SIEGEDSECSiegedSecSiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “Your…
SiestaSiestaFireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure…
SIESTASiestaFireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign. The tools, modus operandi, and infrastructure…
Silence groupSilence groupa relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha…
SILENCE-GROUPSilence groupa relatively new threat actor that’s been operating since mid-2016 Group-IB has exposed the attacks committed by Silence cybercriminal group. While the gang ha…
Silent ChollimaSilent Chollima
KP
Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary …
SILENT-CHOLLIMASilent ChollimaAndariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary …
Silent LibrarianSilent Librarian
IR
Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. Accordi…
SILENT-LIBRARIANSilent LibrarianLast Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute. Accordi…
SilitNetworkSilitNetworkSilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach …
SILITNETWORKSilitNetworkSilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach …
SILKFIN AGENCYSILKFIN AGENCYSILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS re…
SILKFIN-AGENCYSILKFIN AGENCYSILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS re…
SilkSpecterSilkSpecter
CN
SilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers, particularly during peak shoppi…
SILKSPECTERSilkSpecterSilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers, particularly during peak shoppi…
SilverFishSilverFishSilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an at…
SILVERFISHSilverFishSilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an at…
SilverTerrierSilverTerrier
NG
As these tools rise and fall in popularity (and more importantly, as detection rates by antivirus vendors improve), SilverTerrier actors have consistently adop…
SILVERTERRIERSilverTerrierAs these tools rise and fall in popularity (and more importantly, as detection rates by antivirus vendors improve), SilverTerrier actors have consistently adop…
SimaSima
IR
Sima is a group of suspected Iranian origin targeting Iranians in diaspora. In February 2016, Iran-focused individuals received messages purporting to be from …
SIMASimaSima is a group of suspected Iranian origin targeting Iranians in diaspora. In February 2016, Iran-focused individuals received messages purporting to be from …
SINGING SPIDERSINGING SPIDER
SINGING-SPIDERSINGING SPIDER
SingularityMDSingularityMDSingularityMD is a threat actor group that has targeted educational institutions in the US. They gained unauthorized access to their networks by exploiting wea…
SINGULARITYMDSingularityMDSingularityMD is a threat actor group that has targeted educational institutions in the US. They gained unauthorized access to their networks by exploiting wea…
SinobiSinobiSinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure …
SINOBISinobiSinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure …
SkidSecSkidSecSkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda, utilizing techniques…
SKIDSECSkidSecSkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda, utilizing techniques…
SLIME29SLIME29
CN
SLIME29 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private Sector sector. Original…
SLIME29SLIME29
SLIME88SLIME88SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices…
SlingshotSlingshotWhile analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usual…
SLINGSHOTSlingshotWhile analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usual…
SlopAdsSlopAdsSlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors …
SLOPADSSlopAdsSlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors …
SloppyLemmingSloppyLemmingSloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvestin…
SLOPPYLEMMINGSloppyLemmingSloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvestin…
Smishing TriadSmishing Triad
CN
The Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing campaigns. They leverag…
SMISHING-TRIADSmishing TriadThe Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing campaigns. They leverag…
SMOKY SPIDERSMOKY SPIDERSMOKY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SMOKY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga…
SMOKY-SPIDERSMOKY SPIDERMentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.