2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 1,351–1,400 of 2,054 · page 28 of 42
| ID | Title | Summary |
|---|---|---|
| SilitNetwork | SilitNetwork | SilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach … |
| SILITNETWORK | SilitNetwork | SilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach … |
| SILKFIN AGENCY | SILKFIN AGENCY | SILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS re… |
| SILKFIN-AGENCY | SILKFIN AGENCY | SILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS re… |
| SILKPARASITE | SilkParasite | SilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications entities in Kyrgyzstan, U… |
| SilkSpecter | SilkSpecter CN | SilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers, particularly during peak shoppi… |
| SILKSPECTER | SilkSpecter | SilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers, particularly during peak shoppi… |
| SilverFish | SilverFish | SilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an at… |
| SILVERFISH | SilverFish | SilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an at… |
| SilverTerrier | SilverTerrier NG | As these tools rise and fall in popularity (and more importantly, as detection rates by antivirus vendors improve), SilverTerrier actors have consistently adop… |
| SILVERTERRIER | SilverTerrier | As these tools rise and fall in popularity (and more importantly, as detection rates by antivirus vendors improve), SilverTerrier actors have consistently adop… |
| Sima | Sima IR | Sima is a group of suspected Iranian origin targeting Iranians in diaspora. In February 2016, Iran-focused individuals received messages purporting to be from … |
| SIMA | Sima | Sima is a group of suspected Iranian origin targeting Iranians in diaspora. In February 2016, Iran-focused individuals received messages purporting to be from … |
| SINGING SPIDER | SINGING SPIDER | SINGING SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as SINGING SPIDER. |
| SINGING-SPIDER | SINGING SPIDER | |
| SingularityMD | SingularityMD | SingularityMD is a threat actor group that has targeted educational institutions in the US. They gained unauthorized access to their networks by exploiting wea… |
| SINGULARITYMD | SingularityMD | SingularityMD is a threat actor group that has targeted educational institutions in the US. They gained unauthorized access to their networks by exploiting wea… |
| Sinobi | Sinobi | Sinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure … |
| SINOBI | Sinobi | Sinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure … |
| SkidSec | SkidSec | SkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda, utilizing techniques… |
| SKIDSEC | SkidSec | SkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda, utilizing techniques… |
| SLIME29 | SLIME29 CN | SLIME29 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private Sector sector. Original… |
| SLIME29 | SLIME29 | |
| SLIME88 | SLIME88 | SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices… |
| Slingshot | Slingshot | While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usual… |
| SLINGSHOT | Slingshot | While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usual… |
| SlopAds | SlopAds | SlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors … |
| SLOPADS | SlopAds | SlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors … |
| SloppyLemming | SloppyLemming | SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvestin… |
| SLOPPYLEMMING | SloppyLemming | SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvestin… |
| Smishing Triad | Smishing Triad CN | The Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing campaigns. They leverag… |
| SMISHING-TRIAD | Smishing Triad | The Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing campaigns. They leverag… |
| SMOKY SPIDER | SMOKY SPIDER | SMOKY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SMOKY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga… |
| SMOKY-SPIDER | SMOKY SPIDER | Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report. |
| SmugX | SmugX | The campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some e… |
| SMUGX | SmugX | The campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some e… |
| Snake Wine | Snake Wine | While investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered another prolonged campaig… |
| SNAKE-WINE | Snake Wine | While investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered another prolonged campaig… |
| SneakyChef | SneakyChef CN | SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have be… |
| SNEAKYCHEF | SneakyChef | SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have be… |
| SNOWGLOBE | SNOWGLOBE FR | In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulner… |
| SNOWGLOBE | SNOWGLOBE | In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulner… |
| SNOWSOUL | SnowSoul | SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organiza… |
| SOLAR SPIDER | SOLAR SPIDER | SOLAR SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to fi… |
| SOLAR-SPIDER | SOLAR SPIDER | SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and Southeast Asia. |
| Solntsepek | Solntsepek RU | Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobi… |
| SOLNTSEPEK | Solntsepek | Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobi… |
| SongXY | SongXY | SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2… |
| SONGXY | SongXY | SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2… |
| Sowbug | Sowbug | Sowbug has been conducting highly targeted cyber attacks against organizations in South America and Southeast Asia and appears to be heavily focused on foreign… |