2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,351–1,400 of 2,054 · page 28 of 42

IDTitleSummary
SilitNetworkSilitNetworkSilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach …
SILITNETWORKSilitNetworkSilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives. They utilize sophisticated tactics to breach …
SILKFIN AGENCYSILKFIN AGENCYSILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS re…
SILKFIN-AGENCYSILKFIN AGENCYSILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS re…
SILKPARASITESilkParasiteSilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications entities in Kyrgyzstan, U…
SilkSpecterSilkSpecter
CN
SilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers, particularly during peak shoppi…
SILKSPECTERSilkSpecterSilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers, particularly during peak shoppi…
SilverFishSilverFishSilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an at…
SILVERFISHSilverFishSilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the SolarWinds breach as an at…
SilverTerrierSilverTerrier
NG
As these tools rise and fall in popularity (and more importantly, as detection rates by antivirus vendors improve), SilverTerrier actors have consistently adop…
SILVERTERRIERSilverTerrierAs these tools rise and fall in popularity (and more importantly, as detection rates by antivirus vendors improve), SilverTerrier actors have consistently adop…
SimaSima
IR
Sima is a group of suspected Iranian origin targeting Iranians in diaspora. In February 2016, Iran-focused individuals received messages purporting to be from …
SIMASimaSima is a group of suspected Iranian origin targeting Iranians in diaspora. In February 2016, Iran-focused individuals received messages purporting to be from …
SINGING SPIDERSINGING SPIDERSINGING SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as SINGING SPIDER.
SINGING-SPIDERSINGING SPIDER
SingularityMDSingularityMDSingularityMD is a threat actor group that has targeted educational institutions in the US. They gained unauthorized access to their networks by exploiting wea…
SINGULARITYMDSingularityMDSingularityMD is a threat actor group that has targeted educational institutions in the US. They gained unauthorized access to their networks by exploiting wea…
SinobiSinobiSinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure …
SINOBISinobiSinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure …
SkidSecSkidSecSkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda, utilizing techniques…
SKIDSECSkidSecSkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda, utilizing techniques…
SLIME29SLIME29
CN
SLIME29 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private Sector sector. Original…
SLIME29SLIME29
SLIME88SLIME88SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices…
SlingshotSlingshotWhile analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usual…
SLINGSHOTSlingshotWhile analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usual…
SlopAdsSlopAdsSlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors …
SLOPADSSlopAdsSlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally. The threat actors …
SloppyLemmingSloppyLemmingSloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvestin…
SLOPPYLEMMINGSloppyLemmingSloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as credential harvestin…
Smishing TriadSmishing Triad
CN
The Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing campaigns. They leverag…
SMISHING-TRIADSmishing TriadThe Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing campaigns. They leverag…
SMOKY SPIDERSMOKY SPIDERSMOKY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SMOKY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Ga…
SMOKY-SPIDERSMOKY SPIDERMentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
SmugXSmugXThe campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some e…
SMUGXSmugXThe campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some e…
Snake WineSnake WineWhile investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered another prolonged campaig…
SNAKE-WINESnake WineWhile investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered another prolonged campaig…
SneakyChefSneakyChef
CN
SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have be…
SNEAKYCHEFSneakyChefSneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have be…
SNOWGLOBESNOWGLOBE
FR
In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulner…
SNOWGLOBESNOWGLOBEIn 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulner…
SNOWSOULSnowSoulSnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organiza…
SOLAR SPIDERSOLAR SPIDERSOLAR SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to fi…
SOLAR-SPIDERSOLAR SPIDERSOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and Southeast Asia.
SolntsepekSolntsepek
RU
Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobi…
SOLNTSEPEKSolntsepekSolntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobi…
SongXYSongXYSongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2…
SONGXYSongXYSongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2…
SowbugSowbugSowbug has been conducting highly targeted cyber attacks against organizations in South America and Southeast Asia and appears to be heavily focused on foreign…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.