2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,351–1,400 of 2,004 · page 28 of 41

IDTitleSummary
SmugXSmugXThe campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some e…
SMUGXSmugXThe campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda. Although those two correlate to some e…
Snake WineSnake WineWhile investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered another prolonged campaig…
SNAKE-WINESnake WineWhile investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered another prolonged campaig…
SneakyChefSneakyChef
CN
SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have be…
SNEAKYCHEFSneakyChefSneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have be…
SNOWGLOBESNOWGLOBE
FR
In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulner…
SNOWGLOBESNOWGLOBEIn 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild. Two of these zero-day vulner…
SNOWSOULSnowSoulSnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organiza…
SOLAR SPIDERSOLAR SPIDERSOLAR SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to fi…
SOLAR-SPIDERSOLAR SPIDERSOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and Southeast Asia.
SolntsepekSolntsepek
RU
Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobi…
SOLNTSEPEKSolntsepekSolntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobi…
SongXYSongXYSongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2…
SONGXYSongXYSongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2…
SowbugSowbugSowbug has been conducting highly targeted cyber attacks against organizations in South America and Southeast Asia and appears to be heavily focused on foreign…
SOWBUGSowbugSowbug has been conducting highly targeted cyber attacks against organizations in South America and Southeast Asia and appears to be heavily focused on foreign…
Sp1d3rSp1d3rSp1d3r, a threat actor, has been involved in multiple data breaches targeting companies like Truist Bank, Cylance, and Advance Auto Parts. They have stolen and…
SP1D3RSp1d3rSp1d3r, a threat actor, has been involved in multiple data breaches targeting companies like Truist Bank, Cylance, and Advance Auto Parts. They have stolen and…
SpaceBearsSpaceBears
RU
SpaceBears is a ransomware group believed to be based in Moscow, Russia, that has taken credit for several high-profile cyberattacks while primarily operating …
SPACEBEARSSpaceBearsSpaceBears is a ransomware group believed to be based in Moscow, Russia, that has taken credit for several high-profile cyberattacks while primarily operating …
SparklingGoblinSparklingGoblinESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin; this backdoor was use…
SPARKLINGGOBLINSparklingGoblinESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin; this backdoor was use…
SPICY PANDASPICY PANDA
CN
SPICY PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: SPICY PANDA is a Chinese-attributed threat acto…
SPICY-PANDASPICY PANDA
SPIKEDWINESPIKEDWINESPIKEDWINE is a threat actor targeting European officials with a new backdoor called WINELOADER. They use a bait PDF document posing as an invitation letter fr…
SPIKEDWINESPIKEDWINESPIKEDWINE is a threat actor targeting European officials with a new backdoor called WINELOADER. They use a bait PDF document posing as an invitation letter fr…
STAC5143STAC5143STAC5143 is a threat actor group tracked by Sophos, notable for its sophisticated use of Microsoft Office 365's legitimate services to conduct ransomware and d…
STAC5143STAC5143STAC5143 is a threat actor group tracked by Sophos, notable for its sophisticated use of Microsoft Office 365's legitimate services to conduct ransomware and d…
STARDUST CHOLLIMASTARDUST CHOLLIMAOpen-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public re…
STARDUST-CHOLLIMASTARDUST CHOLLIMAOpen-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public re…
Stargazer GoblinStargazer GoblinStargazer Goblin is a threat actor group that operates the Stargazers Ghost Network on GitHub, distributing malware and malicious links through multiple accoun…
STARGAZER-GOBLINStargazer GoblinStargazer Goblin is a threat actor group that operates the Stargazers Ghost Network on GitHub, distributing malware and malicious links through multiple accoun…
Starry AddaxStarry AddaxStarry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile malware called FlexSt…
STARRY-ADDAXStarry AddaxStarry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile malware called FlexSt…
Stealth FalconStealth Falcon
AE
Stealth Falcon is a threat actor (origin AE) catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as FruityArmor, G0038. Operational targeti…
STEALTH-FALCONStealth FalconThis threat actor targets civil society groups and Emirati journalists, activists, and dissidents.
Storm CloudStorm Cloud
CN
Storm Cloud is a Chinese espionage threat actor known for targeting organizations across Asia, particularly Tibetan organizations and individuals. They use a v…
STORM-CLOUDStorm CloudStorm Cloud is a Chinese espionage threat actor known for targeting organizations across Asia, particularly Tibetan organizations and individuals. They use a v…
Storm-0062Storm-0062
CN
The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062. According to the company, the group is launch…
STORM-0062Storm-0062The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062. According to the company, the group is launch…
Storm-0249Storm-0249Storm-0249 is an access broker active since 2021, known for distributing BazaLoader, IcedID, Bumblebee, and Emotet malware. The actor primarily employs phishin…
STORM-0249Storm-0249Storm-0249 is an access broker active since 2021, known for distributing BazaLoader, IcedID, Bumblebee, and Emotet malware. The actor primarily employs phishin…
Storm-0324Storm-0324The threat actor that Microsoft tracks as Storm-0324 is a financially motivated group known to gain initial access using email-based initial infection vectors …
STORM-0324Storm-0324The threat actor that Microsoft tracks as Storm-0324 is a financially motivated group known to gain initial access using email-based initial infection vectors …
Storm-0381Storm-0381
RU
Storm-0381 is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DEV-0381. Original record: Storm-038…
STORM-0381Storm-0381Storm-0381 is a threat actor identified by Microsoft as a Russian cybercrime group. They are known for their use of malvertising to deploy Magniber, a type of …
Storm-0473Storm-0473
KZ
Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth o…
STORM-0473Storm-0473Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth o…
Storm-0494Storm-0494Storm-0494 is a threat actor that facilitates Gootloader infections, which are then exploited by groups like Vice Society to deploy tools such as the Supper ba…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.