2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 101–150 of 2,004 · page 3 of 41

IDTitleSummary
APT3APT3
CN
Symantec described UPS in 2016 report as: 'Buckeye (also known as APT3, Gothic Panda, UPS Team, and TG-0110) is a cyberespionage group that is believed to hav…
APT3APT3Symantec described UPS in 2016 report as: 'Buckeye (also known as APT3, Gothic Panda, UPS Team, and TG-0110) is a cyberespionage group that is believed to hav…
APT30APT30
CN
APT30 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0013. Operational targeting focuses on t…
APT30APT30APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appe…
APT31APT31
CN
FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competeti…
APT31APT31FireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competeti…
APT32APT32
VN
Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple indust…
APT32APT32Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple indust…
APT33APT33
IR
APT33 is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as APT 33, Elfin, MAGNALLIUM (and 7 more). O…
APT33APT33Our analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of …
APT35APT35
IR
FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government th…
APT35APT35FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government th…
APT37APT37
KP
APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its …
APT37APT37APT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its …
APT39APT39
IR
APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a group publicly referred to as "…
APT39APT39APT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a group publicly referred to as "…
APT4APT4
CN
APT4 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as PLA Navy, MAVERICK PANDA, BRONZE EDISON (a…
APT4APT4
APT40APT40
CN
Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-stand…
APT40APT40Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-stand…
APT41APT41
CN
APT41 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0096, TA415, Blackfly (and 17 more). Ope…
APT41APT41APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially ou…
APT42APT42
IR
Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against individuals and organizations o…
APT42APT42Iranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against individuals and organizations o…
APT43APT43• APT43 is a prolific cyber operator that supports the interests of the North Korean regime. The group combines moderately-sophisticated technical capabilities…
APT43APT43• APT43 is a prolific cyber operator that supports the interests of the North Korean regime. The group combines moderately-sophisticated technical capabilities…
APT45APT45
KP
APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and …
APT45APT45APT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and …
APT5APT5
CN
We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than half of the organizations we…
APT5APT5We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than half of the organizations we…
APT6APT6
CN
The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems as far back as 2011 …
APT6APT6The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems as far back as 2011 …
APT73APT73APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that…
APT73APT73APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that…
APT9APT9
CN
APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within…
APT9APT9APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within…
APTIranAPTIran
IR
APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of government ministries, hospi…
APTIRANAPTIranAPTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of government ministries, hospi…
ArcaneDoorArcaneDoorArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these actor…
ARCANEDOORArcaneDoorArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these actor…
AridViperAridViper
PS
AridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a focus on Israel and Palestine…
ARIDVIPERAridViperAridViper is a state-sponsored APT primarily targeting military personnel, journalists, and dissidents in the Middle East, with a focus on Israel and Palestine…
Aslan Neferler TimAslan Neferler Tim
TR
Turkish nationalist hacktivist group that has been active for roughly one year. According to Domaintools, the group’s site has been registered since December 2…
ASLAN-NEFERLER-TIMAslan Neferler TimTurkish nationalist hacktivist group that has been active for roughly one year. According to Domaintools, the group’s site has been registered since December 2…
AsnarökAsnarökAsnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asna…
ASNAR-KAsnarökAsnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asna…
AtlasCrossAtlasCrossNSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this f…
ATLASCROSSAtlasCrossNSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations. Delving deeper into this f…
AttorAttorAttor is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private sector and Government sectors. Original reco…
ATTORAttorAdversary group targeting diplomatic missions and governmental organisations.
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.