2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,601–1,650 of 2,004 · page 33 of 41

IDTitleSummary
TEST-PANDATEST PANDA
TetrisPhantomTetrisPhantomTetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh…
TETRISPHANTOMTetrisPhantomTetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh…
The Big BangThe Big BangWhile it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona…
THE-BIG-BANGThe Big BangWhile it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona…
The GentlemenThe GentlemenThe Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi…
THE-GENTLEMENThe GentlemenThe Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi…
The Gorgon GroupThe Gorgon GroupUnit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon…
THE-GORGON-GROUPThe Gorgon GroupUnit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon…
The Shadow BrokersThe Shadow BrokersThe Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se…
THE-SHADOW-BROKERSThe Shadow BrokersThe Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se…
TheDarkOverlordTheDarkOverlordTheDarkOverlord is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The Dark Overlord is a financially motivated ransomware group …
THEDARKOVERLORDTheDarkOverlordThe Dark Overlord is a financially motivated ransomware group that has been active since 2016. The group is known for targeting large organizations, including …
TheWizardsTheWizardsTheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti…
THEWIZARDSTheWizardsTheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti…
Threat Actor 888Threat Actor 888Threat Actor 888 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Threat actor 888 is a hacker active in 2024, targeting compan…
THREAT-ACTOR-888Threat Actor 888Threat actor 888 is a hacker active in 2024, targeting companies for data breaches. They've hit Microsoft, BMW (Hong Kong), and others in tech, freight, and oi…
ThreatsecThreatsecThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f…
THREATSECThreatsecThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f…
ThripThripThrip is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0076, ATK78. Operational targeting focuses on the Private s…
THRIPThripThis threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and S…
TianWuTianWu
CN
TianWu is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private Sector, Gambling compani…
TIANWUTianWu
TickTick
CN
Tick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese Natio…
TICKTickTick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese Natio…
TIDRONETIDRONE
CN
TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers i…
TIDRONETIDRONETIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers i…
TiltedTempleTiltedTemple
CN
One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activ…
TILTEDTEMPLETiltedTempleOne of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activ…
TINY SPIDERTINY SPIDERTINY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: According to CrowdStrike, this actor is using TinyLoader and TinyP…
TINY-SPIDERTINY SPIDERAccording to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
ToddyCatToddyCatToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little infor…
TODDYCATToddyCatToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little infor…
Tonto TeamTonto Team
CN
Tonto Team is a Chinese-speaking APT group that has been active since at least 2013. They primarily target military, diplomatic, and infrastructure organizatio…
TONTO-TEAMTonto TeamTonto Team is a Chinese-speaking APT group that has been active since at least 2013. They primarily target military, diplomatic, and infrastructure organizatio…
TortoiseshellTortoiseshell
IR
A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain …
TORTOISESHELLTortoiseshellA previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain …
TOXCAR CYBER TEAMTOXCAR CYBER TEAMThe Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing screensho…
TOXCAR-CYBER-TEAMTOXCAR CYBER TEAMThe Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing screensho…
TOXIC PANDATOXIC PANDA
CN
TOXIC PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: TOXIC PANDA is a Chinese-attributed threat acto…
TOXIC-PANDATOXIC PANDAA group targeting dissident groups in China and at the boundaries.
TRACER KITTENTRACER KITTEN
IR
In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a …
TRACER-KITTENTRACER KITTENIn April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a …
TraderTraitorTraderTraitor
KP
TraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administr…
TRADERTRAITORTraderTraitorTraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administr…
TRAVELING SPIDERTRAVELING SPIDERCrowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authenticatio…
TRAVELING-SPIDERTRAVELING SPIDERCrowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authenticatio…
TridentLockerTridentLockerTridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services …
TRIDENTLOCKERTridentLockerTridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services …
TRIPLESTRENGTHTRIPLESTRENGTHTRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking, ransomware, and extortio…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base