2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,601–1,650 of 2,054 · page 33 of 42

IDTitleSummary
TAG-124TAG-124TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting various sectors through p…
TAG-140TAG-140
PK
TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and malware campaigns. Th…
TAG-140TAG-140TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and malware campaigns. Th…
TAG-28TAG-28
CN
TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have…
TAG-28TAG-28TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have…
TAG-56TAG-56
IR
TAG-56 is a threat actor group that shares similarities with the APT42 group. They use tactics such as fake registration pages and spearphishing to target vict…
TAG-56TAG-56TAG-56 is a threat actor group that shares similarities with the APT42 group. They use tactics such as fake registration pages and spearphishing to target vict…
TaidoorTaidoorThe Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Ta…
TAIDOORTaidoorThe Taidoor attackers have been actively engaging in targeted attacks since at least March 4, 2009. Despite some exceptions, the Taidoor campaign often used Ta…
TaskMastersTaskMasters
CN
TaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia…
TASKMASTERSTaskMastersTaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and government sectors in Russia…
Team-XecuterTeam-XecuterTeam-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA. They were involved in a piracy conspiracy against Nintendo, creating and selling ill…
TEAM-XECUTERTeam-XecuterTeam-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA. They were involved in a piracy conspiracy against Nintendo, creating and selling ill…
Team46Team46Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations through spearphishing emai…
TEAM46Team46Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations through spearphishing emai…
TeamPCPTeamPCPTeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and L…
TEAMPCPTeamPCPTeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and L…
TeamSpy CrewTeamSpy Crew
RU
Researchers have uncovered a long-term cyber-espionage campaign that used a combination of legitimate software packages and commodity malware tools to target a…
TEAMSPY-CREWTeamSpy CrewResearchers have uncovered a long-term cyber-espionage campaign that used a combination of legitimate software packages and commodity malware tools to target a…
TeamTNTTeamTNTIn early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Do…
TEAMTNTTeamTNTIn early Febuary, 2021 TeamTNT launched a new campaign against Docker and Kubernetes environments. Using a collection of container images that are hosted in Do…
TeamXRatTeamXRatTeamXRat is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as CorporacaoXRat, CorporationXRat.
TEAMXRATTeamXRat
TeleboyiTeleboyi
CN
Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a si…
TELEBOYITeleboyiTeleboyi is a threat actor reportedly based in China, associated with the PlugX RAT. TeamT5 identified a custom PlugX loader used by Teleboyi that employs a si…
TEMP_HereticTEMP_Heretic
CN
TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Z…
TEMP-HERETICTEMP_HereticTEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns. They exploit vulnerabilities in email platforms, such as Z…
TEMP.HermitTEMP.Hermit
KP
TEMP.Hermit is a North Korean-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: TEMP.Hermit is a North Korean-attributed t…
TEMP-HERMITTEMP.Hermit
TEMP.VelesTEMP.VelesTEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed…
TEMP-VELESTEMP.VelesTEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed…
TEMPER PANDATEMPER PANDA
CN
China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in finan…
TEMPER-PANDATEMPER PANDAChina-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in finan…
TempTickTempTick
CN
This threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media organizations in East Asi…
TEMPTICKTempTickThis threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media organizations in East Asi…
TERBIUMTERBIUMMicrosoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to …
TERBIUMTERBIUMMicrosoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to …
TEST PANDATEST PANDA
CN
TEST PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: TEST PANDA is a Chinese-attributed threat actor …
TEST-PANDATEST PANDA
TetrisPhantomTetrisPhantomTetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh…
TETRISPHANTOMTetrisPhantomTetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations. Wh…
The Big BangThe Big BangWhile it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona…
THE-BIG-BANGThe Big BangWhile it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack awaits, fetching additiona…
The GentlemenThe GentlemenThe Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi…
THE-GENTLEMENThe GentlemenThe Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure vi…
The Gorgon GroupThe Gorgon GroupUnit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon…
THE-GORGON-GROUPThe Gorgon GroupUnit 42 researchers have been tracking Subaat, an attacker, since 2017. Recently Subaat drew our attention due to renewed targeted attack activity. Part of mon…
The Shadow BrokersThe Shadow BrokersThe Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se…
THE-SHADOW-BROKERSThe Shadow BrokersThe Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016. They published several leaks containing hacking tools from the National Se…
TheDarkOverlordTheDarkOverlordTheDarkOverlord is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: The Dark Overlord is a financially motivated ransomware group …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base