2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,651–1,700 of 2,054 · page 34 of 42

IDTitleSummary
THEDARKOVERLORDTheDarkOverlordThe Dark Overlord is a financially motivated ransomware group that has been active since 2016. The group is known for targeting large organizations, including …
THEHATMANTheHatmanTheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major corporations, includi…
TheWizardsTheWizardsTheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti…
THEWIZARDSTheWizardsTheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legiti…
Threat Actor 888Threat Actor 888Threat Actor 888 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Threat actor 888 is a hacker active in 2024, targeting compan…
THREAT-ACTOR-888Threat Actor 888Threat actor 888 is a hacker active in 2024, targeting companies for data breaches. They've hit Microsoft, BMW (Hong Kong), and others in tech, freight, and oi…
ThreatsecThreatsecThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f…
THREATSECThreatsecThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza. They claim to fight for the rights and f…
ThripThripThrip is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as G0076, ATK78. Operational targeting focuses on the Private s…
THRIPThripThis threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and S…
TianWuTianWu
CN
TianWu is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Private Sector, Gambling compani…
TIANWUTianWu
TickTick
CN
Tick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese Natio…
TICKTickTick is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group appears to have close ties to the Chinese Natio…
TIDRONETIDRONE
CN
TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers i…
TIDRONETIDRONETIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly drone manufacturers i…
TiltedTempleTiltedTemple
CN
One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activ…
TILTEDTEMPLETiltedTempleOne of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows servers. The group's activ…
TINY SPIDERTINY SPIDERTINY SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: According to CrowdStrike, this actor is using TinyLoader and TinyP…
TINY-SPIDERTINY SPIDERAccording to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
ToddyCatToddyCatToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little infor…
TODDYCATToddyCatToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little infor…
Tonto TeamTonto Team
CN
Tonto Team is a Chinese-speaking APT group that has been active since at least 2013. They primarily target military, diplomatic, and infrastructure organizatio…
TONTO-TEAMTonto TeamTonto Team is a Chinese-speaking APT group that has been active since at least 2013. They primarily target military, diplomatic, and infrastructure organizatio…
TortoiseshellTortoiseshell
IR
A previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain …
TORTOISESHELLTortoiseshellA previously undocumented attack group is using both custom and off-the-shelf malware to target IT providers in Saudi Arabia in what appear to be supply chain …
TOXCAR CYBER TEAMTOXCAR CYBER TEAMThe Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing screensho…
TOXCAR-CYBER-TEAMTOXCAR CYBER TEAMThe Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing screensho…
TOXIC PANDATOXIC PANDA
CN
TOXIC PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: TOXIC PANDA is a Chinese-attributed threat acto…
TOXIC-PANDATOXIC PANDAA group targeting dissident groups in China and at the boundaries.
TRACER KITTENTRACER KITTEN
IR
In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a …
TRACER-KITTENTRACER KITTENIn April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against multiple hosts at a …
TraderTraitorTraderTraitor
KP
TraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administr…
TRADERTRAITORTraderTraitorTraderTraitor targets blockchain companies through spear-phishing messages. The group sends these messages to employees, particularly those in system administr…
TRAVELING SPIDERTRAVELING SPIDERCrowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authenticatio…
TRAVELING-SPIDERTRAVELING SPIDERCrowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authenticatio…
TridentLockerTridentLockerTridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services …
TRIDENTLOCKERTridentLockerTridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services …
TRIPLESTRENGTHTRIPLESTRENGTHTRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking, ransomware, and extortio…
TRIPLESTRENGTHTRIPLESTRENGTHTRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking, ransomware, and extortio…
TstarkTstark
CN
TStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit targeting CVE-2020-15069 …
TSTARKTstarkTStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit targeting CVE-2020-15069 …
TunnelSnakeTunnelSnake
CN
The TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive toolset and infiltrating…
TUNNELSNAKETunnelSnakeThe TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive toolset and infiltrating…
TurkHackTeamTurkHackTeam
TR
Founded in 2004, Turkhackteam is one of Turkey’s oldest and most high-profile hacking collectives. According to a list compiled on Turkhackteam’s forum, the gr…
TURKHACKTEAMTurkHackTeamFounded in 2004, Turkhackteam is one of Turkey’s oldest and most high-profile hacking collectives. According to a list compiled on Turkhackteam’s forum, the gr…
TurlaTurla
RU
A 2014 Guardian article described Turla as: 'Dubbed the Turla hackers, initial intelligence had indicated western powers were key targets, but it was later det…
TURLATurlaA 2014 Guardian article described Turla as: 'Dubbed the Turla hackers, initial intelligence had indicated western powers were key targets, but it was later det…
TwoSail JunkTwoSail JunkTwoSail Junk directs visitors to its exploit site by posting links within the threads of forum discussions, or creating new topic threads of their own. To date…
TWOSAIL-JUNKTwoSail JunkTwoSail Junk directs visitors to its exploit site by posting links within the threads of forum discussions, or creating new topic threads of their own. To date…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base