2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,851–1,900 of 2,004 · page 38 of 41

IDTitleSummary
UNK-REMOTEROGUEUNK_RemoteRogueUNK_RemoteRogue is a suspected Russian threat actor that has been observed utilizing ClickFix in its infection chains, although this technique is not revolutio…
UNK_SparkyCarpUNK_SparkyCarpBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
UNK-SPARKYCARPUNK_SparkyCarpBetween March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations within the semiconductor…
Unnamed ActorUnnamed Actor
CN
This threat actor compromises civil society groups the Chinese Communist Party views as hostile to its interests, such as Tibetan, Uyghur, Hong Kong, and Taiwa…
UNNAMED-ACTORUnnamed ActorThis threat actor compromises civil society groups the Chinese Communist Party views as hostile to its interests, such as Tibetan, Uyghur, Hong Kong, and Taiwa…
UnsolicitedBookerUnsolicitedBooker
CN
UnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi Arabia, employing a backdoo…
UNSOLICITEDBOOKERUnsolicitedBookerUnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi Arabia, employing a backdoo…
UrpageUrpageWhat sets Urpage attacks apart is its targeting of InPage, a word processor for Urdu and Arabic languages. However, its Delphi backdoor component, which it has…
URPAGEUrpageWhat sets Urpage attacks apart is its targeting of InPage, a word processor for Urdu and Arabic languages. However, its Delphi backdoor component, which it has…
USDoDUSDoDUSDoD is a threat actor known for leaking large databases of personal information, including from companies like Airbus and the U.S. Environmental Protection A…
USDODUSDoDUSDoD is a threat actor known for leaking large databases of personal information, including from companies like Airbus and the U.S. Environmental Protection A…
UserSecUserSec
RU
UserSec is a pro-Russian hacking group that has been active since at least 2022. The group is known for its DDoS attacks and has collaborated with other pro-Ru…
USERSECUserSecUserSec is a pro-Russian hacking group that has been active since at least 2022. The group is known for its DDoS attacks and has collaborated with other pro-Ru…
UTA0178UTA0178
CN
While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the…
UTA0178UTA0178While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the…
UTA0218UTA0218UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data. They exploit vulne…
UTA0218UTA0218UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data. They exploit vulne…
UTA0352UTA0352
RU
UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government of…
UTA0352UTA0352UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government of…
UTA0355UTA0355
RU
UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine. The actor initiates contact…
UTA0355UTA0355UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine. The actor initiates contact…
UTA0388UTA0388
CN
UTA0388 is a China-aligned APT known for spear-phishing campaigns targeting organizations in North America, Asia, and Europe, primarily to deliver a Go-based i…
UTA0388UTA0388UTA0388 is a China-aligned APT known for spear-phishing campaigns targeting organizations in North America, Asia, and Europe, primarily to deliver a Go-based i…
UTG-Q-008UTG-Q-008UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network…
UTG-Q-008UTG-Q-008UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China. They utilize a massive botnet network…
UTG-Q-010UTG-Q-010UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical industry and cryptoc…
UTG-Q-010UTG-Q-010UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical industry and cryptoc…
Vanilla TempestVanilla TempestVice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also bee…
VANILLA-TEMPESTVanilla TempestVice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also bee…
Velvet TempestVelvet TempestVelvet Tempest is a threat actor associated with the BlackCat ransomware group. They have been observed deploying multiple ransomware payloads, including Black…
VELVET-TEMPESTVelvet TempestVelvet Tempest is a threat actor associated with the BlackCat ransomware group. They have been observed deploying multiple ransomware payloads, including Black…
VENOM SPIDERVENOM SPIDERVENOM SPIDER is the developer of a large toolset that includes SKID, VenomKit and Taurus Loader. Under the moniker 'badbullzvenom', the adversary has been an a…
VENOM-SPIDERVENOM SPIDERVENOM SPIDER is the developer of a large toolset that includes SKID, VenomKit and Taurus Loader. Under the moniker 'badbullzvenom', the adversary has been an a…
VICE SPIDERVICE SPIDER
RU
Vice Spider is a Russian-speaking ransomware group that has been active since at least April 2021 and is linked to a significant increase in identity-based att…
VICE-SPIDERVICE SPIDERVice Spider is a Russian-speaking ransomware group that has been active since at least April 2021 and is linked to a significant increase in identity-based att…
ViceLeakerViceLeakerIn May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens. Kaspersky spyware sensors caught the signal of …
VICELEAKERViceLeakerIn May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens. Kaspersky spyware sensors caught the signal of …
VICEROY TIGERVICEROY TIGER
IN
VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors. Older activity targeted multiple secto…
VICEROY-TIGERVICEROY TIGERVICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors. Older activity targeted multiple secto…
Vicious PandaVicious Panda
CN
Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus scare, in order to deliver…
VICIOUS-PANDAVicious PandaCheck Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus scare, in order to deliver…
ViciousTrapViciousTrapViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to redirect incoming traffic…
VICIOUSTRAPViciousTrapViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to redirect incoming traffic…
Viking JackalViking Jackal
AE
Viking Jackal is a threat actor (origin AE) catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Vikingdom. Original record: Viking Jacka…
VIKING-JACKALViking Jackal
VIKING SPIDERVIKING SPIDERVIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware. While public reporting indicates the group began threa…
VIKING-SPIDERVIKING SPIDERVIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware. While public reporting indicates the group began threa…
Void ArachneVoid ArachneVoid Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers for AI software. They …
VOID-ARACHNEVoid ArachneVoid Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers for AI software. They …
Void BalaurVoid BalaurVoid Balaur is a highly active hack-for-hire / cyber mercenary group with a wide range of known target types across the globe. Their services have been observe…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.