2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,901–1,950 of 2,004 · page 39 of 41

IDTitleSummary
VOID-BALAURVoid BalaurVoid Balaur is a highly active hack-for-hire / cyber mercenary group with a wide range of known target types across the globe. Their services have been observe…
Void BansheeVoid BansheeVoid Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CV…
VOID-BANSHEEVoid BansheeVoid Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain. They exploit vulnerabilities like CV…
Void BlizzardVoid Blizzard
RU
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, …
VOID-BLIZZARDVoid BlizzardVoid Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, …
Void ManticoreVoid Manticore
IR
Void Manticore is an Iranian APT group affiliated with MOIS, known for conducting destructive wiping attacks and influence operations. They collaborate with Sc…
VOID-MANTICOREVoid ManticoreVoid Manticore is an Iranian APT group affiliated with MOIS, known for conducting destructive wiping attacks and influence operations. They collaborate with Sc…
Void RabisuVoid RabisuVoid Rabisu is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Tropical Scorpius. Documented victim organisations inc…
VOID-RABISUVoid RabisuVoid Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and countries supporting Ukrain…
Volatile CedarVolatile Cedar
LB
Beginning in late 2012, a carefully orchestrated attack campaign we call Volatile Cedar has been targeting individuals, companies and institutions worldwide. T…
VOLATILE-CEDARVolatile CedarBeginning in late 2012, a carefully orchestrated attack campaign we call Volatile Cedar has been targeting individuals, companies and institutions worldwide. T…
Volt TyphoonVolt Typhoon
CN
[Microsoft] Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderat…
VOLT-TYPHOONVolt Typhoon[Microsoft] Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderat…
VulzSecTeamVulzSecTeam
ID
VulzSec, also known as VulzSecTeam, is a hacktivist group that has been involved in various cyber-attacks. They have targeted government websites in retaliatio…
VULZSECTEAMVulzSecTeamVulzSec, also known as VulzSecTeam, is a hacktivist group that has been involved in various cyber-attacks. They have targeted government websites in retaliatio…
WageMoleWageMole
KP
WageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in Western countries, leveragi…
WAGEMOLEWageMoleWageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in Western countries, leveragi…
WARP PANDAWARP PANDA
CN
WARP PANDA is a China-nexus APT that targets VMware vCenter environments and Microsoft Azure infrastructures, primarily focusing on legal, technology, and manu…
WARP-PANDAWARP PANDAWARP PANDA is a China-nexus APT that targets VMware vCenter environments and Microsoft Azure infrastructures, primarily focusing on legal, technology, and manu…
WassoniteWassonite
KP
WASSONITE is a North Korea-linked APT that has targeted industrial sectors, including electric generation, nuclear energy, manufacturing, and research entities…
WASSONITEWassoniteWASSONITE is a North Korea-linked APT that has targeted industrial sectors, including electric generation, nuclear energy, manufacturing, and research entities…
WatchdogWatchdogThief Libra is a cloud-focused threat group that has a history of cryptojacking operations as well as cloud service platform credential scraping. They were fir…
WATCHDOGWatchdogThief Libra is a cloud-focused threat group that has a history of cryptojacking operations as well as cloud service platform credential scraping. They were fir…
Water BakunawaWater BakunawaWater Bakunawa is a cybercriminal group identified by Trend Micro, responsible for the RansomHub ransomware, which exploits the Zerologon vulnerability to gain…
WATER-BAKUNAWAWater BakunawaWater Bakunawa is a cybercriminal group identified by Trend Micro, responsible for the RansomHub ransomware, which exploits the Zerologon vulnerability to gain…
Water BarghestWater BarghestWater Barghest is a cybercriminal group that has compromised over 20,000 IoT devices by October 2024, monetizing them through a residential proxy marketplace. …
WATER-BARGHESTWater BarghestWater Barghest is a cybercriminal group that has compromised over 20,000 IoT devices by October 2024, monetizing them through a residential proxy marketplace. …
Water CurupiraWater CurupiraWith its emergence in 2022, Water Curupira has established itself as a persistent threat actor targeting organizations primarily in South America and Europe. T…
WATER-CURUPIRAWater CurupiraWith its emergence in 2022, Water Curupira has established itself as a persistent threat actor targeting organizations primarily in South America and Europe. T…
Water GamayunWater Gamayun
RU
Water Gamayun exploits the MSC EvilTwin zero-day vulnerability to compromise systems and exfiltrate data, utilizing custom payloads and advanced data exfiltrat…
WATER-GAMAYUNWater GamayunWater Gamayun exploits the MSC EvilTwin zero-day vulnerability to compromise systems and exfiltrate data, utilizing custom payloads and advanced data exfiltrat…
Water KuritaWater KuritaWater Kurita is a financially motivated cybercriminal entity associated with the Lumma Stealer infostealer-as-a-service operation, primarily active on undergro…
WATER-KURITAWater KuritaWater Kurita is a financially motivated cybercriminal entity associated with the Lumma Stealer infostealer-as-a-service operation, primarily active on undergro…
Water LabbuWater LabbuTrend Micro discovered a threat actor they named Water Labbu that was targeting cryptocurrency scam websites. Typically, cryptocurrency scammers use social eng…
WATER-LABBUWater LabbuTrend Micro discovered a threat actor they named Water Labbu that was targeting cryptocurrency scam websites. Typically, cryptocurrency scammers use social eng…
Water MakaraWater MakaraWater Makara employs the Astaroth banking malware, which features a new defense evasion technique. Their spear phishing campaigns exploit human error by target…
WATER-MAKARAWater MakaraWater Makara employs the Astaroth banking malware, which features a new defense evasion technique. Their spear phishing campaigns exploit human error by target…
Water OrthrusWater OrthrusWater Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware. They target Microsoft 365 users with phishing campaigns to steal …
WATER-ORTHRUSWater OrthrusWater Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware. They target Microsoft 365 users with phishing campaigns to steal …
Water SaciWater Saci
BR
Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to …
WATER-SACIWater SaciWater Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP archives, and PDFs to …
Water SigbinWater Sigbin
CN
The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Ora…
WATER-SIGBINWater SigbinThe 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware. They exploit vulnerabilities in Ora…
WebwormWebworm
CN
Space Pirates is a cybercrime group that has been active since at least 2017. They primarily target Russian companies and have been observed using various malw…
WEBWORMWebwormSpace Pirates is a cybercrime group that has been active since at least 2017. They primarily target Russian companies and have been observed using various malw…
WeedSecWeedSecWeedSec is a threat actor group that recently targeted the online learning and course management platform Moodle. They posted sample databases of Moodle on the…
WEEDSECWeedSecWeedSec is a threat actor group that recently targeted the online learning and course management platform Moodle. They posted sample databases of Moodle on the…
WeRedEvilsWeRedEvils
IL
WeRedEvils is a hacking group that has claimed responsibility for multiple cyber attacks. They targeted the Iranian Electric Grid and the Tasnimnews website, c…
WEREDEVILSWeRedEvilsWeRedEvils is a hacking group that has claimed responsibility for multiple cyber attacks. They targeted the Iranian Electric Grid and the Tasnimnews website, c…
WET PANDAWET PANDA
CN
WET PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Red Chimera. Original record: WET PAN…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.