2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 151–200 of 2,004 · page 4 of 41

IDTitleSummary
AvivoreAvivore
CN
The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that compromise smaller engineering…
AVIVOREAvivoreThe group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that compromise smaller engineering…
Awaken LikhoAwaken LikhoAwaken Likho is an APT group that has targeted Russian government agencies and industrial enterprises, employing techniques such as information gathering via s…
AWAKEN-LIKHOAwaken LikhoAwaken Likho is an APT group that has targeted Russian government agencies and industrial enterprises, employing techniques such as information gathering via s…
Ayyıldız TimAyyıldız Tim
TR
Ayyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002. It performs defacements and DDoS attacks against the websites of governments t…
AYY-LD-Z-TIMAyyıldız TimAyyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002. It performs defacements and DDoS attacks against the websites of governments t…
AzzaSecAzzaSec
IT
AzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various cyberattacks targeting Israel …
AZZASECAzzaSecAzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various cyberattacks targeting Israel …
BackdoorDiplomacyBackdoorDiplomacyAn APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunica…
BACKDOORDIPLOMACYBackdoorDiplomacyAn APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunica…
BadRoryBadRoryKaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The cam…
BADRORYBadRoryKaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian organizations. The cam…
BahamutBahamutBahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They wer…
BAHAMUTBahamutBahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state sponsored actors. They wer…
BAMBOO SPIDERBAMBOO SPIDERBAMBOO SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: BAMBOO SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-…
BAMBOO-SPIDERBAMBOO SPIDERCrowdstrike tracks the developer of Panda Zeus as BAMBOO SPIDER
BANISHED KITTENBANISHED KITTEN
IR
BANISHED KITTEN is an Iranian state-nexus adversary active since at least 2008. While the adversary’s most prominent activity is the July and September 2022 di…
BANISHED-KITTENBANISHED KITTENBANISHED KITTEN is an Iranian state-nexus adversary active since at least 2008. While the adversary’s most prominent activity is the July and September 2022 di…
BatShadowBatShadow
VN
BatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering campaigns, deploying the Go-base…
BATSHADOWBatShadowBatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering campaigns, deploying the Go-base…
BazarCallBazarCallBazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into calling. It’s a technique …
BAZARCALLBazarCallBazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into calling. It’s a technique …
BearlyfyBearlyfy
UA
Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware st…
BEARLYFYBearlyfyBearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom Windows ransomware st…
Beijing GroupBeijing Group
CN
Beijing Group is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as SNEAKY PANDA, Elderwood, Elderwoo…
BEIJING-GROUPBeijing Group
BelialDemonBelialDemonBelialDemon is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Matanbuchus. Original record: BelialDemon is a threat …
BELIALDEMONBelialDemonMentioned as operator of TriumphLoader and Matanbuchus
Belsen GroupBelsen GroupThe Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configura…
BELSEN-GROUPBelsen GroupThe Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configura…
BiBiGunBiBiGun
PS
A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operate…
BIBIGUNBiBiGunA pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operate…
BIG PANDABIG PANDA
CN
BIG PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: BIG PANDA is a Chinese-attributed threat actor ca…
BIG-PANDABIG PANDA
BignosaBignosa
KE
Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla atta…
BIGNOSABignosaBignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with disguised Agent Tesla atta…
BITWISE SPIDERBITWISE SPIDERBITWISE SPIDER has recently and quickly become a significant player in the big game hunting (BGH) landscape. Their dedicated leak site (DLS) has received the h…
BITWISE-SPIDERBITWISE SPIDERBITWISE SPIDER has recently and quickly become a significant player in the big game hunting (BGH) landscape. Their dedicated leak site (DLS) has received the h…
BlackatomBlackatom
PS
Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted to appeal to a niche g…
BLACKATOMBlackatomRecent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted to appeal to a niche g…
BlackgearBlackgear
CN
BLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years. Multiple papers and talks have been released covering this campaign, whic…
BLACKGEARBlackgearBLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years. Multiple papers and talks have been released covering this campaign, whic…
BlackJackBlackJack
UA
Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. …
BLACKJACKBlackJackBlackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and military infrastructure. …
BLACKMASKERSBlackMaskersBlackMaskers Team has emerged as a significant threat actor, particularly targeting Jordan amid the Israel-Iran conflict. They have claimed responsibility for …
BlackmetaBlackmeta
PS
BLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches targeting organizations perceive…
BLACKMETABlackmetaBLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches targeting organizations perceive…
BlackOasisBlackOasisBlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United N…
BLACKOASISBlackOasisBlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United N…
BlacktailBlacktailBlacktail is a cybercrime group that has gained attention for its ransomware campaigns, particularly the Buhti ransomware. They are known for using custom-buil…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.