2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 1,951–2,000 of 2,004 · page 40 of 41

IDTitleSummary
WET-PANDAWET PANDA
White BearWhite Bear
RU
As a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting APT activity that we …
WHITE-BEARWhite BearAs a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting APT activity that we …
WhiteCobraWhiteCobraWhiteCobra is a threat actor that has infiltrated the Visual Studio Code marketplace and Open VSX registry, deploying 24 malicious extensions targeting cryptoc…
WHITECOBRAWhiteCobraWhiteCobra is a threat actor that has infiltrated the Visual Studio Code marketplace and Open VSX registry, deploying 24 malicious extensions targeting cryptoc…
WhiteflyWhiteflyIn July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until n…
WHITEFLYWhiteflyIn July 2018, an attack on Singapore’s largest public health organization, SingHealth, resulted in a reported 1.5 million patient records being stolen. Until n…
WildCardWildCardWildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware. They have since expanded their operations and develop…
WILDCARDWildCardWildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware. They have since expanded their operations and develop…
WildNeutronWildNeutronA corporate espionage group has compromised a string of major corporations over the past three years in order to steal confidential information and intellectua…
WILDNEUTRONWildNeutronA corporate espionage group has compromised a string of major corporations over the past three years in order to steal confidential information and intellectua…
WildPressureWildPressureWildPressure is a threat actor that targets industrial-related entities in the Middle East. They use a variety of programming languages, including C++, VBScrip…
WILDPRESSUREWildPressureWildPressure is a threat actor that targets industrial-related entities in the Middle East. They use a variety of programming languages, including C++, VBScrip…
WindShiftWindShiftIn August of 2018, DarkMatter released a report entitled “In the Trails of WINDSHIFT APT”, which unveiled a threat actor with TTPs very similar to those of Bah…
WINDSHIFTWindShiftIn August of 2018, DarkMatter released a report entitled “In the Trails of WINDSHIFT APT”, which unveiled a threat actor with TTPs very similar to those of Bah…
Winter VivernWinter Vivern
RU
Winter Vivern is a cyberespionage group first revealed by DomainTools in 2021. It is thought to have been active since at least 2020 and it targets governments…
WINTER-VIVERNWinter VivernWinter Vivern is a cyberespionage group first revealed by DomainTools in 2021. It is thought to have been active since at least 2020 and it targets governments…
WIP19WIP19
CN
WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia. They utilize a stolen certificate to sign their malware, inc…
WIP19WIP19WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia. They utilize a stolen certificate to sign their malware, inc…
WIRTEWIRTE
PS
WIRTE is a threat actor group that was first discovered in 2018. They are suspected to be part of the Gaza Cybergang, an Arabic politically motivated cyber cri…
WIRTEWIRTEWIRTE is a threat actor group that was first discovered in 2018. They are suspected to be part of the Gaza Cybergang, an Arabic politically motivated cyber cri…
WitchettyWitchetty
CN
Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some l…
WITCHETTYWitchettyWitchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage operation with some l…
WIZARD SPIDERWIZARD SPIDER
RU
Wizard Spider is reportedly associated with Grim Spider and Lunar Spider. The WIZARD SPIDER threat group is the Russia-based operator of the TrickBot banking m…
WIZARD-SPIDERWIZARD SPIDERWizard Spider is reportedly associated with Grim Spider and Lunar Spider. The WIZARD SPIDER threat group is the Russia-based operator of the TrickBot banking m…
WOLF SPIDERWOLF SPIDER
RO
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthca…
WOLF-SPIDERWOLF SPIDERFIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthca…
WorokWorok
CN
Worok is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government and Energy Company sec…
WOROKWorokWorok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named PowHeartBea…
XakNetXakNet
RU
XakNet is a self-proclaimed hacktivist group that has targeted Ukraine. They claim to be comprised of Russian patriotic volunteers and have conducted various t…
XAKNETXakNetXakNet is a self-proclaimed hacktivist group that has targeted Ukraine. They claim to be comprised of Russian patriotic volunteers and have conducted various t…
XcatzeXcatzeCloud security company Lacework says it discovered a threat actor group named Xcatze that uses a Python named AndroxGh0st to take over AWS servers and send out…
XCATZEXcatzeCloud security company Lacework says it discovered a threat actor group named Xcatze that uses a Python named AndroxGh0st to take over AWS servers and send out…
XDSpyXDSpyRare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since…
XDSPYXDSpyRare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since…
XiaoqiyingXiaoqiying
CN
Xiaoqiying is a primarily Chinese-speaking threat group that is most well known for conducting website defacement and data exfiltration attacks on more than a …
XIAOQIYINGXiaoqiyingXiaoqiying is a primarily Chinese-speaking threat group that is most well known for conducting website defacement and data exfiltration attacks on more than a …
XinXinXinXin
CN
XinXin is a Chinese-speaking threat actor known for its phishing-as-a-service platform, Lucid, which targets global organizations to steal credit card details …
XINXINXinXinXinXin is a Chinese-speaking threat actor known for its phishing-as-a-service platform, Lucid, which targets global organizations to steal credit card details …
Yanbian GangYanbian GangRiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious Android apps purporting …
YANBIAN-GANGYanbian GangRiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious Android apps purporting …
YoroTrooperYoroTrooper
KZ
YoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on …
YOROTROOPERYoroTrooperYoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of Independent States, based on …
Z-Pentest AllianceZ-Pentest Alliance
RU
Z-Pentest Alliance is a pro-Russian hacktivist group known for targeting industrial control systems and operational technology systems, particularly in Italy a…
Z-PENTEST-ALLIANCEZ-Pentest AllianceZ-Pentest Alliance is a pro-Russian hacktivist group known for targeting industrial control systems and operational technology systems, particularly in Italy a…
ZaryaZarya
RU
Zarya is a pro-Russian hacktivist group that emerged in March 2022. Initially operating as a special forces unit under the command of Killnet, Zarya has since …
ZARYAZaryaZarya is a pro-Russian hacktivist group that emerged in March 2022. Initially operating as a special forces unit under the command of Killnet, Zarya has since …
ZEFFSECZeffSecZeffSec is a hacktivist collective focused on infrastructure-level disruption and exposing vulnerabilities in centralized digital networks. In March 2026, the …
ZeroSevenGroupZeroSevenGroupZeroSevenGroup is a threat actor that claims to have breached a U.S. branch of Toyota, stealing 240GB of sensitive data, including employee and customer inform…
ZEROSEVENGROUPZeroSevenGroupZeroSevenGroup is a threat actor that claims to have breached a U.S. branch of Toyota, stealing 240GB of sensitive data, including employee and customer inform…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.