2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 201–250 of 2,004 · page 5 of 41

IDTitleSummary
BLACKTAILBlacktailBlacktail is a cybercrime group that has gained attention for its ransomware campaigns, particularly the Buhti ransomware. They are known for using custom-buil…
BlackTechBlackTech
CN
BlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes a…
BLACKTECHBlackTechBlackTech is a cyber espionage group operating against targets in East Asia, particularly Taiwan, and occasionally, Japan and Hong Kong. Based on the mutexes a…
BlackwoodBlackwood
CN
Blackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and c…
BLACKWOODBlackwoodBlackwood is a China-aligned APT group that has been active since at least 2018. They primarily engage in cyberespionage operations targeting individuals and c…
BladedFelineBladedFeline
IR
BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The gr…
BLADEDFELINEBladedFelineBladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for cyberespionage. The gr…
BladeHawkBladeHawkBladeHawk is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisatio…
BLADEHAWKBladeHawk
Blue TermiteBlue Termite
CN
Blue Termite is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Cloudy Omega, Emdivi. Operational …
BLUE-TERMITEBlue TermiteBlue Termite is a group of suspected Chinese origin active in Japan.
Blue TsunamiBlue Tsunami
IL
Blue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube. They target individuals in various…
BLUE-TSUNAMIBlue TsunamiBlue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube. They target individuals in various…
BlueBottleBlueBottleBluebottle, a cyber-crime group that specializes in targeted attacks against the financial sector, is continuing to mount attacks on banks in Francophone count…
BLUEBOTTLEBlueBottleBluebottle, a cyber-crime group that specializes in targeted attacks against the financial sector, is continuing to mount attacks on banks in Francophone count…
BlueHornetBlueHornetBlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked …
BLUEHORNETBlueHornetBlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia. They have compromised and leaked …
BohriumBohrium
IR
Bohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India. They often cr…
BOHRIUMBohriumBohrium is an Iranian threat actor that has been involved in spear-phishing operations targeting organizations in the US, Middle East, and India. They often cr…
BondnetBondnetBondnet is a threat actor that deploys backdoors and cryptocurrency miners. They use high-performance bots as C2 servers and configure reverse RDP environments…
BONDNETBondnetBondnet is a threat actor that deploys backdoors and cryptocurrency miners. They use high-performance bots as C2 servers and configure reverse RDP environments…
BoolkaBoolkaBoolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL in…
BOOLKABoolkaBoolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration. They have been carrying out opportunistic SQL in…
BOSON SPIDERBOSON SPIDERBOSON SPIDER is a cyber criminal group, which was first identified in 2015, recently and inexplicably went dark in the spring of 2016, appears to be a tightly …
BOSON-SPIDERBOSON SPIDERBOSON SPIDER is a cyber criminal group, which was first identified in 2015, recently and inexplicably went dark in the spring of 2016, appears to be a tightly …
BOSS SPIDERBOSS SPIDERThroughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. …
BOSS-SPIDERBOSS SPIDERThroughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. …
Boulder BearBoulder Bear
RU
Boulder Bear is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Boulder Bear is a Russian-attributed threat ac…
BOULDER-BEARBoulder BearFirst observed activity in December 2013.
BrazenBambooBrazenBamboo
CN
BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families. Their infrastructure includ…
BRAZENBAMBOOBrazenBambooBrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families. Their infrastructure includ…
BreachLaboratoryBreachLaboratoryBreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from various organizations. The…
BREACHLABORATORYBreachLaboratoryBreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from various organizations. The…
BRONZE EDGEWOODBRONZE EDGEWOOD
CN
In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed…
BRONZE-EDGEWOODBRONZE EDGEWOODIn early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia. The threat group deployed…
BRONZE HIGHLANDBRONZE HIGHLAND
CN
BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Thi…
BRONZE-HIGHLANDBRONZE HIGHLANDBRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Thi…
BRONZE SPIRALBRONZE SPIRAL
CN
In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platf…
BRONZE-SPIRALBRONZE SPIRALIn December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability in their Orion Platf…
BRONZE SPRINGBRONZE SPRING
CN
BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense…
BRONZE-SPRINGBRONZE SPRINGBRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual property from defense…
BRONZE STARLIGHTBRONZE STARLIGHT
CN
BRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group leverages HUI Loader to load…
BRONZE-STARLIGHTBRONZE STARLIGHTBRONZE STARLIGHT has been active since mid 2021 and targets organizations globally across a range of industry verticals. The group leverages HUI Loader to load…
BRONZE VAPORBRONZE VAPOR
CN
BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated with this group and open sou…
BRONZE-VAPORBRONZE VAPORBRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin. Artefacts from tools associated with this group and open sou…
BudminerBudminer
CN
Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group. While we have not …
BUDMINERBudminerBased on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group. While we have not …
BuhTrapBuhTrap
RU
Buhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015. Earlier, the group had only f…
BUHTRAPBuhTrapBuhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015. Earlier, the group had only f…
ByteToBreachByteToBreachByteToBreach is a prolific cybercriminal who operates across multiple platforms, including DarkForums and Telegram, and has been active since at least June 202…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.