2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 301–350 of 2,004 · page 7 of 41

IDTitleSummary
CL-STA-1020CL-STA-1020CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control com…
CL-STA-1087CL-STA-1087
CN
CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia. The actor has demonst…
CL-STA-1087CL-STA-1087CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia. The actor has demonst…
CL-UNK-1068CL-UNK-1068CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage. They utilize cross-platform tool…
CleaverCleaver
IR
A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. or…
CLEAVERCleaverA group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. or…
Clever KittenClever Kitten
IR
Clever Kitten is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Group 41. Original record: Clever…
CLEVER-KITTENClever Kitten
CLOCKWORK SPIDERCLOCKWORK SPIDERCLOCKWORK SPIDER is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Opportunistic actor that installs custom root certificate on …
CLOCKWORK-SPIDERCLOCKWORK SPIDEROpportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
CloudSorcererCloudSorcererCloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The ma…
CLOUDSORCERERCloudSorcererCloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data exfiltration. The ma…
CobaltCobaltA criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided s…
COBALTCobaltA criminal group dubbed Cobalt is behind synchronized ATM heists that saw machines across Europe, CIS countries (including Russia), and Malaysia being raided s…
COBALT JUNOCOBALT JUNOCOBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyw…
COBALT-JUNOCOBALT JUNOCOBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon. COBALT JUNO custom spyw…
COBALT KATANACOBALT KATANACOBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group h…
COBALT-KATANACOBALT KATANACOBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated with Kuwait. The group h…
CodefingerCodefingerCodefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. …
CODEFINGERCodefingerCodefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to encrypt victim data. …
Coinbase CartelCoinbase CartelCoinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 vict…
COINBASE-CARTELCoinbase CartelCoinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 vict…
Cold RiverCold RiverIn short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control t…
COLD-RIVERCold RiverIn short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control t…
ComicFormComicFormComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian co…
COMICFORMComicFormComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against organizations in Eurasian co…
Common RavenCommon RavenCommon Raven is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as OPERA1ER, NXSMS, DESKTOP-GROUP. Original record: Thre…
COMMON-RAVENCommon RavenThreat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent pay…
ConfuciousConfucious
IN
Confucius is an APT organization funded by India. It has been carrying out cyber attacks since 2013. Its main targets are India's neighbouring countries such a…
CONFUCIOUSConfuciousConfucius is an APT organization funded by India. It has been carrying out cyber attacks since 2013. Its main targets are India's neighbouring countries such a…
Conquerors Electronic ArmyConquerors Electronic ArmyConquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including civil emergency alert…
CONQUERORS-ELECTRONIC-ARMYConquerors Electronic ArmyConquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including civil emergency alert…
Contagious InterviewContagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, incl…
CONTAGIOUS-INTERVIEWContagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, incl…
Copy-PasteCopy-PasteCopy-Paste is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Operational targeting focuses on the Government sector. Documented victim organisati…
COPY-PASTECopy-PasteThe title ‘Copy-paste compromises’ is derived from the actor’s heavy use of tools copied almost identically from open source given by The Australian Government.
CopyKittensCopyKittens
IR
CopyKittens is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Slayer Kitten, G0052. Operational t…
COPYKITTENSCopyKittens
CoralRaiderCoralRaider
VN
CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They us…
CORALRAIDERCoralRaiderCoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They us…
Corsair JackalCorsair Jackal
TN
Corsair Jackal is a threat actor (origin TN) catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as TunisianCyberArmy. Original record: Cor…
CORSAIR-JACKALCorsair Jackal
Cosmic LynxCosmic LynxCosmic Lynx is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Cosmic Lynx is a Russia-based BEC cybercriminal organization that …
COSMIC-LYNXCosmic LynxCosmic Lynx is a Russia-based BEC cybercriminal organization that has significantly impacted the email threat landscape with sophisticated, high-dollar phishin…
CosmicBeetleCosmicBeetleCosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolse…
COSMICBEETLECosmicBeetleCosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab. The actor utilizes a custom toolse…
CostaRictoCostaRictoCostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware to…
COSTARICTOCostaRictoCostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware to…
Cotton SandstormCotton Sandstorm
IR
Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical maga…
COTTON-SANDSTORMCotton SandstormCotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations. They have targeted various organizations, including the French satirical maga…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.