2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 351–400 of 2,004 · page 8 of 41

IDTitleSummary
CoughingDownCoughingDownCoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes service manipulation an…
COUGHINGDOWNCoughingDownCoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes service manipulation an…
Crimson CollectiveCrimson CollectiveThe Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025. The group asserted it ha…
CRIMSON-COLLECTIVECrimson CollectiveThe Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025. The group asserted it ha…
CryptoChameleonCryptoChameleonCryptoChameleon is a cybercriminal group known for targeting cryptocurrency exchanges and users to steal digital assets, employing tactics such as VIP spear ph…
CRYPTOCHAMELEONCryptoChameleonCryptoChameleon is a cybercriminal group known for targeting cryptocurrency exchanges and users to steal digital assets, employing tactics such as VIP spear ph…
CRYSTALRAYCRYSTALRAYCRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They…
CRYSTALRAYCRYSTALRAYCRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning and exploitation. They…
Cuboid SandstormCuboid Sandstorm
IR
Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the company's network and used it to c…
CUBOID-SANDSTORMCuboid SandstormCuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021. They gained access to the company's network and used it to c…
Curious GorgeCurious Gorge
CN
Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in Ukraine, Russia, Kazakhstan,…
CURIOUS-GORGECurious GorgeCurious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in Ukraine, Russia, Kazakhstan,…
Curly COMradesCurly COMrades
RU
Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ tec…
CURLY-COMRADESCurly COMradesCurly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian interests. They employ tec…
Cutting KittenCutting Kitten
IR
One of the threat actors responsible for the denial of service attacks against U.S in 2012–2013. Three individuals associated with the group—believed to be hav…
CUTTING-KITTENCutting KittenOne of the threat actors responsible for the denial of service attacks against U.S in 2012–2013. Three individuals associated with the group—believed to be hav…
Cyber AllianceCyber Alliance
UA
The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of Ukraine in 2022. They…
CYBER-ALLIANCECyber AllianceThe Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of Ukraine in 2022. They…
Cyber Army of Russia RebornCyber Army of Russia Reborn
CYBER-ARMY-OF-RUSSIA-REBORNCyber Army of Russia Reborn
Cyber Av3ngersCyber Av3ngers
IR
The hacktivist group ‘Cyber Av3ngers’ has historically claimed attacks on Israel’s critical infrastructures. It has been launching DDoS attacks and claiming br…
CYBER-AV3NGERSCyber Av3ngersCyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational technology and industrial control …
Cyber BerkutCyber Berkut
RU
Cyber Berkut is a Russian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Cyber Berkut is a Russian-attributed threat ac…
CYBER-BERKUTCyber Berkut
Cyber Caliphate ArmyCyber Caliphate ArmyCyber Caliphate Army is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Islamic State Hacking Division, CCA, United C…
CYBER-CALIPHATE-ARMYCyber Caliphate Army
Cyber fighters of Izz Ad-Din Al QassamCyber fighters of Izz Ad-Din Al Qassam
IR
Cyber fighters of Izz Ad-Din Al Qassam is a Iranian-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Fraterna…
CYBER-FIGHTERS-OF-IZZ-AD-DIN-AL-QASSAMCyber fighters of Izz Ad-Din Al Qassam
Cyber Islamic ResistanceCyber Islamic Resistance
IR
Cyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website defacements, DDoS attacks, and data…
CYBER-ISLAMIC-RESISTANCECyber Islamic ResistanceCyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website defacements, DDoS attacks, and data…
Cyber PartisansCyber Partisans
BY
The Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and infrastructure in Belarus and …
CYBER-PARTISANSCyber PartisansThe Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and infrastructure in Belarus and …
Cyber SerpCyber Serp
RU
UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting organizations in Ukraine's publi…
CYBER-SERPCyber SerpUAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting organizations in Ukraine's publi…
Cyber ToufanCyber Toufan
IR
Cyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations. The group's tactics suggest potential nat…
CYBER-TOUFANCyber ToufanCyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations. The group's tactics suggest potential nat…
Cyber.Anarchy.SquadCyber.Anarchy.Squad
UA
Cyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure. They have carried out cyberattacks on Russian…
CYBER-ANARCHY-SQUADCyber.Anarchy.SquadCyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure. They have carried out cyberattacks on Russian…
CyberNiggersCyberNiggersCyberNiggers is a threat group known for breaching various organizations, including the US military, federal contractors, and multinational corporations like G…
CYBERNIGGERSCyberNiggersCyberNiggers is a threat group known for breaching various organizations, including the US military, federal contractors, and multinational corporations like G…
DAGGER PANDADAGGER PANDA
CN
Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets…
DAGGER-PANDADAGGER PANDAOperate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets…
Daixin TeamDaixin TeamDaixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att…
DAIXIN-TEAMDaixin TeamDaixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att…
DalbitDalbit
CN
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of…
DALBITDalbitThe group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of…
Dancing SalomeDancing SalomeDancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S…
DANCING-SALOMEDancing SalomeDancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S…
DangerousSavannaDangerousSavannaMalicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr…
DANGEROUSSAVANNADangerousSavannaMalicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.