2,054 indexed
ACTORSThreat actors
2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.
Showing 401–450 of 2,054 · page 9 of 42
| ID | Title | Summary |
|---|---|---|
| DAGGER-PANDA | DAGGER PANDA | Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets… |
| Daixin Team | Daixin Team | Daixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att… |
| DAIXIN-TEAM | Daixin Team | Daixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att… |
| Dalbit | Dalbit CN | The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of… |
| DALBIT | Dalbit | The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of… |
| Dancing Salome | Dancing Salome | Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S… |
| DANCING-SALOME | Dancing Salome | Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S… |
| DangerousSavanna | DangerousSavanna | Malicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr… |
| DANGEROUSSAVANNA | DangerousSavanna | Malicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr… |
| Danti | Danti | Danti is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Danti. |
| DANTI | Danti | |
| DAONLYSPARK | DaOnlySpark | DaOnlySpark is a forum actor claiming to have leaked sensitive data from AdvaCare, including internal financial details, and from Jinko, comprising 3.7 GB of p… |
| Dark Basin | Dark Basin | Dark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups … |
| DARK-BASIN | Dark Basin | Dark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups … |
| Dark Caracal | Dark Caracal LB | Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad… |
| DARK-CARACAL | Dark Caracal | Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad… |
| DarkCasino | DarkCasino | DarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online … |
| DARKCASINO | DarkCasino | DarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online … |
| DarkGaboon | DarkGaboon | DarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to … |
| DARKGABOON | DarkGaboon | DarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to … |
| DarkHotel | DarkHotel KR | Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits t… |
| DARKHOTEL | DarkHotel | Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits t… |
| DarkHydrus | DarkHydrus | In July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a pre… |
| DARKHYDRUS | DarkHydrus | In July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a pre… |
| DarkPink | DarkPink | DarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Euro… |
| DARKPINK | DarkPink | DarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Euro… |
| DarkRaaS | DarkRaaS | DarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple countries, with a recent … |
| DARKRAAS | DarkRaaS | DarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple countries, with a recent … |
| DarkSpectre | DarkSpectre | DarkSpectre is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DarkSpectre. |
| DARKSPECTRE | DarkSpectre | |
| DarkVishnya | DarkVishnya | Dubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers… |
| DARKVISHNYA | DarkVishnya | Dubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers… |
| Deadeye Jackal | Deadeye Jackal SY | The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass… |
| DEADEYE-JACKAL | Deadeye Jackal | The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass… |
| DefrayX | DefrayX | DefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W… |
| DEFRAYX | DefrayX | DefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W… |
| Denim Tsunami | Denim Tsunami AT | Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using… |
| DENIM-TSUNAMI | Denim Tsunami | Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using… |
| Desorden Group | Desorden Group | Desorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se… |
| DESORDEN-GROUP | Desorden Group | Desorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se… |
| DEV-0147 | DEV-0147 CN | DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra… |
| DEV-0147 | DEV-0147 | DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra… |
| DEV-0270 | DEV-0270 IR | Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s… |
| DEV-0270 | DEV-0270 | Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s… |
| DEV-0569 | DEV-0569 | DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech… |
| DEV-0569 | DEV-0569 | DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech… |
| DEV-0586 | DEV-0586 RU | MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw… |
| DEV-0586 | DEV-0586 | MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw… |
| DEV-0928 | DEV-0928 | DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi… |
| DEV-0928 | DEV-0928 | DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi… |