2,054 indexed

ACTORSThreat actors

2054 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 401–450 of 2,054 · page 9 of 42

IDTitleSummary
DAGGER-PANDADAGGER PANDAOperate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets…
Daixin TeamDaixin TeamDaixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att…
DAIXIN-TEAMDaixin TeamDaixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware att…
DalbitDalbit
CN
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of…
DALBITDalbitThe group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of…
Dancing SalomeDancing SalomeDancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S…
DANCING-SALOMEDancing SalomeDancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine. What makes Dancing S…
DangerousSavannaDangerousSavannaMalicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr…
DANGEROUSSAVANNADangerousSavannaMalicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the last two years. The thr…
DantiDantiDanti is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Danti.
DANTIDanti
DAONLYSPARKDaOnlySparkDaOnlySpark is a forum actor claiming to have leaked sensitive data from AdvaCare, including internal financial details, and from Jinko, comprising 3.7 GB of p…
Dark BasinDark BasinDark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups …
DARK-BASINDark BasinDark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups …
Dark CaracalDark Caracal
LB
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad…
DARK-CARACALDark CaracalLookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad…
DarkCasinoDarkCasinoDarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online …
DARKCASINODarkCasinoDarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online …
DarkGaboonDarkGaboonDarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to …
DARKGABOONDarkGaboonDarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to …
DarkHotelDarkHotel
KR
Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits t…
DARKHOTELDarkHotelKaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits t…
DarkHydrusDarkHydrusIn July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a pre…
DARKHYDRUSDarkHydrusIn July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a pre…
DarkPinkDarkPinkDarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Euro…
DARKPINKDarkPinkDarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Euro…
DarkRaaSDarkRaaSDarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple countries, with a recent …
DARKRAASDarkRaaSDarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple countries, with a recent …
DarkSpectreDarkSpectreDarkSpectre is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as DarkSpectre.
DARKSPECTREDarkSpectre
DarkVishnyaDarkVishnyaDubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers…
DARKVISHNYADarkVishnyaDubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers…
Deadeye JackalDeadeye Jackal
SY
The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass…
DEADEYE-JACKALDeadeye JackalThe Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass…
DefrayXDefrayXDefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W…
DEFRAYXDefrayXDefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W…
Denim TsunamiDenim Tsunami
AT
Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using…
DENIM-TSUNAMIDenim TsunamiDenim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using…
Desorden GroupDesorden GroupDesorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se…
DESORDEN-GROUPDesorden GroupDesorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se…
DEV-0147DEV-0147
CN
DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra…
DEV-0147DEV-0147DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra…
DEV-0270DEV-0270
IR
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s…
DEV-0270DEV-0270Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s…
DEV-0569DEV-0569DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech…
DEV-0569DEV-0569DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech…
DEV-0586DEV-0586
RU
MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw…
DEV-0586DEV-0586MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw…
DEV-0928DEV-0928DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi…
DEV-0928DEV-0928DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi…
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.