2,004 indexed

ACTORSThreat actors

2004 threat-actor records from MISP-Galaxy v341. Filter by attributed country, or for country / sector / MITRE-Group facets see /explore/actors. Authored by Adam Lundqvist.

Showing 401–450 of 2,004 · page 9 of 41

IDTitleSummary
DantiDanti
DANTIDanti
Dark BasinDark BasinDark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups …
DARK-BASINDark BasinDark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups …
Dark CaracalDark Caracal
LB
Lookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad…
DARK-CARACALDark CaracalLookout and Electronic Frontier Foundation (EFF) have discovered Dark Caracal, a persistent and prolific actor, who at the time of writing is believed to be ad…
DarkCasinoDarkCasinoDarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online …
DARKCASINODarkCasinoDarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos, network banks, and online …
DarkGaboonDarkGaboonDarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to …
DARKGABOONDarkGaboonDarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily using phishing emails to …
DarkHotelDarkHotel
KR
Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits t…
DARKHOTELDarkHotelKaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits t…
DarkHydrusDarkHydrusIn July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a pre…
DARKHYDRUSDarkHydrusIn July 2018, Unit 42 analyzed a targeted attack using a novel file type against at least one government agency in the Middle East. It was carried out by a pre…
DarkPinkDarkPinkDarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Euro…
DARKPINKDarkPinkDarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in Southeast Asia and Euro…
DarkRaaSDarkRaaSDarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple countries, with a recent …
DARKRAASDarkRaaSDarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple countries, with a recent …
DarkSpectreDarkSpectre
DARKSPECTREDarkSpectre
DarkVishnyaDarkVishnyaDubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers…
DARKVISHNYADarkVishnyaDubbed DarkVishnya, the attacks targeted at least eight banks using readily-available gear such as netbooks or inexpensive laptops, Raspberry Pi mini-computers…
Deadeye JackalDeadeye Jackal
SY
The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass…
DEADEYE-JACKALDeadeye JackalThe Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian President Bashar al-Ass…
DefrayXDefrayXDefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W…
DEFRAYXDefrayXDefrayX is a threat actor group known for their RansomExx ransomware operations. They primarily target Linux operating systems, but also release versions for W…
Denim TsunamiDenim Tsunami
AT
Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using…
DENIM-TSUNAMIDenim TsunamiDenim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using…
Desorden GroupDesorden GroupDesorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se…
DESORDEN-GROUPDesorden GroupDesorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group. The group first emerged under the new name Desorden in Se…
DEV-0147DEV-0147
CN
DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra…
DEV-0147DEV-0147DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the group's data exfiltra…
DEV-0270DEV-0270
IR
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s…
DEV-0270DEV-0270Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known as Nemesis Kitten, a s…
DEV-0569DEV-0569DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech…
DEV-0569DEV-0569DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware. They utilize malicious ads and phishing tech…
DEV-0586DEV-0586
RU
MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw…
DEV-0586DEV-0586MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malw…
DEV-0928DEV-0928DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi…
DEV-0928DEV-0928DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022. They are known for their involvement in high-volume phishing campaigns, usi…
DEV-0950DEV-0950Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to s…
DEV-0950DEV-0950Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain unauthorized access to s…
DEV-1028DEV-1028DEV-1028 is a threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). Original record: Microsoft reported on MCCrash, an IoT botnet operated by the DEV-1028…
DEV-1028DEV-1028Microsoft reported on MCCrash, an IoT botnet operated by the DEV-1028 threat actor and used to launch DDoS attacks against private Minecraft servers.
DEXTOROUS SPIDERDEXTOROUS SPIDER
DEXTOROUS-SPIDERDEXTOROUS SPIDER
DiceyFDiceyF
CN
DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended period. They have exhi…
DICEYFDiceyFDiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended period. They have exhi…
DieNetDieNetDieNet is a hacktivist group that emerged in March 2025, known for conducting DDoS attacks targeting entities associated with political figures, such as Trump …
DIENETDieNetDieNet is a hacktivist group that emerged in March 2025, known for conducting DDoS attacks targeting entities associated with political figures, such as Trump …
Sourced from MISP-Galaxy Threat Actor cluster v341 (CC-0). Curated by Adam Lundqvist, Founder at SQUR.
Threat actors — by country | SQUR Knowledge Base