Threat Actors page 1 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

1937CN hacktivist
1937CN is a Chinese hacking group that has been active since at least 2013.
313 Team hacktivist
313 Team is an Iraq-based threat actor that has conducted coordinated DDoS campaigns targeting multiple government servers in the UAE…
ALLANITE nation-state
Also known as Palmetto Fusion. ALLANITE is a suspected Russian cyber espionage group, that has primarily targeted the electric utility sector within the United States…
ALTDOS criminal
ALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia.
ANDROMEDA SPIDER criminal
ANDROMEDA SPIDER, also known as the Andromeda malware group, is involved in cybercrime activities primarily focused on financial gain.
ANTHROPOID SPIDER criminal
Also known as Empire Monkey, CobaltGoblin. Publicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian…
APT-C-12 Espionage
Also known as Sapphire Mushroom, Blue Mushroom, NuclearCrisis. According to 360 TIC the actor has carried out continuous cyber espionage activities since 2011 on key units and departments of the…
APT-C-23 Espionage
Also known as Mantis, Arid Viper, Desert Falcon. APT-C-23 is a threat group that has been active since at least 2014.
APT-C-27 nation-state
Also known as GoldMouse, Golden RAT, ATK80. A threat actor which is ac tive since at least November 2014.
APT-C-34 nation-state
Also known as Golden Falcon. As reported by ZDNet, Chinese cyber-security vendor Qihoo 360 published a report on 2019-11-29 exposing an extensive hacking operation…
APT-C-36 Espionage
Also known as Blind Eagle, TAG-144, AguilaCiega. APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018.
APT-C-60 nation-state
Also known as APT-Q-12. APT-C-60 is a suspected nation-state threat actor known for conducting cyber espionage activities.
APT.3102 nation-state
APT.3102 is a Chinese nation-state threat actor known for targeting governmental and tech sectors primarily for espionage purposes.
APT1 Espionage
Also known as Comment Crew, Comment Group, Comment Panda. APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s…
APT12 Espionage
Also known as IXESHE, DynCalc, Numbered Panda. APT12 is a threat group that has been attributed to China.
APT14 Espionage
Also known as ANCHOR PANDA, QAZTeam, ALUMINUM. PLA Navy Anchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and military…
APT16 Espionage
Also known as SVCMONDR. APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.
APT17 Espionage
Also known as Deputy Dog, Group 8, AURORA PANDA. APT17 is a China-based threat group that has conducted network intrusions against U.S.
APT18 Espionage
Also known as TG-0416, Dynamite Panda, Threat Group-0416. APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing…
APT19 Espionage
Also known as Codoso, C0d0so0, Codoso Team. APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical…
APT20 nation-state
Also known as VIOLIN PANDA, TH3Bug, Crawling Taurus. We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer.
APT21 Espionage
Also known as HAMMER PANDA, TEMP.Zhenbao, NetTraveler. APT21, also known as HAMMER PANDA and TEMP.Zhenbao, is a Chinese threat actor known for conducting cyber espionage operations.
APT26 nation-state
Also known as JerseyMikes, TURBINE PANDA, BRONZE EXPRESS. APT26, also known by aliases such as JerseyMikes and TURBINE PANDA, is a nation-state cyber threat actor linked to China.
APT28 Espionage
Also known as IRON TWILIGHT, SNAKEMACKEREL, Swallowtail. APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service…
APT29 Espionage
Also known as IRON RITUAL, IRON HEMLOCK, NobleBaron. APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).
APT3 Espionage
Also known as Gothic Panda, Pirpi, UPS Team. APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security.
APT30 Espionage
APT30 is a threat group suspected to be associated with the Chinese government.
APT32 Espionage
Also known as SeaLotus, OceanLotus, APT-C-00. APT32 is a suspected Vietnam-based threat group that has been active since at least 2014.
APT33 Espionage
Also known as HOLMIUM, Elfin, Peach Sandstorm. APT33 is a suspected Iranian threat group that has carried out operations since at least 2013.
APT34
APT37 nation-state
Also known as InkySquid, ScarCruft, Reaper. APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012.
APT38 nation-state
Also known as NICKEL GLADSTONE, BeagleBoyz, Bluenoroff. APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the…
APT39 nation-state
Also known as ITG07, Chafer, Remix Kitten. APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through…
APT4 Espionage
Also known as PLA Navy, MAVERICK PANDA, BRONZE EDISON. APT4, also known as PLA Navy, is a nation-state cyber espionage group attributed to China.
APT41 nation-statecriminal
Also known as Wicked Panda, Brass Typhoon, BARIUM. APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated…
APT42 Espionage
Also known as UNC788, CALANQUE. APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.
APT43 nation-state
• APT43 is a prolific cyber operator that supports the interests of the North Korean regime.
APT45 nation-state
APT45 is a North Korean cyber threat actor that has been active since at least 2009.
APT5 nation-state
Also known as Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD. APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and…
APT6 nation-state
Also known as 1.php Group. The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems…
APT73 criminal
Also known as Eraleig. APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th.
APT9 nation-state
Also known as NIGHTSHADE PANDA, Red Pegasus, Group 27. APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular…
APTIran nation-state
APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of…
Ababil of Minab hacktivist
Ababil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in threat…
Actor240524 nation-state
Actor240524 is a newly identified APT group that targeted Azerbaijani and Israeli diplomats through spear-phishing emails to steal…
Adrastea criminal
Adrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen…
AeroBlade unknown
AeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States.
Aggressive Inventory Zombies criminal
Also known as AIZ. Aggressive Inventory Zombies is a threat actor involved in a large-scale phishing and pig-butchering network targeting retail brands and…
Agrius nation-state
Also known as Pink Sandstorm, AMERICIUM, Agonizing Serpens. Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an…
Ajax Security Team Espionage
Also known as Operation Woolen-Goldfish, AjaxTM, Rocket Kitten. Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran.
Akira criminal
Also known as GOLD SAHARA, PUNK SPIDER, Howling Scorpius. Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.
Alpha Spider criminal
Also known as ALPHV Ransomware Group. ALPHA SPIDER is a threat actor known for developing and operating the Alphv ransomware as a service.
Altahrea Team hacktivist
Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020.
Altoufan Team hacktivist
ALTOUFAN TEAM is a politically motivated hacktivist group with anti-Zionism, anti-monarchy, and pro-14-February movement sentiments.
Amaranth-Dragon nation-state
Amaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exhibiting…
Amethyst Rain nation-state
Also known as VolcanicTimber, Volatile Cedar. Microsoft threat actor profile. Origin/Threat: Lebanon.
Andariel nation-state
Also known as Silent Chollima, PLUTONIUM, Onyx Sleet. Andariel is a North Korean state-sponsored threat group that has been active since at least 2009.
Angry Likho nation-state
Also known as Sticky Werewolf. Angry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Russia and…
Anonymous KSA hacktivist
Anonymous KSA is a Saudi hacking group that has executed cyber attacks targeting Indian institutions, including a significant breach of…
Anonymous Sudan Denial of service
Since January 23, 2023, a threat actor identifying as "Anonymous Sudan" has been conducting denial of service (DDoS) attacks against…
Anonymous64 nation-statehacktivist
Also known as Anonymous 64. Anonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electronic…
Antique Typhoon nation-state
Also known as Storm-0558. Microsoft threat actor profile. Origin/Threat: China.
Antlion nation-state
Antlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan.
Aoqin Dragon nation-state
Also known as UNC94. Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013.
AppMilad nation-state
AppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad.
AppleJeus nation-state
Also known as Gleaming Pisces, Citrine Sleet, UNC1720. AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau.
Aquatic Panda nation-state
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage.
ArcaneDoor nation-state
ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors.
Armored Likho
Also known as Eagle Werewolf. Armored Likho is an APT group targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.
Aslan Neferler Tim Denial of service
Also known as Lion Soldiers Team, Phantom Turk. Turkish nationalist hacktivist group that has been active for roughly one year.
Asnarök criminal
Also known as Personal Panda. Asnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices…
AtlasCross nation-state
NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations.
Attor Espionage
Adversary group targeting diplomatic missions and governmental organisations.
Avivore nation-state
The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that…
Awaken Likho nation-state
Also known as Core Werewolf. Awaken Likho is an APT group that has targeted Russian government agencies and industrial enterprises, employing techniques such as…
Axiom nation-state
Also known as Group 72. Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors…
Ayyıldız Tim Denial of service
Also known as Crescent and Star. Ayyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002.
AzzaSec hacktivist
AzzaSec is a hacktivist group that originated in Italy.
BAMBOO SPIDER criminal
Crowdstrike tracks the developer of Panda Zeus as BAMBOO SPIDER
BARIUM nation-state
Microsoft Threat Intelligence associates Winnti with multiple activity groups—collections of malware, supporting infrastructure, online…
BIG PANDA nation-state
BIG PANDA is a state-sponsored Chinese cyber threat actor known for conducting espionage operations targeting primarily government sectors…
BITTER nation-state
Also known as T-APT-17, APT-C-08, Orange Yali. BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013.
BITWISE SPIDER criminal
BITWISE SPIDER has recently and quickly become a significant player in the big game hunting (BGH) landscape.
BOSON SPIDER criminal
BOSON SPIDER is a cyber criminal group, which was first identified in 2015, recently and inexplicably went dark in the spring of 2016…
BOSS SPIDER criminal
Also known as GOLD LOWELL. Throughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known…
BRONZE BUTLER Espionage
Also known as REDBALDKNIGHT, Tick, Nian. BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008.
BRONZE EDGEWOOD nation-state
Also known as Red Hariasa. In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia.
BRONZE SPIRAL nation-state
In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability…
BRONZE SPRING nation-state
Also known as UNC302. BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual…
BRONZE VAPOR nation-state
BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin.
BackdoorDiplomacy nation-state
Also known as BackDip, CloudComputating, Quarian. BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017.
BadRory nation-state
Kaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian…
Bahamut nation-state
Bahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state…
BatShadow nation-state
BatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering campaigns…
BazarCall criminal
Also known as BazzarCall, BazaCall. BazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into…
Bearlyfy criminal
Also known as Labubu. Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom…
BelialDemon criminal
Also known as Matanbuchus. Mentioned as operator of TriumphLoader and Matanbuchus
Belsen Group criminalnation-state
The Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls…
Berry Sandstorm nation-state
Also known as Storm-0852. Microsoft threat actor profile. Origin/Threat: Iran.
BiBiGun hacktivist
A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems.