Threat Actors page 1 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- 1937CN hacktivist
- 1937CN is a Chinese hacking group that has been active since at least 2013.
- 313 Team hacktivist
- 313 Team is an Iraq-based threat actor that has conducted coordinated DDoS campaigns targeting multiple government servers in the UAE…
- ALLANITE nation-state
- Also known as Palmetto Fusion. ALLANITE is a suspected Russian cyber espionage group, that has primarily targeted the electric utility sector within the United States…
- ALTDOS criminal
- ALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia.
- ANDROMEDA SPIDER criminal
- ANDROMEDA SPIDER, also known as the Andromeda malware group, is involved in cybercrime activities primarily focused on financial gain.
- ANTHROPOID SPIDER criminal
- Also known as Empire Monkey, CobaltGoblin. Publicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian…
- APT-C-12 Espionage
- Also known as Sapphire Mushroom, Blue Mushroom, NuclearCrisis. According to 360 TIC the actor has carried out continuous cyber espionage activities since 2011 on key units and departments of the…
- APT-C-23 Espionage
- Also known as Mantis, Arid Viper, Desert Falcon. APT-C-23 is a threat group that has been active since at least 2014.
- APT-C-27 nation-state
- Also known as GoldMouse, Golden RAT, ATK80. A threat actor which is ac tive since at least November 2014.
- APT-C-34 nation-state
- Also known as Golden Falcon. As reported by ZDNet, Chinese cyber-security vendor Qihoo 360 published a report on 2019-11-29 exposing an extensive hacking operation…
- APT-C-36 Espionage
- Also known as Blind Eagle, TAG-144, AguilaCiega. APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018.
- APT-C-60 nation-state
- Also known as APT-Q-12. APT-C-60 is a suspected nation-state threat actor known for conducting cyber espionage activities.
- APT.3102 nation-state
- APT.3102 is a Chinese nation-state threat actor known for targeting governmental and tech sectors primarily for espionage purposes.
- APT1 Espionage
- Also known as Comment Crew, Comment Group, Comment Panda. APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s…
- APT12 Espionage
- Also known as IXESHE, DynCalc, Numbered Panda. APT12 is a threat group that has been attributed to China.
- APT14 Espionage
- Also known as ANCHOR PANDA, QAZTeam, ALUMINUM. PLA Navy Anchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and military…
- APT16 Espionage
- Also known as SVCMONDR. APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.
- APT17 Espionage
- Also known as Deputy Dog, Group 8, AURORA PANDA. APT17 is a China-based threat group that has conducted network intrusions against U.S.
- APT18 Espionage
- Also known as TG-0416, Dynamite Panda, Threat Group-0416. APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing…
- APT19 Espionage
- Also known as Codoso, C0d0so0, Codoso Team. APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical…
- APT20 nation-state
- Also known as VIOLIN PANDA, TH3Bug, Crawling Taurus. We’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer.
- APT21 Espionage
- Also known as HAMMER PANDA, TEMP.Zhenbao, NetTraveler. APT21, also known as HAMMER PANDA and TEMP.Zhenbao, is a Chinese threat actor known for conducting cyber espionage operations.
- APT26 nation-state
- Also known as JerseyMikes, TURBINE PANDA, BRONZE EXPRESS. APT26, also known by aliases such as JerseyMikes and TURBINE PANDA, is a nation-state cyber threat actor linked to China.
- APT28 Espionage
- Also known as IRON TWILIGHT, SNAKEMACKEREL, Swallowtail. APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service…
- APT29 Espionage
- Also known as IRON RITUAL, IRON HEMLOCK, NobleBaron. APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).
- APT3 Espionage
- Also known as Gothic Panda, Pirpi, UPS Team. APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security.
- APT30 Espionage
- APT30 is a threat group suspected to be associated with the Chinese government.
- APT32 Espionage
- Also known as SeaLotus, OceanLotus, APT-C-00. APT32 is a suspected Vietnam-based threat group that has been active since at least 2014.
- APT33 Espionage
- Also known as HOLMIUM, Elfin, Peach Sandstorm. APT33 is a suspected Iranian threat group that has carried out operations since at least 2013.
- APT34
- APT37 nation-state
- Also known as InkySquid, ScarCruft, Reaper. APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012.
- APT38 nation-state
- Also known as NICKEL GLADSTONE, BeagleBoyz, Bluenoroff. APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the…
- APT39 nation-state
- Also known as ITG07, Chafer, Remix Kitten. APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through…
- APT4 Espionage
- Also known as PLA Navy, MAVERICK PANDA, BRONZE EDISON. APT4, also known as PLA Navy, is a nation-state cyber espionage group attributed to China.
- APT41 nation-statecriminal
- Also known as Wicked Panda, Brass Typhoon, BARIUM. APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated…
- APT42 Espionage
- Also known as UNC788, CALANQUE. APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.
- APT43 nation-state
- • APT43 is a prolific cyber operator that supports the interests of the North Korean regime.
- APT45 nation-state
- APT45 is a North Korean cyber threat actor that has been active since at least 2009.
- APT5 nation-state
- Also known as Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD. APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and…
- APT6 nation-state
- Also known as 1.php Group. The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems…
- APT73 criminal
- Also known as Eraleig. APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th.
- APT9 nation-state
- Also known as NIGHTSHADE PANDA, Red Pegasus, Group 27. APT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular…
- APTIran nation-state
- APTIran has claimed responsibility for a large-scale campaign targeting Israeli critical infrastructure, asserting infiltration of…
- Ababil of Minab hacktivist
- Ababil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in threat…
- Actor240524 nation-state
- Actor240524 is a newly identified APT group that targeted Azerbaijani and Israeli diplomats through spear-phishing emails to steal…
- Adrastea criminal
- Adrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen…
- AeroBlade unknown
- AeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States.
- Aggressive Inventory Zombies criminal
- Also known as AIZ. Aggressive Inventory Zombies is a threat actor involved in a large-scale phishing and pig-butchering network targeting retail brands and…
- Agrius nation-state
- Also known as Pink Sandstorm, AMERICIUM, Agonizing Serpens. Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an…
- Ajax Security Team Espionage
- Also known as Operation Woolen-Goldfish, AjaxTM, Rocket Kitten. Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran.
- Akira criminal
- Also known as GOLD SAHARA, PUNK SPIDER, Howling Scorpius. Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.
- Alpha Spider criminal
- Also known as ALPHV Ransomware Group. ALPHA SPIDER is a threat actor known for developing and operating the Alphv ransomware as a service.
- Altahrea Team hacktivist
- Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020.
- Altoufan Team hacktivist
- ALTOUFAN TEAM is a politically motivated hacktivist group with anti-Zionism, anti-monarchy, and pro-14-February movement sentiments.
- Amaranth-Dragon nation-state
- Amaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exhibiting…
- Amethyst Rain nation-state
- Also known as VolcanicTimber, Volatile Cedar. Microsoft threat actor profile. Origin/Threat: Lebanon.
- Andariel nation-state
- Also known as Silent Chollima, PLUTONIUM, Onyx Sleet. Andariel is a North Korean state-sponsored threat group that has been active since at least 2009.
- Angry Likho nation-state
- Also known as Sticky Werewolf. Angry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Russia and…
- Anonymous KSA hacktivist
- Anonymous KSA is a Saudi hacking group that has executed cyber attacks targeting Indian institutions, including a significant breach of…
- Anonymous Sudan Denial of service
- Since January 23, 2023, a threat actor identifying as "Anonymous Sudan" has been conducting denial of service (DDoS) attacks against…
- Anonymous64 nation-statehacktivist
- Also known as Anonymous 64. Anonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electronic…
- Antique Typhoon nation-state
- Also known as Storm-0558. Microsoft threat actor profile. Origin/Threat: China.
- Antlion nation-state
- Antlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan.
- Aoqin Dragon nation-state
- Also known as UNC94. Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013.
- AppMilad nation-state
- AppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad.
- AppleJeus nation-state
- Also known as Gleaming Pisces, Citrine Sleet, UNC1720. AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau.
- Aquatic Panda nation-state
- Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage.
- ArcaneDoor nation-state
- ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors.
- Armored Likho
- Also known as Eagle Werewolf. Armored Likho is an APT group targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.
- Aslan Neferler Tim Denial of service
- Also known as Lion Soldiers Team, Phantom Turk. Turkish nationalist hacktivist group that has been active for roughly one year.
- Asnarök criminal
- Also known as Personal Panda. Asnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices…
- AtlasCross nation-state
- NSFOCUS Security Labs recently discovered a new attack process based on phishing documents in their daily threat-hunting operations.
- Attor Espionage
- Adversary group targeting diplomatic missions and governmental organisations.
- Avivore nation-state
- The group’s existence came to light during Context’s investigation of a number of attacks against multinational enterprises that…
- Awaken Likho nation-state
- Also known as Core Werewolf. Awaken Likho is an APT group that has targeted Russian government agencies and industrial enterprises, employing techniques such as…
- Axiom nation-state
- Also known as Group 72. Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors…
- Ayyıldız Tim Denial of service
- Also known as Crescent and Star. Ayyıldız (Crescent and Star) Tim is a nationalist hacking group founded in 2002.
- AzzaSec hacktivist
- AzzaSec is a hacktivist group that originated in Italy.
- BAMBOO SPIDER criminal
- Crowdstrike tracks the developer of Panda Zeus as BAMBOO SPIDER
- BARIUM nation-state
- Microsoft Threat Intelligence associates Winnti with multiple activity groups—collections of malware, supporting infrastructure, online…
- BIG PANDA nation-state
- BIG PANDA is a state-sponsored Chinese cyber threat actor known for conducting espionage operations targeting primarily government sectors…
- BITTER nation-state
- Also known as T-APT-17, APT-C-08, Orange Yali. BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013.
- BITWISE SPIDER criminal
- BITWISE SPIDER has recently and quickly become a significant player in the big game hunting (BGH) landscape.
- BOSON SPIDER criminal
- BOSON SPIDER is a cyber criminal group, which was first identified in 2015, recently and inexplicably went dark in the spring of 2016…
- BOSS SPIDER criminal
- Also known as GOLD LOWELL. Throughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known…
- BRONZE BUTLER Espionage
- Also known as REDBALDKNIGHT, Tick, Nian. BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008.
- BRONZE EDGEWOOD nation-state
- Also known as Red Hariasa. In early 2021 CTU researchers observed BRONZE EDGEWOOD exploiting the Microsoft Exchange Server of an organization in Southeast Asia.
- BRONZE SPIRAL nation-state
- In December 2020, the IT management software provider SolarWinds announced that an unidentified threat actor had exploited a vulnerability…
- BRONZE SPRING nation-state
- Also known as UNC302. BRONZE SPRING is a threat group that CTU researchers assess with high confidence operates on behalf of China in the theft of intellectual…
- BRONZE VAPOR nation-state
- BRONZE VAPOR is a targeted threat group assessed with moderate confidence to be of Chinese origin.
- BackdoorDiplomacy nation-state
- Also known as BackDip, CloudComputating, Quarian. BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017.
- BadRory nation-state
- Kaspersky researchers have identified a new APT group named BadRory that has mounted two waves of spear-phishing attacks against Russian…
- Bahamut nation-state
- Bahamut is a threat actor primarily operating in Middle East and Central Asia, suspected to be a private contractor to several state…
- BatShadow nation-state
- BatShadow is a Vietnamese threat actor that targets job seekers and digital marketing professionals through social engineering campaigns…
- BazarCall criminal
- Also known as BazzarCall, BazaCall. BazarCall campaigns forgo malicious links or attachments in email messages in favor of phone numbers that recipients are misled into…
- Bearlyfy criminal
- Also known as Labubu. Bearlyfy has been attributed to over 70 cyber attacks targeting Russian companies since its emergence in January 2025, employing a custom…
- BelialDemon criminal
- Also known as Matanbuchus. Mentioned as operator of TriumphLoader and Matanbuchus
- Belsen Group criminalnation-state
- The Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls…
- Berry Sandstorm nation-state
- Also known as Storm-0852. Microsoft threat actor profile. Origin/Threat: Iran.
- BiBiGun hacktivist
- A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems.