Threat Actors page 10 of 12
1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- TetrisPhantom nation-state
- TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by…
- The Big Bang unknown
- While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack…
- The Gentlemen criminal
- The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical…
- The Shadow Brokers nation-state
- Also known as The ShadowBrokers, TSB, Shadow Brokers. The Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016.
- The White Company nation-state
- The White Company is a likely state-sponsored threat actor with advanced capabilities.
- TheDarkOverlord criminal
- The Dark Overlord is a financially motivated ransomware group that has been active since 2016.
- TheHatman
- TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major…
- TheWizards nation-state
- TheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC…
- Threat Actor 888 criminal
- Threat actor 888 is a hacker active in 2024, targeting companies for data breaches.
- Threat Group-1314 unknown
- Also known as TG-1314. Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.
- Threat Group-3390 Espionage
- Also known as Earth Smilodon, TG-3390, Emissary Panda. Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.
- Threatsec hacktivist
- ThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza.
- Thrip Espionage
- Also known as ATK78. Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S.
- TianWu nation-state
- TianWu is a nation-state threat actor believed to operate from China, primarily focused on cyber-espionage targeting government and…
- TiltedTemple nation-state
- Also known as DEV-0322, Circle Typhoon. One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows…
- ToddyCat nation-state
- Also known as Websiic. ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage…
- Tomato Tempest nation-state
- Also known as SPURR, Vatet. Tomato Tempest, also known as SPURR and Vatet, is a highly sophisticated nation-state threat actor group known for cyber-espionage…
- Tonto Team nation-state
- Also known as Earth Akhlut, BRONZE HUNTLEY, CactusPete. Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and…
- TraderTraitor nation-state
- Also known as Jade Sleet, UNC4899, Pukchong. TraderTraitor targets blockchain companies through spear-phishing messages.
- Transparent Tribe nation-state
- Also known as COPPER FIELDSTONE, APT36, Mythic Leopard. Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic…
- TridentLocker criminal
- TridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including…
- Tropic Trooper nation-state
- Also known as Pirate Panda, KeyBoy, PIRATE PANDA. Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong.
- Tstark nation-state
- TStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit…
- Tumbleweed Typhoon nation-state
- Also known as THORIUM, Karst. Microsoft threat actor profile. Origin/Threat: China.
- TunnelSnake nation-state
- The TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive…
- TurkHackTeam hacktivist
- Also known as Turk Hack Team. Founded in 2004, Turkhackteam is one of Turkey’s oldest and most high-profile hacking collectives.
- Turla Espionage
- Also known as IRON HUNTER, Group 88, Waterbug. Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB).
- TwoSail Junk nation-state
- Also known as Operation Poisoned News. TwoSail Junk directs visitors to its exploit site by posting links within the threads of forum discussions, or creating new topic threads…
- UAC-0006 criminal
- UAC-0006 is a financially motivated threat actor that has been active since at least 2013.
- UAC-0020 nation-state
- Also known as Vermin, SickSync. Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin.
- UAC-0050 nation-state
- UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine.
- UAC-0063 nation-state
- UAC-0063 is a threat actor linked to Russian APT28, known for targeting government entities in Ukraine and Central Asia for cyber…
- UAC-0094 nation-state
- State Service of Special Communication and Information Protection of Ukraine spotted a new wave of cyber attacks aimed at gaining access…
- UAC-0099 nation-state
- UAC-0099 is a threat actor that has been active since at least May 2023, targeting Ukrainian entities.
- UAC-0102 nation-state
- UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks.
- UAC-0118 hacktivist
- Also known as FRwL, FromRussiaWithLove. From Russia with Love, is a threat actor group that emerged during the Russia-Ukraine war in 2022.
- UAC-0149 nation-state
- UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware.
- UAC-0154 nation-state
- UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military.
- UAC-0184 nation-state
- UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks.
- UAC-0185 nation-state
- Also known as UNC4221. UAC-0185 has been active since at least 2022, primarily targeting Ukrainian defense organizations through credential theft via messaging…
- UAC-0194 nation-state
- UAC-0194 is a Russian threat actor linked to the exploitation of the Windows zero-day CVE-2024-43451, which was used in attacks against…
- UAC-0215 nation-state
- UAC-0215 is an APT group that has orchestrated a phishing campaign targeting public institutions, major industries, and military units in…
- UAC-0219 nation-state
- UAC-0219 is a hacking group observed conducting cyber-espionage operations targeting Ukrainian critical sectors, primarily utilising…
- UAC-0226 nation-state
- UAC-0226 is a cyber-espionage group targeting Ukrainian military, law enforcement, and local government entities—particularly near the…
- UAC-0227 nation-state
- UAC-0227 is an APT group that has been active since at least March 2025, targeting local governments, critical infrastructure, and various…
- UAC-0239 nation-state
- UAC-0239 has been observed conducting spearphishing attacks targeting the Defence Forces and local state agencies of Ukraine…
- UAC-0241 nation-state
- UAC-0241 is a threat actor tracked by CERT-UA, active from May to November 2025, targeting educational institutions and government bodies…
- UAC-0245 nation-state
- Threat actors, tracked under the identifier UAC-0245 and targeting Ukraine, employ malicious XLL files disguised as critical documents.
- UAT-10362 nation-state
- UAT-10362 is a threat actor identified by Cisco Talos, conducting spear-phishing campaigns targeting Taiwanese NGOs and suspected…
- UAT-10608 criminal
- UAT-10608 is a threat cluster observed by Cisco Talos conducting a large-scale, automated credential-harvesting campaign against…
- UAT-11795
- UAT-11795 is a sophisticated, Russian-speaking, financially motivated adversary conducting malicious campaigns targeting users in the U.S.
- UAT-5394 nation-state
- UAT-5394 is a state-sponsored North Korean threat actor known for developing the MoonPeak RAT, which is based on XenoRAT.
- UAT-5918 nation-state
- UAT-5918 is an APT group that targets entities in Taiwan, primarily in telecommunications, healthcare, and IT sectors, to establish…
- UAT-6382 nation-state
- UAT-6382 is a Chinese-speaking threat actor that exploits CVE-2025-0944 to gain access to enterprise networks, particularly targeting…
- UAT-7237 nation-state
- UAT-7237 is a Chinese-speaking APT group that has been active since at least 2022, primarily targeting web infrastructure entities in…
- UAT-7810
- UAT-7810 is an APT actor responsible for maintaining the LapDogs ORB network and developing custom malware, including the backdoors…
- UAT-8099 criminal
- UAT-8099 is a Chinese-speaking cybercrime group primarily engaged in SEO fraud and the theft of high-value credentials, configuration…
- UAT-8302 nation-state
- UAT-8302 is a sophisticated China-nexus APT group targeting government entities in South America and southeastern Europe, deploying…
- UAT-8616 nation-state
- UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023.
- UAT-8837 nation-state
- UAT-8837 is a sophisticated China-linked APT group exploiting critical zero-day vulnerabilities, such as CVE-2025-53690 in the Sitecore…
- UAT-9244 nation-state
- UAT-9244 is a China-nexus APT actor, disclosed by Cisco Talos on March 5, 2026, assessed with high confidence as closely associated with…
- UAT-9686 nation-state
- UAT-9686 is a Chinese state-sponsored APT known for targeting networking infrastructure and edge appliances through a sophisticated…
- UAT-9921 nation-state
- Also known as VoidLink Operator. UAT-9921 is a China-nexus threat actor active since 2019, tracked by Cisco Talos.
- UNC1069 nation-state
- Also known as MASAN, CryptoCore. CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing…
- UNC1088
- Also known as RAVINE CASTLE. UNC1088 is a China-nexus threat cluster tracked by Mandiant, renamed RAVINE CASTLE under Google Threat Intelligence's updated naming system.
- UNC1549 nation-state
- Also known as Nimbus Manticore. UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC.
- UNC1860 nation-state
- UNC1860 is a persistent and opportunistic Iranian state-sponsored threat actor that is likely affiliated with Iran’s Ministry of…
- UNC1878 criminal
- UNC1878 is a financially motivated threat actor that monetizes network access via the deployment of RYUK ransomware.
- UNC215 nation-state
- UNC215 is a Chinese nation-state threat actor that has been active since at least 2014.
- UNC2447 criminal
- UNC2447 is a financially motivated threat actor with ties to multiple hacker groups.
- UNC2452
- Also known as NOBELIUM, StellarParticle, Dark Halo. UNC2452 is a suspected Russian state-sponsored threat group responsible for the 2020 SolarWinds software supply chain intrusion.
- UNC2465 criminal
- UNC2465 is a threat actor known for deploying the SMOKEDHAM .NET backdoor and DARKSIDE ransomware, utilizing TTPs such as phishing…
- UNC2529
- UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures…
- UNC2565 criminal
- Also known as Hive0127. UNC2565 is a threat group that has used the GOOTLOADER downloader to deliver Cobalt Strike BEACON.
- UNC2630 nation-state
- UNC2630 is a threat actor believed to be affiliated with the Chinese government.
- UNC2659 nation-state
- UNC2659 has been active since at least January 2021.
- UNC2717 nation-state
- UNC2717 is a threat actor that engages in espionage activities aligned with Chinese government priorities.
- UNC2814 nation-state
- UNC2814 is a suspected PRC-nexus cyber espionage group that has targeted telecommunications providers and government entities globally…
- UNC2970 nation-state
- UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes…
- UNC3524 Espionage
- Mandiant observed this group operating since December 2019.
- UNC3569 nation-state
- China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web…
- UNC3886 nation-state
- UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and…
- UNC3890 nation-state
- A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare…
- UNC3973 criminal
- UNC3973 is a financially motivated threat actor tracked by Mandiant, distinguished from the broader BASTA ransomware ecosystem (primarily…
- UNC4191 nation-state
- UNC4191 is a China-linked threat actor that has been involved in cyber espionage campaigns targeting public and private sectors primarily…
- UNC4393 criminal
- Also known as Storm-1811, CURLY SPIDER, STAC5777. UNC4393 is a financially motivated threat actor primarily using BASTA ransomware.
- UNC4487 criminal
- UNC4487 is a threat actor that targeted Ukrainian government officials by compromising a Ukrainian auto insurance website essential for…
- UNC4536 criminal
- UNC4536 is a threat actor that distributes malware, including ICEDID, REDLINESTEALER, and CARBANAK, primarily through malvertising and…
- UNC4540 nation-state
- UNC4540 is a suspected Chinese threat actor targeting unpatched SonicWall Secure Mobile Access appliances to deploy custom malware that…
- UNC4736 nation-state
- UNC4736 is a North Korean threat actor that has been involved in supply chain attacks targeting software chains of 3CX and X_TRADER.
- UNC4841 nation-state
- Also known as SLIME57. UNC4841 is a well-resourced threat actor that has utilized a wide range of malware and purpose-built tooling to enable their global…
- UNC4990 criminal
- UNC4990 is a financially motivated threat actor that has been active since at least 2020.
- UNC5174 nation-state
- Also known as Uteus. UNC5174, a Chinese state-sponsored threat actor, has been identified by Mandiant for exploiting critical vulnerabilities in F5 BIG-IP and…
- UNC5266 nation-state
- Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE…
- UNC5291 nation-state
- UNC5291 is a cluster of targeted probing activity that we assess with moderate confidence is associated with UNC3236, also known publicly…
- UNC5325 nation-state
- UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances.
- UNC5330 nation-state
- UNC5330 is a suspected China-nexus espionage actor.
- UNC5337 nation-state
- UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan.
- UNC5342 nation-state
- UNC5342 is a North Korea-linked APT that employs the EtherHiding technique to deliver malware and facilitate cryptocurrency theft.
- UNC5537 criminal
- UNC5537 is a financially motivated threat actor targeting Snowflake customer databases.