Threat Actors page 10 of 12

1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

TetrisPhantom nation-state
TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by…
The Big Bang unknown
While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack…
The Gentlemen criminal
The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical…
The Shadow Brokers nation-state
Also known as The ShadowBrokers, TSB, Shadow Brokers. The Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016.
The White Company nation-state
The White Company is a likely state-sponsored threat actor with advanced capabilities.
TheDarkOverlord criminal
The Dark Overlord is a financially motivated ransomware group that has been active since 2016.
TheHatman
TheHatman is a highly organized threat actor known for systematically listing and selling internal employee directories stolen from major…
TheWizards nation-state
TheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC…
Threat Actor 888 criminal
Threat actor 888 is a hacker active in 2024, targeting companies for data breaches.
Threat Group-1314 unknown
Also known as TG-1314. Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.
Threat Group-3390 Espionage
Also known as Earth Smilodon, TG-3390, Emissary Panda. Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.
Threatsec hacktivist
ThreatSec is a hacktivist group that has targeted various organizations, including internet service providers in Gaza.
Thrip Espionage
Also known as ATK78. Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S.
TianWu nation-state
TianWu is a nation-state threat actor believed to operate from China, primarily focused on cyber-espionage targeting government and…
TiltedTemple nation-state
Also known as DEV-0322, Circle Typhoon. One of their notable tools is a custom backdoor called SockDetour, which operates filelessly and socketlessly on compromised Windows…
ToddyCat nation-state
Also known as Websiic. ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage…
Tomato Tempest nation-state
Also known as SPURR, Vatet. Tomato Tempest, also known as SPURR and Vatet, is a highly sophisticated nation-state threat actor group known for cyber-espionage…
Tonto Team nation-state
Also known as Earth Akhlut, BRONZE HUNTLEY, CactusPete. Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and…
TraderTraitor nation-state
Also known as Jade Sleet, UNC4899, Pukchong. TraderTraitor targets blockchain companies through spear-phishing messages.
Transparent Tribe nation-state
Also known as COPPER FIELDSTONE, APT36, Mythic Leopard. Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic…
TridentLocker criminal
TridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including…
Tropic Trooper nation-state
Also known as Pirate Panda, KeyBoy, PIRATE PANDA. Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong.
Tstark nation-state
TStark is a threat actor identified by X-Ops, associated with a cluster of devices that executed the bookmark buffer overflow exploit…
Tumbleweed Typhoon nation-state
Also known as THORIUM, Karst. Microsoft threat actor profile. Origin/Threat: China.
TunnelSnake nation-state
The TunnelSnake campaign demonstrates the activity of a sophisticated actor that invests significant resources in designing an evasive…
TurkHackTeam hacktivist
Also known as Turk Hack Team. Founded in 2004, Turkhackteam is one of Turkey’s oldest and most high-profile hacking collectives.
Turla Espionage
Also known as IRON HUNTER, Group 88, Waterbug. Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB).
TwoSail Junk nation-state
Also known as Operation Poisoned News. TwoSail Junk directs visitors to its exploit site by posting links within the threads of forum discussions, or creating new topic threads…
UAC-0006 criminal
UAC-0006 is a financially motivated threat actor that has been active since at least 2013.
UAC-0020 nation-state
Also known as Vermin, SickSync. Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin.
UAC-0050 nation-state
UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine.
UAC-0063 nation-state
UAC-0063 is a threat actor linked to Russian APT28, known for targeting government entities in Ukraine and Central Asia for cyber…
UAC-0094 nation-state
State Service of Special Communication and Information Protection of Ukraine spotted a new wave of cyber attacks aimed at gaining access…
UAC-0099 nation-state
UAC-0099 is a threat actor that has been active since at least May 2023, targeting Ukrainian entities.
UAC-0102 nation-state
UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks.
UAC-0118 hacktivist
Also known as FRwL, FromRussiaWithLove. From Russia with Love, is a threat actor group that emerged during the Russia-Ukraine war in 2022.
UAC-0149 nation-state
UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware.
UAC-0154 nation-state
UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military.
UAC-0184 nation-state
UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks.
UAC-0185 nation-state
Also known as UNC4221. UAC-0185 has been active since at least 2022, primarily targeting Ukrainian defense organizations through credential theft via messaging…
UAC-0194 nation-state
UAC-0194 is a Russian threat actor linked to the exploitation of the Windows zero-day CVE-2024-43451, which was used in attacks against…
UAC-0215 nation-state
UAC-0215 is an APT group that has orchestrated a phishing campaign targeting public institutions, major industries, and military units in…
UAC-0219 nation-state
UAC-0219 is a hacking group observed conducting cyber-espionage operations targeting Ukrainian critical sectors, primarily utilising…
UAC-0226 nation-state
UAC-0226 is a cyber-espionage group targeting Ukrainian military, law enforcement, and local government entities—particularly near the…
UAC-0227 nation-state
UAC-0227 is an APT group that has been active since at least March 2025, targeting local governments, critical infrastructure, and various…
UAC-0239 nation-state
UAC-0239 has been observed conducting spearphishing attacks targeting the Defence Forces and local state agencies of Ukraine…
UAC-0241 nation-state
UAC-0241 is a threat actor tracked by CERT-UA, active from May to November 2025, targeting educational institutions and government bodies…
UAC-0245 nation-state
Threat actors, tracked under the identifier UAC-0245 and targeting Ukraine, employ malicious XLL files disguised as critical documents.
UAT-10362 nation-state
UAT-10362 is a threat actor identified by Cisco Talos, conducting spear-phishing campaigns targeting Taiwanese NGOs and suspected…
UAT-10608 criminal
UAT-10608 is a threat cluster observed by Cisco Talos conducting a large-scale, automated credential-harvesting campaign against…
UAT-11795
UAT-11795 is a sophisticated, Russian-speaking, financially motivated adversary conducting malicious campaigns targeting users in the U.S.
UAT-5394 nation-state
UAT-5394 is a state-sponsored North Korean threat actor known for developing the MoonPeak RAT, which is based on XenoRAT.
UAT-5918 nation-state
UAT-5918 is an APT group that targets entities in Taiwan, primarily in telecommunications, healthcare, and IT sectors, to establish…
UAT-6382 nation-state
UAT-6382 is a Chinese-speaking threat actor that exploits CVE-2025-0944 to gain access to enterprise networks, particularly targeting…
UAT-7237 nation-state
UAT-7237 is a Chinese-speaking APT group that has been active since at least 2022, primarily targeting web infrastructure entities in…
UAT-7810
UAT-7810 is an APT actor responsible for maintaining the LapDogs ORB network and developing custom malware, including the backdoors…
UAT-8099 criminal
UAT-8099 is a Chinese-speaking cybercrime group primarily engaged in SEO fraud and the theft of high-value credentials, configuration…
UAT-8302 nation-state
UAT-8302 is a sophisticated China-nexus APT group targeting government entities in South America and southeastern Europe, deploying…
UAT-8616 nation-state
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023.
UAT-8837 nation-state
UAT-8837 is a sophisticated China-linked APT group exploiting critical zero-day vulnerabilities, such as CVE-2025-53690 in the Sitecore…
UAT-9244 nation-state
UAT-9244 is a China-nexus APT actor, disclosed by Cisco Talos on March 5, 2026, assessed with high confidence as closely associated with…
UAT-9686 nation-state
UAT-9686 is a Chinese state-sponsored APT known for targeting networking infrastructure and edge appliances through a sophisticated…
UAT-9921 nation-state
Also known as VoidLink Operator. UAT-9921 is a China-nexus threat actor active since 2019, tracked by Cisco Talos.
UNC1069 nation-state
Also known as MASAN, CryptoCore. CryptoCore is a North Korean APT known for targeting cryptocurrency exchanges and financial institutions, employing spear-phishing…
UNC1088
Also known as RAVINE CASTLE. UNC1088 is a China-nexus threat cluster tracked by Mandiant, renamed RAVINE CASTLE under Google Threat Intelligence's updated naming system.
UNC1549 nation-state
Also known as Nimbus Manticore. UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC.
UNC1860 nation-state
UNC1860 is a persistent and opportunistic Iranian state-sponsored threat actor that is likely affiliated with Iran’s Ministry of…
UNC1878 criminal
UNC1878 is a financially motivated threat actor that monetizes network access via the deployment of RYUK ransomware.
UNC215 nation-state
UNC215 is a Chinese nation-state threat actor that has been active since at least 2014.
UNC2447 criminal
UNC2447 is a financially motivated threat actor with ties to multiple hacker groups.
UNC2452
Also known as NOBELIUM, StellarParticle, Dark Halo. UNC2452 is a suspected Russian state-sponsored threat group responsible for the 2020 SolarWinds software supply chain intrusion.
UNC2465 criminal
UNC2465 is a threat actor known for deploying the SMOKEDHAM .NET backdoor and DARKSIDE ransomware, utilizing TTPs such as phishing…
UNC2529
UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures…
UNC2565 criminal
Also known as Hive0127. UNC2565 is a threat group that has used the GOOTLOADER downloader to deliver Cobalt Strike BEACON.
UNC2630 nation-state
UNC2630 is a threat actor believed to be affiliated with the Chinese government.
UNC2659 nation-state
UNC2659 has been active since at least January 2021.
UNC2717 nation-state
UNC2717 is a threat actor that engages in espionage activities aligned with Chinese government priorities.
UNC2814 nation-state
UNC2814 is a suspected PRC-nexus cyber espionage group that has targeted telecommunications providers and government entities globally…
UNC2970 nation-state
UNC2970 is a North Korean threat actor that primarily targets organizations through spear-phishing emails with job recruitment themes…
UNC3524 Espionage
Mandiant observed this group operating since December 2019.
UNC3569 nation-state
China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web…
UNC3886 nation-state
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and…
UNC3890 nation-state
A suspected Iranian threat activity cluster has been linked to attacks aimed at Israeli shipping, government, energy, and healthcare…
UNC3973 criminal
UNC3973 is a financially motivated threat actor tracked by Mandiant, distinguished from the broader BASTA ransomware ecosystem (primarily…
UNC4191 nation-state
UNC4191 is a China-linked threat actor that has been involved in cyber espionage campaigns targeting public and private sectors primarily…
UNC4393 criminal
Also known as Storm-1811, CURLY SPIDER, STAC5777. UNC4393 is a financially motivated threat actor primarily using BASTA ransomware.
UNC4487 criminal
UNC4487 is a threat actor that targeted Ukrainian government officials by compromising a Ukrainian auto insurance website essential for…
UNC4536 criminal
UNC4536 is a threat actor that distributes malware, including ICEDID, REDLINESTEALER, and CARBANAK, primarily through malvertising and…
UNC4540 nation-state
UNC4540 is a suspected Chinese threat actor targeting unpatched SonicWall Secure Mobile Access appliances to deploy custom malware that…
UNC4736 nation-state
UNC4736 is a North Korean threat actor that has been involved in supply chain attacks targeting software chains of 3CX and X_TRADER.
UNC4841 nation-state
Also known as SLIME57. UNC4841 is a well-resourced threat actor that has utilized a wide range of malware and purpose-built tooling to enable their global…
UNC4990 criminal
UNC4990 is a financially motivated threat actor that has been active since at least 2020.
UNC5174 nation-state
Also known as Uteus. UNC5174, a Chinese state-sponsored threat actor, has been identified by Mandiant for exploiting critical vulnerabilities in F5 BIG-IP and…
UNC5266 nation-state
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE…
UNC5291 nation-state
UNC5291 is a cluster of targeted probing activity that we assess with moderate confidence is associated with UNC3236, also known publicly…
UNC5325 nation-state
UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances.
UNC5330 nation-state
UNC5330 is a suspected China-nexus espionage actor.
UNC5337 nation-state
UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan.
UNC5342 nation-state
UNC5342 is a North Korea-linked APT that employs the EtherHiding technique to deliver malware and facilitate cryptocurrency theft.
UNC5537 criminal
UNC5537 is a financially motivated threat actor targeting Snowflake customer databases.