Threat Actors page 11 of 12
1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- UNC5820 unknown
- UNC5820 is a threat actor exploiting the CVE-2024-47575 vulnerability in Fortinet's FortiManager, allowing them to bypass authentication…
- UNC6032 criminal
- UNC6032 is a threat actor that weaponizes interest in AI tools, specifically targeting users with fake "AI video generator" websites to…
- UNC6040 criminal
- UNC6040 is a financially motivated threat cluster that employs vishing to gain access to organizations' Salesforce environments…
- UNC6148 criminal
- UNC6148 is a financially motivated threat actor that targets SonicWall Secure Mobile Access 100 series appliances, leveraging stolen…
- UNC6201 nation-state
- UNC6201 is a sophisticated Chinese state-sponsored hacking group that exploited CVE-2026–22769, a critical vulnerability in Dell…
- UNC6293 nation-state
- UNC6293 is a Russian state-sponsored threat actor identified by Google's Threat Intelligence Group (GTIG), which associates them with…
- UNC6353 nation-state
- UNC6353 is a suspected Russian espionage group known for targeting government and defense sectors with advanced techniques.
- UNC6384 nation-state
- Also known as Vertigo Panda. UNC6384 (also tracked as Vertigo Panda) is a Chinese-affiliated APT that conducts targeted espionage campaigns primarily against…
- UNC6395 criminal
- The actor systematically exported large volumes of data from numerous corporate Salesforce instances.
- UNC6426 criminal
- UNC6426 exploited a supply chain compromise of the nx npm package to steal a developer's GitHub Personal Access Token and gain access to a…
- UNC6485 nation-state
- UNC6485 is a cyber-espionage group exploiting CVE-2025-12480 in Gladinet’s Triofox file-sharing platform to gain initial network access…
- UNC6508 nation-state
- UNC6508 is a PRC-nexus threat actor targeting North American academic, medical, and military research institutions, employing tactics such…
- UNC6619 nation-state
- Also known as TGR-STA-1030, Shadow Campaigns. TGR-STA-1030 is a state-aligned cyberespionage group operating out of Asia, known for compromising government and critical infrastructure…
- UNC6671 criminal
- UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter…
- UNC6691 criminal
- financially motivated threat actor operating from China
- UNC6692 nation-state
- UNC6692 is a threat actor that employs social engineering tactics, such as impersonating IT helpdesk personnel, to gain initial access to…
- UNC6748 nation-state
- UNC6748 targets users in Saudi Arabia through a fake Snapchat website, employing a backdoor known as GHOSTKNIFE for data exfiltration.
- UNC788 nation-state
- UNC788 is a group of hackers from Iran that has targeted people in the Middle East.
- UNG0002 nation-state
- UNG0002 is a technically adept APT conducting large-scale cyber espionage campaigns targeting strategic sectors in China, Hong Kong, and…
- UNG0901 nation-state
- Also known as Operation CargoTalon, Unknown-Group-901. UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing…
- UNION PANDA nation-state
- UNION PANDA is a Chinese nation-state threat actor known for conducting cyber espionage.
- UNION SPIDER nation-state
- Adversary targeting manufacturing and industrial organizations.
- UNK_AcademicFlare nation-state
- UNK_AcademicFlare is a suspected Russia-aligned threat actor that conducts device code phishing campaigns by leveraging compromised email…
- UNK_DropPitch nation-state
- Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations…
- UNK_FistBump nation-state
- Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations…
- UNK_RemoteRogue nation-state
- UNK_RemoteRogue is a suspected Russian threat actor that has been observed utilizing ClickFix in its infection chains, although this…
- UNK_SparkyCarp nation-state
- Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations…
- USDoD hacktivist
- USDoD is a threat actor known for leaking large databases of personal information, including from companies like Airbus and the U.S.
- UTA0178 nation-state
- Also known as UNC5221, Red Dev 61. While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools…
- UTA0218 nation-state
- UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data.
- UTA0352 nation-state
- UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often…
- UTA0355 nation-state
- UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine.
- UTA0388 nation-state
- UTA0388 is a China-aligned APT known for spear-phishing campaigns targeting organizations in North America, Asia, and Europe, primarily to…
- UTA0533
- UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026.
- UTG-Q-008 nation-state
- UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China.
- UTG-Q-010 criminal
- UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical…
- Ukrainian Cyber Alliance hacktivist
- Also known as UCA. Cyber Alliance is a hacktivist group that has demonstrated capabilities in exploiting vulnerabilities, such as CVE-2023-22515 in…
- Unfading Sea Haze nation-state
- Unfading Sea Haze is a threat actor focused on espionage, targeting government and military organizations in the South China Sea region…
- Unit 8200 Espionage
- Also known as Duqu Group. Unit 8200 is an Israeli intelligence unit known for conducting cyber espionage and signals intelligence operations.
- Unnamed Actor Espionage
- This threat actor compromises civil society groups the Chinese Communist Party views as hostile to its interests, such as Tibetan, Uyghur…
- UnsolicitedBooker nation-state
- UnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi…
- Urpage nation-state
- What sets Urpage attacks apart is its targeting of InPage, a word processor for Urdu and Arabic languages.
- UserSec hacktivist
- UserSec is a pro-Russian hacking group that has been active since at least 2022.
- VENOM SPIDER criminal
- Also known as badbullzvenom, badbullz. VENOM SPIDER is the developer of a large toolset that includes SKID, VenomKit and Taurus Loader.
- VICE SPIDER criminal
- Vice Spider is a Russian-speaking ransomware group that has been active since at least April 2021 and is linked to a significant increase…
- VICEROY TIGER nation-state
- Also known as OPERATION HANGOVER, Donot Team, APT-C-35. VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors.
- VIKING SPIDER criminal
- VIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware.
- VOID MANTICORE EspionageInformation OperationsSabotage
- Also known as COBALT MYSTIQUE, Handala Hack, Homeland Justice. VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).
- Vanilla Tempest criminal
- Also known as DEV-0832, VICE SPIDER, Vice Society. Vice Society is a ransomware group that has been active since at least June 2021.
- Velvet Ant nation-state
- Velvet Ant is a threat actor operating since at least 2021.
- Velvet Tempest criminal
- Also known as DEV-0504, ALPHA SPIDER. Velvet Tempest is a threat actor associated with the BlackCat ransomware group.
- ViceLeaker unknown
- In May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens.
- Vicious Panda nation-state
- Also known as SixLittleMonkeys. Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus…
- ViciousTrap criminal
- ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to…
- Viking Jackal nation-state
- Also known as Vikingdom. Viking Jackal, also known as Vikingdom, is a nation-state threat actor believed to operate in the Middle East.
- Void Arachne criminal
- Also known as Silver Fox. Void Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers…
- Void Balaur criminal
- Void Balaur is a highly active hack-for-hire / cyber mercenary group with a wide range of known target types across the globe.
- Void Banshee criminal
- Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain.
- Void Blizzard nation-state
- Also known as LAUNDRY BEAR, UAC-0190, Laundry Bear. Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government…
- Void Rabisu criminalnation-state
- Also known as Tropical Scorpius. Void Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and…
- Volatile Cedar nation-state
- Also known as Lebanese Cedar, DeftTorero. Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide.
- Volga Flood nation-state
- Also known as Storm-1841, Rybar. Microsoft threat actor profile. Origin/Threat: Russia, Influence operations.
- Volt Typhoon nation-state
- Also known as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391. Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting…
- VulzSecTeam hacktivist
- Also known as VulzSec. VulzSec, also known as VulzSecTeam, is a hacktivist group that has been involved in various cyber-attacks.
- WARP PANDA nation-state
- WARP PANDA is a China-nexus APT that targets VMware vCenter environments and Microsoft Azure infrastructures, primarily focusing on legal…
- WET PANDA nation-state
- Also known as Red Chimera. WET PANDA, also known as Red Chimera, is a Chinese nation-state threat actor group known for conducting cyber espionage campaigns…
- WIP19 nation-state
- WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia.
- WIRTE nation-state
- Also known as Ashen Lepus. WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least…
- WageMole nation-state
- Also known as Famous Chollima, UNC5267, Nickel Tapestry. WageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in…
- Wassonite nation-state
- WASSONITE is a North Korea-linked APT that has targeted industrial sectors, including electric generation, nuclear energy, manufacturing…
- Watchdog criminal
- Also known as Thief Libra. Thief Libra is a cloud-focused threat group that has a history of cryptojacking operations as well as cloud service platform credential…
- Water Bakunawa criminal
- Water Bakunawa is a cybercriminal group identified by Trend Micro, responsible for the RansomHub ransomware, which exploits the Zerologon…
- Water Barghest criminal
- Water Barghest is a cybercriminal group that has compromised over 20,000 IoT devices by October 2024, monetizing them through a…
- Water Curupira criminal
- With its emergence in 2022, Water Curupira has established itself as a persistent threat actor targeting organizations primarily in South…
- Water Galura criminal
- Also known as GOLD FEATHER. Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the…
- Water Gamayun nation-state
- Water Gamayun exploits the MSC EvilTwin zero-day vulnerability to compromise systems and exfiltrate data, utilizing custom payloads and…
- Water Kurita criminal
- Water Kurita is a financially motivated cybercriminal entity associated with the Lumma Stealer infostealer-as-a-service operation…
- Water Labbu criminal
- Trend Micro discovered a threat actor they named Water Labbu that was targeting cryptocurrency scam websites.
- Water Makara criminal
- Water Makara employs the Astaroth banking malware, which features a new defense evasion technique.
- Water Orthrus criminal
- Water Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware.
- Water Saci criminal
- Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP…
- Water Sigbin criminal
- Also known as 8220 Gang. The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware.
- WeRedEvils hacktivist
- WeRedEvils is a hacking group that has claimed responsibility for multiple cyber attacks.
- Webworm criminal
- Also known as Space Pirates. Space Pirates is a cybercrime group that has been active since at least 2017.
- WeedSec hacktivist
- WeedSec is a threat actor group that recently targeted the online learning and course management platform Moodle.
- Wheat Tempest criminal
- Also known as GOLD, Gatak. Microsoft threat actor profile. Origin/Threat: Financially motivated.
- White Bear Espionage
- Also known as Skipper Turla. As a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting…
- WhiteCobra criminal
- WhiteCobra is a threat actor that has infiltrated the Visual Studio Code marketplace and Open VSX registry, deploying 24 malicious…
- Whitefly nation-state
- Whitefly is a cyber espionage group that has been operating since at least 2017.
- WildCard unknown
- Wildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware.
- WildNeutron criminal
- Also known as Butterfly, Morpho, Sphinx Moth. A corporate espionage group has compromised a string of major corporations over the past three years in order to steal confidential…
- WildPressure nation-state
- WildPressure is a threat actor that targets industrial-related entities in the Middle East.
- Windigo criminal
- The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to…
- Windshift nation-state
- Also known as Bahamut, Windy Phoenix. Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government…
- Winnti Group nation-state
- Also known as Blackfly. Winnti Group is a threat group with Chinese origins that has been active since at least 2010.
- Winter Vivern nation-state
- Also known as TA473, UAC-0114, TAG-70. Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and…
- Wisteria Tsunami nation-state
- Also known as DEV-0605, CyberRoot, MintedSoil. Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
- Witchetty nation-state
- Also known as LookingFrog. Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage…
- Wizard Spider criminal
- Also known as UNC1878, TEMP.MixMaster, Grim Spider. Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at…
- Worok Espionage
- Worok is a cyber espionage group, mostly targeting Central Asia.