Threat Actors page 11 of 12

1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

UNC5820 unknown
UNC5820 is a threat actor exploiting the CVE-2024-47575 vulnerability in Fortinet's FortiManager, allowing them to bypass authentication…
UNC6032 criminal
UNC6032 is a threat actor that weaponizes interest in AI tools, specifically targeting users with fake "AI video generator" websites to…
UNC6040 criminal
UNC6040 is a financially motivated threat cluster that employs vishing to gain access to organizations' Salesforce environments…
UNC6148 criminal
UNC6148 is a financially motivated threat actor that targets SonicWall Secure Mobile Access 100 series appliances, leveraging stolen…
UNC6201 nation-state
UNC6201 is a sophisticated Chinese state-sponsored hacking group that exploited CVE-2026–22769, a critical vulnerability in Dell…
UNC6293 nation-state
UNC6293 is a Russian state-sponsored threat actor identified by Google's Threat Intelligence Group (GTIG), which associates them with…
UNC6353 nation-state
UNC6353 is a suspected Russian espionage group known for targeting government and defense sectors with advanced techniques.
UNC6384 nation-state
Also known as Vertigo Panda. UNC6384 (also tracked as Vertigo Panda) is a Chinese-affiliated APT that conducts targeted espionage campaigns primarily against…
UNC6395 criminal
The actor systematically exported large volumes of data from numerous corporate Salesforce instances.
UNC6426 criminal
UNC6426 exploited a supply chain compromise of the nx npm package to steal a developer's GitHub Personal Access Token and gain access to a…
UNC6485 nation-state
UNC6485 is a cyber-espionage group exploiting CVE-2025-12480 in Gladinet’s Triofox file-sharing platform to gain initial network access…
UNC6508 nation-state
UNC6508 is a PRC-nexus threat actor targeting North American academic, medical, and military research institutions, employing tactics such…
UNC6619 nation-state
Also known as TGR-STA-1030, Shadow Campaigns. TGR-STA-1030 is a state-aligned cyberespionage group operating out of Asia, known for compromising government and critical infrastructure…
UNC6671 criminal
UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter…
UNC6691 criminal
financially motivated threat actor operating from China
UNC6692 nation-state
UNC6692 is a threat actor that employs social engineering tactics, such as impersonating IT helpdesk personnel, to gain initial access to…
UNC6748 nation-state
UNC6748 targets users in Saudi Arabia through a fake Snapchat website, employing a backdoor known as GHOSTKNIFE for data exfiltration.
UNC788 nation-state
UNC788 is a group of hackers from Iran that has targeted people in the Middle East.
UNG0002 nation-state
UNG0002 is a technically adept APT conducting large-scale cyber espionage campaigns targeting strategic sectors in China, Hong Kong, and…
UNG0901 nation-state
Also known as Operation CargoTalon, Unknown-Group-901. UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing…
UNION PANDA nation-state
UNION PANDA is a Chinese nation-state threat actor known for conducting cyber espionage.
UNION SPIDER nation-state
Adversary targeting manufacturing and industrial organizations.
UNK_AcademicFlare nation-state
UNK_AcademicFlare is a suspected Russia-aligned threat actor that conducts device code phishing campaigns by leveraging compromised email…
UNK_DropPitch nation-state
Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations…
UNK_FistBump nation-state
Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations…
UNK_RemoteRogue nation-state
UNK_RemoteRogue is a suspected Russian threat actor that has been observed utilizing ClickFix in its infection chains, although this…
UNK_SparkyCarp nation-state
Between March and June 2025, Proofpoint identified multiple China-aligned threat actors specifically targeting Taiwanese organizations…
USDoD hacktivist
USDoD is a threat actor known for leaking large databases of personal information, including from companies like Airbus and the U.S.
UTA0178 nation-state
Also known as UNC5221, Red Dev 61. While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools…
UTA0218 nation-state
UTA0218 is a threat actor with advanced capabilities, targeting organizations to establish a reverse shell, acquire tools, and extract data.
UTA0352 nation-state
UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often…
UTA0355 nation-state
UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine.
UTA0388 nation-state
UTA0388 is a China-aligned APT known for spear-phishing campaigns targeting organizations in North America, Asia, and Europe, primarily to…
UTA0533
UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026.
UTG-Q-008 nation-state
UTG-Q-008 is a threat actor targeting Linux platforms, primarily focusing on government and enterprise entities in China.
UTG-Q-010 criminal
UTG-Q-010 is a financially motivated APT group from East Asia that has been active since late 2022, primarily targeting the pharmaceutical…
Ukrainian Cyber Alliance hacktivist
Also known as UCA. Cyber Alliance is a hacktivist group that has demonstrated capabilities in exploiting vulnerabilities, such as CVE-2023-22515 in…
Unfading Sea Haze nation-state
Unfading Sea Haze is a threat actor focused on espionage, targeting government and military organizations in the South China Sea region…
Unit 8200 Espionage
Also known as Duqu Group. Unit 8200 is an Israeli intelligence unit known for conducting cyber espionage and signals intelligence operations.
Unnamed Actor Espionage
This threat actor compromises civil society groups the Chinese Communist Party views as hostile to its interests, such as Tibetan, Uyghur…
UnsolicitedBooker nation-state
UnsolicitedBooker is a China-aligned APT group known for its persistent targeting of an unnamed international organization in Saudi…
Urpage nation-state
What sets Urpage attacks apart is its targeting of InPage, a word processor for Urdu and Arabic languages.
UserSec hacktivist
UserSec is a pro-Russian hacking group that has been active since at least 2022.
VENOM SPIDER criminal
Also known as badbullzvenom, badbullz. VENOM SPIDER is the developer of a large toolset that includes SKID, VenomKit and Taurus Loader.
VICE SPIDER criminal
Vice Spider is a Russian-speaking ransomware group that has been active since at least April 2021 and is linked to a significant increase…
VICEROY TIGER nation-state
Also known as OPERATION HANGOVER, Donot Team, APT-C-35. VICEROY TIGER is an adversary with a nexus to India that has historically targeted entities throughout multiple sectors.
VIKING SPIDER criminal
VIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware.
VOID MANTICORE EspionageInformation OperationsSabotage
Also known as COBALT MYSTIQUE, Handala Hack, Homeland Justice. VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).
Vanilla Tempest criminal
Also known as DEV-0832, VICE SPIDER, Vice Society. Vice Society is a ransomware group that has been active since at least June 2021.
Velvet Ant nation-state
Velvet Ant is a threat actor operating since at least 2021.
Velvet Tempest criminal
Also known as DEV-0504, ALPHA SPIDER. Velvet Tempest is a threat actor associated with the BlackCat ransomware group.
ViceLeaker unknown
In May 2018, we discovered a campaign targeting dozens of mobile Android devices belonging to Israeli citizens.
Vicious Panda nation-state
Also known as SixLittleMonkeys. Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus…
ViciousTrap criminal
ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to…
Viking Jackal nation-state
Also known as Vikingdom. Viking Jackal, also known as Vikingdom, is a nation-state threat actor believed to operate in the Middle East.
Void Arachne criminal
Also known as Silver Fox. Void Arachne is a threat actor group targeting Chinese-speaking users with malicious MSI files containing legitimate software installers…
Void Balaur criminal
Void Balaur is a highly active hack-for-hire / cyber mercenary group with a wide range of known target types across the globe.
Void Banshee criminal
Void Banshee is an APT group targeting North America, Europe, and Southeast Asia for information theft and financial gain.
Void Blizzard nation-state
Also known as LAUNDRY BEAR, UAC-0190, Laundry Bear. Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government…
Void Rabisu criminalnation-state
Also known as Tropical Scorpius. Void Rabisu is an intrusion set associated with both financially motivated ransomware attacks and targeted campaigns on Ukraine and…
Volatile Cedar nation-state
Also known as Lebanese Cedar, DeftTorero. Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide.
Volga Flood nation-state
Also known as Storm-1841, Rybar. Microsoft threat actor profile. Origin/Threat: Russia, Influence operations.
Volt Typhoon nation-state
Also known as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391. Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting…
VulzSecTeam hacktivist
Also known as VulzSec. VulzSec, also known as VulzSecTeam, is a hacktivist group that has been involved in various cyber-attacks.
WARP PANDA nation-state
WARP PANDA is a China-nexus APT that targets VMware vCenter environments and Microsoft Azure infrastructures, primarily focusing on legal…
WET PANDA nation-state
Also known as Red Chimera. WET PANDA, also known as Red Chimera, is a Chinese nation-state threat actor group known for conducting cyber espionage campaigns…
WIP19 nation-state
WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia.
WIRTE nation-state
Also known as Ashen Lepus. WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least…
WageMole nation-state
Also known as Famous Chollima, UNC5267, Nickel Tapestry. WageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in…
Wassonite nation-state
WASSONITE is a North Korea-linked APT that has targeted industrial sectors, including electric generation, nuclear energy, manufacturing…
Watchdog criminal
Also known as Thief Libra. Thief Libra is a cloud-focused threat group that has a history of cryptojacking operations as well as cloud service platform credential…
Water Bakunawa criminal
Water Bakunawa is a cybercriminal group identified by Trend Micro, responsible for the RansomHub ransomware, which exploits the Zerologon…
Water Barghest criminal
Water Barghest is a cybercriminal group that has compromised over 20,000 IoT devices by October 2024, monetizing them through a…
Water Curupira criminal
With its emergence in 2022, Water Curupira has established itself as a persistent threat actor targeting organizations primarily in South…
Water Galura criminal
Also known as GOLD FEATHER. Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the…
Water Gamayun nation-state
Water Gamayun exploits the MSC EvilTwin zero-day vulnerability to compromise systems and exfiltrate data, utilizing custom payloads and…
Water Kurita criminal
Water Kurita is a financially motivated cybercriminal entity associated with the Lumma Stealer infostealer-as-a-service operation…
Water Labbu criminal
Trend Micro discovered a threat actor they named Water Labbu that was targeting cryptocurrency scam websites.
Water Makara criminal
Water Makara employs the Astaroth banking malware, which features a new defense evasion technique.
Water Orthrus criminal
Water Orthrus is a threat actor known for distributing CopperStealer and CopperPhish malware.
Water Saci criminal
Water Saci is a sophisticated cyber threat actor operating in Brazil, utilizing a multi-format attack chain that includes HTA files, ZIP…
Water Sigbin criminal
Also known as 8220 Gang. The 8220 Gang, also known as Water Sigbin, is a threat actor group that focuses on deploying cryptocurrency-mining malware.
WeRedEvils hacktivist
WeRedEvils is a hacking group that has claimed responsibility for multiple cyber attacks.
Webworm criminal
Also known as Space Pirates. Space Pirates is a cybercrime group that has been active since at least 2017.
WeedSec hacktivist
WeedSec is a threat actor group that recently targeted the online learning and course management platform Moodle.
Wheat Tempest criminal
Also known as GOLD, Gatak. Microsoft threat actor profile. Origin/Threat: Financially motivated.
White Bear Espionage
Also known as Skipper Turla. As a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting…
WhiteCobra criminal
WhiteCobra is a threat actor that has infiltrated the Visual Studio Code marketplace and Open VSX registry, deploying 24 malicious…
Whitefly nation-state
Whitefly is a cyber espionage group that has been operating since at least 2017.
WildCard unknown
Wildcard is a threat actor that initially targeted Israel's educational sector with the SysJoker malware.
WildNeutron criminal
Also known as Butterfly, Morpho, Sphinx Moth. A corporate espionage group has compromised a string of major corporations over the past three years in order to steal confidential…
WildPressure nation-state
WildPressure is a threat actor that targets industrial-related entities in the Middle East.
Windigo criminal
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to…
Windshift nation-state
Also known as Bahamut, Windy Phoenix. Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government…
Winnti Group nation-state
Also known as Blackfly. Winnti Group is a threat group with Chinese origins that has been active since at least 2010.
Winter Vivern nation-state
Also known as TA473, UAC-0114, TAG-70. Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and…
Wisteria Tsunami nation-state
Also known as DEV-0605, CyberRoot, MintedSoil. Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
Witchetty nation-state
Also known as LookingFrog. Witchetty was first documented by ESET in April 2022, who concluded that it was one of three sub-groups of TA410, a broad cyber-espionage…
Wizard Spider criminal
Also known as UNC1878, TEMP.MixMaster, Grim Spider. Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at…
Worok Espionage
Worok is a cyber espionage group, mostly targeting Central Asia.