Threat Actors page 12 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- XinXin criminal
- Also known as changqixinyun, Black Technology. XinXin is a Chinese-speaking threat actor known for its phishing-as-a-service platform, Lucid, which targets global organizations to steal…
- Yanbian Gang criminal
- RiskIQ characterizes the Yanbian Gang as a group that targeted South Korean Android mobile banking customers since 2013 with malicious…
- YoroTrooper nation-state
- Also known as Salted Earth, Sturgeon Fisher, ShadowSilk. YoroTrooper’s main targets are government or energy organizations in Azerbaijan, Tajikistan, Kyrgyzstan and other Commonwealth of…
- Yulong Flood nation-state
- Also known as Storm-1852. Microsoft threat actor profile. Origin/Threat: China, Influence operations.
- Z-Pentest Alliance hacktivistnation-state
- Also known as Z-Pentest. Z-Pentest Alliance is a pro-Russian hacktivist group known for targeting industrial control systems and operational technology systems…
- ZIRCONIUM nation-state
- Also known as APT31, Violet Typhoon, JUDGMENT PANDA. ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US…
- ZOMBIE SPIDER criminal
- On April 7, 2017, Pytor Levashov — who predominantly used the alias Severa or Peter Severa and whom Falcon Intelligence tracks as ZOMBIE…
- Zarya hacktivist
- Also known as UAC-0109. Zarya is a pro-Russian hacktivist group that emerged in March 2022.
- ZeffSec hacktivist
- Also known as Zeff Security. ZeffSec is a hacktivist collective focused on infrastructure-level disruption and exposing vulnerabilities in centralized digital networks.
- ZeroBytes
- ZeroBytes is a hacker who claimed responsibility for an attack on France's DGFiP's Professional Cadastral Data Server (SPDC), alleging the…
- ZeroSevenGroup criminal
- ZeroSevenGroup is a threat actor that claims to have breached a U.S.
- ZooPark nation-state
- ZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015.
- [Unnamed group] hacktivistunknown
- Over the last few weeks, several significant leaks regarding a number of Iranian APTs took place.
- [Vault 7/8] insidernation-state
- An unnamed source leaked almost 10,000 documents describing a large number of 0-day vulnerabilities, methodologies and tools that had been…
- admin@338 Espionage
- Also known as Admin338, Team338, MAGNESIUM. admin@338 is a China-based cyber threat group.
- luoxk criminal
- Luoxk is a malware campaign targeting web servers throughout Asia, Europe and North America.
- menuPass Espionage
- Also known as Cicada, POTASSIUM, Stone Panda. menuPass is a threat group that has been active since at least 2006.
- puNK-003 nation-state
- puNK-003 is a North Korean APT group known for deploying the Lilith RAT, a sophisticated C++ remote access trojan, and its AutoIt variant…