Threat Actors page 2 of 12
1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- BiBiGun hacktivist
- A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems.
- Bignosa criminal
- Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with…
- BlackByte criminal
- Also known as Hecamede. BlackByte is a ransomware threat actor operating since at least 2021.
- BlackJack nation-state
- Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and…
- BlackMaskers hacktivist
- Also known as BlackMaskers Team. BlackMaskers Team has emerged as a significant threat actor, particularly targeting Jordan amid the Israel-Iran conflict.
- BlackOasis nation-state
- BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group.
- BlackTech nation-state
- Also known as Palmerworm, CIRCUIT PANDA, Temp.Overboard. BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan…
- Blackatom Espionage
- Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted…
- Blackgear nation-state
- Also known as Topgear, Comnie. BLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years.
- Blackmeta hacktivist
- Also known as SN Blackmeta. BLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches targeting…
- Blacktail criminal
- Blacktail is a cybercrime group that has gained attention for its ransomware campaigns, particularly the Buhti ransomware.
- Blackwood nation-state
- Blackwood is a China-aligned APT group that has been active since at least 2018.
- BladeHawk Espionage
- BladeHawk is a cyber espionage group with a focus on South Asian countries, particularly targeting government and telecommunications…
- BladedFeline nation-state
- BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for…
- Blue Mockingbird criminal
- Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on…
- Blue Termite Espionage
- Also known as Cloudy Omega, Emdivi. Blue Termite is a group of suspected Chinese origin active in Japan.
- Blue Tsunami criminal
- Also known as Black Cube. Blue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube.
- BlueBottle criminal
- Bluebottle, a cyber-crime group that specializes in targeted attacks against the financial sector, is continuing to mount attacks on banks…
- BlueHornet nation-state
- Also known as APT49, AgainstTheWest. BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia.
- Bondnet criminal
- Bondnet is a threat actor that deploys backdoors and cryptocurrency miners.
- Booba Project
- The Booba Project is a ransomware group that has claimed responsibility for attacks on multiple organizations, including Betz Industries…
- Boolka criminal
- Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration.
- Boulder Bear nation-state
- First observed activity in December 2013.
- Bouncing Golf nation-state
- Bouncing Golf is a cyberespionage campaign targeting Middle Eastern countries.
- BrazenBamboo nation-state
- BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families.
- BreachLaboratory criminal
- BreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from…
- Budminer nation-state
- Also known as Budminer cyberespionage group. Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group.
- BuhTrap criminal
- Buhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015.
- ByteToBreach criminal
- ByteToBreach is a prolific cybercriminal who operates across multiple platforms, including DarkForums and Telegram, and has been active…
- CHRYSENE Espionage
- Also known as OilRig, Greenbug. Adversaries abusing ICS (based on Dragos Inc adversary list).
- CIRCUS SPIDER criminal
- According to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIRCUS…
- CL-STA-0043 nation-state
- Also known as TGR-STA-0043. CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the…
- CL-STA-0048 nation-state
- Also known as CL STA 0048. CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunications…
- CL-STA-1009 nation-state
- CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which…
- CL-STA-1020 nation-state
- CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy…
- CL-STA-1087 nation-state
- CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia.
- CL-UNK-1068 nation-state
- CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage.
- CLOCKWORK SPIDER nation-statecriminal
- Opportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
- COBALT JUNO nation-state
- Also known as APT-C-38 (QiAnXin), SABER LION, TG-2884 (SCWX CTU). COBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon.
- COBALT KATANA nation-state
- Also known as Hive0081 (IBM), SectorD01 (NHSC), xHunt campaign (Palo Alto). COBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated…
- CRYSTALRAY criminal
- CRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning…
- CURIUM Espionage
- Also known as Crimson Sandstorm, TA456, Tortoise Shell. CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in…
- Cadelle nation-state
- Symantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity began…
- Caliente Bandits criminal
- Also known as TA2721. Caliente Bandits is a highly active threat group that targets multiple industries, including finance and entertainment.
- Calypso nation-state
- Also known as BRONZE MEDLEY, Red Lamassu. For the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, during the…
- Camaro Dragon nation-state
- In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution…
- Caracal Kitten nation-state
- Also known as APT-Q-58. Caracal Kitten is an APT group that has been targeting activists associated with the Kurdistan Democratic Party.
- Caramel Tsunami nation-state
- Also known as SOURGUM, Candiru, DEV-0236. Caramel Tsunami is a threat actor that specializes in spyware attacks.
- Carbanak criminal
- Also known as Anunak. Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013.
- Carderbee criminal
- Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee.
- CardinalLizard nation-state
- CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018.
- Careto Espionage
- Also known as The Mask, Mask, Ugly Face. This threat actor targets governments, diplomatic missions, private companies in the energy sector, and academics for espionage purposes.
- Carmine Tsunami nation-state
- Also known as DEV-0196, QuaDream. Carmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream.
- CashRewindo criminal
- CashRewindo is a sophisticated threat actor leveraging aged domains in global malvertising campaigns to direct victims to investment scam…
- Cavern Manticore
- Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS.
- CeranaKeeper nation-state
- CeranaKeeper is a China-aligned APT that has been active since at least early 2022, primarily targeting governmental institutions in Asian…
- ChainedShark nation-state
- Also known as Actor240820. ChainedShark is an APT group targeting China's scientific research sector, particularly professionals in international relations and…
- Chamelgang nation-state
- Also known as CamoFei. In Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company.
- Charming Kitten Espionage
- Also known as Newscaster, Parastoo, iKittens. Charming Kitten is an Iranian cyber espionage group that has been active since approximately 2014.
- Chaya_004 nation-state
- Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell…
- Chernovite nation-state
- Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM.
- Chimera nation-state
- Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as…
- Chronus Group hacktivist
- Chronus Team is a hacktivist group known for defacement attacks and data leaks, primarily targeting public-sector organizations in Mexico.
- CiberInteligenciaSV hacktivist
- CiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums.
- Cinnamon Tempest nation-state
- Also known as DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT. Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on…
- Clay Typhoon nation-state
- Also known as Storm-2416. Microsoft threat actor profile. Origin/Threat: China.
- Cleaver Espionage
- Also known as Threat Group 2889, TG-2889, Operation Cleaver. Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver.
- Clever Kitten nation-state
- Also known as Group 41. Clever Kitten, also known as Group 41, is an Iranian nation-state threat actor primarily focused on cyber-espionage.
- CloudSorcerer nation-state
- CloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data…
- Cobalt Group criminal
- Also known as GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider. Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016.
- Codefinger criminal
- Codefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to…
- Coinbase Cartel criminal
- Coinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has…
- Cold River nation-state
- Also known as Nahr Elbard, Nahr el bared. In short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled…
- ComicForm criminal
- ComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against…
- Common Raven criminal
- Also known as OPERA1ER, NXSMS, DESKTOP-GROUP. Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to…
- Conference Crew
- Also known as CONFERENCE CASTLE. Conference Crew is a China-nexus threat cluster renamed CONFERENCE CASTLE under Google Threat Intelligence's updated naming system.
- Confucious nation-state
- Confucius is an APT organization funded by India.
- Confucius nation-state
- Also known as Confucius APT. Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and…
- Conquerors Electronic Army hacktivist
- Conquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including…
- Contagious Interview nation-state
- Also known as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan. Contagious Interview is a North Korea–aligned threat group active since 2023.
- Copy-Paste Espionage
- The title ‘Copy-paste compromises’ is derived from the actor’s heavy use of tools copied almost identically from open source given by The…
- CopyKittens Espionage
- Also known as Slayer Kitten. CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013.
- Coral Sleet nation-state
- Also known as Storm-1877. Microsoft threat actor profile. Origin/Threat: North Korea.
- CoralRaider criminal
- CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since…
- Corsair Jackal hacktivist
- Also known as TunisianCyberArmy. Corsair Jackal, also known as TunisianCyberArmy, is a hacktivist group operating primarily from Tunisia.
- Cosmic Lynx Business Email Compromise
- Cosmic Lynx is a Russia-based BEC cybercriminal organization that has significantly impacted the email threat landscape with…
- CosmicBeetle criminal
- CosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab.
- CostaRicto
- CostaRicto is a suspected hacker-for-hire cyber espionage campaign that has targeted multiple industries worldwide since at least 2019.
- Cotton Sandstorm Information Operations
- Also known as Emennet Pasargad, Holy Souls, MARNANBRIDGE. Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations.
- CoughingDown nation-state
- CoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes…
- Crescent Typhoon nation-state
- Also known as CESIUM. Microsoft threat actor profile. Origin/Threat: China.
- Crimson Collective criminal
- The Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025.
- CryptoChameleon criminal
- Also known as UNC5356. CryptoChameleon is a cybercriminal group known for targeting cryptocurrency exchanges and users to steal digital assets, employing tactics…
- Cuboid Sandstorm nation-state
- Also known as DEV-0228, IMPERIAL KITTEN. Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021.
- Curious Gorge Espionage
- Also known as UNC3742. Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in…
- Curly COMrades nation-state
- Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian…
- Cutting Kitten Denial of service
- Also known as ITsecTeam. One of the threat actors responsible for the denial of service attacks against U.S in 2012–2013.
- Cyber Alliance hacktivist
- The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of…
- Cyber Army of Russia Reborn nation-state
- The 'Cyber Army of Russia Reborn' is a nation-state actor linked to Russia, known for conducting advanced cyber espionage operations…
- Cyber Av3ngers nation-state
- Also known as CyberAv3ngers, Shahid Kaveh Group. Cyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational technology…