Threat Actors page 2 of 12

1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

BiBiGun hacktivist
A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems.
Bignosa criminal
Bignosa is a threat actor known for launching malware campaigns targeting Australian and US organizations using phishing emails with…
BlackByte criminal
Also known as Hecamede. BlackByte is a ransomware threat actor operating since at least 2021.
BlackJack nation-state
Blackjack, a threat actor linked to Ukraine's security apparatus, has targeted critical Russian entities such as ISPs, utilities, and…
BlackMaskers hacktivist
Also known as BlackMaskers Team. BlackMaskers Team has emerged as a significant threat actor, particularly targeting Jordan amid the Israel-Iran conflict.
BlackOasis nation-state
BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group.
BlackTech nation-state
Also known as Palmerworm, CIRCUIT PANDA, Temp.Overboard. BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan…
Blackatom Espionage
Recent campaigns suggest Hamas-linked actors may be advancing their TTPs to include intricate social engineering lures specially crafted…
Blackgear nation-state
Also known as Topgear, Comnie. BLACKGEAR is an espionage campaign which has targeted users in Taiwan for many years.
Blackmeta hacktivist
Also known as SN Blackmeta. BLACKMETA is a pro-Palestinian hacktivist group that has claimed responsibility for a series of DDoS attacks and data breaches targeting…
Blacktail criminal
Blacktail is a cybercrime group that has gained attention for its ransomware campaigns, particularly the Buhti ransomware.
Blackwood nation-state
Blackwood is a China-aligned APT group that has been active since at least 2018.
BladeHawk Espionage
BladeHawk is a cyber espionage group with a focus on South Asian countries, particularly targeting government and telecommunications…
BladedFeline nation-state
BladedFeline is an Iran-aligned APT group that has been active since at least 2017, targeting Iraqi and Kurdish government officials for…
Blue Mockingbird criminal
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on…
Blue Termite Espionage
Also known as Cloudy Omega, Emdivi. Blue Termite is a group of suspected Chinese origin active in Japan.
Blue Tsunami criminal
Also known as Black Cube. Blue Tsunami, also known as Black Cube, is a cyber mercenary group associated with the private intelligence firm Black Cube.
BlueBottle criminal
Bluebottle, a cyber-crime group that specializes in targeted attacks against the financial sector, is continuing to mount attacks on banks…
BlueHornet nation-state
Also known as APT49, AgainstTheWest. BlueHornet is an advanced persistent threat group targeting government organizations in China, North Korea, Iran, and Russia.
Bondnet criminal
Bondnet is a threat actor that deploys backdoors and cryptocurrency miners.
Booba Project
The Booba Project is a ransomware group that has claimed responsibility for attacks on multiple organizations, including Betz Industries…
Boolka criminal
Boolka is a threat actor known for infecting websites with malicious JavaScript scripts for data exfiltration.
Boulder Bear nation-state
First observed activity in December 2013.
Bouncing Golf nation-state
Bouncing Golf is a cyberespionage campaign targeting Middle Eastern countries.
BrazenBamboo nation-state
BrazenBamboo is a Chinese state-affiliated threat actor known for developing the LIGHTSPY, DEEPDATA, and DEEPPOST malware families.
BreachLaboratory criminal
BreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from…
Budminer nation-state
Also known as Budminer cyberespionage group. Based on the evidence we have presented Symantec attributed the activity involving theDripion malware to the Budminer advanced threat group.
BuhTrap criminal
Buhtrap has been active since 2014, however their first attacks against financial institutions were only detected in August 2015.
ByteToBreach criminal
ByteToBreach is a prolific cybercriminal who operates across multiple platforms, including DarkForums and Telegram, and has been active…
CHRYSENE Espionage
Also known as OilRig, Greenbug. Adversaries abusing ICS (based on Dragos Inc adversary list).
CIRCUS SPIDER criminal
According to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIRCUS…
CL-STA-0043 nation-state
Also known as TGR-STA-0043. CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the…
CL-STA-0048 nation-state
Also known as CL STA 0048. CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunications…
CL-STA-1009 nation-state
CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which…
CL-STA-1020 nation-state
CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy…
CL-STA-1087 nation-state
CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia.
CL-UNK-1068 nation-state
CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage.
CLOCKWORK SPIDER nation-statecriminal
Opportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
COBALT JUNO nation-state
Also known as APT-C-38 (QiAnXin), SABER LION, TG-2884 (SCWX CTU). COBALT JUNO has operated since at least 2013 and focused on targets located in the Middle East including Iran, Jordan, Egypt & Lebanon.
COBALT KATANA nation-state
Also known as Hive0081 (IBM), SectorD01 (NHSC), xHunt campaign (Palo Alto). COBALT KATANA has been active since at least March 2018, and it focuses many of its operations on organizations based in or associated…
CRYSTALRAY criminal
CRYSTALRAY is a threat actor known for leveraging open source tools like zmap and SSH-Snake to conduct widespread vulnerability scanning…
CURIUM Espionage
Also known as Crimson Sandstorm, TA456, Tortoise Shell. CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in…
Cadelle nation-state
Symantec telemetry identified Cadelle and Chafer activity dating from as far back as July 2014, however, it’s likely that activity began…
Caliente Bandits criminal
Also known as TA2721. Caliente Bandits is a highly active threat group that targets multiple industries, including finance and entertainment.
Calypso nation-state
Also known as BRONZE MEDLEY, Red Lamassu. For the first time, the activity of the Calypso group was detected by specialists of PT Expert Security Center in March 2019, during the…
Camaro Dragon nation-state
In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution…
Caracal Kitten nation-state
Also known as APT-Q-58. Caracal Kitten is an APT group that has been targeting activists associated with the Kurdistan Democratic Party.
Caramel Tsunami nation-state
Also known as SOURGUM, Candiru, DEV-0236. Caramel Tsunami is a threat actor that specializes in spyware attacks.
Carbanak criminal
Also known as Anunak. Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013.
Carderbee criminal
Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee.
CardinalLizard nation-state
CardinalLizard, a cyber threat actor linked to China, has targeted entities in Asia since 2018.
Careto Espionage
Also known as The Mask, Mask, Ugly Face. This threat actor targets governments, diplomatic missions, private companies in the energy sector, and academics for espionage purposes.
Carmine Tsunami nation-state
Also known as DEV-0196, QuaDream. Carmine Tsunami is a threat actor linked to an Israel-based private sector offensive actor called QuaDream.
CashRewindo criminal
CashRewindo is a sophisticated threat actor leveraging aged domains in global malvertising campaigns to direct victims to investment scam…
Cavern Manticore
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS.
CeranaKeeper nation-state
CeranaKeeper is a China-aligned APT that has been active since at least early 2022, primarily targeting governmental institutions in Asian…
ChainedShark nation-state
Also known as Actor240820. ChainedShark is an APT group targeting China's scientific research sector, particularly professionals in international relations and…
Chamelgang nation-state
Also known as CamoFei. In Q2 2021, the PT Expert Security Center incident response team conducted an investigation in an energy company.
Charming Kitten Espionage
Also known as Newscaster, Parastoo, iKittens. Charming Kitten is an Iranian cyber espionage group that has been active since approximately 2014.
Chaya_004 nation-state
Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell…
Chernovite nation-state
Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM.
Chimera nation-state
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as…
Chronus Group hacktivist
Chronus Team is a hacktivist group known for defacement attacks and data leaks, primarily targeting public-sector organizations in Mexico.
CiberInteligenciaSV hacktivist
CiberInteligenciaSV is a threat actor that leaked 5.1 million Salvadoran records on Breach Forums.
Cinnamon Tempest nation-state
Also known as DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT. Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on…
Clay Typhoon nation-state
Also known as Storm-2416. Microsoft threat actor profile. Origin/Threat: China.
Cleaver Espionage
Also known as Threat Group 2889, TG-2889, Operation Cleaver. Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver.
Clever Kitten nation-state
Also known as Group 41. Clever Kitten, also known as Group 41, is an Iranian nation-state threat actor primarily focused on cyber-espionage.
CloudSorcerer nation-state
CloudSorcerer is a sophisticated APT targeting Russian government entities, utilizing cloud infrastructure for stealth monitoring and data…
Cobalt Group criminal
Also known as GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider. Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016.
Codefinger criminal
Codefinger is a ransomware group that targets Amazon S3 buckets by exploiting AWS’s Server-Side Encryption with Customer Provided Keys to…
Coinbase Cartel criminal
Coinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has…
Cold River nation-state
Also known as Nahr Elbard, Nahr el bared. In short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled…
ComicForm criminal
ComicForm is an emerging cyber threat actor tracked since at least April 2025, specializing in targeted phishing campaigns against…
Common Raven criminal
Also known as OPERA1ER, NXSMS, DESKTOP-GROUP. Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to…
Conference Crew
Also known as CONFERENCE CASTLE. Conference Crew is a China-nexus threat cluster renamed CONFERENCE CASTLE under Google Threat Intelligence's updated naming system.
Confucious nation-state
Confucius is an APT organization funded by India.
Confucius nation-state
Also known as Confucius APT. Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and…
Conquerors Electronic Army hacktivist
Conquerors Electronic Army operates under the “Wa’d al-Akhira” banner and has claimed multiple attacks against Israeli targets, including…
Contagious Interview nation-state
Also known as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan. Contagious Interview is a North Korea–aligned threat group active since 2023.
Copy-Paste Espionage
The title ‘Copy-paste compromises’ is derived from the actor’s heavy use of tools copied almost identically from open source given by The…
CopyKittens Espionage
Also known as Slayer Kitten. CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013.
Coral Sleet nation-state
Also known as Storm-1877. Microsoft threat actor profile. Origin/Threat: North Korea.
CoralRaider criminal
CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since…
Corsair Jackal hacktivist
Also known as TunisianCyberArmy. Corsair Jackal, also known as TunisianCyberArmy, is a hacktivist group operating primarily from Tunisia.
Cosmic Lynx Business Email Compromise
Cosmic Lynx is a Russia-based BEC cybercriminal organization that has significantly impacted the email threat landscape with…
CosmicBeetle criminal
CosmicBeetle is a threat actor known for deploying the ScRansom ransomware, which has replaced its previous variant, Scarab.
CostaRicto
CostaRicto is a suspected hacker-for-hire cyber espionage campaign that has targeted multiple industries worldwide since at least 2019.
Cotton Sandstorm Information Operations
Also known as Emennet Pasargad, Holy Souls, MARNANBRIDGE. Cotton Sandstorm is an Iranian threat actor involved in hack-and-leak operations.
CoughingDown nation-state
CoughingDown is a threat group attributed to various cyber campaigns, including the deployment of the EAGERBEE backdoor, which utilizes…
Crescent Typhoon nation-state
Also known as CESIUM. Microsoft threat actor profile. Origin/Threat: China.
Crimson Collective criminal
The Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025.
CryptoChameleon criminal
Also known as UNC5356. CryptoChameleon is a cybercriminal group known for targeting cryptocurrency exchanges and users to steal digital assets, employing tactics…
Cuboid Sandstorm nation-state
Also known as DEV-0228, IMPERIAL KITTEN. Cuboid Sandstorm is an Iranian threat actor that targeted an Israel-based IT company in July 2021.
Curious Gorge Espionage
Also known as UNC3742. Curious Gorge, a group TAG attributes to China's PLA SSF, has conducted campaigns against government and military organizations in…
Curly COMrades nation-state
Curly COMrades is a threat actor identified by Amazon Threat Intelligence and Bitdefender, believed to operate in support of Russian…
Cutting Kitten Denial of service
Also known as ITsecTeam. One of the threat actors responsible for the denial of service attacks against U.S in 2012–2013.
Cyber Alliance hacktivist
The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of…
Cyber Army of Russia Reborn nation-state
The 'Cyber Army of Russia Reborn' is a nation-state actor linked to Russia, known for conducting advanced cyber espionage operations…
Cyber Av3ngers nation-state
Also known as CyberAv3ngers, Shahid Kaveh Group. Cyber Av3ngers is an Iranian IRGC Cyber-Electronic Command-affiliated threat actor that targets internet-exposed operational technology…