Threat Actors page 3 of 12

1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Cyber Berkut hacktivist
Cyber Berkut is a pro-Russian hacktivist group known for conducting cyber attacks primarily against Ukrainian government and media…
Cyber Caliphate Army hacktivist
Also known as Islamic State Hacking Division, CCA, United Cyber Caliphate. The Cyber Caliphate Army, also known as the Islamic State Hacking Division and United Cyber Caliphate, is a hacktivist group with…
Cyber Islamic Resistance hacktivist
Cyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website defacements…
Cyber Partisans hacktivist
The Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and…
Cyber Serp nation-state
Also known as UAC-0255. UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting…
Cyber Toufan nation-state
Cyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations.
Cyber fighters of Izz Ad-Din Al Qassam hacktivist
Also known as Fraternal Jackal. The Cyber fighters of Izz Ad-Din Al Qassam was a hacktivist group notable for orchestrating Operation Ababil, targeting financial…
Cyber.Anarchy.Squad hacktivist
Also known as Cyber Anarchy Squad. Cyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure.
CyberAv3ngers nation-state
Also known as Soldiers of Soloman. The CyberAv3ngers are a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group.
CyberNiggers criminal
CyberNiggers is a threat group known for breaching various organizations, including the US military, federal contractors, and…
DAGGER PANDA Espionage
Also known as IceFog, Trident, RedFoxtrot. Operate since at least 2011, from several locations in China, with members in Korea and Japan as well.
DEV-0147 nation-state
DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the…
DEV-0270 nation-state
Also known as Nemesis Kitten, Storm-0270. Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known…
DEV-0569 criminal
Also known as Storm-0569. DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware.
DEV-0928 criminal
DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022.
DEV-0950 criminal
Also known as Lace Tempest, FIN11, TA505. Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain…
DEV-1028 criminal
Microsoft reported on MCCrash, an IoT botnet operated by the DEV-1028 threat actor and used to launch DDoS attacks against private…
DEXTOROUS SPIDER criminal
DEXTOROUS SPIDER is a financially motivated cybercriminal group known for targeting the financial sector and technology firms using…
DIZZY PANDA nation-state
Also known as LadyBoyle. DIZZY PANDA, also known as LadyBoyle, is a sophisticated cyber espionage group believed to be linked to a nation-state.
DNSpionage nation-state
Also known as COBALT EDGEWATER. Cisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a…
DOPPEL SPIDER criminal
Also known as GOLD HERON. In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as…
DUNGEON SPIDER criminal
DUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and…
Daffodil Gust nation-state
Also known as Stealth Falcon, Fruity Armor, Project Raven. Microsoft threat actor profile. Origin/Threat: United Arab Emirates.
Daggerfly Espionage
Also known as Evasive Panda, BRONZE HIGHLAND, Daggerfly. Daggerfly is a People's Republic of China-linked APT entity active since at least 2012.
Daixin Team criminal
Daixin is a threat actor group that has been active since at least June 2022.
Dalbit criminal
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands…
Dancing Salome nation-state
Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine.
DangerousSavanna criminal
Malicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the…
Danti nation-state
Danti is a sophisticated threat actor group known for targeting government and telecommunications sectors in India, Russia, and China.
Dark Basin criminal
Dark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents.
Dark Caracal nation-state
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated…
DarkCasino criminal
DarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos…
DarkGaboon criminal
Also known as Vengeful Wolf, room155. DarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily…
DarkHydrus nation-state
Also known as LazyMeerkat, Obscure Serpens. DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016.
DarkPink nation-state
Also known as Saaiwc. DarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in…
DarkRaaS criminal
DarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple…
DarkSpectre nation-state
DarkSpectre is a sophisticated nation-state cyber threat actor suspected of engaging in cyber espionage activities.
DarkVishnya criminal
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe.
Darkhotel Espionage
Also known as DUBNIUM, Zigzag Hail, Fallout Team. Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004.
Deadeye Jackal hacktivistnation-state
Also known as SyrianElectronicArmy, SEA. The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian…
Deep Panda nation-state
Also known as Shell Crew, WebMasters, KungFu Kittens. Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and…
DefrayX criminal
Also known as Hive0091. DefrayX is a threat actor group known for their RansomExx ransomware operations.
Denim Tsunami nation-state
Also known as KNOTWEED, DSIRF, DEV-0291. Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers.
Desorden Group criminal
Desorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group.
DiceyF nation-state
DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended…
DieNet hacktivist
Also known as Shiite_Harvest. DieNet is a hacktivist group that emerged in March 2025, known for conducting DDoS attacks targeting entities associated with political…
Domestic Kitten nation-state
Also known as Bouncing Golf, APT-C-50. An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information…
DragonBreath criminal
Also known as Golden Eye Dog, APT-Q-27,. Golden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering…
DragonForce hacktivist
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and…
DragonOK Espionage
Also known as Moafee, BRONZE OVERBROOK, Shallow Taurus. DragonOK is a threat group that has targeted Japanese organizations with phishing emails.
DragonRank criminal
DragonRank is a threat actor primarily targeting web application services in Asia and Europe, utilizing TTPs associated with Simplified…
DragonSpark nation-state
DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia.
Dragonbridge nation-state
Also known as Spamouflage Dragon. DRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political interests of…
Dragonfly Espionage
Also known as TEMP.Isotope, DYMALLOY, Berserk Bear. Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.
Dragonfly 2.0
Also known as IRON LIBERTY, DYMALLOY, Berserk Bear. Dragonfly 2.0 is a suspected Russian group that has targeted government entities and multiple U.S.
DriftingCloud nation-state
DriftingCloud is a persistent threat actor known for targeting various industries and locations.
DriveSurge criminal
DriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and…
Dust Storm
Dust Storm is a threat group that has targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast…
EC2 Grouper criminalunknown
EC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments.
ELECTRIC PANDA nation-state
ELECTRIC PANDA is a suspected Chinese nation-state group known for conducting cyber espionage operations targeting defense, government…
ELOQUENT PANDA nation-state
ELOQUENT PANDA is a Chinese nation-state threat actor known for cyber espionage activities primarily targeting government, technological…
ELUSIVE COMET criminal
ELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks…
EXOTIC LILY criminal
Also known as DEV-0413. EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including…
Earth Alux nation-state
Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government…
Earth Baxia nation-state
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region…
Earth Berberoka nation-state
Also known as GamblingPuppet. According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites.
Earth Estries nation-state
Trend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal.
Earth Freybug nation-state
Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially…
Earth Kapre nation-state
Also known as RedCurl, Red Wolf, GOLD BLADE. Earth Kapre is an APT group specializing in cyberespionage.
Earth Kitsune nation-state
Earth Kitsune is an advanced persistent threat actor that has been active since at least 2019.
Earth Krahang nation-state
Earth Krahang is an APT group targeting government organizations worldwide.
Earth Kurma nation-state
Earth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data…
Earth Lamia nation-state
Also known as UNC5454. Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government…
Earth Longzhi nation-state
Also known as SnakeCharmer. Earth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack…
Earth Lusca nation-state
Also known as TAG-22, Charcoal Typhoon, CHROMIUM. Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019.
Earth Naga nation-state
Earth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and…
Earth Wendigo nation-state
Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research…
Earth Yako nation-state
Also known as Operation RestyLink, Enelink. Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan.
Edalat-e Ali hacktivist
Edalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as…
Educated Manticore nation-state
Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting…
Elderwood Espionage
Also known as Elderwood Gang, Beijing Group, Sneaky Panda. Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation…
Ember Bear Sabotage
Also known as UNC2589, Bleeding Bear, DEV-0586. Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff…
Equation Espionage
Also known as Tilded Team, EQGRP. Equation is a sophisticated threat group that employs multiple remote access tools.
Evil Corp criminal
Also known as GOLD DRAKE. Evil Corp is an internaltional cybercrime network.
EvilPost unknown
No detailed information is available about the threat actor EvilPost at this time.
EvilTraffic criminal
Also known as Operation EvilTraffic. Malware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised…
EvilWeb hacktivist
EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak method…
Evilbyte hacktivist
EvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking…
Evilnum criminal
Also known as DeathStalker, TA4563, Jointworm. Evilnum is a financially motivated threat group that has been active since at least 2018.
ExCobalt nation-state
ExCobalt is an APT group that has been active since at least 2016 and is believed to be linked to the notorious Cobalt Gang.
ExfilSquad
ExfilSquad is an emerging data-extortion group that surfaced on July 26, 2026, operating a Tor-hosted Data Leak Site to publicly claim…
Exilware
Exilware is a Brazilian threat actor operating the "Infect Marketplace," which commercializes access to compromised systems using the…
FASTCash nation-state
Treasury has identified a sophisticated cyber-enabled ATM cash out campaign we are calling FASTCash.
FIN1 criminal
FireEye first identified this activity during a recent investigation at an organization in the financial industry.
FIN10 criminal
FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016.
FIN11 criminal
Also known as TEMP.Warlock, UNC902. FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion.
FIN13 criminal
Also known as Elephant Beetle, TG2003. FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and…
FIN4 criminal
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market…
FIN5 criminal
FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information.
FIN6 criminal
Also known as Magecart Group 6, ITG08, Skeleton Spider. FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces.