Threat Actors page 3 of 12
1,122 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Cyber Berkut hacktivist
- Cyber Berkut is a pro-Russian hacktivist group known for conducting cyber attacks primarily against Ukrainian government and media…
- Cyber Caliphate Army hacktivist
- Also known as Islamic State Hacking Division, CCA, United Cyber Caliphate. The Cyber Caliphate Army, also known as the Islamic State Hacking Division and United Cyber Caliphate, is a hacktivist group with…
- Cyber Islamic Resistance hacktivist
- Cyber Islamic Resistance is a hacktivist collective ideologically aligned with Iran, engaging in operations such as website defacements…
- Cyber Partisans hacktivist
- The Cyber Partisans, a hacktivist group based in Belarus, has been involved in various cyber-attacks targeting organizations and…
- Cyber Serp nation-state
- Also known as UAC-0255. UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting…
- Cyber Toufan nation-state
- Cyber Toufan is a threat actor group that has gained prominence for its cyberattacks targeting Israeli organizations.
- Cyber fighters of Izz Ad-Din Al Qassam hacktivist
- Also known as Fraternal Jackal. The Cyber fighters of Izz Ad-Din Al Qassam was a hacktivist group notable for orchestrating Operation Ababil, targeting financial…
- Cyber.Anarchy.Squad hacktivist
- Also known as Cyber Anarchy Squad. Cyber Anarchy Squad is a pro-Ukrainian hacktivist group known for targeting Russian companies and infrastructure.
- CyberAv3ngers nation-state
- Also known as Soldiers of Soloman. The CyberAv3ngers are a suspected Iranian Government Islamic Revolutionary Guard Corps (IRGC)-affiliated APT group.
- CyberNiggers criminal
- CyberNiggers is a threat group known for breaching various organizations, including the US military, federal contractors, and…
- DAGGER PANDA Espionage
- Also known as IceFog, Trident, RedFoxtrot. Operate since at least 2011, from several locations in China, with members in Korea and Japan as well.
- DEV-0147 nation-state
- DEV-0147 is a China-based cyber espionage actor was observed compromising diplomatic targets in South America, a notable expansion of the…
- DEV-0270 nation-state
- Also known as Nemesis Kitten, Storm-0270. Microsoft threat intelligence teams have been tracking multiple ransomware campaigns and have tied these attacks to DEV-0270, also known…
- DEV-0569 criminal
- Also known as Storm-0569. DEV-0569, also known as Storm-0569, is a threat actor group that has been observed deploying the Royal ransomware.
- DEV-0928 criminal
- DEV-0928 is a threat actor that has been tracked by Microsoft since September 2022.
- DEV-0950 criminal
- Also known as Lace Tempest, FIN11, TA505. Lace Tempest, also known as DEV-0950, is a threat actor that exploited vulnerabilities in software such as SysAid and PaperCut to gain…
- DEV-1028 criminal
- Microsoft reported on MCCrash, an IoT botnet operated by the DEV-1028 threat actor and used to launch DDoS attacks against private…
- DEXTOROUS SPIDER criminal
- DEXTOROUS SPIDER is a financially motivated cybercriminal group known for targeting the financial sector and technology firms using…
- DIZZY PANDA nation-state
- Also known as LadyBoyle. DIZZY PANDA, also known as LadyBoyle, is a sophisticated cyber espionage group believed to be linked to a nation-state.
- DNSpionage nation-state
- Also known as COBALT EDGEWATER. Cisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a…
- DOPPEL SPIDER criminal
- Also known as GOLD HERON. In June 2019, CrowdStrike Intelligence observed a source code fork of BitPaymer and began tracking the new ransomware strain as…
- DUNGEON SPIDER criminal
- DUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and…
- Daffodil Gust nation-state
- Also known as Stealth Falcon, Fruity Armor, Project Raven. Microsoft threat actor profile. Origin/Threat: United Arab Emirates.
- Daggerfly Espionage
- Also known as Evasive Panda, BRONZE HIGHLAND, Daggerfly. Daggerfly is a People's Republic of China-linked APT entity active since at least 2012.
- Daixin Team criminal
- Daixin is a threat actor group that has been active since at least June 2022.
- Dalbit criminal
- The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands…
- Dancing Salome nation-state
- Dancing Salome is the Kaspersky codename for an APT actor with a primary focus on ministries of foreign affairs, think tanks, and Ukraine.
- DangerousSavanna criminal
- Malicious campaign called DangerousSavanna has been targeting multiple major financial service groups in French-speaking Africa for the…
- Danti nation-state
- Danti is a sophisticated threat actor group known for targeting government and telecommunications sectors in India, Russia, and China.
- Dark Basin criminal
- Dark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents.
- Dark Caracal nation-state
- Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated…
- DarkCasino criminal
- DarkCasino is an economically motivated APT group that targets online trading platforms, including cryptocurrencies, online casinos…
- DarkGaboon criminal
- Also known as Vengeful Wolf, room155. DarkGaboon is a financially motivated APT group that has been independently targeting Russian organizations since May 2023, primarily…
- DarkHydrus nation-state
- Also known as LazyMeerkat, Obscure Serpens. DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016.
- DarkPink nation-state
- Also known as Saaiwc. DarkPink is an APT group that has been active since mid-2021, primarily targeting government, military, and non-profit organizations in…
- DarkRaaS criminal
- DarkRaaS is a threat actor specializing in selling unauthorized access to various organizations' systems and networks across multiple…
- DarkSpectre nation-state
- DarkSpectre is a sophisticated nation-state cyber threat actor suspected of engaging in cyber espionage activities.
- DarkVishnya criminal
- DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe.
- Darkhotel Espionage
- Also known as DUBNIUM, Zigzag Hail, Fallout Team. Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004.
- Deadeye Jackal hacktivistnation-state
- Also known as SyrianElectronicArmy, SEA. The Syrian Electronic Army (SEA) is a group of computer hackers which first surfaced online in 2011 to support the government of Syrian…
- Deep Panda nation-state
- Also known as Shell Crew, WebMasters, KungFu Kittens. Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and…
- DefrayX criminal
- Also known as Hive0091. DefrayX is a threat actor group known for their RansomExx ransomware operations.
- Denim Tsunami nation-state
- Also known as KNOTWEED, DSIRF, DEV-0291. Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers.
- Desorden Group criminal
- Desorden (Disorder in Spanish, previously known as ChaosCC), is a financially motivated hacker group.
- DiceyF nation-state
- DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended…
- DieNet hacktivist
- Also known as Shiite_Harvest. DieNet is a hacktivist group that emerged in March 2025, known for conducting DDoS attacks targeting entities associated with political…
- Domestic Kitten nation-state
- Also known as Bouncing Golf, APT-C-50. An extensive surveillance operation targets specific groups of individuals with malicious mobile apps that collect sensitive information…
- DragonBreath criminal
- Also known as Golden Eye Dog, APT-Q-27,. Golden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering…
- DragonForce hacktivist
- DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and…
- DragonOK Espionage
- Also known as Moafee, BRONZE OVERBROOK, Shallow Taurus. DragonOK is a threat group that has targeted Japanese organizations with phishing emails.
- DragonRank criminal
- DragonRank is a threat actor primarily targeting web application services in Asia and Europe, utilizing TTPs associated with Simplified…
- DragonSpark nation-state
- DragonSpark is a threat actor that has been conducting attacks primarily targeting organizations in East Asia.
- Dragonbridge nation-state
- Also known as Spamouflage Dragon. DRAGONBRIDGE is a Chinese state-sponsored threat actor known for engaging in information operations to promote the political interests of…
- Dragonfly Espionage
- Also known as TEMP.Isotope, DYMALLOY, Berserk Bear. Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16.
- Dragonfly 2.0
- Also known as IRON LIBERTY, DYMALLOY, Berserk Bear. Dragonfly 2.0 is a suspected Russian group that has targeted government entities and multiple U.S.
- DriftingCloud nation-state
- DriftingCloud is a persistent threat actor known for targeting various industries and locations.
- DriveSurge criminal
- DriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and…
- Dust Storm
- Dust Storm is a threat group that has targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southeast…
- EC2 Grouper criminalunknown
- EC2 Grouper is a prolific threat actor known for leveraging AWS tools for PowerShell to conduct automated attacks in cloud environments.
- ELECTRIC PANDA nation-state
- ELECTRIC PANDA is a suspected Chinese nation-state group known for conducting cyber espionage operations targeting defense, government…
- ELOQUENT PANDA nation-state
- ELOQUENT PANDA is a Chinese nation-state threat actor known for cyber espionage activities primarily targeting government, technological…
- ELUSIVE COMET criminal
- ELUSIVE COMET is a threat actor responsible for significant cryptocurrency theft through sophisticated social engineering attacks…
- EXOTIC LILY criminal
- Also known as DEV-0413. EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including…
- Earth Alux nation-state
- Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government…
- Earth Baxia nation-state
- Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region…
- Earth Berberoka nation-state
- Also known as GamblingPuppet. According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites.
- Earth Estries nation-state
- Trend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal.
- Earth Freybug nation-state
- Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially…
- Earth Kapre nation-state
- Also known as RedCurl, Red Wolf, GOLD BLADE. Earth Kapre is an APT group specializing in cyberespionage.
- Earth Kitsune nation-state
- Earth Kitsune is an advanced persistent threat actor that has been active since at least 2019.
- Earth Krahang nation-state
- Earth Krahang is an APT group targeting government organizations worldwide.
- Earth Kurma nation-state
- Earth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data…
- Earth Lamia nation-state
- Also known as UNC5454. Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government…
- Earth Longzhi nation-state
- Also known as SnakeCharmer. Earth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack…
- Earth Lusca nation-state
- Also known as TAG-22, Charcoal Typhoon, CHROMIUM. Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019.
- Earth Naga nation-state
- Earth Naga is an APT group that has persistently targeted high-value organizations, including government agencies, telecommunications, and…
- Earth Wendigo nation-state
- Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research…
- Earth Yako nation-state
- Also known as Operation RestyLink, Enelink. Earth Yako is a threat actor that has been actively targeting researchers in academic organizations and think tanks in Japan.
- Edalat-e Ali hacktivist
- Edalat-e Ali is a hacktivist group known for disrupting Iranian state-run TV and radio transmissions during significant events, such as…
- Educated Manticore nation-state
- Educated Manticore is an Iranian APT group aligned with the Islamic Revolutionary Guard Corps, primarily engaged in espionage targeting…
- Elderwood Espionage
- Also known as Elderwood Gang, Beijing Group, Sneaky Panda. Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation…
- Ember Bear Sabotage
- Also known as UNC2589, Bleeding Bear, DEV-0586. Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff…
- Equation Espionage
- Also known as Tilded Team, EQGRP. Equation is a sophisticated threat group that employs multiple remote access tools.
- Evil Corp criminal
- Also known as GOLD DRAKE. Evil Corp is an internaltional cybercrime network.
- EvilPost unknown
- No detailed information is available about the threat actor EvilPost at this time.
- EvilTraffic criminal
- Also known as Operation EvilTraffic. Malware experts at CSE Cybsec uncovered a massive malvertising campaign dubbed EvilTraffic leveraging tens of thousands compromised…
- EvilWeb hacktivist
- EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak method…
- Evilbyte hacktivist
- EvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking…
- Evilnum criminal
- Also known as DeathStalker, TA4563, Jointworm. Evilnum is a financially motivated threat group that has been active since at least 2018.
- ExCobalt nation-state
- ExCobalt is an APT group that has been active since at least 2016 and is believed to be linked to the notorious Cobalt Gang.
- ExfilSquad
- ExfilSquad is an emerging data-extortion group that surfaced on July 26, 2026, operating a Tor-hosted Data Leak Site to publicly claim…
- Exilware
- Exilware is a Brazilian threat actor operating the "Infect Marketplace," which commercializes access to compromised systems using the…
- FASTCash nation-state
- Treasury has identified a sophisticated cyber-enabled ATM cash out campaign we are calling FASTCash.
- FIN1 criminal
- FireEye first identified this activity during a recent investigation at an organization in the financial industry.
- FIN10 criminal
- FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016.
- FIN11 criminal
- Also known as TEMP.Warlock, UNC902. FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion.
- FIN13 criminal
- Also known as Elephant Beetle, TG2003. FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and…
- FIN4 criminal
- FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market…
- FIN5 criminal
- FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information.
- FIN6 criminal
- Also known as Magecart Group 6, ITG08, Skeleton Spider. FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces.