Threat Actors page 4 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- FOXY PANDA nation-state
- Adversary group targeting telecommunication and technology organizations.
- Fail0verflow hacktivist
- Also known as Team Twiizer. Fail0verflow is a hacking group known for exploiting vulnerabilities in gaming consoles, notably the Nintendo Wii and PlayStation 3.
- Fallow Squall nation-state
- Also known as PLATINUM, PARASITE, RUBYVINE. Microsoft threat actor profile. Origin/Threat: Singapore.
- Femwar02 criminal
- Femwar02 is a previously unknown pro-Russian ransomware threat actor that emerged in early 2026, linked to a major cyberattack on Italy's…
- Ferocious Kitten nation-state
- Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
- FishMedley nation-state
- Verticals targeted during Operation FishMedley include governments, NGOs, and think tanks, across Asia, Europe, and the United States.
- Fishing Elephant nation-state
- Also known as Outrider Tiger. Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan.
- Flash Kitten nation-state
- This suspected Iran-based adversary conducted long-running SWC campaigns from December 2016 until public disclosure in July 2018.
- Flax Typhoon nation-state
- Also known as Ethereal Panda, Storm-0919, ETHEREAL PANDA. Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan.
- FlowerStorm criminal
- FlowerStorm is a phishing-as-a-service platform that mimics legitimate services to bypass multi-factor authentication structure.
- FlyingYeti nation-state
- Also known as Storm-1837, Flying Yeti. FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities.
- Fox Kitten nation-state
- Also known as UNC757, Parisite, Pioneer Kitten. Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in…
- Fox Tempest
- Fox Tempest is a financially motivated threat actor that operated a malware-signing-as-a-service (MSaaS) sold to other cybercriminals to…
- Frankenstein
- Frankenstein is a campaign carried out between January and April 2019 by unknown threat actors.
- FrostyNeighbor nation-state
- FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine…
- FulcrumSec criminal
- FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics.
- FunkSec criminal
- Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education…
- FusionCore criminal
- The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore.
- Fxmsp criminal
- Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground.
- GADOLINIUM nation-state
- GADOLINIUM is a nation-state activity group that has been compromising targets for nearly a decade with a worldwide focus on the maritime…
- GALLIUM nation-state
- Also known as Granite Typhoon, Red Dev 4, Alloy Taurus. GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial…
- GC01 criminal
- Also known as Golden Chickens, Golden Chickens01, Golden Chickens 01. From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter…
- GC02 criminal
- Also known as Golden Chickens, Golden Chickens02, Golden Chickens 02. From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter…
- GCMAN criminal
- GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
- GHOST STADIUM criminal
- GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300…
- GIBBERISH PANDA nation-state
- GIBBERISH PANDA is a nation-state threat actor linked to China, primarily focused on espionage.
- GOBLIN PANDA nation-state
- Also known as Conimes, Cycldek. Goblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups.
- GOFFEE nation-state
- GOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with…
- GOLD BURLAP criminal
- Also known as CYBORG SPIDER. GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as…
- GOLD DUPONT criminal
- Also known as SPRITE SPIDER. GOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka…
- GOLD EVERGREEN criminal
- GOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until…
- GOLD FAIRFAX criminal
- GOLD FAIRFAX is a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit…
- GOLD FLANDERS criminal
- GOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails…
- GOLD GALLEON criminal
- GOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry…
- GOLD GARDEN criminal
- GOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018…
- GOLD MANSARD criminal
- GOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019.
- GOLD NORTHFIELD criminal
- Operational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD…
- GOLD REBELLION criminal
- Also known as WANDERING SPIDER, White Dev 115, Dark Scorpius. GOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware.
- GOLD RIVERVIEW criminal
- GOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on…
- GOLD SKYLINE criminal
- GOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by…
- GOLD SOUTHFIELD criminal
- Also known as Pinchy Spider. GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS).
- GOLD SYMPHONY criminal
- GOLD SYMPHONY is a financially motivated cybercrime group, likely based in Russia, that is responsible for the development and sale on…
- GOLD WATERFALL criminal
- GOLD WATERFALL is a group of financially motivated cybercriminals responsible for the creation, distribution, and operation of the…
- GOLD WINTER criminal
- GOLD WINTER are a financially motivated group, likely based in Russia, who operate the Hades ransomware.
- GREF nation-state
- GREF is a China-aligned APT group that has been active since at least March 2017.
- GRIM SPIDER criminal
- Also known as GOLD ULRICK. GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations…
- GTFire criminal
- GTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs…
- GTG-1002 nation-state
- GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately 30…
- GURU SPIDER criminal
- Early in 2018, CrowdStrike Intelligence observed GURU SPIDER supporting the distribution of multiple crimeware families through its…
- Gallmaker nation-state
- Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017.
- GamaCopy nation-state
- GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical…
- Gamaredon Group nation-state
- Also known as IRON TILDEN, Primitive Bear, ACTINIUM. Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and…
- GambleForce criminal
- GambleForce is a threat actor specializing in SQL injection attacks.
- Gammax
- Gammax is a ransomware group that has claimed responsibility for attacks on various organizations, including MTCO in Saudi Arabia, RE/MAX…
- Gelsemium
- Also known as 狼毒草. Gelsemium is a cyberespionage group that has been active since at least 2014, targeting governmental institutions, electronics…
- Ghost Jackal nation-state
- Ghost Jackal is a nation-state threat actor known for conducting cyber-espionage campaigns against government and defense sectors.
- GhostEmperor nation-state
- Also known as FamousSparrow, UNC2286, Salt Typhoon. GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia.
- GhostNet nation-state
- Also known as Snooping Dragon. Cyber espionage is an issue whose time has come.
- GhostR criminal
- Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the…
- GhostRedirector nation-state
- GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in…
- GhostSec hacktivist
- Also known as Ghost Security. GhostSec is a hacktivist group that emerged as an offshoot of Anonymous.
- Ghostwriter nation-state
- Also known as UNC1151, TA445, PUSHCHA. Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas…
- Gitloker criminal
- Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data.
- GlobalSecretGroup
- Global Secret is a ransomware group that has claimed attacks on various organizations across multiple countries, including the USA, India…
- Gnosticplayers criminal
- The hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption…
- GoldFactory criminal
- GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the…
- GoldenJackal nation-state
- GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic.
- GopherWhisper nation-state
- GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Microsoft 365…
- Gorgon Group criminal
- Also known as Subaat, ATK92, Pasty Gemini. Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan.
- Gorilla criminal
- Gorilla is a threat-actor operating a DoS-as-a-service service controlled on Telegram.
- GozNym criminal
- IBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware.
- Gray Sandstorm nation-state
- Also known as DEV-0343. Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012.
- GrayBravo nation-state
- Also known as TAG-150. TAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including…
- GrayCharlie criminal
- GrayCharlie is a threat actor that compromises WordPress sites to inject malicious JavaScript, redirecting visitors to NetSupport RAT…
- Grayling nation-state
- Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading…
- GreedyBear criminal
- GreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 150…
- GreenSpot nation-state
- Also known as PoisonVine, APT-Q-20. GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, and…
- Greenbug nation-state
- Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government…
- GreyEnergy nation-state
- ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation…
- GreyVibe nation-state
- GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities.
- Groundbait nation-state
- Groundbait is a group targeting anti-government separatists in the self-declared Donetsk and Luhansk People’s Republics.
- Group5 nation-state
- Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite.
- Guacamaya hacktivist
- Guacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America…
- HAFNIUM nation-state
- Also known as Operation Exchange Marauder, Silk Typhoon, ATK233. HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021.
- HEXANE Espionage
- Also known as Lyceum, Siamesekitten, Spirlin. HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider…
- HIVE-0145 criminal
- Also known as Hive0145. Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware…
- HOUND SPIDER criminal
- According to Crowdstrike, HOUND SPIDER affiliates arrested in Romania on December,2017
- HURRICANE PANDA nation-state
- We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large…
- Hacking Team nation-state
- The many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in…
- Hagga criminal
- Also known as Aggah, TH-157. Hagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims…
- Handala hacktivist
- Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft…
- Head Mare hacktivist
- Head Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called…
- HellHounds nation-state
- Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog.
- Hellsing Espionage
- This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States.
- HenBox Espionage
- This threat actor targets Uighurs—a minority ethnic group located primarily in northwestern China—and devices from Chinese mobile phone…
- HexagonalRodent criminal
- HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers.
- Hezb criminal
- Also known as Mimo. Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities.
- HiddenArt nation-state
- It was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the personal…
- Higaisa nation-state
- Higaisa is a threat group suspected to have South Korean origins.
- HikkI-Chan criminal
- Hikki-Chan has claimed responsibility for multiple significant data breaches, including the theft of data from 390.4 million users of…