Threat Actors page 4 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

FOXY PANDA nation-state
Adversary group targeting telecommunication and technology organizations.
Fail0verflow hacktivist
Also known as Team Twiizer. Fail0verflow is a hacking group known for exploiting vulnerabilities in gaming consoles, notably the Nintendo Wii and PlayStation 3.
Fallow Squall nation-state
Also known as PLATINUM, PARASITE, RUBYVINE. Microsoft threat actor profile. Origin/Threat: Singapore.
Femwar02 criminal
Femwar02 is a previously unknown pro-Russian ransomware threat actor that emerged in early 2026, linked to a major cyberattack on Italy's…
Ferocious Kitten nation-state
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
FishMedley nation-state
Verticals targeted during Operation FishMedley include governments, NGOs, and think tanks, across Asia, Europe, and the United States.
Fishing Elephant nation-state
Also known as Outrider Tiger. Fishing Elephant is a threat actor that primarily targets victims in Bangladesh and Pakistan.
Flash Kitten nation-state
This suspected Iran-based adversary conducted long-running SWC campaigns from December 2016 until public disclosure in July 2018.
Flax Typhoon nation-state
Also known as Ethereal Panda, Storm-0919, ETHEREAL PANDA. Flax Typhoon is a Chinese state-sponsored threat actor that primarily targets organizations in Taiwan.
FlowerStorm criminal
FlowerStorm is a phishing-as-a-service platform that mimics legitimate services to bypass multi-factor authentication structure.
FlyingYeti nation-state
Also known as Storm-1837, Flying Yeti. FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities.
Fox Kitten nation-state
Also known as UNC757, Parisite, Pioneer Kitten. Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in…
Fox Tempest
Fox Tempest is a financially motivated threat actor that operated a malware-signing-as-a-service (MSaaS) sold to other cybercriminals to…
Frankenstein
Frankenstein is a campaign carried out between January and April 2019 by unknown threat actors.
FrostyNeighbor nation-state
FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine…
FulcrumSec criminal
FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics.
FunkSec criminal
Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education…
FusionCore criminal
The CYFIRMA research team has identified a new up-and-coming European threat actor group known as FusionCore.
Fxmsp criminal
Throughout 2017 and 2018, Fxmsp established a network of trusted proxy resellers to promote their breaches on the criminal underground.
GADOLINIUM nation-state
GADOLINIUM is a nation-state activity group that has been compromising targets for nearly a decade with a worldwide focus on the maritime…
GALLIUM nation-state
Also known as Granite Typhoon, Red Dev 4, Alloy Taurus. GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial…
GC01 criminal
Also known as Golden Chickens, Golden Chickens01, Golden Chickens 01. From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter…
GC02 criminal
Also known as Golden Chickens, Golden Chickens02, Golden Chickens 02. From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter…
GCMAN criminal
GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
GHOST STADIUM criminal
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300…
GIBBERISH PANDA nation-state
GIBBERISH PANDA is a nation-state threat actor linked to China, primarily focused on espionage.
GOBLIN PANDA nation-state
Also known as Conimes, Cycldek. Goblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups.
GOFFEE nation-state
GOFFEE is a threat actor that has targeted entities in the Russian Federation since early 2022, employing spear phishing emails with…
GOLD BURLAP criminal
Also known as CYBORG SPIDER. GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as…
GOLD DUPONT criminal
Also known as SPRITE SPIDER. GOLD DUPONT is a financially motivated cybercriminal threat group that specializes in post-intrusion ransomware attacks using 777 (aka…
GOLD EVERGREEN criminal
GOLD EVERGREEN was a financially motivated cybercriminal threat group that operated the Gameover Zeus (aka Mapp, P2P Zeus) botnet until…
GOLD FAIRFAX criminal
GOLD FAIRFAX is a financially motivated cybercriminal threat group responsible for the creation, distribution, and operation of the Ramnit…
GOLD FLANDERS criminal
GOLD FLANDERS is a financially motivated group responsible for distributed denial of service (DDOS) attacks linked to extortion emails…
GOLD GALLEON criminal
GOLD GALLEON is a financially motivated cybercriminal threat group comprised of at least 20 criminal associates that collectively carry…
GOLD GARDEN criminal
GOLD GARDEN was a financially motivated cybercriminal threat group that authored and operated the GandCrab ransomware from January 2018…
GOLD MANSARD criminal
GOLD MANSARD is a financially motivated cybercriminal threat group that operated the Nemty ransomware from August 2019.
GOLD NORTHFIELD criminal
Operational since at least October 2020, GOLD NORTHFIELD is a financially motivated cybercriminal threat group that leverages GOLD…
GOLD REBELLION criminal
Also known as WANDERING SPIDER, White Dev 115, Dark Scorpius. GOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware.
GOLD RIVERVIEW criminal
GOLD RIVERVIEW was a financially motivated cybercriminal group that facilitated the distribution of malware- and scam-laden spam email on…
GOLD SKYLINE criminal
GOLD SKYLINE is a financially motivated cybercriminal threat group operating from Nigeria engaged in high-value wire fraud facilitated by…
GOLD SOUTHFIELD criminal
Also known as Pinchy Spider. GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS).
GOLD SYMPHONY criminal
GOLD SYMPHONY is a financially motivated cybercrime group, likely based in Russia, that is responsible for the development and sale on…
GOLD WATERFALL criminal
GOLD WATERFALL is a group of financially motivated cybercriminals responsible for the creation, distribution, and operation of the…
GOLD WINTER criminal
GOLD WINTER are a financially motivated group, likely based in Russia, who operate the Hades ransomware.
GREF nation-state
GREF is a China-aligned APT group that has been active since at least March 2017.
GRIM SPIDER criminal
Also known as GOLD ULRICK. GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations…
GTFire criminal
GTFire is a threat actor that leverages Google Firebase for hosting phishing pages and Google Translate to disguise malicious URLs…
GTG-1002 nation-state
GTG-1002 is a Chinese state-sponsored APT that conducted a large-scale autonomous cyber espionage campaign targeting approximately 30…
GURU SPIDER criminal
Early in 2018, CrowdStrike Intelligence observed GURU SPIDER supporting the distribution of multiple crimeware families through its…
Gallmaker nation-state
Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017.
GamaCopy nation-state
GamaCopy is a threat actor first discovered in June 2023, known for launching cyberattacks against Russia’s defense and critical…
Gamaredon Group nation-state
Also known as IRON TILDEN, Primitive Bear, ACTINIUM. Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and…
GambleForce criminal
GambleForce is a threat actor specializing in SQL injection attacks.
Gammax
Gammax is a ransomware group that has claimed responsibility for attacks on various organizations, including MTCO in Saudi Arabia, RE/MAX…
Gelsemium
Also known as 狼毒草. Gelsemium is a cyberespionage group that has been active since at least 2014, targeting governmental institutions, electronics…
Ghost Jackal nation-state
Ghost Jackal is a nation-state threat actor known for conducting cyber-espionage campaigns against government and defense sectors.
GhostEmperor nation-state
Also known as FamousSparrow, UNC2286, Salt Typhoon. GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia.
GhostNet nation-state
Also known as Snooping Dragon. Cyber espionage is an issue whose time has come.
GhostR criminal
Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the…
GhostRedirector nation-state
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in…
GhostSec hacktivist
Also known as Ghost Security. GhostSec is a hacktivist group that emerged as an offshoot of Anonymous.
Ghostwriter nation-state
Also known as UNC1151, TA445, PUSHCHA. Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas…
Gitloker criminal
Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data.
GlobalSecretGroup
Global Secret is a ransomware group that has claimed attacks on various organizations across multiple countries, including the USA, India…
Gnosticplayers criminal
The hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption…
GoldFactory criminal
GoldFactory is a threat actor group attributed to developing sophisticated mobile banking malware targeting victims primarily in the…
GoldenJackal nation-state
GoldenJackal activity is characterized by the use of compromised WordPress websites as a method to host C2-related logic.
GopherWhisper nation-state
GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Microsoft 365…
Gorgon Group criminal
Also known as Subaat, ATK92, Pasty Gemini. Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan.
Gorilla criminal
Gorilla is a threat-actor operating a DoS-as-a-service service controlled on Telegram.
GozNym criminal
IBM X-Force Research uncovered a Trojan hybrid spawned from the Nymaim and Gozi ISFB malware.
Gray Sandstorm nation-state
Also known as DEV-0343. Gray Sandstorm is an Iran-linked threat actor that has been active since at least 2012.
GrayBravo nation-state
Also known as TAG-150. TAG-150, also known as GrayBravo, is a sophisticated threat actor responsible for developing multiple custom malware families, including…
GrayCharlie criminal
GrayCharlie is a threat actor that compromises WordPress sites to inject malicious JavaScript, redirecting visitors to NetSupport RAT…
Grayling nation-state
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading…
GreedyBear criminal
GreedyBear is a sophisticated threat actor responsible for over $1 million in cryptocurrency theft through a campaign involving 150…
GreenSpot nation-state
Also known as PoisonVine, APT-Q-20. GreenSpot is an APT group believed to operate from Taiwan, active since at least 2007, primarily targeting government, academic, and…
Greenbug nation-state
Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government…
GreyEnergy nation-state
ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation…
GreyVibe nation-state
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities.
Groundbait nation-state
Groundbait is a group targeting anti-government separatists in the self-declared Donetsk and Luhansk People’s Republics.
Group5 nation-state
Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite.
Guacamaya hacktivist
Guacamaya has conducted multiple hack and leak campaigns against military and police agencies and mining companies across Latin America…
HAFNIUM nation-state
Also known as Operation Exchange Marauder, Silk Typhoon, ATK233. HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021.
HEXANE Espionage
Also known as Lyceum, Siamesekitten, Spirlin. HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider…
HIVE-0145 criminal
Also known as Hive0145. Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware…
HOUND SPIDER criminal
According to Crowdstrike, HOUND SPIDER affiliates arrested in Romania on December,2017
HURRICANE PANDA nation-state
We have investigated their intrusions since 2013 and have been battling them nonstop over the last year at several large…
Hacking Team nation-state
The many 0-days that had been collected by Hacking Team and which became publicly available during the breach of their organization in…
Hagga criminal
Also known as Aggah, TH-157. Hagga is believed to have been using Agent Tesla, 2021’s sixth most prevalent malware, to steal sensitive information from his victims…
Handala hacktivist
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft…
Head Mare hacktivist
Head Mare is a hacktivism focussed threat actor group known for targeting Russia and Belarus sectors using a remote access malware called…
HellHounds nation-state
Hellhounds is an APT group targeting organizations in Russia, using a modified version of Pupy RAT called Decoy Dog.
Hellsing Espionage
This threat actor uses spear-phishing techniques to compromise diplomatic targets in Southeast Asia, India, and the United States.
HenBox Espionage
This threat actor targets Uighurs—a minority ethnic group located primarily in northwestern China—and devices from Chinese mobile phone…
HexagonalRodent criminal
HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers.
Hezb criminal
Also known as Mimo. Hezb is a group deploying cryptominers when new exploit are available for public facing vulnerabilities.
HiddenArt nation-state
It was observed that a mobile network threat actor designated as ‘HiddenArt’ actively sustains a capacity to remotely access the personal…
Higaisa nation-state
Higaisa is a threat group suspected to have South Korean origins.
HikkI-Chan criminal
Hikki-Chan has claimed responsibility for multiple significant data breaches, including the theft of data from 390.4 million users of…