Threat Actors page 5 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Hive0117 criminal
Hive0117 is a financially motivated cybercriminal group that conducts phishing campaigns to deliver the fileless malware DarkWatchman…
Hive0137 criminal
Being one of the most active malware distributors, Hive0137 demonstrates a willingness to explore new payloads and technologies such as…
Hive0163 criminal
Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering…
HollowQuill nation-state
SEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known…
HomeLand Justice nation-state
HomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021.
Honeybee
Honeybee is a campaign led by an unknown actor that targets humanitarian aid organizations and has been active in Vietnam, Singapore…
HookAds criminal
HookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online…
Houken nation-state
Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain…
Houndstooth Typhoon nation-state
Also known as HASSIUM, DRAGNET PANDA, isoon. Microsoft threat actor profile. Origin/Threat: China.
HummingBad criminal
This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue.
Hunt3r Kill3rs nation-state
Hunt3r Kill3rs is a newly emerged threat group claiming expertise in cyber operations, including ICS breaches and web application…
Hyadina
Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows…
IMPERSONATING PANDA nation-state
IMPERSONATING PANDA is a sophisticated nation-state threat actor believed to be sponsored by China.
INC Ransom criminal
Also known as GOLD IONIC. INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at…
INDOHAXSEC TEAM hacktivistcriminal
INDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt…
INJ3CTOR3 criminal
INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and…
IRIDIUM nation-state
Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a…
IRLeaks criminal
IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where…
IcePeony nation-state
IcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and…
Inception Espionage
Also known as Inception Framework, Cloud Atlas, Clean Ursa. Inception is a cyber espionage group active since at least 2014.
IndigoZebra nation-state
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
Indrik Spider criminal
Also known as Evil Corp, Manatee Tempest, DEV-0243. Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014.
Infrastructure Destruction Squad nation-state
Also known as Dark Engine. Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy…
Infy Espionage
Also known as Operation Mermaid, Prince of Persia, Foudre. Infy is a group of suspected Iranian origin.
Inteid hacktivist
Inteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS…
IntelBroker criminal
IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook…
InvisiMole Espionage
Adversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine.
Iron Group criminal
Also known as Iron Cyber Group. Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms.
IronErn440 criminal
IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since…
IronHusky nation-state
IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation…
ItaDuke nation-state
Also known as DarkUniverse, SIG27. ItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an…
JACKPOT PANDA
Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities…
JINX-0126 criminal
Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL…
JINX-0164 criminal
JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through…
Jabaroot hacktivist
Also known as Jabaroot DZ. JabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the…
Jade Sleet nation-state
Also known as Storm-0954, LABYRINTH CHOLLIMA. Microsoft threat actor profile. Origin/Threat: North Korea.
JadePuffer
JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate…
Jasper Sleet nation-state
Also known as Storm-0287. Microsoft threat actor profile. Origin/Threat: North Korea.
JavaGhost criminal
JavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data…
JuiceLedger criminal
JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly.
KAX17 unknown
KAX17 is a sophisticated threat actor that has been active since at least 2017.
Kairos criminal
Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily…
Karakurt Extortion
Also known as Karakurt Lair. Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and…
Karkadann nation-state
Also known as Piwiks. Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle…
Kasablanka criminal
The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using…
Kazu criminal
Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and…
Ke3chang Espionage
Also known as APT15, Mirage, Vixen Panda. Ke3chang is a threat group attributed to actors operating out of China.
Keksec criminal
The threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of…
KelvinSecurity hacktivist
KelvinSecurity is a hacker group that has been active since at least 2015.
Keymous+ hacktivist
Also known as keymous, Keymous Plus. Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and…
Killnet Denial of service
A group targeting various countries using Denial of Services attacked.
Kimsuky nation-state
Also known as Black Banshee, Velvet Chollima, Emerald Sleet. Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012.
Kinsing criminal
Also known as Money Libra. This group started operating during the first quarter of 2022.
Kiss-a-Dog criminal
CrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure.
KromSec hacktivist
KromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists.
Krybit criminal
Krybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange…
LAPSUS$ criminal
Also known as DEV-0537, Strawberry Tempest, SLIPPY SPIDER. LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021.
LEAD nation-state
In contrast, LEAD has established a far greater reputation for industrial espionage.
LIMINAL PANDA nation-state
LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for…
LUNAR SPIDER criminal
Also known as GOLD SWATHMORE. According to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections.
LabHost criminal
LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks.
Lamashtu criminal
Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site…
Lancefly nation-state
Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia.
Larva-208 criminal
Also known as EncryptHub. LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware.
Larva-24005 nation-state
Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily…
Larva-24009
Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting…
Larva-24010 unknown
The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider.
Larva-26002 criminal
Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks.
Larva-26005
Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea.
Larva-26009
Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
Larva-26010
Larva-26010 targets web servers and MS-SQL servers in Korea to install SoftEther VPN, using the systems as VPN servers.
Larva‑25012 criminal
Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer.
Lazarus Group EspionageSabotage
Also known as Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace. Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB).
LazyScripter criminal
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
Leafminer nation-state
Also known as Raspite. Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least…
Leviathan Espionage
Also known as MUDCARP, Kryptonite Panda, Gadolinium. Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan…
Libyan Scorpions nation-state
Libyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is…
Lifting Zmiy unknown
Rostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs.
LightBasin nation-state
Also known as UNC1945, CL-CRI-0025. UNC1945 is an APT group that has been targeting telecommunications companies globally.
Lilac Typhoon nation-state
Also known as DEV-0234. Lilac Typhoon is a threat actor attributed to China.
LilacSquid nation-state
LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021.
LinkC Pub criminal
Also known as LinkC. Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and…
LofyGang criminal
LofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022.
LongNosedGoblin nation-state
LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage.
Longhorn Espionage
Also known as Lamberts, the Lamberts, APT-C-39. Longhorn has been active since at least 2011.
Lotus Blossom Espionage
Also known as DRAGONFISH, Spring Dragon, RADIUM. Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009.
Lucky Cat nation-state
Also known as TA413, White Dev 9. A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of…
LulzIntel hacktivist
The threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin…
LulzSec Black hacktivist
LulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical…
LuminousMoth nation-state
LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020.
Luna Moth criminal
Also known as Silent Ransom, TG2729. Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social…
Luna Tempest criminal
Microsoft threat actor profile. Origin/Threat: Financially motivated.
MAGNETIC SPIDER nation-state
MAGNETIC SPIDER is a Russian state-sponsored threat group specializing in cyber espionage.
MALLARD SPIDER criminal
Also known as GOLD LAGOON. Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
MIMIC SPIDER unknown
MIMIC SPIDER is mentioned in two summary reports only
MONSOON
MONTY SPIDER criminal
Also known as Spandex Tempest. Spambots continued to decline in 2019, with MONTY SPIDER’s CraP2P spambot falling silent in April.
MORH4x hacktivist
MORH4x is a self-proclaimed Moroccan hacking group that claimed responsibility for a data leak from Algeria's pharmaceutical industry…
MUMMY SPIDER criminal
Also known as TA542, GOLD CRESTWOOD. MUMMY SPIDER is a criminal entity linked to the core development of the malware most commonly known as Emotet or Geodo.
Machete Espionage
Also known as APT-C-43, El Machete, machete-apt. Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010.