Threat Actors page 5 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Hive0117 criminal
- Hive0117 is a financially motivated cybercriminal group that conducts phishing campaigns to deliver the fileless malware DarkWatchman…
- Hive0137 criminal
- Being one of the most active malware distributors, Hive0137 demonstrates a willingness to explore new payloads and technologies such as…
- Hive0163 criminal
- Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering…
- HollowQuill nation-state
- SEQRITE Labs APT-Team has been tracking and has uncovered a campaign targeting the Baltic State Technical University, a well-known…
- HomeLand Justice nation-state
- HomeLand Justice is an Iranian state-sponsored cyber threat group that has been active since at least May 2021.
- Honeybee
- Honeybee is a campaign led by an unknown actor that targets humanitarian aid organizations and has been active in Vietnam, Singapore…
- HookAds criminal
- HookAds is a malvertising campaign that purchases cheap ad space on low quality ad networks commonly used by adult web sites, online…
- Houken nation-state
- Houken is a Chinese state-sponsored threat actor that exploits zero-day vulnerabilities in Ivanti Cloud Services Appliance devices to gain…
- Houndstooth Typhoon nation-state
- Also known as HASSIUM, DRAGNET PANDA, isoon. Microsoft threat actor profile. Origin/Threat: China.
- HummingBad criminal
- This group created a malware that takes over Android devices and generates $300,000 per month in fraudulent ad revenue.
- Hunt3r Kill3rs nation-state
- Hunt3r Kill3rs is a newly emerged threat group claiming expertise in cyber operations, including ICS breaches and web application…
- Hyadina
- Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows…
- IMPERSONATING PANDA nation-state
- IMPERSONATING PANDA is a sophisticated nation-state threat actor believed to be sponsored by China.
- INC Ransom criminal
- Also known as GOLD IONIC. INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at…
- INDOHAXSEC TEAM hacktivistcriminal
- INDOHAXSEC TEAM is an Indonesian group that claims to have developed a web-based version of WannaCry, asserting the ability to encrypt…
- INJ3CTOR3 criminal
- INJ3CTOR3 is a threat actor first identified in 2020, known for targeting vulnerabilities in VoIP systems, specifically CVE-2019-19006 and…
- IRIDIUM nation-state
- Resecurity’s research indicates that the attack on Parliament is a part of a multi-year cyberespionage campaign orchestrated by a…
- IRLeaks criminal
- IRLeaks is a threat actor known for significant cyberattacks targeting Iranian organizations, including a major breach of SnappFood, where…
- IcePeony nation-state
- IcePeony is a China-nexus APT group that has been active since at least 2023, targeting government agencies, academic institutions, and…
- Inception Espionage
- Also known as Inception Framework, Cloud Atlas, Clean Ursa. Inception is a cyber espionage group active since at least 2014.
- IndigoZebra nation-state
- IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
- Indrik Spider criminal
- Also known as Evil Corp, Manatee Tempest, DEV-0243. Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014.
- Infrastructure Destruction Squad nation-state
- Also known as Dark Engine. Dark Engine has emerged as a significant threat actor targeting industrial control systems and SCADA systems in sectors such as metallurgy…
- Infy Espionage
- Also known as Operation Mermaid, Prince of Persia, Foudre. Infy is a group of suspected Iranian origin.
- Inteid hacktivist
- Inteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS…
- IntelBroker criminal
- IntelBroker is a threat actor known for orchestrating high-profile data breaches targeting companies like Apple, Zscaler, and Facebook…
- InvisiMole Espionage
- Adversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine.
- Iron Group criminal
- Also known as Iron Cyber Group. Iron group has developed multiple types of malware (backdoors, crypto-miners, and ransomware) for Windows, Linux and Android platforms.
- IronErn440 criminal
- IronErn440 is a threat actor tracked by Oligo Security for orchestrating the ShadowRay 2.0 campaign, an evolution of attacks since…
- IronHusky nation-state
- IronHusky is a Chinese-based threat actor first attributed in July 2017 targeting Russian and Mongolian governments, as well as aviation…
- ItaDuke nation-state
- Also known as DarkUniverse, SIG27. ItaDuke is an actor known since 2013. It used PDF exploits for dropping malware and Twitter accounts to store C2 server urls. On 2018, an…
- JACKPOT PANDA
- Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities…
- JINX-0126 criminal
- Wiz Threat Research identified a new variant of an ongoing malicious campaign targeting misconfigured and publicly exposed PostgreSQL…
- JINX-0164 criminal
- JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through…
- Jabaroot hacktivist
- Also known as Jabaroot DZ. JabaRoot is an Algerian hacker group that has targeted Moroccan government systems, successfully exfiltrating sensitive data from the…
- Jade Sleet nation-state
- Also known as Storm-0954, LABYRINTH CHOLLIMA. Microsoft threat actor profile. Origin/Threat: North Korea.
- JadePuffer
- JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate…
- Jasper Sleet nation-state
- Also known as Storm-0287. Microsoft threat actor profile. Origin/Threat: North Korea.
- JavaGhost criminal
- JavaGhost is a threat actor group that has targeted cloud environments, particularly AWS, for phishing campaigns without engaging in data…
- JuiceLedger criminal
- JuiceLedger is a threat actor known for infostealing through their JuiceStealer .NET assembly.
- KAX17 unknown
- KAX17 is a sophisticated threat actor that has been active since at least 2017.
- Kairos criminal
- Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily…
- Karakurt Extortion
- Also known as Karakurt Lair. Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and…
- Karkadann nation-state
- Also known as Piwiks. Karkadann is a threat actor that has been active since at least October 2020, targeting government bodies and news outlets in the Middle…
- Kasablanka criminal
- The Kasablanka group is a cyber-criminal organization that has specifically targeted Russia between September and December 2022, using…
- Kazu criminal
- Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and…
- Ke3chang Espionage
- Also known as APT15, Mirage, Vixen Panda. Ke3chang is a threat group attributed to actors operating out of China.
- Keksec criminal
- The threat group behind EnemyBot, Keksec, is well-resourced and has the ability to update and add new capabilities to its arsenal of…
- KelvinSecurity hacktivist
- KelvinSecurity is a hacker group that has been active since at least 2015.
- Keymous+ hacktivist
- Also known as keymous, Keymous Plus. Keymous is a threat actor known for executing extensive DDoS attacks across multiple Arab countries, targeting government ministries and…
- Killnet Denial of service
- A group targeting various countries using Denial of Services attacked.
- Kimsuky nation-state
- Also known as Black Banshee, Velvet Chollima, Emerald Sleet. Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012.
- Kinsing criminal
- Also known as Money Libra. This group started operating during the first quarter of 2022.
- Kiss-a-Dog criminal
- CrowdStrike identified a cryptojacking campaign targeting vulnerable Docker and Kubernetes infrastructure.
- KromSec hacktivist
- KromSec is a hacktivist group that claims to be composed of hackers, activists, writers, and journalists.
- Krybit criminal
- Krybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange…
- LAPSUS$ criminal
- Also known as DEV-0537, Strawberry Tempest, SLIPPY SPIDER. LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021.
- LEAD nation-state
- In contrast, LEAD has established a far greater reputation for industrial espionage.
- LIMINAL PANDA nation-state
- LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for…
- LUNAR SPIDER criminal
- Also known as GOLD SWATHMORE. According to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections.
- LabHost criminal
- LabHost is a threat actor group targeting Canadian Banks with Phishing-as-a-Service attacks.
- Lamashtu criminal
- Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site…
- Lancefly nation-state
- Lancefly targets government, aviation, and telecom organizations in South and Southeast Asia.
- Larva-208 criminal
- Also known as EncryptHub. LARVA-208 is a financially motivated threat actor employing sophisticated phishing campaigns to harvest credentials and deploy ransomware.
- Larva-24005 nation-state
- Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily…
- Larva-24009
- Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting…
- Larva-24010 unknown
- The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider.
- Larva-26002 criminal
- Larva-26002 targets improperly managed MS-SQL servers, exploiting vulnerabilities such as brute force and dictionary attacks.
- Larva-26005
- Larva-26005 is a threat actor confirmed to be distributing Xctdoor, a RAT, to users in Korea.
- Larva-26009
- Larva-26009 targets MS-SQL servers and has been observed installing the XMRig CoinMiner.
- Larva-26010
- Larva-26010 targets web servers and MS-SQL servers in Korea to install SoftEther VPN, using the systems as VPN servers.
- Larva‑25012 criminal
- Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer.
- Lazarus Group EspionageSabotage
- Also known as Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace. Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB).
- LazyScripter criminal
- LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
- Leafminer nation-state
- Also known as Raspite. Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least…
- Leviathan Espionage
- Also known as MUDCARP, Kryptonite Panda, Gadolinium. Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan…
- Libyan Scorpions nation-state
- Libyan Scorpions is a malware operation in use since September 2015 and operated by a politically motivated group whose main objective is…
- Lifting Zmiy unknown
- Rostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs.
- LightBasin nation-state
- Also known as UNC1945, CL-CRI-0025. UNC1945 is an APT group that has been targeting telecommunications companies globally.
- Lilac Typhoon nation-state
- Also known as DEV-0234. Lilac Typhoon is a threat actor attributed to China.
- LilacSquid nation-state
- LilacSquid is an APT actor targeting a variety of industries worldwide since at least 2021.
- LinkC Pub criminal
- Also known as LinkC. Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and…
- LofyGang criminal
- LofyGang has been found to be linked to more than 200 malicious packages, with thousands of installations throughout 2022.
- LongNosedGoblin nation-state
- LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage.
- Longhorn Espionage
- Also known as Lamberts, the Lamberts, APT-C-39. Longhorn has been active since at least 2011.
- Lotus Blossom Espionage
- Also known as DRAGONFISH, Spring Dragon, RADIUM. Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009.
- Lucky Cat nation-state
- Also known as TA413, White Dev 9. A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of…
- LulzIntel hacktivist
- The threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin…
- LulzSec Black hacktivist
- LulzSec Black is a hacktivist group that has claimed responsibility for coordinated DDoS attacks against Cyprus' government and critical…
- LuminousMoth nation-state
- LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020.
- Luna Moth criminal
- Also known as Silent Ransom, TG2729. Luna Moth conducts high-tempo callback phishing campaigns targeting legal and financial organizations in the U.S., using social…
- Luna Tempest criminal
- Microsoft threat actor profile. Origin/Threat: Financially motivated.
- MAGNETIC SPIDER nation-state
- MAGNETIC SPIDER is a Russian state-sponsored threat group specializing in cyber espionage.
- MALLARD SPIDER criminal
- Also known as GOLD LAGOON. Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
- MIMIC SPIDER unknown
- MIMIC SPIDER is mentioned in two summary reports only
- MONSOON
- MONTY SPIDER criminal
- Also known as Spandex Tempest. Spambots continued to decline in 2019, with MONTY SPIDER’s CraP2P spambot falling silent in April.
- MORH4x hacktivist
- MORH4x is a self-proclaimed Moroccan hacking group that claimed responsibility for a data leak from Algeria's pharmaceutical industry…
- MUMMY SPIDER criminal
- Also known as TA542, GOLD CRESTWOOD. MUMMY SPIDER is a criminal entity linked to the core development of the malware most commonly known as Emotet or Geodo.
- Machete Espionage
- Also known as APT-C-43, El Machete, machete-apt. Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010.