Threat Actors page 6 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Madi Espionage
Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign.
MageCart criminal
Digital threat management company RiskIQ tracks the activity of MageCart group and reported their use of web-based card skimmers since 2016.
Magic Hound nation-state
Also known as TA453, COBALT ILLUSION, Charming Kitten. Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf…
Magic Kitten nation-state
Also known as Group 42, VOYEUR. Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013…
MalKamak nation-state
MalKamak is an Iranian threat actor that has been operating since at least 2018.
Malsmoke criminal
Malsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content…
Malteiro criminal
Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019.
Mana Team nation-state
Mana Team is a Chinese nation-state threat actor group known for conducting cyber espionage activities primarily against government and…
Markopolo criminal
Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax.
Massgrave criminal
Massgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling…
Medusa Group criminal
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a…
Metador nation-state
Metador is a suspected cyber espionage group that was first reported in September 2022.
Mirage Tiger nation-state
Mirage Tiger is a suspected nation-state threat actor known for conducting cyber espionage operations targeting government and…
MirrorFace nation-state
Also known as Earth Kasha. MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based…
Moafee nation-state
Moafee is a threat group that appears to operate from the Guandong Province of China.
Mocha Manakin criminal
Mocha Manakin is a threat actor that employs the paste and run technique for initial access, tricking users into executing scripts that…
ModernStealer
ModernStealer is linked to underground posts offering sensitive military, government, nuclear, and aerospace material, with connections to…
ModifiedElephant nation-state
Our research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we…
Mofang Espionage
Also known as Superman, BRONZE WALKER. Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure.
Mogilevich criminal
Mogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs…
Molatori criminal
Molatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on…
Molerats Espionage
Also known as Operation Molerats, Gaza Cybergang, Gaza Hackers Team. Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012.
MoneyTaker criminal
In less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and…
Moonstone Sleet nation-state
Also known as Storm-1789, LABYRINTH CHOLLIMA. Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations.
Mora_001 criminal
Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit…
Moses Staff nation-state
Also known as DEV-0500, Marigold Sandstorm, VENGEFUL KITTEN. Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021.
Moshen Dragon nation-state
Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia.
Moskalvzapoe criminal
Also known as MAN1, TA511. Moskalvzapoe, also known as MAN1 or TA511, is a financially motivated threat actor group known for deploying malspam campaigns targeting…
MoustachedBouncer Espionage
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
Mr_Rot13 criminal
Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since…
MuddyWater Espionage
Also known as Earth Vetala, MERCURY, Static Kitten. MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).
MurenShark nation-state
Also known as Actor210426. MurenShark is an advanced persistent threat group that operates primarily in the Middle East, with a focus on targeting Turkey.
Mustang Panda Espionage
Also known as TA416, RedDelta, BRONZE PRESIDENT. Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012.
Mustard Tempest criminal
Also known as DEV-0206, TA569, GOLD PRELUDE. Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017.
Mysterious Elephant
Mysterious Elephant is an APT group active since 2023 that primarily targets government and foreign affairs entities across South Asia…
Mythic Likho criminal
Also known as Arcane Werewolf. Arcane Werewolf has been observed targeting Russian manufacturing enterprises through phishing emails that lead to malicious links and…
N4ughtysecTU criminal
In March 2022, a hacking group calling themselves N4ughtySecTU claimed to have breached TransUnion’s systems and threatened to leak four…
NARWHAL SPIDER criminal
Also known as GOLD ESSEX, TA544, Storm-0302. NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an…
NB65 hacktivist
Also known as Network Battalion 65. Network Battalion 65 is an hactivist group with ties to Anonymous, known for attacking Russian companies and performing hack-and-leak…
NEODYMIUM nation-state
NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims.
NOBELIUM nation-state
Threat actor behind the attacks against SolarWinds, the SUNBURST backdoor, TEARDROP malware, GoldMax malware.
NOCTURNAL SPIDER criminal
Mentioned as MaaS operator in CrowdStrike's 2020 Report.
NOMAD PANDA nation-state
In the first quarter of 2018, CrowdStrike Intelligence identified NOMAD PANDA activity targeting Central Asian nations with exploit…
NOTROBIN nation-state
Researchers at FireEye report finding a hacking group (dubbed NOTROBIN) that has been bundling mitigation code for NetScaler servers with…
Naikon Espionage
Also known as PLA Unit 78020, OVERRIDE PANDA, Camerashy. Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu…
Nam3L3ss criminal
Nam3L3ss is a threat actor who has leaked data from 25 companies, including over 2.8 million lines of Amazon employee data, which was…
Narketing163 criminal
Narketing163 is a financially motivated threat actor named after one of their frequently used email addresses ([email protected]).
Natohub criminal
Natohub is a hacker who claimed to have stolen 42,000 documents from the UN’s International Civil Aviation Organization and is offering…
Nazar nation-state
Also known as SIG37. This actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation'…
NetRunnerPR criminal
NetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan…
NewsPenguin nation-state
NewsPenguin is threat actor that has been targeting organizations in Pakistan.
Nexus Zeta criminal
Nexus Zeta is no stranger when it comes to implementing SOAP related exploits.
Nickel Alley nation-state
NICKEL ALLEY is a North Korean threat group that targets technology professionals through fake job opportunities, employing social…
Night Dragon
Night Dragon is a campaign name for activity involving a threat group that has conducted activity originating primarily in China.
Night Tsunami nation-state
Also known as DEV-0336, NSO Group. Microsoft threat actor profile. Origin/Threat: Israel.
NightEagle Espionage
Also known as APT-Q-95. NightEagle is an advanced Threat Actor that targeted China's High-Tech Industry and Military Organisation, leveraging sophisticated…
Nitro nation-state
Also known as Covert Grove. These attackers were the subject of an extensive report by Symantec in 2011, which termed the attackers Nitro and stated: 'The goal of the…
NoName057(16) Denial of service
Also known as NoName057, NoName05716, 05716nnm. NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications…
Nomadic Octopus nation-state
Also known as DustSquad. Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments…
Nullbulge criminal
NullBulge is a cybercriminal threat group targeting AI and gaming focused entities.
NyxarGroup criminal
NyxarGroup is a threat actor involved in a coordinated data brokerage ecosystem across Latin America, primarily targeting government…
OUTLAW SPIDER criminal
On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S.
OVERLORD SPIDER criminal
OVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised…
OilAlpha nation-state
OilAlpha has almost exclusively relied on infrastructure associated with the Public Telecommunication Corporation (PTC), a Yemeni…
OilRig Espionage
Also known as COBALT GYPSY, IRN2, APT34. OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014.
Oka Flood nation-state
Also known as Storm-1679. Microsoft threat actor profile. Origin/Threat: Russia, Influence operations.
OldGremlin criminal
OldGremlin is a Russian-speaking ransomware group that has been active for several years.
OnionDog Espionage
This threat actor targets the South Korean government, transportation, and energy sectors.
Opal Sleet nation-state
Also known as OSMIUM, Konni, Vedalia. Konni is a threat actor associated with APT37, a North Korean cyber crime group.
Operation BugDrop Espionage
This threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine.
Operation Cobalt Whisper nation-state
Operation Cobalt Whisper is a cyber espionage campaign targeting government and defense sectors.
Operation Comando criminal
Operation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality…
Operation DRBControl nation-state
Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019.
Operation Emmental criminal
Also known as Retefe Gang, Retefe Group. Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012.
Operation ForumTroll nation-state
Operation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025.
Operation Ghoul criminal
Operation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and…
Operation Kabar Cobra nation-state
Operation Kabar Cobra is a sophisticated cyber espionage campaign attributed to a nation-state actor, primarily targeting government…
Operation Parliament Espionage
This threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations…
Operation Poison Needles nation-state
What’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution…
Operation Red Signature nation-state
The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to…
Operation Shadow Force nation-state
Also known as TA-ShadowCricket, Larva-24013. Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity…
Operation ShadowHammer nation-state
Newly discovered supply chain attack that leveraged ASUS Live Update software.
Operation Sharpshooter nation-state
The McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear…
Operation Soft Cell nation-state
In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out…
Operation Triangulation nation-state
Operation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits.
Operation WizardOpium nation-stateunknown
We are calling these attacks Operation WizardOpium.
Operation Wocao
Operation Wocao described activities carried out by a China-based cyber espionage adversary.
Orangeworm criminal
Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015…
Orova
Orova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple…
OurMine hacktivist
OurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services.
OverFlame hacktivist
OverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and…
PALE PANDA nation-state
PALE PANDA is a Chinese nation-state threat actor known for cyber espionage activities primarily targeting the defense, government, and…
PARINACOTA criminal
Also known as Wine Tempest, Wadhrama. One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as…
PINCHY SPIDER criminal
First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY…
PIZZO SPIDER criminal
Also known as DD4BC, Ambiorx. PIZZO SPIDER, also known as DD4BC and Ambiorx, is a financially-motivated cybercriminal group primarily targeting financial services…
PLATINUM nation-state
Also known as TwoForOne, ATK33. PLATINUM is an activity group that has targeted victims since at least 2009.
POISON CARP nation-state
Also known as Evil Eye, Red Dev 16, Earth Empusa. Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text…
POISONUS PANDA nation-state
POISONUS PANDA is a suspected Chinese nation-state threat actor known for conducting cyber espionage operations against government and…
POLONIUM Espionage
Also known as Plaid Rain, UNC4453, GREATRIFT. POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information…
PREDATOR PANDA nation-state
PREDATOR PANDA is a Chinese cyber espionage group known for targeting the defense, government, and technology sectors.