Threat Actors page 6 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Madi Espionage
- Kaspersky Lab and Seculert worked together to sinkhole the Madi Command & Control (C&C) servers to monitor the campaign.
- MageCart criminal
- Digital threat management company RiskIQ tracks the activity of MageCart group and reported their use of web-based card skimmers since 2016.
- Magic Hound nation-state
- Also known as TA453, COBALT ILLUSION, Charming Kitten. Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf…
- Magic Kitten nation-state
- Also known as Group 42, VOYEUR. Earliest activity back to November 2008. An established group of cyber attackers based in Iran, who carried on several campaigns in 2013…
- MalKamak nation-state
- MalKamak is an Iranian threat actor that has been operating since at least 2018.
- Malsmoke criminal
- Malsmoke primarily targets Japanese users through malvertising campaigns that deliver Zloader malware, often leveraging adult content…
- Malteiro criminal
- Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019.
- Mana Team nation-state
- Mana Team is a Chinese nation-state threat actor group known for conducting cyber espionage activities primarily against government and…
- Markopolo criminal
- Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax.
- Massgrave criminal
- Massgrave is a hacking group that has developed a method to bypass Microsoft's software licensing for Windows and Office, enabling…
- Medusa Group criminal
- Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a…
- Metador nation-state
- Metador is a suspected cyber espionage group that was first reported in September 2022.
- Mirage Tiger nation-state
- Mirage Tiger is a suspected nation-state threat actor known for conducting cyber espionage operations targeting government and…
- MirrorFace nation-state
- Also known as Earth Kasha. MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based…
- Moafee nation-state
- Moafee is a threat group that appears to operate from the Guandong Province of China.
- Mocha Manakin criminal
- Mocha Manakin is a threat actor that employs the paste and run technique for initial access, tricking users into executing scripts that…
- ModernStealer
- ModernStealer is linked to underground posts offering sensitive military, government, nuclear, and aerospace material, with connections to…
- ModifiedElephant nation-state
- Our research into these intrusions revealed a decade of persistent malicious activity targeting specific groups and individuals that we…
- Mofang Espionage
- Also known as Superman, BRONZE WALKER. Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure.
- Mogilevich criminal
- Mogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs…
- Molatori criminal
- Molatori is a threat actor group identified by Malwarebytes researchers, known for utilizing malicious ScreenConnect clients hosted on…
- Molerats Espionage
- Also known as Operation Molerats, Gaza Cybergang, Gaza Hackers Team. Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012.
- MoneyTaker criminal
- In less than two years, this group has conducted over 20 successful attacks on financial institutions and legal firms in the USA, UK and…
- Moonstone Sleet nation-state
- Also known as Storm-1789, LABYRINTH CHOLLIMA. Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations.
- Mora_001 criminal
- Mora_001 is a threat actor exhibiting a distinct operational signature that combines opportunistic attacks with ties to the LockBit…
- Moses Staff nation-state
- Also known as DEV-0500, Marigold Sandstorm, VENGEFUL KITTEN. Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021.
- Moshen Dragon nation-state
- Moshen Dragon is a Chinese-aligned cyberespionage threat actor operating in Central Asia.
- Moskalvzapoe criminal
- Also known as MAN1, TA511. Moskalvzapoe, also known as MAN1 or TA511, is a financially motivated threat actor group known for deploying malspam campaigns targeting…
- MoustachedBouncer Espionage
- MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
- Mr_Rot13 criminal
- Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since…
- MuddyWater Espionage
- Also known as Earth Vetala, MERCURY, Static Kitten. MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS).
- MurenShark nation-state
- Also known as Actor210426. MurenShark is an advanced persistent threat group that operates primarily in the Middle East, with a focus on targeting Turkey.
- Mustang Panda Espionage
- Also known as TA416, RedDelta, BRONZE PRESIDENT. Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012.
- Mustard Tempest criminal
- Also known as DEV-0206, TA569, GOLD PRELUDE. Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017.
- Mysterious Elephant
- Mysterious Elephant is an APT group active since 2023 that primarily targets government and foreign affairs entities across South Asia…
- Mythic Likho criminal
- Also known as Arcane Werewolf. Arcane Werewolf has been observed targeting Russian manufacturing enterprises through phishing emails that lead to malicious links and…
- N4ughtysecTU criminal
- In March 2022, a hacking group calling themselves N4ughtySecTU claimed to have breached TransUnion’s systems and threatened to leak four…
- NARWHAL SPIDER criminal
- Also known as GOLD ESSEX, TA544, Storm-0302. NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an…
- NB65 hacktivist
- Also known as Network Battalion 65. Network Battalion 65 is an hactivist group with ties to Anonymous, known for attacking Russian companies and performing hack-and-leak…
- NEODYMIUM nation-state
- NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims.
- NOBELIUM nation-state
- Threat actor behind the attacks against SolarWinds, the SUNBURST backdoor, TEARDROP malware, GoldMax malware.
- NOCTURNAL SPIDER criminal
- Mentioned as MaaS operator in CrowdStrike's 2020 Report.
- NOMAD PANDA nation-state
- In the first quarter of 2018, CrowdStrike Intelligence identified NOMAD PANDA activity targeting Central Asian nations with exploit…
- NOTROBIN nation-state
- Researchers at FireEye report finding a hacking group (dubbed NOTROBIN) that has been bundling mitigation code for NetScaler servers with…
- Naikon Espionage
- Also known as PLA Unit 78020, OVERRIDE PANDA, Camerashy. Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu…
- Nam3L3ss criminal
- Nam3L3ss is a threat actor who has leaked data from 25 companies, including over 2.8 million lines of Amazon employee data, which was…
- Narketing163 criminal
- Narketing163 is a financially motivated threat actor named after one of their frequently used email addresses ([email protected]).
- Natohub criminal
- Natohub is a hacker who claimed to have stolen 42,000 documents from the UN’s International Civil Aviation Organization and is offering…
- Nazar nation-state
- Also known as SIG37. This actor was identified by Juan Andres Guerrero-Saade from the SIG37 cluster as published in the ShadowBrokers' 'Lost in Translation'…
- NetRunnerPR criminal
- NetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan…
- NewsPenguin nation-state
- NewsPenguin is threat actor that has been targeting organizations in Pakistan.
- Nexus Zeta criminal
- Nexus Zeta is no stranger when it comes to implementing SOAP related exploits.
- Nickel Alley nation-state
- NICKEL ALLEY is a North Korean threat group that targets technology professionals through fake job opportunities, employing social…
- Night Dragon
- Night Dragon is a campaign name for activity involving a threat group that has conducted activity originating primarily in China.
- Night Tsunami nation-state
- Also known as DEV-0336, NSO Group. Microsoft threat actor profile. Origin/Threat: Israel.
- NightEagle Espionage
- Also known as APT-Q-95. NightEagle is an advanced Threat Actor that targeted China's High-Tech Industry and Military Organisation, leveraging sophisticated…
- Nitro nation-state
- Also known as Covert Grove. These attackers were the subject of an extensive report by Symantec in 2011, which termed the attackers Nitro and stated: 'The goal of the…
- NoName057(16) Denial of service
- Also known as NoName057, NoName05716, 05716nnm. NoName057(16) is performing DDoS attacks on websites belonging to governments, news agencies, armies, suppliers, telecommunications…
- Nomadic Octopus nation-state
- Also known as DustSquad. Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments…
- Nullbulge criminal
- NullBulge is a cybercriminal threat group targeting AI and gaming focused entities.
- NyxarGroup criminal
- NyxarGroup is a threat actor involved in a coordinated data brokerage ecosystem across Latin America, primarily targeting government…
- OUTLAW SPIDER criminal
- On May 7, 2019, Mayor Bernard “Jack” Young confirmed that the network for the U.S.
- OVERLORD SPIDER criminal
- OVERLORD SPIDER, aka The Dark Overlord. Similar to ransomware operators today, OVERLORD SPIDER likely purchased RDP access to compromised…
- OilAlpha nation-state
- OilAlpha has almost exclusively relied on infrastructure associated with the Public Telecommunication Corporation (PTC), a Yemeni…
- OilRig Espionage
- Also known as COBALT GYPSY, IRN2, APT34. OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014.
- Oka Flood nation-state
- Also known as Storm-1679. Microsoft threat actor profile. Origin/Threat: Russia, Influence operations.
- OldGremlin criminal
- OldGremlin is a Russian-speaking ransomware group that has been active for several years.
- OnionDog Espionage
- This threat actor targets the South Korean government, transportation, and energy sectors.
- Opal Sleet nation-state
- Also known as OSMIUM, Konni, Vedalia. Konni is a threat actor associated with APT37, a North Korean cyber crime group.
- Operation BugDrop Espionage
- This threat actor targets critical infrastructure entities in the oil and gas sector, primarily in Ukraine.
- Operation Cobalt Whisper nation-state
- Operation Cobalt Whisper is a cyber espionage campaign targeting government and defense sectors.
- Operation Comando criminal
- Operation Comando is a pure cybercrime campaign, possibly with Brazilian origin, with a concrete and persistent focus on the hospitality…
- Operation DRBControl nation-state
- Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019.
- Operation Emmental criminal
- Also known as Retefe Gang, Retefe Group. Operation Emmental, also known as the Retefe gang, is a threat actor group that has been active since at least 2012.
- Operation ForumTroll nation-state
- Operation ForumTroll is a sophisticated cyber espionage campaign discovered by Kaspersky in mid-March 2025.
- Operation Ghoul criminal
- Operation Ghoul is a profit-driven threat actor that targeted over 130 organizations in 30 countries, primarily in the industrial and…
- Operation Kabar Cobra nation-state
- Operation Kabar Cobra is a sophisticated cyber espionage campaign attributed to a nation-state actor, primarily targeting government…
- Operation Parliament Espionage
- This threat actor uses spear-phishing techniques to target parliaments, government ministries, academics, and media organizations…
- Operation Poison Needles nation-state
- What’s noteworthy is that according to the introduction on the compromised website of the polyclinic (http://www.p2f.ru), the institution…
- Operation Red Signature nation-state
- The threat actors compromised the update server of a remote support solutions provider to deliver a remote access tool called 9002 RAT to…
- Operation Shadow Force nation-state
- Also known as TA-ShadowCricket, Larva-24013. Operation Shadow Force is a group of malware that is representative of Shadow Force and Wgdrop from 2013 to 2020, and is a group activity…
- Operation ShadowHammer nation-state
- Newly discovered supply chain attack that leveraged ASUS Live Update software.
- Operation Sharpshooter nation-state
- The McAfee Advanced Threat Research team and McAfee Labs Malware Operations Group have discovered a new global campaign targeting nuclear…
- Operation Soft Cell nation-state
- In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out…
- Operation Triangulation nation-state
- Operation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits.
- Operation WizardOpium nation-stateunknown
- We are calling these attacks Operation WizardOpium.
- Operation Wocao
- Operation Wocao described activities carried out by a China-based cyber espionage adversary.
- Orangeworm criminal
- Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015…
- Orova
- Orova is a ransomware group that has claimed attacks on various targets, including Yost Home Improvements in the USA and multiple…
- OurMine hacktivist
- OurMine is known for celebrity internet accounts, often causing cyber vandalism, to advertise their commercial services.
- OverFlame hacktivist
- OverFlame is a hacktivist group known for executing DDoS attacks and website defacements, primarily targeting government institutions and…
- PALE PANDA nation-state
- PALE PANDA is a Chinese nation-state threat actor known for cyber espionage activities primarily targeting the defense, government, and…
- PARINACOTA criminal
- Also known as Wine Tempest, Wadhrama. One actor that has emerged in this trend of human-operated attacks is an active, highly adaptive group that frequently drops Wadhrama as…
- PINCHY SPIDER criminal
- First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY…
- PIZZO SPIDER criminal
- Also known as DD4BC, Ambiorx. PIZZO SPIDER, also known as DD4BC and Ambiorx, is a financially-motivated cybercriminal group primarily targeting financial services…
- PLATINUM nation-state
- Also known as TwoForOne, ATK33. PLATINUM is an activity group that has targeted victims since at least 2009.
- POISON CARP nation-state
- Also known as Evil Eye, Red Dev 16, Earth Empusa. Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text…
- POISONUS PANDA nation-state
- POISONUS PANDA is a suspected Chinese nation-state threat actor known for conducting cyber espionage operations against government and…
- POLONIUM Espionage
- Also known as Plaid Rain, UNC4453, GREATRIFT. POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information…
- PREDATOR PANDA nation-state
- PREDATOR PANDA is a Chinese cyber espionage group known for targeting the defense, government, and technology sectors.