Threat Actors page 7 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

PROMETHIUM nation-state
Also known as StrongPity, SmallPity. PROMETHIUM is an activity group focused on espionage that has been active since at least 2012.
Pacha Group criminal
Antd is a miner found in the wild on September 18, 2018.
Packrat hacktivistnation-state
A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists…
PassCV nation-state
The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen…
Patched Lightning nation-state
Also known as Storm-0113. Patched Lightning, also known as Storm-0113, is a nation-state cyber threat actor known for targeting government and technology sectors…
Patchwork Espionage
Also known as Hangover Group, Dropping Elephant, Chinastrats. Patchwork is a cyber espionage group that was first observed in December 2015.
PayTool criminal
PayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians…
Pearl Sleet nation-state
Also known as DEV-0215, LAWRENCIUM. Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012.
People's Cyber Army of Russia nation-state
The People's Cyber Army of Russia is believed to be a state-sponsored group, engaging in cyber espionage activities.
Pepper Typhoon nation-state
Also known as LIMINAL PANDA, CL-STA-0969. Microsoft threat actor profile. Origin/Threat: China.
PerSwaysion criminal
PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives.
PhantomControl nation-state
PhantomControl is a sophisticated threat actor that emerged in November 2023.
Phlox Tempest criminal
Also known as DEV-0796, ClickPirate, Chrome Loader. Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious…
Pickaxe criminal
Also known as Prying Libra. Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day.
Pinstripe Lightning nation-state
Also known as NIOBIUM, RENEGADE JACKAL, Desert Falcons. Microsoft threat actor profile from the public naming mapping feed.
PittyTiger nation-state
Also known as PITTY PANDA, Temp.Pittytiger. PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
Play criminal
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government…
PlushDaemon nation-state
PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South…
PoisonSeed criminal
PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily…
Poseidon Group criminal
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005.
PowerPool criminal
Also known as IAmTheKing. Malware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code…
Predatory Sparrow Sabotage
Also known as Indra, Gonjeshke Darande. A self-proclaimed hacktivist group that carried out attacks against Iranian railway systems and against Iranian steel plants.
ProCC criminal
ProCC is a threat actor targeting the hospitality sector with remote access Trojan malware.
Prolific Puma criminal
Prolific Puma provides an underground link shortening service to criminals.
Prophet Spider criminal
Also known as GOLD MELODY, UNC961. PROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web…
Pumpkin Sandstorm nation-state
Also known as DEV-0146, ZeroCleare. Microsoft threat actor profile. Origin/Threat: Iran.
PurpleHaze nation-state
PurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors…
Putter Panda Espionage
Also known as APT2, MSUpdater, PLA Unit 61486. Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department…
R00tK1T criminal
R00TK1T is a hacking group known for sophisticated cyber attacks targeting governmental agencies in Malaysia, including data exfiltration…
RADIO PANDA nation-state
Also known as Shrouded Crossbow. RADIO PANDA, also known as Shrouded Crossbow, is believed to be a state-sponsored Chinese cyber espionage group.
RATPAK SPIDER criminal
In July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked.
REF2924 nation-state
A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed…
REF5961 nation-state
Elastic's security team has published a report on REF5961, a cyber-espionage group they found on the network of a Foreign Affairs Ministry…
REF7707 nation-state
Also known as CL-STA-0049, Jewelbug. REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families…
RGB-TEAM hacktivist
RGB-TEAM is a previously unknown Russian-speaking threat actor.
RIDDLE SPIDER criminal
According to Crowdstrike, RIDDLE SPIDER is the operator behind the avaddon ransomware
RTM criminal
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in…
RUBYCARP criminal
RUBYCARP is a financially-motivated threat actor group likely based in Romania, with a history of at least 10 years of activity.
RaHDit hacktivistnation-state
Also known as Russian Angry Hackers Did It. RaHDit is a pro-Kremlin hacktivist group known for orchestrating hack-and-leak operations, including the publication of personal…
Rancor Espionage
Also known as Rancor group, Rancor Group, Rancor Taurus. Rancor is a threat group that has led targeted campaigns against the South East Asia region.
RansomHouse criminal
This group started operating during the first quarter of 2022.
RansomHub criminal
RansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware.
RansomVC criminal
Also known as Ransomed.vc. Ransomed.VC burst onto the scene with a well-orchestrated PR campaign, encompassing a clearnet site and multiple communication channels…
Rebel Jackal Defacement
Also known as FallagaTeam. This is a pro-Islamist organization that generally conducts attacks motivated by real world events in which its members believe that…
Reckless Rabbit criminal
Reckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with…
Red Charon nation-state
Throughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack.
Red Dev 17 nation-state
In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a…
Red Menshen nation-state
Also known as Red Dev 18, Earth Bluecrow. Since 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East…
Red Nue nation-state
Also known as LuoYu. Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow.
Red-Lili criminal
RED-LILI is an active threat actor that has been identified by Checkmarx SCS research team.
RedAlpha nation-state
Also known as DeepCliff, Red Dev 3. Recorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years.
RedCurl nation-state
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada…
RedDelta nation-state
Likely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized…
RedEcho nation-state
RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure…
RedGolf Financial TheftEspionage
Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows…
RedJuliett nation-state
RedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in…
RedKitten nation-state
RedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in…
RedStinger nation-state
Also known as Bad Magic. In October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the…
Redfly nation-state
Redfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months.
ResumeLooters criminal
Since the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites.
Returned Libra criminal
Also known as 8220 Mining Group. Returned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017.
RevengeHotels criminal
RevengeHotels is a targeted cybercrime campaign that has been active since 2015, primarily targeting hotels, hostels, and tourism companies.
RipperSec hacktivist
RipperSec is a pro-Palestinian, likely Malaysian hacktivist group created in June 2023, known for conducting DDoS attacks, data breaches…
Roaming Mantis criminal
Also known as Roaming Mantis Group. According to new research by Kaspersky's GReAT team, the online criminal activities of the Roaming Mantis Group have continued to evolve…
Roaming Tiger nation-state
Also known as BRONZE WOODLAND, Rotten Tomato. Roaming Tiger, also known as BRONZE WOODLAND and Rotten Tomato, is a sophisticated nation-state group primarily focused on cyber espionage.
Rocke criminal
Also known as Aged Libra. Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources…
RomCom nation-state
Also known as Storm-0978, UAT-5647, Underground Team. ROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially…
Ruby Sleet nation-state
Also known as CERIUM, VELVET CHOLLIMA. Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security.
RuskiNet hacktivist
RuskiNet is a pro-Russian hacktivist collective associated with disruptive operations including DDoS attacks, website defacements…
Ruthless Rabbit criminal
Ruthless Rabbit has been running investment scam campaigns since November 2022, primarily targeting users in Russia, Poland, Romania, and…
Ruza Flood nation-state
Microsoft threat actor profile. Origin/Threat: Russia, Influence operations.
SABRE PANDA nation-state
SABRE PANDA is a Chinese state-sponsored threat actor known for conducting cyber espionage operations targeting defense, government, and…
SALTY SPIDER criminal
Beginning in January 2018 and persisting through the first half of the year, CrowdStrike Intelligence observed SALTY SPIDER, developer and…
SAMBASPIDER criminal
SAMBASPIDER is a threat actor associated to the Mispadu malware.
SAMURAI PANDA Espionage
Also known as PLA Navy, Wisp Team. SAMURAI PANDA, also known as PLA Navy and Wisp Team, is a Chinese nation-state threat actor linked to cyber espionage activities targeting…
SCARLETEEL criminal
SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes.
SCULLY SPIDER criminal
Mentioned as operator of DanaBot in CrowdStrike's 2020 Report.
SEXi criminal
SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments.
SHADOW-AETHER-015 criminal
SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity…
SHADOW-VOID-042 nation-state
SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing…
SHADOW-WATER-063 criminal
SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian…
SHARK SPIDER criminal
This group's activity was first observed in November 2013.
SILKFIN AGENCY criminal
SILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed…
SINGING SPIDER criminal
SINGING SPIDER is a financially motivated cybercriminal group known for their advanced techniques in targeting the financial services and…
SLIME29 nation-state
SLIME29 is a China-based advanced persistent threat group primarily focused on cyber espionage.
SLIME88 nation-state
SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT…
SMOKY SPIDER criminal
Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
SNOWGLOBE Espionage
Also known as Animal Farm, ATK8. In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild.
SOLAR SPIDER criminal
SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and…
SPICY PANDA nation-state
SPICY PANDA is a Chinese threat actor known for its advanced cyber espionage activities targeting various sectors such as government…
SPIKEDWINE nation-state
SPIKEDWINE is a threat actor targeting European officials with a new backdoor called WINELOADER.
STAC5143 criminal
STAC5143 is a threat actor group tracked by Sophos, notable for its sophisticated use of Microsoft Office 365's legitimate services to…
SWEED criminal
Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we're calling "SWEED,"…
SYLHET GANG-SG hacktivist
SYLHET GANG-SG is a hacktivist group that has targeted critical infrastructure and various entities, including the Central European…
Saad Tycoon criminal
Saad Tycoon is the operator and alleged developer of the Tycoon 2FA PhaaS, a phishing service that targets users for financial gain.
Saint Bear nation-state
Also known as Storm-0587, TA471, UAC-0056. Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia.
Salt Typhoon nation-state
Also known as OPERATOR PANDA, GhostEmperor, FamousSparrow. Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for…
SandCat nation-state
SandCat, on the other hand, is a group that was discovered more recently by Kaspersky.
Sandman APT Espionage
First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG…
Sands Casino nation-state
The Sands Casino cyber attack was a significant incident where Iranian-linked actors targeted the Sands Corporation in the United States…