Threat Actors page 7 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- PROMETHIUM nation-state
- Also known as StrongPity, SmallPity. PROMETHIUM is an activity group focused on espionage that has been active since at least 2012.
- Pacha Group criminal
- Antd is a miner found in the wild on September 18, 2018.
- Packrat hacktivistnation-state
- A threat group that has been active for at least seven years has used malware, phishing and disinformation tactics to target activists…
- PassCV nation-state
- The PassCV group continues to be one of the most successful and active threat groups that leverage a wide array of stolen…
- Patched Lightning nation-state
- Also known as Storm-0113. Patched Lightning, also known as Storm-0113, is a nation-state cyber threat actor known for targeting government and technology sectors…
- Patchwork Espionage
- Also known as Hangover Group, Dropping Elephant, Chinastrats. Patchwork is a cyber espionage group that was first observed in December 2015.
- PayTool criminal
- PayTool is a threat actor that operates a phishing ecosystem focused on traffic violation and fine payment scams targeting Canadians…
- Pearl Sleet nation-state
- Also known as DEV-0215, LAWRENCIUM. Pearl Sleet is a nation state activity group based in North Korea that has been active since at least 2012.
- People's Cyber Army of Russia nation-state
- The People's Cyber Army of Russia is believed to be a state-sponsored group, engaging in cyber espionage activities.
- Pepper Typhoon nation-state
- Also known as LIMINAL PANDA, CL-STA-0969. Microsoft threat actor profile. Origin/Threat: China.
- PerSwaysion criminal
- PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives.
- PhantomControl nation-state
- PhantomControl is a sophisticated threat actor that emerged in November 2023.
- Phlox Tempest criminal
- Also known as DEV-0796, ClickPirate, Chrome Loader. Phlox Tempest is a threat actor responsible for a large-scale click fraud campaign targeting users through YouTube comments and malicious…
- Pickaxe criminal
- Also known as Prying Libra. Prying Libra, also known as Pickaxe, is a threat actor active since at least August 2017, and continues to remain active to this day.
- Pinstripe Lightning nation-state
- Also known as NIOBIUM, RENEGADE JACKAL, Desert Falcons. Microsoft threat actor profile from the public naming mapping feed.
- PittyTiger nation-state
- Also known as PITTY PANDA, Temp.Pittytiger. PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
- Play criminal
- Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government…
- PlushDaemon nation-state
- PlushDaemon is a China-aligned APT group that has conducted cyberespionage operations against targets in China, Taiwan, Hong Kong, South…
- PoisonSeed criminal
- PoisonSeed is a threat actor employing an MFA-resistant phishing kit to acquire credentials from individuals and organizations, primarily…
- Poseidon Group criminal
- Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005.
- PowerPool criminal
- Also known as IAmTheKing. Malware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code…
- Predatory Sparrow Sabotage
- Also known as Indra, Gonjeshke Darande. A self-proclaimed hacktivist group that carried out attacks against Iranian railway systems and against Iranian steel plants.
- ProCC criminal
- ProCC is a threat actor targeting the hospitality sector with remote access Trojan malware.
- Prolific Puma criminal
- Prolific Puma provides an underground link shortening service to criminals.
- Prophet Spider criminal
- Also known as GOLD MELODY, UNC961. PROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web…
- Pumpkin Sandstorm nation-state
- Also known as DEV-0146, ZeroCleare. Microsoft threat actor profile. Origin/Threat: Iran.
- PurpleHaze nation-state
- PurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors…
- Putter Panda Espionage
- Also known as APT2, MSUpdater, PLA Unit 61486. Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department…
- R00tK1T criminal
- R00TK1T is a hacking group known for sophisticated cyber attacks targeting governmental agencies in Malaysia, including data exfiltration…
- RADIO PANDA nation-state
- Also known as Shrouded Crossbow. RADIO PANDA, also known as Shrouded Crossbow, is believed to be a state-sponsored Chinese cyber espionage group.
- RATPAK SPIDER criminal
- In July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked.
- REF2924 nation-state
- A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed…
- REF5961 nation-state
- Elastic's security team has published a report on REF5961, a cyber-espionage group they found on the network of a Foreign Affairs Ministry…
- REF7707 nation-state
- Also known as CL-STA-0049, Jewelbug. REF7707 is a cyber campaign targeting government entities, particularly a foreign ministry in South America, utilizing malware families…
- RGB-TEAM hacktivist
- RGB-TEAM is a previously unknown Russian-speaking threat actor.
- RIDDLE SPIDER criminal
- According to Crowdstrike, RIDDLE SPIDER is the operator behind the avaddon ransomware
- RTM criminal
- RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in…
- RUBYCARP criminal
- RUBYCARP is a financially-motivated threat actor group likely based in Romania, with a history of at least 10 years of activity.
- RaHDit hacktivistnation-state
- Also known as Russian Angry Hackers Did It. RaHDit is a pro-Kremlin hacktivist group known for orchestrating hack-and-leak operations, including the publication of personal…
- Rancor Espionage
- Also known as Rancor group, Rancor Group, Rancor Taurus. Rancor is a threat group that has led targeted campaigns against the South East Asia region.
- RansomHouse criminal
- This group started operating during the first quarter of 2022.
- RansomHub criminal
- RansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware.
- RansomVC criminal
- Also known as Ransomed.vc. Ransomed.VC burst onto the scene with a well-orchestrated PR campaign, encompassing a clearnet site and multiple communication channels…
- Rebel Jackal Defacement
- Also known as FallagaTeam. This is a pro-Islamist organization that generally conducts attacks motivated by real world events in which its members believe that…
- Reckless Rabbit criminal
- Reckless Rabbit lures victims into investment scams through malicious Facebook advertisements that lead to fake news articles with…
- Red Charon nation-state
- Throughout 2019, multiple companies in the Taiwan high-tech ecosystem were victims of an advanced persistent threat (APT) attack.
- Red Dev 17 nation-state
- In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a…
- Red Menshen nation-state
- Also known as Red Dev 18, Earth Bluecrow. Since 2021, Red Menshen, a China based threat actor, which has been observed targeting telecommunications providers across the Middle East…
- Red Nue nation-state
- Also known as LuoYu. Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow.
- Red-Lili criminal
- RED-LILI is an active threat actor that has been identified by Checkmarx SCS research team.
- RedAlpha nation-state
- Also known as DeepCliff, Red Dev 3. Recorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years.
- RedCurl nation-state
- RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada…
- RedDelta nation-state
- Likely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized…
- RedEcho nation-state
- RedEcho is a People’s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure…
- RedGolf Financial TheftEspionage
- Recorded Future’s Insikt Group has identified a large cluster of new operational infrastructure associated with use of the custom Windows…
- RedJuliett nation-state
- RedJuliett is a likely Chinese state-sponsored threat actor targeting government, academic, technology, and diplomatic organizations in…
- RedKitten nation-state
- RedKitten is a campaign targeting Iranian interests, particularly NGOs and individuals documenting human rights abuses, first observed in…
- RedStinger nation-state
- Also known as Bad Magic. In October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the…
- Redfly nation-state
- Redfly hacked a national electricity grid organization in Asia and maintained persistent access to the network for about six months.
- ResumeLooters criminal
- Since the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites.
- Returned Libra criminal
- Also known as 8220 Mining Group. Returned Libra, also known as 8220 Mining Group, is a cloud threat actor group that has been active since at least 2017.
- RevengeHotels criminal
- RevengeHotels is a targeted cybercrime campaign that has been active since 2015, primarily targeting hotels, hostels, and tourism companies.
- RipperSec hacktivist
- RipperSec is a pro-Palestinian, likely Malaysian hacktivist group created in June 2023, known for conducting DDoS attacks, data breaches…
- Roaming Mantis criminal
- Also known as Roaming Mantis Group. According to new research by Kaspersky's GReAT team, the online criminal activities of the Roaming Mantis Group have continued to evolve…
- Roaming Tiger nation-state
- Also known as BRONZE WOODLAND, Rotten Tomato. Roaming Tiger, also known as BRONZE WOODLAND and Rotten Tomato, is a sophisticated nation-state group primarily focused on cyber espionage.
- Rocke criminal
- Also known as Aged Libra. Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources…
- RomCom nation-state
- Also known as Storm-0978, UAT-5647, Underground Team. ROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially…
- Ruby Sleet nation-state
- Also known as CERIUM, VELVET CHOLLIMA. Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security.
- RuskiNet hacktivist
- RuskiNet is a pro-Russian hacktivist collective associated with disruptive operations including DDoS attacks, website defacements…
- Ruthless Rabbit criminal
- Ruthless Rabbit has been running investment scam campaigns since November 2022, primarily targeting users in Russia, Poland, Romania, and…
- Ruza Flood nation-state
- Microsoft threat actor profile. Origin/Threat: Russia, Influence operations.
- SABRE PANDA nation-state
- SABRE PANDA is a Chinese state-sponsored threat actor known for conducting cyber espionage operations targeting defense, government, and…
- SALTY SPIDER criminal
- Beginning in January 2018 and persisting through the first half of the year, CrowdStrike Intelligence observed SALTY SPIDER, developer and…
- SAMBASPIDER criminal
- SAMBASPIDER is a threat actor associated to the Mispadu malware.
- SAMURAI PANDA Espionage
- Also known as PLA Navy, Wisp Team. SAMURAI PANDA, also known as PLA Navy and Wisp Team, is a Chinese nation-state threat actor linked to cyber espionage activities targeting…
- SCARLETEEL criminal
- SCARLETEEL is a threat actor that primarily targets cloud environments, specifically AWS and Kubernetes.
- SCULLY SPIDER criminal
- Mentioned as operator of DanaBot in CrowdStrike's 2020 Report.
- SEXi criminal
- SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments.
- SHADOW-AETHER-015 criminal
- SHADOW-AETHER-015 is a highly adaptable cybercriminal group known for identity abuse and cloud compromise, primarily targeting identity…
- SHADOW-VOID-042 nation-state
- SHADOW-VOID-042 is a provisional intrusion set tracked by Trend Micro, active in October-November 2025, conducting spear-phishing…
- SHADOW-WATER-063 criminal
- SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian…
- SHARK SPIDER criminal
- This group's activity was first observed in November 2013.
- SILKFIN AGENCY criminal
- SILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed…
- SINGING SPIDER criminal
- SINGING SPIDER is a financially motivated cybercriminal group known for their advanced techniques in targeting the financial services and…
- SLIME29 nation-state
- SLIME29 is a China-based advanced persistent threat group primarily focused on cyber espionage.
- SLIME88 nation-state
- SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT…
- SMOKY SPIDER criminal
- Mentioned as operator of SmokeLoader in CrowdStrike's 2020 Report.
- SNOWGLOBE Espionage
- Also known as Animal Farm, ATK8. In 2014, researchers at Kaspersky Lab discovered and reported on three zero-days that were being used in cyberattacks in the wild.
- SOLAR SPIDER criminal
- SOLAR SPIDER’s phishing campaigns deliver the JSOutProx RAT to financial institutions across Africa, the Middle East, South Asia and…
- SPICY PANDA nation-state
- SPICY PANDA is a Chinese threat actor known for its advanced cyber espionage activities targeting various sectors such as government…
- SPIKEDWINE nation-state
- SPIKEDWINE is a threat actor targeting European officials with a new backdoor called WINELOADER.
- STAC5143 criminal
- STAC5143 is a threat actor group tracked by Sophos, notable for its sophisticated use of Microsoft Office 365's legitimate services to…
- SWEED criminal
- Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we're calling "SWEED,"…
- SYLHET GANG-SG hacktivist
- SYLHET GANG-SG is a hacktivist group that has targeted critical infrastructure and various entities, including the Central European…
- Saad Tycoon criminal
- Saad Tycoon is the operator and alleged developer of the Tycoon 2FA PhaaS, a phishing service that targets users for financial gain.
- Saint Bear nation-state
- Also known as Storm-0587, TA471, UAC-0056. Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia.
- Salt Typhoon nation-state
- Also known as OPERATOR PANDA, GhostEmperor, FamousSparrow. Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for…
- SandCat nation-state
- SandCat, on the other hand, is a group that was discovered more recently by Kaspersky.
- Sandman APT Espionage
- First disclosed in 2023, the Sandman APT is likely associated with suspected China-based threat clusters known for using the KEYPLUG…
- Sands Casino nation-state
- The Sands Casino cyber attack was a significant incident where Iranian-linked actors targeted the Sands Corporation in the United States…