Threat Actors page 8 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Sandworm Team Espionage
Also known as ELECTRUM, Telebots, IRON VIKING. Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main…
Sath-ı Müdafaa Denial of service
A Turkish hacking group, Sath-ı Müdafaa, is encouraging individuals to join its DDoS-for-Points platform that features points and prizes…
ScamClub criminal
ScamClub is a threat actor involved in malvertising activities since 2018.
Scarab Espionage
Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small…
Scarlet Mimic nation-statehacktivist
Also known as Golfing Taurus. Scarlet Mimic is a threat group that has targeted minority rights activists.
Scarred Manticore nation-state
Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers.
Scattered Canary criminal
When the first member of Scattered Canary, who, for the purposes of this report, we call Alpha, began his operations, he was a lone…
Scattered Lapsus Hunters
Also known as Scattered Lapsus$ Hunters. Launched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on…
Scattered Spider criminal
Also known as Roasted 0ktapus, Octo Tempest, Storm-0875. Scattered Spider is a native English-speaking cybercriminal group active since at least 2022.
ScreamedJungle criminal
ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript…
Scripted Sparrow criminal
Scripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating…
Sea Turtle nation-state
Also known as Teal Kurma, Marbled Dust, Cosmic Wolf. Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations…
Sefid Flood nation-state
Microsoft threat actor profile. Origin/Threat: Iran, Influence operations.
Shadow Network nation-state
Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and…
Shadow-Earth-053 nation-state
SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically…
ShadowSyndicate criminal
ShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple…
ShadyPanda criminal
ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity…
ShaggyPanther nation-state
ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia.
Shahid Hemmat nation-state
Shahid Hemmat is an IRGC-CEC affiliated hacking group linked to cyberattacks targeting U.S.
Shamoon Group nation-state
Also known as Cutting Sword of Justice. Shamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle…
SharpPanda nation-state
Also known as Sharp Dragon. SharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018.
Sharpshooter
Operation Sharpshooter is the name of a cyber espionage campaign discovered in October 2018 targeting nuclear, defense, energy, and…
ShinyHunters criminal
Also known as UNC6240, Bling Libra. ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona.
ShroudedSnooper nation-state
In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications…
SideCopy nation-state
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel…
Sidewinder nation-state
Also known as T-APT-04, Rattlesnake, APT-C-17. Sidewinder is a suspected Indian threat actor group that has been active since at least 2012.
SiegedSec hacktivist
SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine.
Siesta nation-state
FireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign.
Silence criminal
Also known as Whisper Spider, WHISPER SPIDER. Silence is a financially motivated threat actor targeting financial institutions in different countries.
Silent Librarian nation-state
Also known as TA407, COBALT DICKENS, Mabna Institute. Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector…
SilitNetwork criminal
SilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives.
SilkParasite
SilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications…
SilkSpecter criminal
SilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers…
SilverFish nation-state
SilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the…
SilverTerrier criminal
SilverTerrier is a Nigerian threat group that has been seen active since 2014.
Sima nation-state
Sima is a group of suspected Iranian origin targeting Iranians in diaspora.
SingularityMD criminal
SingularityMD is a threat actor group that has targeted educational institutions in the US.
Sinobi criminal
Sinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing…
SkidSec hacktivist
Also known as SkidSec Leaks. SkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda…
Slingshot nation-state
While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file…
SlopAds criminal
SlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally.
SloppyLemming nation-state
SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as…
Smishing Triad criminal
The Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing…
SmugX nation-state
The campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda.
Snake Wine nation-state
While investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered…
SneakyChef nation-state
SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations…
SnowSoul criminal
SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily…
Solntsepek nation-state
Solntsepek is a threat actor group with ties to the Russian military unit GRU.
SongXY nation-state
SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns.
Sowbug Espionage
Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly…
Sp1d3r criminal
Sp1d3r, a threat actor, has been involved in multiple data breaches targeting companies like Truist Bank, Cylance, and Advance Auto Parts.
SpaceBears criminal
SpaceBears is a ransomware group believed to be based in Moscow, Russia, that has taken credit for several high-profile cyberattacks while…
SparklingGoblin nation-state
ESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin…
Star Blizzard nation-state
Also known as SEABORGIUM, Callisto Group, TA446. Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019.
Stargazer Goblin criminal
Stargazer Goblin is a threat actor group that operates the Stargazers Ghost Network on GitHub, distributing malware and malicious links…
Starry Addax hacktivist
Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile…
Stealth Falcon Espionage
Also known as FruityArmor. Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since…
Stealth Mango and Tangelo Espionage
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in…
Stolen Pencil Espionage
Also known as Velvet Chollima, Black Banshee, Thallium. Stolen Pencil is a threat group likely originating from DPRK that has been active since at least May 2018.
Storm Cloud nation-state
Storm Cloud is a Chinese espionage threat actor known for targeting organizations across Asia, particularly Tibetan organizations and…
Storm-0062 nation-state
Also known as Oro0lxy, DarkShadow. The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062.
Storm-0249 criminal
Also known as DEV-0249. Storm-0249 is an access broker active since 2021, known for distributing BazaLoader, IcedID, Bumblebee, and Emotet malware.
Storm-0252
Also known as CHATTY SPIDER. Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-0259 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-0288 criminal
Also known as FIN8. Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-0324 criminal
Also known as DEV-0324, Sagrid, TA543. The threat actor that Microsoft tracks as Storm-0324 is a financially motivated group known to gain initial access using email-based…
Storm-0381 criminal
Also known as DEV-0381. Storm-0381 is a threat actor identified by Microsoft as a Russian cybercrime group.
Storm-0408 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-0473 nation-state
Also known as UNC2849. Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019.
Storm-0485 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-0494 criminal
Storm-0494 is a threat actor that facilitates Gootloader infections, which are then exploited by groups like Vice Society to deploy tools…
Storm-0501 criminal
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations.
Storm-0506 criminal
Storm-0506 (DEV-0506) is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta…
Storm-0530 nation-state
Also known as DEV-0530, H0lyGh0st. H0lyGh0st is a North Korean threat actor that has been active since June 2021.
Storm-0539 criminal
Storm-0539 is a financially motivated threat actor that has been active since at least 2021.
Storm-0558 Espionage
Storm-0558 is a China-based threat actor with espionage objectives.
Storm-0569 criminal
Microsoft threat actor profile. Origin/Threat: Financially motivated.
Storm-0593 nation-state
Also known as InvisiMole. Microsoft threat actor profile. Origin/Threat: Russia.
Storm-0671 nation-state
Also known as UNC2596, Tropicalscorpius. Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-0826 criminal
Storm-0826 is a financially motivated cybercriminal group operating as an affiliate within the Black Basta ransomware-as-a-service (RaaS)…
Storm-0829 criminal
Also known as DEV-0829, Nwgen Team. Nwgen is a group that focuses on data exfiltration and ransomware activities.
Storm-0835 criminal
Cybercriminals have launched a phishing campaign targeting senior executives in U.S.
Storm-0867 criminal
Also known as DEV-0867. Storm-0867 is a threat actor that has been active since 2012 and has targeted various industries and regions.
Storm-0940 nation-state
Also known as CovertNetwork-1658, ORB07. Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force…
Storm-1044 criminal
Also known as DEV-1044. Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider.
Storm-1084 nation-state
Also known as DEV-1084. Storm-1084 is a threat actor that has been observed collaborating with the MuddyWater group.
Storm-1099 nation-state
Storm-1099 is a sophisticated Russia-affiliated influence actor that has been conducting pro-Russia influence operations targeting…
Storm-1101 criminal
Also known as DEV-1101. DEV-1101 is a threat actor tracked by Microsoft who is responsible for developing and advertising phishing kits, specifically AiTM…
Storm-1113 criminal
Also known as APOTHECARY SPIDER. Storm-1113 is a threat actor that acts both as an access broker focused on malware distribution through search advertisements and as an…
Storm-1125 nation-state
Also known as MoustachedBouncer. Microsoft threat actor profile. Origin/Threat: Belarus.
Storm-1133 nation-state
In early 2023, Microsoft In early 2023, observed a wave of activity from a Gaza-based group that we track as Storm-1133 targeting Israeli…
Storm-1152 criminal
Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts.
Storm-1167 criminal
Also known as DEV-1167. Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit.
Storm-1175 criminal
Storm-1175 is a cybercriminal group known for deploying Medusa ransomware and exploiting public-facing applications for initial access.
Storm-1194 unknown
Also known as MONTI. Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-1249 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-1283 criminal
Storm-1283 is a threat actor that targeted Microsoft Azure cloud platform.
Storm-1286 criminal
Storm-1286 is a threat actor that engages in large-scale spamming activities, primarily targeting user accounts without multifactor…
Storm-1295 criminal
Also known as DEV-1295. Storm-1295 is a threat actor group that operates the Greatness phishing-as-a-service platform.
Storm-1516 nation-state
Also known as CopyCop. CopyCop is a Russian covert influence network that has established over 300 fictional media websites targeting the US, France, Canada, and…