Threat Actors page 8 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Sandworm Team Espionage
- Also known as ELECTRUM, Telebots, IRON VIKING. Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main…
- Sath-ı Müdafaa Denial of service
- A Turkish hacking group, Sath-ı Müdafaa, is encouraging individuals to join its DDoS-for-Points platform that features points and prizes…
- ScamClub criminal
- ScamClub is a threat actor involved in malvertising activities since 2018.
- Scarab Espionage
- Scarab APT was first spotted in 2015, but is believed to have been active since at least 2012, conducting surgical attacks against a small…
- Scarlet Mimic nation-statehacktivist
- Also known as Golfing Taurus. Scarlet Mimic is a threat group that has targeted minority rights activists.
- Scarred Manticore nation-state
- Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers.
- Scattered Canary criminal
- When the first member of Scattered Canary, who, for the purposes of this report, we call Alpha, began his operations, he was a lone…
- Scattered Lapsus Hunters
- Also known as Scattered Lapsus$ Hunters. Launched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on…
- Scattered Spider criminal
- Also known as Roasted 0ktapus, Octo Tempest, Storm-0875. Scattered Spider is a native English-speaking cybercriminal group active since at least 2022.
- ScreamedJungle criminal
- ScreamedJungle is a threat actor that exploits vulnerabilities in outdated Magento e-commerce platforms to inject malicious JavaScript…
- Scripted Sparrow criminal
- Scripted Sparrow is a prolific Business Email Compromise (BEC) collective that conducts highly targeted phishing campaigns, impersonating…
- Sea Turtle nation-state
- Also known as Teal Kurma, Marbled Dust, Cosmic Wolf. Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations…
- Sefid Flood nation-state
- Microsoft threat actor profile. Origin/Threat: Iran, Influence operations.
- Shadow Network nation-state
- Shadows in the Cloud documents a complex ecosystem of cyber espionage that systematically compromised government, business, academic, and…
- Shadow-Earth-053 nation-state
- SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically…
- ShadowSyndicate criminal
- ShadowSyndicate is a threat actor associated with various ransomware groups, using a consistent Secure Shell fingerprint across multiple…
- ShadyPanda criminal
- ShadyPanda is a threat actor behind a 7-year campaign that has infected 4.3 million users through extensions masquerading as productivity…
- ShaggyPanther nation-state
- ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia.
- Shahid Hemmat nation-state
- Shahid Hemmat is an IRGC-CEC affiliated hacking group linked to cyberattacks targeting U.S.
- Shamoon Group nation-state
- Also known as Cutting Sword of Justice. Shamoon Group is an Iran-linked threat actor associated with destructive Shamoon wiper operations targeting organizations in the Middle…
- SharpPanda nation-state
- Also known as Sharp Dragon. SharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018.
- Sharpshooter
- Operation Sharpshooter is the name of a cyber espionage campaign discovered in October 2018 targeting nuclear, defense, energy, and…
- ShinyHunters criminal
- Also known as UNC6240, Bling Libra. ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona.
- ShroudedSnooper nation-state
- In September 2023, Cisco Talos identified a new malware family that it calls ‘HTTPSnoop’ being deployed against telecommunications…
- SideCopy nation-state
- SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel…
- Sidewinder nation-state
- Also known as T-APT-04, Rattlesnake, APT-C-17. Sidewinder is a suspected Indian threat actor group that has been active since at least 2012.
- SiegedSec hacktivist
- SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine.
- Siesta nation-state
- FireEye recently looked deeper into the activity discussed in TrendMicro’s blog and dubbed the “Siesta” campaign.
- Silence criminal
- Also known as Whisper Spider, WHISPER SPIDER. Silence is a financially motivated threat actor targeting financial institutions in different countries.
- Silent Librarian nation-state
- Also known as TA407, COBALT DICKENS, Mabna Institute. Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector…
- SilitNetwork criminal
- SilitNetwork is a hacking group known for targeting high-profile entities, such as airlines, for various motives.
- SilkParasite
- SilkParasite is an activity cluster tracked by Bitdefender across Central Asia, primarily targeting government and telecommunications…
- SilkSpecter criminal
- SilkSpecter is a Chinese financially motivated threat actor that orchestrates phishing campaigns targeting e-commerce shoppers…
- SilverFish nation-state
- SilverFish is believed to be a Russian cyberespionage group that has been involved in various cyberattacks, including the use of the…
- SilverTerrier criminal
- SilverTerrier is a Nigerian threat group that has been seen active since 2014.
- Sima nation-state
- Sima is a group of suspected Iranian origin targeting Iranians in diaspora.
- SingularityMD criminal
- SingularityMD is a threat actor group that has targeted educational institutions in the US.
- Sinobi criminal
- Sinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing…
- SkidSec hacktivist
- Also known as SkidSec Leaks. SkidSec is a threat group that has engaged in operations targeting exposed printers in South Korea to disseminate North Korean propaganda…
- Slingshot nation-state
- While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file…
- SlopAds criminal
- SlopAds is a sophisticated ad fraud and click fraud operation involving a collection of 224 apps, downloaded over 38 million times globally.
- SloppyLemming nation-state
- SloppyLemming is an advanced actor that uses multiple cloud service providers to facilitate different aspects of their activities, such as…
- Smishing Triad criminal
- The Smishing Triad is a Chinese-speaking threat group known for targeting postal services and their customers globally through smishing…
- SmugX nation-state
- The campaign, called SmugX, overlaps with previously reported activity by Chinese APT actors RedDelta and Mustang Panda.
- Snake Wine nation-state
- While investigating some of the smaller name servers that APT28/Sofacy routinely use to host their infrastructure, Cylance discovered…
- SneakyChef nation-state
- SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations…
- SnowSoul criminal
- SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily…
- Solntsepek nation-state
- Solntsepek is a threat actor group with ties to the Russian military unit GRU.
- SongXY nation-state
- SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns.
- Sowbug Espionage
- Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly…
- Sp1d3r criminal
- Sp1d3r, a threat actor, has been involved in multiple data breaches targeting companies like Truist Bank, Cylance, and Advance Auto Parts.
- SpaceBears criminal
- SpaceBears is a ransomware group believed to be based in Moscow, Russia, that has taken credit for several high-profile cyberattacks while…
- SparklingGoblin nation-state
- ESET researchers have discovered a new undocumented modular backdoor, SideWalk, being used by an APT group they’ve named SparklingGoblin…
- Star Blizzard nation-state
- Also known as SEABORGIUM, Callisto Group, TA446. Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019.
- Stargazer Goblin criminal
- Stargazer Goblin is a threat actor group that operates the Stargazers Ghost Network on GitHub, distributing malware and malicious links…
- Starry Addax hacktivist
- Starry Addax is a threat actor targeting human rights activists associated with the Sahrawi Arab Democratic Republic using a novel mobile…
- Stealth Falcon Espionage
- Also known as FruityArmor. Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since…
- Stealth Mango and Tangelo Espionage
- This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in…
- Stolen Pencil Espionage
- Also known as Velvet Chollima, Black Banshee, Thallium. Stolen Pencil is a threat group likely originating from DPRK that has been active since at least May 2018.
- Storm Cloud nation-state
- Storm Cloud is a Chinese espionage threat actor known for targeting organizations across Asia, particularly Tibetan organizations and…
- Storm-0062 nation-state
- Also known as Oro0lxy, DarkShadow. The cyberattack campaign that Microsoft uncovered was launched by a China-linked hacking group called Storm-0062.
- Storm-0249 criminal
- Also known as DEV-0249. Storm-0249 is an access broker active since 2021, known for distributing BazaLoader, IcedID, Bumblebee, and Emotet malware.
- Storm-0252
- Also known as CHATTY SPIDER. Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-0259 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-0288 criminal
- Also known as FIN8. Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-0324 criminal
- Also known as DEV-0324, Sagrid, TA543. The threat actor that Microsoft tracks as Storm-0324 is a financially motivated group known to gain initial access using email-based…
- Storm-0381 criminal
- Also known as DEV-0381. Storm-0381 is a threat actor identified by Microsoft as a Russian cybercrime group.
- Storm-0408 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-0473 nation-state
- Also known as UNC2849. Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019.
- Storm-0485 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-0494 criminal
- Storm-0494 is a threat actor that facilitates Gootloader infections, which are then exploited by groups like Vice Society to deploy tools…
- Storm-0501 criminal
- Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations.
- Storm-0506 criminal
- Storm-0506 (DEV-0506) is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta…
- Storm-0530 nation-state
- Also known as DEV-0530, H0lyGh0st. H0lyGh0st is a North Korean threat actor that has been active since June 2021.
- Storm-0539 criminal
- Storm-0539 is a financially motivated threat actor that has been active since at least 2021.
- Storm-0558 Espionage
- Storm-0558 is a China-based threat actor with espionage objectives.
- Storm-0569 criminal
- Microsoft threat actor profile. Origin/Threat: Financially motivated.
- Storm-0593 nation-state
- Also known as InvisiMole. Microsoft threat actor profile. Origin/Threat: Russia.
- Storm-0671 nation-state
- Also known as UNC2596, Tropicalscorpius. Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-0826 criminal
- Storm-0826 is a financially motivated cybercriminal group operating as an affiliate within the Black Basta ransomware-as-a-service (RaaS)…
- Storm-0829 criminal
- Also known as DEV-0829, Nwgen Team. Nwgen is a group that focuses on data exfiltration and ransomware activities.
- Storm-0835 criminal
- Cybercriminals have launched a phishing campaign targeting senior executives in U.S.
- Storm-0867 criminal
- Also known as DEV-0867. Storm-0867 is a threat actor that has been active since 2012 and has targeted various industries and regions.
- Storm-0940 nation-state
- Also known as CovertNetwork-1658, ORB07. Storm-0940 is a Chinese threat actor active since at least 2021, known for gaining initial access through password spray and brute-force…
- Storm-1044 criminal
- Also known as DEV-1044. Storm-1044 has been identified as part of a cyber campaign in collaboration with Twisted Spider.
- Storm-1084 nation-state
- Also known as DEV-1084. Storm-1084 is a threat actor that has been observed collaborating with the MuddyWater group.
- Storm-1099 nation-state
- Storm-1099 is a sophisticated Russia-affiliated influence actor that has been conducting pro-Russia influence operations targeting…
- Storm-1101 criminal
- Also known as DEV-1101. DEV-1101 is a threat actor tracked by Microsoft who is responsible for developing and advertising phishing kits, specifically AiTM…
- Storm-1113 criminal
- Also known as APOTHECARY SPIDER. Storm-1113 is a threat actor that acts both as an access broker focused on malware distribution through search advertisements and as an…
- Storm-1125 nation-state
- Also known as MoustachedBouncer. Microsoft threat actor profile. Origin/Threat: Belarus.
- Storm-1133 nation-state
- In early 2023, Microsoft In early 2023, observed a wave of activity from a Gaza-based group that we track as Storm-1133 targeting Israeli…
- Storm-1152 criminal
- Storm-1152, a cybercriminal group, was recently taken down by Microsoft for illegally reselling Outlook accounts.
- Storm-1167 criminal
- Also known as DEV-1167. Storm-1167 is a threat actor tracked by Microsoft, known for their use of an AiTM phishing kit.
- Storm-1175 criminal
- Storm-1175 is a cybercriminal group known for deploying Medusa ransomware and exploiting public-facing applications for initial access.
- Storm-1194 unknown
- Also known as MONTI. Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-1249 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-1283 criminal
- Storm-1283 is a threat actor that targeted Microsoft Azure cloud platform.
- Storm-1286 criminal
- Storm-1286 is a threat actor that engages in large-scale spamming activities, primarily targeting user accounts without multifactor…
- Storm-1295 criminal
- Also known as DEV-1295. Storm-1295 is a threat actor group that operates the Greatness phishing-as-a-service platform.
- Storm-1516 nation-state
- Also known as CopyCop. CopyCop is a Russian covert influence network that has established over 300 fictional media websites targeting the US, France, Canada, and…