Threat Actors page 9 of 12
1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.
- Storm-1567 criminal
- Also known as PUNK SPIDER. Microsoft threat actor profile. Origin/Threat: Financially motivated.
- Storm-1575 criminal
- Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform.
- Storm-1607 unknown
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-1674 criminal
- Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware.
- Storm-1679 nation-state
- Storm-1679 is a Russian disinformation group believed to be a spinoff of the Internet Research Agency, actively engaged in influence…
- Storm-1747 criminal
- Storm-1747 is an intrusion set that develops and operates the Tycoon 2FA phishing kit, which has been active since at least mid-2023 and…
- Storm-1811 criminal
- Also known as CURLY SPIDER. Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment.
- Storm-1849 nation-state
- Also known as UAT4356. UAT4356 is a state-sponsored threat actor that targeted government networks globally through a campaign named ArcaneDoor.
- Storm-1865 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-1977 criminal
- Storm-1977 is a sophisticated threat actor that conducts password-spraying attacks targeting cloud tenants, particularly in the education…
- Storm-1982 nation-state
- Also known as SneakyCheff, UNK_SweetSpecter. Microsoft threat actor profile. Origin/Threat: China.
- Storm-2035 nation-state
- Microsoft threat actor profile. Origin/Threat: Iran, Influence operations.
- Storm-2077 nation-state
- Also known as TAG-100, RedNovember. TAG-100 is a cyber-espionage APT that targets government and private sector organizations globally, exploiting vulnerabilities in…
- Storm-2139 criminal
- Storm-2139 is a cybercrime group that exploited stolen API keys from compromised Azure OpenAI Service accounts to generate harmful…
- Storm-2227 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-2372 nation-state
- Storm-2372 is a suspected nation-state actor aligned with Russian interests, engaging in device code phishing campaigns targeting…
- Storm-2460 criminal
- Also known as Lumma Stealer. Storm-2460 is a threat actor that has exploited elevation of privilege vulnerabilities to deploy PipeMagic malware and ransomware…
- Storm-2470 nation-state
- Microsoft threat actor profile. Origin/Threat: China.
- Storm-2477 nation-state
- Microsoft threat actor profile. Origin/Threat: Group in development.
- Storm-2561 criminal
- Storm-2561 is a cybercriminal threat actor known for a credential theft campaign that employs SEO poisoning to distribute fake VPN clients.
- Storm-2603 nation-state
- The group Microsoft tracks as Storm-2603 is assessed with medium confidence to be a China-based threat actor.
- Storm-2657 criminal
- Also known as Payroll Pirates. Storm-2657 is a financially motivated threat actor targeting US-based organizations, particularly in higher education, to compromise…
- Storm-2755 criminal
- Microsoft threat actor profile. Origin/Threat: Financially motivated.
- Storm-2945
- Storm-2945 is a sub-cluster of Midnight Blizzard conducting targeted traffic manipulation attacks on hospitality sector networks served by…
- Storm-2949 nation-state
- Storm-2949 is a sophisticated threat actor that exploited Microsoft’s Self-Service Password Reset process to compromise high-value…
- Storm-2981 criminal
- Also known as Coinbase Cartel. Microsoft threat actor profile. Origin/Threat: Group in development.
- Strider Espionage
- Also known as ProjectSauron, Sauron, Project Sauron. Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and…
- StucxTeam hacktivist
- Stucx is a threat actor known for targeting Israeli systems, including SCADA systems and the Red Alert missile protection system.
- Suckfly nation-state
- Also known as BRONZE OLIVE, Group 46. Suckfly is a China-based threat group that has been active since at least 2014.
- Sunglow Blizzard nation-state
- Also known as DEV-0665. DEV-0665 is a threat actor associated with the HermeticWiper attacks.
- Swan Vector nation-state
- Seqrite Labs APT-Team has recently uncovered a campaign which we have termed as Swan Vector, that has been targeting the nations across…
- TA2101 criminal
- Also known as Maze Team, TWISTED SPIDER, GOLD VILLAGE. Proofpoint researchers detected campaigns from a relatively new actor, tracked internally as TA2101, targeting German companies and…
- TA2536 criminal
- TA2536, which has been active since at least 2015, is likely Nigerian based on its unique linguistic style, tactics and tools.
- TA2541 criminal
- TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries…
- TA2552 criminal
- Since January 2020, Proofpoint researchers have tracked an actor abusing Microsoft Office 365 (O365) third-party application (3PA) access…
- TA2719 criminal
- In late March 2020, Proofpoint researchers began tracking a new actor with a penchant for using NanoCore and later AsyncRAT, popular…
- TA2722 criminal
- Also known as Balikbayan Foxes. TA2722 is a highly active threat actor that targets various industries including Shipping/Logistics, Manufacturing, Business Services…
- TA2723 criminal
- TA2723 is a financially-motivated, high-volume credential phishing threat actor known for spoofing Microsoft OneDrive, LinkedIn, and…
- TA2725 criminal
- TA2725 is a threat actor that has been tracked since March 2022.
- TA402 nation-state
- TA402 is an APT group that has been tracked by Proofpoint since 2020.
- TA406 nation-state
- TA406 is engaging in malware distribution, phishing, intelligence collection, and cryptocurrency theft, resulting in a wide range of…
- TA410 nation-state
- Early in August 2019, Proofpoint described what appeared to be state-sponsored activity targeting the US utilities sector with malware…
- TA428 nation-state
- Also known as Colourful Panda, BRONZE DUDLEY. Proofpoint researchers have identified a targeted APT campaign that utilized malicious RTF documents to deliver custom malware to…
- TA444 nation-state
- TA444 is a North Korea state-sponsored threat actor that primarily focuses on financially motivated operations.
- TA453 nation-state
- TA453 has employed the use of compromised accounts, malware, and confrontational lures to go after targets with a range of backgrounds…
- TA455 nation-state
- TA455 is an Iranian APT group targeting the aerospace industry through a campaign known as the “Iranian Dream Job Campaign,” utilizing…
- TA459 nation-state
- TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
- TA482 nation-state
- Since early 2022, Proofpoint researchers have observed a prolific threat actor, tracked as TA482, regularly engaging in credential…
- TA4903 criminal
- TA4903 is a financially motivated threat actor known for conducting credential phishing and business email compromise campaigns.
- TA4922 criminal
- TA4922 is a Chinese-speaking cybercrime cluster that employs localized HR, payroll, tax, and invoice lures to deliver various malware…
- TA499 nation-state
- Also known as Vovan, Lexus. TA499, also known as Vovan and Lexus, is a Russia-aligned threat actor that has aggressively engaged in email campaigns since at least 2021.
- TA505 criminal
- Also known as Hive0065, Spandex Tempest, CHIMBORAZO. TA505 is a cyber criminal group that has been active since at least 2014.
- TA516 criminal
- This actor typically distributes instances of the SmokeLoader intermediate downloader, which, in turn, downloads additional malware of the…
- TA530 criminalnation-state
- TA530, who we previously examined in relation to large-scale personalized phishing campaigns
- TA547 criminal
- TA547 is responsible for many other campaigns since at least November 2017.
- TA551 criminal
- Also known as GOLD CABIN, Shathak, Shakthak. TA551 is a financially-motivated threat group that has been active since at least 2018.
- TA554 criminal
- Also known as TH-163. Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad.
- TA555 criminal
- Beginning in May 2018, Proofpoint researchers observed a previously undocumented downloader dubbed AdvisorsBot appearing in malicious…
- TA558 criminal
- Since 2018, security researchers tracked a financially-motivated cybercrime actor, TA558, targeting hospitality, travel, and related…
- TA570 criminal
- Also known as DEV-0450. One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.
- TA571 criminal
- TA571 is a spam distributor actor known for delivering a variety of malware, including DarkGate, NetSupport RAT, and information stealers.
- TA575 criminal
- TA575 is a Dridex affiliate tracked by Proofpoint since late 2020.
- TA577 criminal
- Also known as Hive0118. TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing…
- TA578 criminal
- TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including…
- TA579 criminal
- TA579, a threat actor that Proofpoint researchers have been tracking since August 2021.
- TA584 criminal
- Also known as Storm-0900. TA584 is a prominent initial access broker tracked by Proofpoint since November 2020, known for its high-volume campaigns targeting…
- TA800 criminal
- This attacker is an affiliate distributor of the The Trick, also known as Trickbot, and BazaLoader.
- TA829 nation-state
- TA829 is a Russia-aligned threat actor that employs the RomCom RAT for intelligence-gathering and financially motivated cyberattacks…
- TA866 Financial Theft
- According to Proofpoint, TA866 is a newly identified threat actor that distributes malware via email utilizing both commodity and custom…
- TAG-112 nation-state
- TAG-112 is a Chinese state-sponsored APT that compromised Tibetan websites, including Tibet Post and Gyudmed Tantric University, to…
- TAG-124 criminal
- Also known as LandUpdate808. TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting…
- TAG-140 nation-state
- TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and…
- TAG-28 nation-state
- TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and…
- TAG-56 nation-state
- TAG-56 is a threat actor group that shares similarities with the APT42 group.
- TEMP.Hermit nation-state
- TEMP.Hermit is a suspected North Korean threat actor linked to cyber-espionage campaigns.
- TEMP.Veles nation-state
- Also known as XENOTIME, Xenotime, ATK91. TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure.
- TEMP_Heretic nation-state
- TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns.
- TERBIUM nation-state
- Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of…
- TEST PANDA nation-state
- Test Panda is a suspected China-based threat actor group involved in cyber espionage operations targeting government, technology, and…
- TIDRONE nation-state
- Also known as Earth Ammit, VENOM. TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly…
- TINY SPIDER criminal
- According to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
- TOXCAR CYBER TEAM criminal
- The Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S.
- TOXIC PANDA nation-state
- A group targeting dissident groups in China and at the boundaries.
- TRACER KITTEN nation-state
- In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against…
- TRAVELING SPIDER criminal
- Crowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER.
- TRIPLESTRENGTH criminal
- TRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking…
- Taidoor
- Also known as Earth Aughisky. Taidoor has been deprecated, as the only technique it was linked to was deprecated in ATT&CK v7.
- Taizi Flood nation-state
- Also known as Dragonbridge, Spamouflage. Microsoft threat actor profile. Origin/Threat: China, Influence operations.
- TaskMasters nation-state
- Also known as BlueTraveller. TaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and…
- Team-Xecuter criminal
- Team-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA.
- Team46 nation-state
- Also known as TaxOff. Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations…
- TeamPCP criminal
- Also known as Altered Spider, PCPCat, ShellForce. TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025.
- TeamSpy Crew Espionage
- Also known as TeamSpy, Team Bear, Anger Bear. Researchers have uncovered a long-term cyber-espionage campaign that used a combination of legitimate software packages and commodity…
- TeamTNT criminal
- Also known as Adept Libra. TeamTNT is a threat group that has primarily targeted cloud and containerized environments.
- TeamXRat criminal
- Also known as CorporacaoXRat, CorporationXRat. TeamXRat, also known as CorporacaoXRat or CorporationXRat, is a criminal group primarily targeting the financial sector in Brazil.
- Teleboyi nation-state
- Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT.
- TempTick nation-state
- This threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media…
- TetrisPhantom nation-state
- TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by…
- The Big Bang unknown
- While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack…
- The Gentlemen criminal
- The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical…