Threat Actors page 9 of 12

1,118 threat actors profiled on the Maltiverse Threat Observatory, listed alphabetically. Each profile collects aliases, MITRE ATT&CK mapping, arsenal and campaigns, detection rules and the indicators of compromise attributed to it.

Storm-1567 criminal
Also known as PUNK SPIDER. Microsoft threat actor profile. Origin/Threat: Financially motivated.
Storm-1575 criminal
Storm-1575 is a threat actor identified by Microsoft as being involved in phishing campaigns using the Dadsec platform.
Storm-1607 unknown
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-1674 criminal
Storm-1674 is an access broker known for using tools based on the publicly available TeamsPhisher tool to distribute DarkGate malware.
Storm-1679 nation-state
Storm-1679 is a Russian disinformation group believed to be a spinoff of the Internet Research Agency, actively engaged in influence…
Storm-1747 criminal
Storm-1747 is an intrusion set that develops and operates the Tycoon 2FA phishing kit, which has been active since at least mid-2023 and…
Storm-1811 criminal
Also known as CURLY SPIDER. Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment.
Storm-1849 nation-state
Also known as UAT4356. UAT4356 is a state-sponsored threat actor that targeted government networks globally through a campaign named ArcaneDoor.
Storm-1865 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-1977 criminal
Storm-1977 is a sophisticated threat actor that conducts password-spraying attacks targeting cloud tenants, particularly in the education…
Storm-1982 nation-state
Also known as SneakyCheff, UNK_SweetSpecter. Microsoft threat actor profile. Origin/Threat: China.
Storm-2035 nation-state
Microsoft threat actor profile. Origin/Threat: Iran, Influence operations.
Storm-2077 nation-state
Also known as TAG-100, RedNovember. TAG-100 is a cyber-espionage APT that targets government and private sector organizations globally, exploiting vulnerabilities in…
Storm-2139 criminal
Storm-2139 is a cybercrime group that exploited stolen API keys from compromised Azure OpenAI Service accounts to generate harmful…
Storm-2227 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-2372 nation-state
Storm-2372 is a suspected nation-state actor aligned with Russian interests, engaging in device code phishing campaigns targeting…
Storm-2460 criminal
Also known as Lumma Stealer. Storm-2460 is a threat actor that has exploited elevation of privilege vulnerabilities to deploy PipeMagic malware and ransomware…
Storm-2470 nation-state
Microsoft threat actor profile. Origin/Threat: China.
Storm-2477 nation-state
Microsoft threat actor profile. Origin/Threat: Group in development.
Storm-2561 criminal
Storm-2561 is a cybercriminal threat actor known for a credential theft campaign that employs SEO poisoning to distribute fake VPN clients.
Storm-2603 nation-state
The group Microsoft tracks as Storm-2603 is assessed with medium confidence to be a China-based threat actor.
Storm-2657 criminal
Also known as Payroll Pirates. Storm-2657 is a financially motivated threat actor targeting US-based organizations, particularly in higher education, to compromise…
Storm-2755 criminal
Microsoft threat actor profile. Origin/Threat: Financially motivated.
Storm-2945
Storm-2945 is a sub-cluster of Midnight Blizzard conducting targeted traffic manipulation attacks on hospitality sector networks served by…
Storm-2949 nation-state
Storm-2949 is a sophisticated threat actor that exploited Microsoft’s Self-Service Password Reset process to compromise high-value…
Storm-2981 criminal
Also known as Coinbase Cartel. Microsoft threat actor profile. Origin/Threat: Group in development.
Strider Espionage
Also known as ProjectSauron, Sauron, Project Sauron. Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and…
StucxTeam hacktivist
Stucx is a threat actor known for targeting Israeli systems, including SCADA systems and the Red Alert missile protection system.
Suckfly nation-state
Also known as BRONZE OLIVE, Group 46. Suckfly is a China-based threat group that has been active since at least 2014.
Sunglow Blizzard nation-state
Also known as DEV-0665. DEV-0665 is a threat actor associated with the HermeticWiper attacks.
Swan Vector nation-state
Seqrite Labs APT-Team has recently uncovered a campaign which we have termed as Swan Vector, that has been targeting the nations across…
TA2101 criminal
Also known as Maze Team, TWISTED SPIDER, GOLD VILLAGE. Proofpoint researchers detected campaigns from a relatively new actor, tracked internally as TA2101, targeting German companies and…
TA2536 criminal
TA2536, which has been active since at least 2015, is likely Nigerian based on its unique linguistic style, tactics and tools.
TA2541 criminal
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries…
TA2552 criminal
Since January 2020, Proofpoint researchers have tracked an actor abusing Microsoft Office 365 (O365) third-party application (3PA) access…
TA2719 criminal
In late March 2020, Proofpoint researchers began tracking a new actor with a penchant for using NanoCore and later AsyncRAT, popular…
TA2722 criminal
Also known as Balikbayan Foxes. TA2722 is a highly active threat actor that targets various industries including Shipping/Logistics, Manufacturing, Business Services…
TA2723 criminal
TA2723 is a financially-motivated, high-volume credential phishing threat actor known for spoofing Microsoft OneDrive, LinkedIn, and…
TA2725 criminal
TA2725 is a threat actor that has been tracked since March 2022.
TA402 nation-state
TA402 is an APT group that has been tracked by Proofpoint since 2020.
TA406 nation-state
TA406 is engaging in malware distribution, phishing, intelligence collection, and cryptocurrency theft, resulting in a wide range of…
TA410 nation-state
Early in August 2019, Proofpoint described what appeared to be state-sponsored activity targeting the US utilities sector with malware…
TA428 nation-state
Also known as Colourful Panda, BRONZE DUDLEY. Proofpoint researchers have identified a targeted APT campaign that utilized malicious RTF documents to deliver custom malware to…
TA444 nation-state
TA444 is a North Korea state-sponsored threat actor that primarily focuses on financially motivated operations.
TA453 nation-state
TA453 has employed the use of compromised accounts, malware, and confrontational lures to go after targets with a range of backgrounds…
TA455 nation-state
TA455 is an Iranian APT group targeting the aerospace industry through a campaign known as the “Iranian Dream Job Campaign,” utilizing…
TA459 nation-state
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
TA482 nation-state
Since early 2022, Proofpoint researchers have observed a prolific threat actor, tracked as TA482, regularly engaging in credential…
TA4903 criminal
TA4903 is a financially motivated threat actor known for conducting credential phishing and business email compromise campaigns.
TA4922 criminal
TA4922 is a Chinese-speaking cybercrime cluster that employs localized HR, payroll, tax, and invoice lures to deliver various malware…
TA499 nation-state
Also known as Vovan, Lexus. TA499, also known as Vovan and Lexus, is a Russia-aligned threat actor that has aggressively engaged in email campaigns since at least 2021.
TA505 criminal
Also known as Hive0065, Spandex Tempest, CHIMBORAZO. TA505 is a cyber criminal group that has been active since at least 2014.
TA516 criminal
This actor typically distributes instances of the SmokeLoader intermediate downloader, which, in turn, downloads additional malware of the…
TA530 criminalnation-state
TA530, who we previously examined in relation to large-scale personalized phishing campaigns
TA547 criminal
TA547 is responsible for many other campaigns since at least November 2017.
TA551 criminal
Also known as GOLD CABIN, Shathak, Shakthak. TA551 is a financially-motivated threat group that has been active since at least 2018.
TA554 criminal
Also known as TH-163. Since May 2018, Proofpoint researchers have observed email campaigns using a new downloader called sLoad.
TA555 criminal
Beginning in May 2018, Proofpoint researchers observed a previously undocumented downloader dubbed AdvisorsBot appearing in malicious…
TA558 criminal
Since 2018, security researchers tracked a financially-motivated cybercrime actor, TA558, targeting hospitality, travel, and related…
TA570 criminal
Also known as DEV-0450. One of the most active Qbot malware affiliates, Proofpoint has tracked the large cybercrime threat actor TA570 since 2018.
TA571 criminal
TA571 is a spam distributor actor known for delivering a variety of malware, including DarkGate, NetSupport RAT, and information stealers.
TA575 criminal
TA575 is a Dridex affiliate tracked by Proofpoint since late 2020.
TA577 criminal
Also known as Hive0118. TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing…
TA578 criminal
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including…
TA579 criminal
TA579, a threat actor that Proofpoint researchers have been tracking since August 2021.
TA584 criminal
Also known as Storm-0900. TA584 is a prominent initial access broker tracked by Proofpoint since November 2020, known for its high-volume campaigns targeting…
TA800 criminal
This attacker is an affiliate distributor of the The Trick, also known as Trickbot, and BazaLoader.
TA829 nation-state
TA829 is a Russia-aligned threat actor that employs the RomCom RAT for intelligence-gathering and financially motivated cyberattacks…
TA866 Financial Theft
According to Proofpoint, TA866 is a newly identified threat actor that distributes malware via email utilizing both commodity and custom…
TAG-112 nation-state
TAG-112 is a Chinese state-sponsored APT that compromised Tibetan websites, including Tibet Post and Gyudmed Tantric University, to…
TAG-124 criminal
Also known as LandUpdate808. TAG-124 is a threat actor that employs a traffic distribution system to distribute malware, primarily using MintsLoader and targeting…
TAG-140 nation-state
TAG-140 is a threat actor group that primarily targets Indian government entities, employing cyber espionage tactics such as phishing and…
TAG-28 nation-state
TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and…
TAG-56 nation-state
TAG-56 is a threat actor group that shares similarities with the APT42 group.
TEMP.Hermit nation-state
TEMP.Hermit is a suspected North Korean threat actor linked to cyber-espionage campaigns.
TEMP.Veles nation-state
Also known as XENOTIME, Xenotime, ATK91. TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure.
TEMP_Heretic nation-state
TEMP_Heretic is a threat actor that has been observed engaging in targeted spear-phishing campaigns.
TERBIUM nation-state
Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of…
TEST PANDA nation-state
Test Panda is a suspected China-based threat actor group involved in cyber espionage operations targeting government, technology, and…
TIDRONE nation-state
Also known as Earth Ammit, VENOM. TIDRONE is an unidentified threat actor linked to Chinese-speaking groups, with a focus on military-related industry chains, particularly…
TINY SPIDER criminal
According to CrowdStrike, this actor is using TinyLoader and TinyPOS, potentially buying access through Dridex infections.
TOXCAR CYBER TEAM criminal
The Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S.
TOXIC PANDA nation-state
A group targeting dissident groups in China and at the boundaries.
TRACER KITTEN nation-state
In April 2020, Crowstrike Falcon OverWatch discovered Iran-based adversary TRACER KITTEN conducting malicious interactive activity against…
TRAVELING SPIDER criminal
Crowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER.
TRIPLESTRENGTH criminal
TRIPLESTRENGTH is a financially motivated threat actor targeting cloud environments and on-premises infrastructures for cryptojacking…
Taidoor
Also known as Earth Aughisky. Taidoor has been deprecated, as the only technique it was linked to was deprecated in ATT&CK v7.
Taizi Flood nation-state
Also known as Dragonbridge, Spamouflage. Microsoft threat actor profile. Origin/Threat: China, Influence operations.
TaskMasters nation-state
Also known as BlueTraveller. TaskMasters is a state-sponsored Chinese APT that has been active since at least 2010, primarily targeting industrial, energy, and…
Team-Xecuter criminal
Team-Xecuter is a hacking group led by Gary Bowser, also known as GaryOPA.
Team46 nation-state
Also known as TaxOff. Team46 is a sophisticated APT group active since at least late 2024, targeting Russian government, academic, and media organizations…
TeamPCP criminal
Also known as Altered Spider, PCPCat, ShellForce. TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025.
TeamSpy Crew Espionage
Also known as TeamSpy, Team Bear, Anger Bear. Researchers have uncovered a long-term cyber-espionage campaign that used a combination of legitimate software packages and commodity…
TeamTNT criminal
Also known as Adept Libra. TeamTNT is a threat group that has primarily targeted cloud and containerized environments.
TeamXRat criminal
Also known as CorporacaoXRat, CorporationXRat. TeamXRat, also known as CorporacaoXRat or CorporationXRat, is a criminal group primarily targeting the financial sector in Brazil.
Teleboyi nation-state
Teleboyi is a threat actor reportedly based in China, associated with the PlugX RAT.
TempTick nation-state
This threat actor targets organizations in the finance, defense, aerospace, technology, health-care, and automotive sectors and media…
TetrisPhantom nation-state
TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by…
The Big Bang unknown
While it is not clear exactly what the attacker is looking for, what is clear is that once he finds it, a second stage of the attack…
The Gentlemen criminal
The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical…