https://www.cybeta.io/
Cybeta | Blending Data Science with a Threat Actor Mindset
Cybeta generates predictive analytics about the likelihood of future cyber events while delivering actionable intelligence on pre-attack infrastructure and...
data sciencethreat actorblendingmindset
https://cloud.google.com/blog/topics/threat-intelligence/apt37-overlooked-north-korean-actor
APT37 (Reaper) | The Overlooked North Korean Threat Actor | Google Cloud Blog
APT37's recent activity reveals that the group's operations are expanding in scope and sophistication
north koreanthreat actorgoogle cloudreaperoverlooked
https://thehackernews.com/2023/05/vietnamese-threat-actor-infects-500000.html?m=1
Vietnamese Threat Actor Infects 500,000 Devices Using 'Malverposting' Tactics
A Vietnamese threat actor has infected over 500,000 devices worldwide with malware through a 'malverposting' campaign on social media platforms.
threat actorvietnamesedevicesusingtactics
https://feedly.com/new-features/posts/know-your-enemy-collect-and-share-threat-actor-intelligence
Know your enemy: Collect and share threat actor intelligence | Feedly
Sep 12, 2023 - Collect, analyze, and share threat actor intelligence 7X faster than alternative searches.
know your enemythreat actor intelligencecollectsharefeedly
https://thehackernews.com/2023/05/vietnamese-threat-actor-infects-500000.html?m=0
Vietnamese Threat Actor Infects 500,000 Devices Using 'Malverposting' Tactics
A Vietnamese threat actor has infected over 500,000 devices worldwide with malware through a 'malverposting' campaign on social media platforms.
threat actorvietnamesedevicesusingtactics
https://0x3obad.github.io/posts/payload-ransomware-writeup/
Payload Threat Actor Ransomware | 0x3oBAD
Apr 5, 2026 - Deep Technical Analysis Of Payload Ransomware
threat actorpayloadransomware
https://docs.feedly.com/article/780-discovering-threat-actor-insights-cards-in-the-ttp-agent-feedly
Discovering Threat Actor Insights Cards in the TTP Agent - Feedly Documentation
One of the most powerful features of the TTP Agent is the ability to pivot directly from TTPs into Threat Actor Insights Cards. This embedded intelligence layer
threat actorin thediscoveringinsightscards
https://developers.feedly.com/reference/get-threat-actor-metadata
Get Threat Actor Metadata
Retrieves metadata and details about a specific threat actor.
threat actorgetmetadata
https://www.proofpoint.com/au/blog/threat-insight/threat-actor-abuses-cloudflare-tunnels-deliver-rats
Threat Actor Abuses Cloudflare Tunnels to Deliver RATs | Proofpoint AU
Aug 1, 2024 - Key findings Proofpoint has observed an increase in malware delivery via TryCloudflare Tunnel abuse. The activity is financially motivated and delivers...
threat actorcloudflare tunnelsabusesdeliverrats
https://thegoldenmessenger.blogspot.com/2016/06/new-threat-actor-uses-vba-macros-in.html
New threat actor uses VBA macros in targeted attacks ~ Malware Reversing
In recent years, the revival of malicious VBA macros has become quite popular among cyber criminals. At the beginning of last year, a new th...
threat actorvba macrosnewuses
https://riskybiznews.substack.com/p/risky-biz-news-threat-actor-stole
Risky Biz News: Threat actor stole data for 100,000 npm users
In other news: New Office zero-day; Russia test VPN ban; and FIDO2 security flaws.
biz newsthreat actor
https://dpo.hku.hk/news/deloitte%3A-threat-actor-intelbroker-allegedly-claims-leak-of-deloitte-internal-communications
Deloitte: Threat Actor IntelBroker Allegedly Claims Leak of Deloitte Internal Communications
threat actordeloitteallegedlyclaimsleak
https://thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html?ref=x64.onl
New Threat Actor 'Void Arachne' Targets Chinese Users with Malicious VPN Installers
Discover the latest cybersecurity threat targeting Chinese-speaking users with malicious VPN installers and AI-driven malware campaigns.
threat actor
https://apt.etda.or.th/cgi-bin/showcard.cgi?g=Mustang%20Panda%2C%20Bronze%20President&n=1
Mustang Panda, Bronze President - Threat Group Cards: A Threat Actor Encyclopedia
mustang pandagroup cardsbronzepresidentthreat
https://malpedia.caad.fkie.fraunhofer.de/actor/ruby_sleet
Ruby Sleet (Threat Actor)
Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices,...
rubysleetthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/uta0352
UTA0352 (Threat Actor)
UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/gnosticplayers
Gnosticplayers (Threat Actor)
The hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt....
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/test_panda
TEST PANDA (Threat Actor)
Details for the TEST PANDA threat actor (from the MISP Galaxy Project).
testpandathreatactor
https://github.com/MISP/threat-actor-intelligence-server
GitHub - MISP/threat-actor-intelligence-server: A simple ReST server to lookup threat actors (by...
A simple ReST server to lookup threat actors (by name, synonym or UUID) and returning the corresponding MISP galaxy information about the known threat actors....
threat actor intelligence
https://malpedia.caad.fkie.fraunhofer.de/actor/cleaver
Cleaver (Threat Actor)
A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S....
cleaverthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/gold_rebellion
GOLD REBELLION (Threat Actor)
GOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware. The group posted its first victim...
goldrebellionthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/lucky_cat
Lucky Cat (Threat Actor)
A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to...
lucky catthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/cyber_alliance
Cyber Alliance (Threat Actor)
The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of Ukraine in 2022. They...
cyberalliancethreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/scarred_manticore
Scarred Manticore (Threat Actor)
Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety...
scarredmanticorethreatactor
https://unit42.paloaltonetworks.com/popping-eagle-malware/?pdf=print&lg=en&_wpnonce=9ce32c3677
Popping Eagle: How Global Analytics Uncovered a Stealthy Threat Actor
Jun 5, 2024 - We observed a specially crafted DLL hijacking attack used by a previously unknown piece of malware that we dubbed Popping Eagle.
global analyticspoppingeagleuncoveredstealthy
https://malpedia.caad.fkie.fraunhofer.de/actor/greenbug
Greenbug (Threat Actor)
Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government, investment, and...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/silent_librarian
Silent Librarian (Threat Actor)
Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute....
silentlibrarianthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/gold_southfield
GOLD SOUTHFIELD (Threat Actor)
GOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various...
goldsouthfieldthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/chaya_004
Chaya_004 (Threat Actor)
Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell backdoors and various pen...
chayathreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/apt19
APT19 (Threat Actor)
Adversary group targeting financial, technology, non-profit organisations.
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/earth_krahang
Earth Krahang (Threat Actor)
Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors...
earththreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/cyber_caliphate_army
Cyber Caliphate Army (Threat Actor)
Details for the Cyber Caliphate Army threat actor (from the MISP Galaxy Project).
cybercaliphatearmythreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/vicioustrap
ViciousTrap (Threat Actor)
ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to redirect incoming traffic...
threatactor
https://dmpdump.github.io/posts/Low_Detection_backdoor_NHAS_RSSH/
Likely Chinese Threat Actor Uses Low Detection Linux Backdoor and NHAS Reverse SSH | dmpdump
May 1, 2025 - On April 22, 2025, MalwareHunterTeam shared a hash for a low detection Linux ELF with 2 hard-coded IP addresses: 43.159.18[.]135 and 119.42.148[.]187. Upon...
https://malpedia.caad.fkie.fraunhofer.de/actor/oilrig
OilRig (Threat Actor)
OilRig is an Iranian threat group operating primarily in the Middle East by targeting organizations in this region that are in a variety of different...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/toxcar_cyber_team
TOXCAR CYBER TEAM (Threat Actor)
The Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing...
cyber teamthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/unc4990
UNC4990 (Threat Actor)
UNC4990 is a financially motivated threat actor that has been active since at least 2020. They primarily target users in Italy and rely on USB devices for...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/krybit
Krybit (Threat Actor)
Krybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/scully_spider
SCULLY SPIDER (Threat Actor)
Mentioned as operator of DanaBot in CrowdStrike's 2020 Report.
scullyspiderthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/flyingyeti
FlyingYeti (Threat Actor)
FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/camaro_dragon
Camaro Dragon (Threat Actor)
In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of...
camarodragonthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/apt16
APT16 (Threat Actor)
Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/markopolo
Markopolo (Threat Actor)
Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog...
markopolothreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/apt15
APT15 (Threat Actor)
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/evilbyte
Evilbyte (Threat Actor)
EvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation...
threatactor
https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools?hl=en
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog
Google Threat Intelligence Group's findings on adversarial misuse of AI, including Gemini and other non-Google tools.
https://techcommunity.microsoft.com/discussions/microsoft-security/new-blog-post--threat-actor-dev-0322-exploiting-zoho-manageengine-adselfservice-/2943858
New Blog Post | Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus | Microsoft...
Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus - Microsoft Security Blog Microsoft has detected exploits being used to compromise...
new blog post
https://malpedia.caad.fkie.fraunhofer.de/actor/linkc_pub
LinkC Pub (Threat Actor)
Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider,...
linkcpubthreatactor
https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/?pdf=print&lg=en&_wpnonce=99541e2cbe
Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)
Aug 1, 2025 - A comprehensive list of threat actor groups tracked by Unit 42, along with information such as summaries and industries typically impacted.
https://malpedia.caad.fkie.fraunhofer.de/actor/moskalvzapoe
Moskalvzapoe (Threat Actor)
Details for the Moskalvzapoe threat actor (from the MISP Galaxy Project).
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/thrip
Thrip (Threat Actor)
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and...
thripthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/resumelooters
ResumeLooters (Threat Actor)
Since the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites. The group employs a variety of simple techniques, including SQL...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/purplehaze
PurpleHaze (Threat Actor)
PurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors such as...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/worok
Worok (Threat Actor)
Worok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/caracal_kitten
Caracal Kitten (Threat Actor)
Caracal Kitten is an APT group that has been targeting activists associated with the Kurdistan Democratic Party. They employ a mobile remote access Trojan to...
caracalkittenthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/blue_termite
Blue Termite (Threat Actor)
Blue Termite is a group of suspected Chinese origin active in Japan.
bluetermitethreatactor
https://cybersecuritytoday.libsyn.com/cyber-security-today-march-25-2024-a-suspected-china-threat-actor-going-after-unpatched-f5-and-screenconnet-installations
Cybersecurity Today: Cyber Security Today, March 25, 2024 - A suspected China threat actor going...
This episode reports on a new campaign stealing email passwords, the latest data breaches, and more
https://malpedia.caad.fkie.fraunhofer.de/actor/ukrainian_cyber_alliance
Ukrainian Cyber Alliance (Threat Actor)
Cyber Alliance is a hacktivist group that has demonstrated capabilities in exploiting vulnerabilities, such as CVE-2023-22515 in Confluence, to escalate...
ukrainiancyberalliancethreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/grayling
Grayling (Threat Actor)
Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling...
graylingthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/uta0178
UTA0178 (Threat Actor)
While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the...
threatactor
https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/?pdf=download&lg=en&_wpnonce=d4b794fb6b
Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack
Nov 18, 2025 - A nation-state attacker is using novel Airstalk malware in supply chain attacks to exfiltrate browser data. Airstalk misuses the AirWatch API.
https://malpedia.caad.fkie.fraunhofer.de/actor/sweed
SWEED (Threat Actor)
Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we're calling "SWEED," including such notable...
sweedthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/apt6
APT6 (Threat Actor)
The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems as far back as 2011...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/lazarus_group
Lazarus Group (Threat Actor)
Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the...
lazarus groupthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/handala
Handala (Threat Actor)
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive...
handalathreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/ghostr
GhostR (Threat Actor)
Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/ghost_jackal
Ghost Jackal (Threat Actor)
Details for the Ghost Jackal threat actor (from the MISP Galaxy Project).
ghostjackalthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/operation_soft_cell
Operation Soft Cell (Threat Actor)
In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor...
soft celloperationthreatactor
https://anchorednarratives.substack.com/p/trouble-in-asia-and-the-middle-east
Trouble in Asia and the Middle East. Tracking the TransparentTribe threat actor.
A case study into a threat actor that is likely originating from Pakistan which is leveraging CrimsonRat and malicious documents to control their targets.
asia and the middle easttrouble
https://malpedia.caad.fkie.fraunhofer.de/actor/unc5537
UNC5537 (Threat Actor)
UNC5537 is a financially motivated threat actor targeting Snowflake customer databases. They use stolen credentials obtained from infostealer malware to access...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/red_dev_17
Red Dev 17 (Threat Actor)
In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat...
reddevthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/apt28
APT28 (Threat Actor)
The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/carderbee
Carderbee (Threat Actor)
Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/red_nue
Red Nue (Threat Actor)
Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows...
rednuethreatactor
https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/?pdf=print&lg=en&_wpnonce=e3725c6bf3
Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)
Aug 1, 2025 - A comprehensive list of threat actor groups tracked by Unit 42, along with information such as summaries and industries typically impacted.
https://www.thenationalnews.com/world/new-threat-to-saudi-arabia-comes-from-two-fronts-and-one-actor-iran-1.910654
New threat to Saudi Arabia comes from two fronts and one actor - Iran | The National
Jul 5, 2021 - Strikes on oil plants part of a wider Iranian strategy with several objectives
https://malpedia.caad.fkie.fraunhofer.de/actor/tetrisphantom
TetrisPhantom (Threat Actor)
TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations....
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/storm-0506
Storm-0506 (Threat Actor)
Storm-0506 (DEV-0506) is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta ransomware-as-a-service (RaaS)...
stormthreatactor
https://www.bitdefender.com/en-us/blog/businessinsights/alleged-north-korean-threat-actor-targets-select-victims-with-another-critical-zero-day-vulnerability-attack
Alleged North Korean Threat Actor Targets Select Victims with another Critical Zero-Day...
Attributing cyberattacks and advanced malware to a particular country or entity is usually troublesome.
https://malpedia.caad.fkie.fraunhofer.de/actor/hexagonalrodent
HexagonalRodent (Threat Actor)
HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/mallard_spider
MALLARD SPIDER (Threat Actor)
Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
mallardspiderthreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/hive-0145
HIVE-0145 (Threat Actor)
Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware to target email...
hivethreatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/muddywater
MuddyWater (Threat Actor)
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/chernovite
Chernovite (Threat Actor)
Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM. They are known for...
threatactor
https://malpedia.caad.fkie.fraunhofer.de/actor/dalbit
Dalbit (Threat Actor)
The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of...
threatactor
https://www.indiatoday.in/entertainment/television/story/asim-riaz-slams-abhinav-shukla-death-threat-lawrence-bishnoi-gang-rubina-dilaik-spat-battleground-2711951-2025-04-21
Asim Riaz's rebuttal to actor Abhinav Shukla after the latter receives death threat from Lawrence...
Apr 21, 2025 - Amidst a heated controversy, rapper Asim Riaz has addressed actor Abhinav Shukla's claims of receiving death threats from an alleged Lawrence Bishnoi gang...
https://malpedia.caad.fkie.fraunhofer.de/actor/vicious_panda
Vicious Panda (Threat Actor)
Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus scare, in order to deliver...
viciouspandathreatactor