Robuta

https://www.cybeta.io/ Cybeta | Blending Data Science with a Threat Actor Mindset Cybeta generates predictive analytics about the likelihood of future cyber events while delivering actionable intelligence on pre-attack infrastructure and... data sciencethreat actorblendingmindset https://cloud.google.com/blog/topics/threat-intelligence/apt37-overlooked-north-korean-actor APT37 (Reaper) | The Overlooked North Korean Threat Actor | Google Cloud Blog APT37's recent activity reveals that the group's operations are expanding in scope and sophistication north koreanthreat actorgoogle cloudreaperoverlooked https://thehackernews.com/2023/05/vietnamese-threat-actor-infects-500000.html?m=1 Vietnamese Threat Actor Infects 500,000 Devices Using 'Malverposting' Tactics A Vietnamese threat actor has infected over 500,000 devices worldwide with malware through a 'malverposting' campaign on social media platforms. threat actorvietnamesedevicesusingtactics https://feedly.com/new-features/posts/know-your-enemy-collect-and-share-threat-actor-intelligence Know your enemy: Collect and share threat actor intelligence | Feedly Sep 12, 2023 - Collect, analyze, and share threat actor intelligence 7X faster than alternative searches. know your enemythreat actor intelligencecollectsharefeedly https://thehackernews.com/2023/05/vietnamese-threat-actor-infects-500000.html?m=0 Vietnamese Threat Actor Infects 500,000 Devices Using 'Malverposting' Tactics A Vietnamese threat actor has infected over 500,000 devices worldwide with malware through a 'malverposting' campaign on social media platforms. threat actorvietnamesedevicesusingtactics https://0x3obad.github.io/posts/payload-ransomware-writeup/ Payload Threat Actor Ransomware | 0x3oBAD Apr 5, 2026 - Deep Technical Analysis Of Payload Ransomware threat actorpayloadransomware https://docs.feedly.com/article/780-discovering-threat-actor-insights-cards-in-the-ttp-agent-feedly Discovering Threat Actor Insights Cards in the TTP Agent - Feedly Documentation One of the most powerful features of the TTP Agent is the ability to pivot directly from TTPs into Threat Actor Insights Cards. This embedded intelligence layer threat actorin thediscoveringinsightscards https://developers.feedly.com/reference/get-threat-actor-metadata Get Threat Actor Metadata Retrieves metadata and details about a specific threat actor. threat actorgetmetadata https://www.proofpoint.com/au/blog/threat-insight/threat-actor-abuses-cloudflare-tunnels-deliver-rats Threat Actor Abuses Cloudflare Tunnels to Deliver RATs | Proofpoint AU Aug 1, 2024 - Key findings Proofpoint has observed an increase in malware delivery via TryCloudflare Tunnel abuse. The activity is financially motivated and delivers... threat actorcloudflare tunnelsabusesdeliverrats https://thegoldenmessenger.blogspot.com/2016/06/new-threat-actor-uses-vba-macros-in.html New threat actor uses VBA macros in targeted attacks ~ Malware Reversing In recent years, the revival of malicious VBA macros has become quite popular among cyber criminals. At the beginning of last year, a new th... threat actorvba macrosnewuses https://riskybiznews.substack.com/p/risky-biz-news-threat-actor-stole Risky Biz News: Threat actor stole data for 100,000 npm users In other news: New Office zero-day; Russia test VPN ban; and FIDO2 security flaws. biz newsthreat actor https://dpo.hku.hk/news/deloitte%3A-threat-actor-intelbroker-allegedly-claims-leak-of-deloitte-internal-communications Deloitte: Threat Actor IntelBroker Allegedly Claims Leak of Deloitte Internal Communications threat actordeloitteallegedlyclaimsleak https://thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html?ref=x64.onl New Threat Actor 'Void Arachne' Targets Chinese Users with Malicious VPN Installers Discover the latest cybersecurity threat targeting Chinese-speaking users with malicious VPN installers and AI-driven malware campaigns. threat actor https://apt.etda.or.th/cgi-bin/showcard.cgi?g=Mustang%20Panda%2C%20Bronze%20President&n=1 Mustang Panda, Bronze President - Threat Group Cards: A Threat Actor Encyclopedia mustang pandagroup cardsbronzepresidentthreat https://malpedia.caad.fkie.fraunhofer.de/actor/ruby_sleet Ruby Sleet (Threat Actor) Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices,... rubysleetthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/uta0352 UTA0352 (Threat Actor) UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/gnosticplayers Gnosticplayers (Threat Actor) The hacker said that he put up the data for sale mainly because these companies had failed to protect passwords with strong encryption algorithms like bcrypt.... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/test_panda TEST PANDA (Threat Actor) Details for the TEST PANDA threat actor (from the MISP Galaxy Project). testpandathreatactor https://github.com/MISP/threat-actor-intelligence-server GitHub - MISP/threat-actor-intelligence-server: A simple ReST server to lookup threat actors (by... A simple ReST server to lookup threat actors (by name, synonym or UUID) and returning the corresponding MISP galaxy information about the known threat actors.... threat actor intelligence https://malpedia.caad.fkie.fraunhofer.de/actor/cleaver Cleaver (Threat Actor) A group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S.... cleaverthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/gold_rebellion GOLD REBELLION (Threat Actor) GOLD REBELLION is a financially motivated cybercriminal threat group that operates the Black Basta name-and-shame ransomware. The group posted its first victim... goldrebellionthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/lucky_cat Lucky Cat (Threat Actor) A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to... lucky catthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/cyber_alliance Cyber Alliance (Threat Actor) The Ukrainian Cyber Alliance is a pro-Ukraine hacktivist group formed in 2016, primarily targeting Russian entities since the invasion of Ukraine in 2022. They... cyberalliancethreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/scarred_manticore Scarred Manticore (Threat Actor) Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers. These include a variety... scarredmanticorethreatactor https://unit42.paloaltonetworks.com/popping-eagle-malware/?pdf=print&lg=en&_wpnonce=9ce32c3677 Popping Eagle: How Global Analytics Uncovered a Stealthy Threat Actor Jun 5, 2024 - We observed a specially crafted DLL hijacking attack used by a previously unknown piece of malware that we dubbed Popping Eagle. global analyticspoppingeagleuncoveredstealthy https://malpedia.caad.fkie.fraunhofer.de/actor/greenbug Greenbug (Threat Actor) Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government, investment, and... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/silent_librarian Silent Librarian (Threat Actor) Last Friday, Deputy Attorney General Rod Rosenstein announced the indictment of nine Iranians who worked for an organization named the Mabna Institute.... silentlibrarianthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/gold_southfield GOLD SOUTHFIELD (Threat Actor) GOLD SOUTHFIELD is a financially motivated cybercriminal threat group that authors and operates the REvil (aka Sodinokibi) ransomware on behalf of various... goldsouthfieldthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/chaya_004 Chaya_004 (Threat Actor) Chaya_004 is a Chinese threat actor identified through malicious infrastructure, including a network of servers hosting Supershell backdoors and various pen... chayathreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/apt19 APT19 (Threat Actor) Adversary group targeting financial, technology, non-profit organisations. threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/earth_krahang Earth Krahang (Threat Actor) Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors... earththreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/cyber_caliphate_army Cyber Caliphate Army (Threat Actor) Details for the Cyber Caliphate Army threat actor (from the MISP Galaxy Project). cybercaliphatearmythreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/vicioustrap ViciousTrap (Threat Actor) ViciousTrap has compromised over 5,500 edge devices, transforming them into honeypots and utilizing a shell script called NetGhost to redirect incoming traffic... threatactor https://dmpdump.github.io/posts/Low_Detection_backdoor_NHAS_RSSH/ Likely Chinese Threat Actor Uses Low Detection Linux Backdoor and NHAS Reverse SSH | dmpdump May 1, 2025 - On April 22, 2025, MalwareHunterTeam shared a hash for a low detection Linux ELF with 2 hard-coded IP addresses: 43.159.18[.]135 and 119.42.148[.]187. Upon... https://malpedia.caad.fkie.fraunhofer.de/actor/oilrig OilRig (Threat Actor) OilRig is an Iranian threat group operating primarily in the Middle East by targeting organizations in this region that are in a variety of different... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/toxcar_cyber_team TOXCAR CYBER TEAM (Threat Actor) The Toxcar Cyber Team has claimed responsibility for a data leak involving Mastercard, asserting that the attack targeted the U.S. site and providing... cyber teamthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/unc4990 UNC4990 (Threat Actor) UNC4990 is a financially motivated threat actor that has been active since at least 2020. They primarily target users in Italy and rely on USB devices for... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/krybit Krybit (Threat Actor) Krybit is a ransomware group that operates as a ransomware-as-a-service provider, offering affiliates 80% of ransom proceeds in exchange for technical support... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/scully_spider SCULLY SPIDER (Threat Actor) Mentioned as operator of DanaBot in CrowdStrike's 2020 Report. scullyspiderthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/flyingyeti FlyingYeti (Threat Actor) FlyingYeti is a Russia-aligned threat actor targeting Ukrainian military entities. They conduct reconnaissance activities and launch phishing campaigns using... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/camaro_dragon Camaro Dragon (Threat Actor) In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of... camarodragonthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/apt16 APT16 (Threat Actor) Between November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/markopolo Markopolo (Threat Actor) Markopolo is a threat actor known for running scams targeting cryptocurrency users through a fake app called Vortax. They use social media and a dedicated blog... markopolothreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/apt15 APT15 (Threat Actor) This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes. threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/evilbyte Evilbyte (Threat Actor) EvilByte is a hacktivist group that has conducted several high-profile cyber attacks in 2024, including breaching MyFatoorah's banking system in retaliation... threatactor https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools?hl=en GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog Google Threat Intelligence Group's findings on adversarial misuse of AI, including Gemini and other non-Google tools. https://techcommunity.microsoft.com/discussions/microsoft-security/new-blog-post--threat-actor-dev-0322-exploiting-zoho-manageengine-adselfservice-/2943858 New Blog Post | Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus | Microsoft... Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus - Microsoft Security Blog Microsoft has detected exploits being used to compromise... new blog post https://malpedia.caad.fkie.fraunhofer.de/actor/linkc_pub LinkC Pub (Threat Actor) Linkc is a newly emerged ransomware group that operates an onion-based data leak site and has claimed one victim, a U.S.-based AI and cloud service provider,... linkcpubthreatactor https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/?pdf=print&lg=en&_wpnonce=99541e2cbe Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025) Aug 1, 2025 - A comprehensive list of threat actor groups tracked by Unit 42, along with information such as summaries and industries typically impacted. https://malpedia.caad.fkie.fraunhofer.de/actor/moskalvzapoe Moskalvzapoe (Threat Actor) Details for the Moskalvzapoe threat actor (from the MISP Galaxy Project). threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/thrip Thrip (Threat Actor) This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and... thripthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/resumelooters ResumeLooters (Threat Actor) Since the beginning of 2023, ResumeLooters have been able to compromise at least 65 websites. The group employs a variety of simple techniques, including SQL... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/purplehaze PurpleHaze (Threat Actor) PurpleHaze is a China-nexus threat actor tracked by SentinelLABS, linked to APT15, known for targeting critical infrastructure sectors such as... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/worok Worok (Threat Actor) Worok is a cyber espionage group, mostly targeting Central Asia. The group toolset includes a C++ loader named CLRLoad, a PowerShell backdoor named... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/caracal_kitten Caracal Kitten (Threat Actor) Caracal Kitten is an APT group that has been targeting activists associated with the Kurdistan Democratic Party. They employ a mobile remote access Trojan to... caracalkittenthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/blue_termite Blue Termite (Threat Actor) Blue Termite is a group of suspected Chinese origin active in Japan. bluetermitethreatactor https://cybersecuritytoday.libsyn.com/cyber-security-today-march-25-2024-a-suspected-china-threat-actor-going-after-unpatched-f5-and-screenconnet-installations Cybersecurity Today: Cyber Security Today, March 25, 2024 - A suspected China threat actor going... This episode reports on a new campaign stealing email passwords, the latest data breaches, and more https://malpedia.caad.fkie.fraunhofer.de/actor/ukrainian_cyber_alliance Ukrainian Cyber Alliance (Threat Actor) Cyber Alliance is a hacktivist group that has demonstrated capabilities in exploiting vulnerabilities, such as CVE-2023-22515 in Confluence, to escalate... ukrainiancyberalliancethreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/grayling Grayling (Threat Actor) Grayling activity was first observed in early 2023, when a number of victims were identified with distinctive malicious DLL side-loading activity. Grayling... graylingthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/uta0178 UTA0178 (Threat Actor) While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the... threatactor https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/?pdf=download&lg=en&_wpnonce=d4b794fb6b Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack Nov 18, 2025 - A nation-state attacker is using novel Airstalk malware in supply chain attacks to exfiltrate browser data. Airstalk misuses the AirWatch API. https://malpedia.caad.fkie.fraunhofer.de/actor/sweed SWEED (Threat Actor) Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we're calling "SWEED," including such notable... sweedthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/apt6 APT6 (Threat Actor) The FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems as far back as 2011... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/lazarus_group Lazarus Group (Threat Actor) Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the... lazarus groupthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/handala Handala (Threat Actor) Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive... handalathreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/ghostr GhostR (Threat Actor) Ghostr is a financially motivated threat actor known for stealing a confidential database containing 5.3 million records from the World-Check and leaking about... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/ghost_jackal Ghost Jackal (Threat Actor) Details for the Ghost Jackal threat actor (from the MISP Galaxy Project). ghostjackalthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/operation_soft_cell Operation Soft Cell (Threat Actor) In 2018, the Cybereason Nocturnus team identified an advanced, persistent attack targeting global telecommunications providers carried out by a threat actor... soft celloperationthreatactor https://anchorednarratives.substack.com/p/trouble-in-asia-and-the-middle-east Trouble in Asia and the Middle East. Tracking the TransparentTribe threat actor. A case study into a threat actor that is likely originating from Pakistan which is leveraging CrimsonRat and malicious documents to control their targets. asia and the middle easttrouble https://malpedia.caad.fkie.fraunhofer.de/actor/unc5537 UNC5537 (Threat Actor) UNC5537 is a financially motivated threat actor targeting Snowflake customer databases. They use stolen credentials obtained from infostealer malware to access... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/red_dev_17 Red Dev 17 (Threat Actor) In 2021, PwC started tracking a series of intrusions under the moniker of Red Dev 17 that they assess were highly likely conducted by a China-based threat... reddevthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/apt28 APT28 (Threat Actor) The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/carderbee Carderbee (Threat Actor) Symantec recently reported on activity attributed to a threat actor group dubbed Carderbee. In the campaign, the threat actors target entities in Hong Kong and... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/red_nue Red Nue (Threat Actor) Red Nue, active since at least 2017, is known for its use of the multi-platform LootRAt backdoor, also known as ReverseWindow. LootRAT has variants for Windows... rednuethreatactor https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/?pdf=print&lg=en&_wpnonce=e3725c6bf3 Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025) Aug 1, 2025 - A comprehensive list of threat actor groups tracked by Unit 42, along with information such as summaries and industries typically impacted. https://www.thenationalnews.com/world/new-threat-to-saudi-arabia-comes-from-two-fronts-and-one-actor-iran-1.910654 New threat to Saudi Arabia comes from two fronts and one actor - Iran | The National Jul 5, 2021 - Strikes on oil plants part of a wider Iranian strategy with several objectives https://malpedia.caad.fkie.fraunhofer.de/actor/tetrisphantom TetrisPhantom (Threat Actor) TetrisPhantom relies on compromising of certain type of secure USB drives that provide hardware encryption and is commonly used by government organizations.... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/storm-0506 Storm-0506 (Threat Actor) Storm-0506 (DEV-0506) is a financially motivated cybercriminal group operating as a core affiliate within the Black Basta ransomware-as-a-service (RaaS)... stormthreatactor https://www.bitdefender.com/en-us/blog/businessinsights/alleged-north-korean-threat-actor-targets-select-victims-with-another-critical-zero-day-vulnerability-attack Alleged North Korean Threat Actor Targets Select Victims with another Critical Zero-Day... Attributing cyberattacks and advanced malware to a particular country or entity is usually troublesome. https://malpedia.caad.fkie.fraunhofer.de/actor/hexagonalrodent HexagonalRodent (Threat Actor) HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/mallard_spider MALLARD SPIDER (Threat Actor) Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER mallardspiderthreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/hive-0145 HIVE-0145 (Threat Actor) Hive0145 is a financially motivated initial access broker that has been active since late 2022, primarily utilizing Strela Stealer malware to target email... hivethreatactor https://malpedia.caad.fkie.fraunhofer.de/actor/muddywater MuddyWater (Threat Actor) The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/chernovite Chernovite (Threat Actor) Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM. They are known for... threatactor https://malpedia.caad.fkie.fraunhofer.de/actor/dalbit Dalbit (Threat Actor) The group usually targets vulnerable servers to breach information including internal data from companies or encrypts files and demands money. Their targets of... threatactor https://www.indiatoday.in/entertainment/television/story/asim-riaz-slams-abhinav-shukla-death-threat-lawrence-bishnoi-gang-rubina-dilaik-spat-battleground-2711951-2025-04-21 Asim Riaz's rebuttal to actor Abhinav Shukla after the latter receives death threat from Lawrence... Apr 21, 2025 - Amidst a heated controversy, rapper Asim Riaz has addressed actor Abhinav Shukla's claims of receiving death threats from an alleged Lawrence Bishnoi gang... https://malpedia.caad.fkie.fraunhofer.de/actor/vicious_panda Vicious Panda (Threat Actor) Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus scare, in order to deliver... viciouspandathreatactor