https://malpedia.caad.fkie.fraunhofer.de/actor/greyenergy
GreyEnergy (Threat Actor)
ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks
threat actor
https://heimdalsecurity.com/blog/500k-reward-poly-network/
Threat Actor Returns Poly Network Stolen Assets and Receives 500K Reward
Aug 24, 2021 - The last $141 million were given back to the company that suffered the biggest worldwide cryptocurrency theft. The hacker got a 500K reward.
threat actorreturnspolynetworkstolen
https://cioaxis.com/hottopics/security/ransomware-threat-actor-behind-december-attack-via-exchange-identified-by-rackspace
Ransomware Threat Actor Behind December Attack via Exchange Identified by Rackspace - CIO AXIS
Jan 5, 2023 - CrowdStrike previously connected Play, the threat actor, to a new Outlook Web Access exploit method used in multiple attacks. Rackspace Technology has...
threat actorransomwarebehinddecemberattack
https://keybase.io/cocksucker420420
cocksucker420420 (threat actor) | Keybase
cocksucker420420 (threat actor) is now on Keybase, an open source app for encryption and cryptography.
threat actorkeybase
https://www.fortra.com/blog/velociraptor-dfir-tool-abused-wsus-rce-cve-2025-59287
Threat Actor Abuse of Velociraptor DFIR Tool in WSUS RCE Attack |CVE-2025-59287 | Fortra
Learn how attackers exploited WSUS RCE (CVE-2025-59287) and abused Velociraptor DFIR, VS Code tunneling, and Cloudflare Workers for persistence and C2....
threat actorabusevelociraptordfirtool
https://securityaffairs.com/107124/data-breach/us-gun-exchange-data-breach.html
Threat actor leaked data for U.S. gun exchange site on hacking forum
Aug 14, 2020 - A threat actor has released the databases of Utah-based gun exchange and hunting sites for free on a cybercrime forum.
threat actoru son hackingleakeddata
https://digitalterminal.in/tech-companies/crowdstrike-unveils-warp-panda-a-sophisticated-china-nexus-threat-actor
CrowdStrike Unveils WARP PANDA, a Sophisticated China-Nexus Threat Actor
CrowdStrike has identified multiple intrusions targeting VMware vCenter environments at U.S.-based entities, in which newly identified China-nexus adversary...
a sophisticatedthreat actorcrowdstrikewarppanda
https://cyberwebspider.com/cyber-security-news/microsoft-and-crowdstrike-teaming-up-to-bring-clarity-to-threat-actor-mapping/
Microsoft and CrowdStrike Teaming Up to Bring Clarity To Threat Actor Mapping - Cyber Web Spider...
Jun 3, 2025 - Microsoft and CrowdStrike introduced a groundbreaking collaboration yesterday to streamline the complicated panorama of cyberthreat actor identification,
threat actormicrosoftcrowdstriketeamingbring
https://www.metacurity.com/new-threat-actor-exotic-lily-is-an/
New Threat Actor Exotic Lily Is an Access Broker for Russian Hackers, Including the Conti Gang
Jul 8, 2024 - Russia says it's facing unprecedented wave of hacking attacks, CISA warns of SATCOM threats, Anonymous seemingly took control of cameras inside Russia to...
threat actorrussian hackersnewexoticlily
https://www.menlosecurity.com/ko-kr/resources/threat-actor-november-2021-ta551-threat-bulletin
Threat Actor - November 2021 - TA551 | Menlo Security
Menlo Labs is tracking a new campaign from threat group TA551, that is possibly targeting a small group of victims.
threat actormenlo securitynovember
https://zimperium.com/blog/kimsuky-infamous-threat-actor-churns-out-more-advanced-malware
Kimsuky Threat Actor Churns Out Advanced Malware - Zimperium
Learn about Kimsuky's new malware tactics and how Zimperium customers are protected against these cybersecurity threats.
threat actorkimsukyadvancedmalwarezimperium
https://nquiringminds.com/cybernews-summaries/ab746e304ca994537cd37838aacbc85b/
Checkmarx Warns of Unknown Threat Actor Targeting Developers with Malicious npm Packages |...
threat actornpm packagescheckmarxwarnsunknown
https://cyberinsider.com/threat-actor-claims-sale-of-318-million-otelier-records/
Threat Actor Claims Sale of 318 Million Otelier Records
Jan 21, 2025 - Threat actor "Ay4me" is selling 318 million records on BreachForums, allegedly stolen from Otelier, a cloud-based hotel management platform.
threat actorclaimssalemillionrecords
https://www.huntress.com/threat-library/threat-actors/solar-spider
Solar Spider Threat Actor Profile: TTPs, IOCs & Attacks | Huntress
A profile of Solar Spider, a financially motivated eCrime group known for phishing attacks on banks using the JSOutProx RAT.
threat actorsolarspiderprofilettps
https://www.paubox.com/blog/threat-actor-hazy-hawk-hijacks-abandoned-cloud-resources
Threat actor 'Hazy Hawk' hijacks abandoned cloud resources
A threat actor known as Hazy Hawk is hijacking abandoned cloud resources from reputable organizations by exploiting DNS misconfigurations.
threat actorcloud resourceshazyhawkabandoned
https://securitybrief.asia/story/cybersecurity-firm-group-ib-tracks-major-new-threat-actor-gambleforce
Cybersecurity firm Group-IB tracks major new threat actor GambleForce
Threat actor GambleForce has struck 24 organisations in 8 countries in 3 months, exploiting SQL vulnerabilities to steal sensitive data.
threat actorcybersecurityfirmgroupib
https://strobes.co/vi/threat-actors/APT30/
APT30 - Threat Actor Profile & Exploited CVEs | Strobes VI | Strobes VI
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not
threat actorprofileexploitedcvesstrobes
https://www.crowdstrike.com/en-us/blog/meet-crowdstrikes-adversary-of-the-month-for-october-dungeon-spider/
DUNGEON SPIDER | Threat Actor Profile | CrowdStrike
DUNGEON SPIDER is a group of eCrime hackers that conduct opportunistic targeting aimed at deploying the Locky ransomware. Learn about their targets and methods.
threat actordungeonspiderprofilecrowdstrike
https://thecyberwire.com/newsletters/research-briefing/4/48
Sandworm deploys new ransomware against Ukraine. Chinese threat actor uses USB sticks to spread...
CYBERCOM and DARPA announce new pilot program.
threat actorusb stickssandwormnewransomware
https://iplogger.org/de/blog/tag/threat-actor/
threat-actor
::description_blog_tag
threat actor
https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel
TA558 Threat Actor Targets Hospitality & Travel | Proofpoint US
Jun 30, 2023 - Learn about TA558, the financially-motivated threat actor targeting hospitality, hotel, and travel organizations. Find out what our researchers have learned.
threat actortargetshospitalitytravelproofpoint
https://moderniqs.com/app/data_collection_threat_actor_profile_synthesizer/
Threat actor profile synthesizer for threat analysis
The threat actor profile synthesizer helps you collect vital data on threat actors, their tactics, and incidents to enhance your security insights.
threat actorprofilesynthesizeranalysis
https://groups.oasis-open.org/discussion/september-2024-monthly-meeting-uploaded
September 2024 Monthly Meeting uploaded | OASIS Threat Actor Context (TAC) TC
Submitter's message TAC:Please join us for our call on Oct. 25th.Jane Ginn -- Jane Ginn Document Name: September 2024 Monthly MeetingDescri
monthly meetingthreat actorseptemberuploadedoasis
https://www.redhotcyber.com/post/coinbase-usa-threat-actor-dichiara-di-vendere-un-database-di-600-000-utenti/
Coinbase USA: Threat Actor dichiara di vendere un database di 600.000 utenti
Sep 8, 2025 - Recentemente Threat Actors ha pubblicato all'interno di un forum underground la violazione del database di Coinbase di 600 000 utenti.
threat actorcoinbaseusadivendere
https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack |...
A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack.
supply chain attacknorth koreathreat actornpm packagenexus
https://www.hendryadrian.com/inside-the-intelligence-center-financially-driven-chinese-threat-actor-silkspecter-targeting-black-friday-shoppers/
Inside the Intelligence Center: Financially Driven Chinese Threat Actor SilkSpecter Targeting Black...
Oct 14, 2025 - In October 2024, EclecticIQ analysts identified a phishing campaign targeting e-commerce shoppers in Europe and the USA, attributed to a Chinese threat actor...
the intelligencethreat actorinsidecenterfinancially
https://dailysecurityreview.com/threat-actors/water-saci-threat-actor-evolves-tactics-with-sophisticated-infection-chain/
Water Saci Threat Actor Evolves Tactics with Sophisticated Infection Chain - Threat Actors
Dec 5, 2025 - Water Saci advances its attack methods, exploiting WhatsApp to spread malware using HTA files and PDFs.
threat actorwaterevolvestacticssophisticated
https://www.bitdefender.com/en-gb/blog/businessinsights/deep-dive-into-unfading-sea-haze-a-new-threat-actor-in-the-south-china-sea
Deep Dive Into Unfading Sea Haze: A New Threat Actor in the South China Sea
In a recent investigation by Bitdefender Labs, a series of cyberattacks targeting high-level organizations in South China Sea countries revealed a previously...
in the southdeep divethreat actorseahaze
https://www.securitymagazine.com/articles/93589-threat-actor-ta505-exploiting-zerologon-to-attack-and-gain-account-control-privileges
Threat actor TA505 exploiting ZeroLogon to attack and gain account control privileges | 2020-10-12...
Microsoft recently warned that more cybercriminals have started to incorporate exploit code for the ZeroLogon vulnerability in their attacks. Threat actor...
threat actorexploitingattackgainaccount
https://www.cybertransactiongateway.com/security-bug-in-stealc-malware-panel-let-researchers-spy-on-threat-actor-operations/
Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations - Cyber...
Cybersecurity researchers have disclosed a cross-site scripting (XSS) vulnerability in the web-based control panel used by operators of the StealC information...
threat actorsecuritybugstealcmalware
https://www.pcrisk.com/internet-threat-news/33743-threat-actor-storm-0501-deploys-ransomware-in-cloud-environments
Threat Actor Storm-0501 Deploys Ransomware In Cloud Environments
threat actorcloud environmentsstormransomware
https://www.malwarebytes.com/glossary/threat-actor
Threat actor | Malwarebytes Glossary
In cybersecurity, a threat actor is a group or person behind a malicious incident. As it is sometimes unclear whether an...
threat actormalwarebytesglossary
https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/?pdf=download&lg=en&_wpnonce=d4b794fb6b
Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack
Nov 18, 2025 - A nation-state attacker is using novel Airstalk malware in supply chain attacks to exfiltrate browser data. Airstalk misuses the AirWatch API.
supply chain attacknation statethreat actorsuspecteduses
https://blog.netmanageit.com/threat-actor-profile-interlock-ransomware/
Threat Actor Profile: Interlock Ransomware
Aug 15, 2025 - NetmanageIT OpenCTI - opencti.netmanageit.com
threat actorprofileinterlockransomware
https://www.channelpronetwork.com/2020/07/22/mcafee-report-shows-threat-actor-evolution-during-pandemic/
McAfee Report Shows Threat Actor Evolution During Pandemic - The ChannelPro Network
Jul 22, 2020 - Key Findings Cybercriminals leverage pandemic as entry mechanism into systems across the globe McAfee Advanced Programs Group releases daily COVID-19 threat...
the channelpro networkthreat actormcafeereportshows
https://thehackernews.com/2023/02/new-threat-actor-wip26-targeting.html
New Threat Actor WIP26 Targeting Telecom Service Providers in the Middle East
Cybersecurity experts are cautioning of a new, previously unreported threat actor located in the Middle East that is targeting telecommunications s
telecom service providersin the middlethreat actornewtargeting
https://www.thestack.technology/purpleurchin-freejacking-sysdig-research-cryptomining/
Mystery threat actor PURPLEURCHIN in "abnormal" freejacking campaign
Apr 4, 2025 - Security researchers at Sysdig say that they have identified a previously unreported threat actor running an "abnormal" cryptomining campaign
threat actormysteryabnormalcampaign
https://www.coalitioninc.com/en-gb/blog/security-labs/sim-swapping-extortion
Threat Actor Claims 100% Success With SIM-Swapping Extortion
SIM-swapping extortion attacks are on the rise due to self-service password resets, which help threat actors bypass interaction with their victims.
threat actorsim swappingclaimssuccessextortion
https://www.endorlabs.com/learn/teampcp-isnt-done?ref=alphasec.io
TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits LiteLLM's 95 Million...
Two backdoored versions of litellm (1.82.7 and 1.82.8) shipped with a full credential harvester, Kubernetes lateral movement toolkit, and persistent backdoor.
threat actorteampcpdonebehindtrivy
https://www.helpnetsecurity.com/2023/10/11/exploited-cve-2023-22515/
Critical Atlassian Confluence vulnerability exploited by state-backed threat actor - Help Net...
Oct 16, 2023 - A critical flaw in Atlassian Confluence Data Center and Server (CVE-2023-22515) has been exploited by a state-backed threat actor.
atlassian confluenceby statethreat actorcriticalvulnerability
https://www.newstalk.com/news/ticketmaster-owner-confirms-data-hack-by-criminal-threat-actor-1731007
Ticketmaster owner confirms data hack by 'criminal threat actor' | Newstalk
A group of hackers claimed to have stolen data belonging to more than 500 million global Ticketmaster customers
threat actorticketmasterownerdatahack
https://dig.watch/updates/storm-0324-a-threat-actor-targets-microsoft-teams-for-phishing-campaigns
Storm-0324: A threat actor targets Microsoft Teams for phishing campaigns | Digital Watch...
Sep 14, 2023 - The phishing lures can potentially open the door for follow-on attacks, according to Microsoft's security researchers.
threat actormicrosoft teamsphishing campaignsdigital watchstorm
https://www.ictsecuritymagazine.com/tag/cyber-threat-actor/
cyber threat actor - ICT Security Magazine
cyber threatict securityactormagazine