Robuta

https://malpedia.caad.fkie.fraunhofer.de/actor/greyenergy GreyEnergy (Threat Actor) ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks threat actor https://heimdalsecurity.com/blog/500k-reward-poly-network/ Threat Actor Returns Poly Network Stolen Assets and Receives 500K Reward Aug 24, 2021 - The last $141 million were given back to the company that suffered the biggest worldwide cryptocurrency theft. The hacker got a 500K reward. threat actorreturnspolynetworkstolen https://cioaxis.com/hottopics/security/ransomware-threat-actor-behind-december-attack-via-exchange-identified-by-rackspace Ransomware Threat Actor Behind December Attack via Exchange Identified by Rackspace - CIO AXIS Jan 5, 2023 - CrowdStrike previously connected Play, the threat actor, to a new Outlook Web Access exploit method used in multiple attacks. Rackspace Technology has... threat actorransomwarebehinddecemberattack https://keybase.io/cocksucker420420 cocksucker420420 (threat actor) | Keybase cocksucker420420 (threat actor) is now on Keybase, an open source app for encryption and cryptography. threat actorkeybase https://www.fortra.com/blog/velociraptor-dfir-tool-abused-wsus-rce-cve-2025-59287 Threat Actor Abuse of Velociraptor DFIR Tool in WSUS RCE Attack |CVE-2025-59287 | Fortra Learn how attackers exploited WSUS RCE (CVE-2025-59287) and abused Velociraptor DFIR, VS Code tunneling, and Cloudflare Workers for persistence and C2.... threat actorabusevelociraptordfirtool https://securityaffairs.com/107124/data-breach/us-gun-exchange-data-breach.html Threat actor leaked data for U.S. gun exchange site on hacking forum Aug 14, 2020 - A threat actor has released the databases of Utah-based gun exchange and hunting sites for free on a cybercrime forum. threat actoru son hackingleakeddata https://digitalterminal.in/tech-companies/crowdstrike-unveils-warp-panda-a-sophisticated-china-nexus-threat-actor CrowdStrike Unveils WARP PANDA, a Sophisticated China-Nexus Threat Actor CrowdStrike has identified multiple intrusions targeting VMware vCenter environments at U.S.-based entities, in which newly identified China-nexus adversary... a sophisticatedthreat actorcrowdstrikewarppanda https://cyberwebspider.com/cyber-security-news/microsoft-and-crowdstrike-teaming-up-to-bring-clarity-to-threat-actor-mapping/ Microsoft and CrowdStrike Teaming Up to Bring Clarity To Threat Actor Mapping - Cyber Web Spider... Jun 3, 2025 - Microsoft and CrowdStrike introduced a groundbreaking collaboration yesterday to streamline the complicated panorama of cyberthreat actor identification, threat actormicrosoftcrowdstriketeamingbring https://www.metacurity.com/new-threat-actor-exotic-lily-is-an/ New Threat Actor Exotic Lily Is an Access Broker for Russian Hackers, Including the Conti Gang Jul 8, 2024 - Russia says it's facing unprecedented wave of hacking attacks, CISA warns of SATCOM threats, Anonymous seemingly took control of cameras inside Russia to... threat actorrussian hackersnewexoticlily https://www.menlosecurity.com/ko-kr/resources/threat-actor-november-2021-ta551-threat-bulletin Threat Actor - November 2021 - TA551 | Menlo Security Menlo Labs is tracking a new campaign from threat group TA551, that is possibly targeting a small group of victims. threat actormenlo securitynovember https://zimperium.com/blog/kimsuky-infamous-threat-actor-churns-out-more-advanced-malware Kimsuky Threat Actor Churns Out Advanced Malware - Zimperium Learn about Kimsuky's new malware tactics and how Zimperium customers are protected against these cybersecurity threats. threat actorkimsukyadvancedmalwarezimperium https://nquiringminds.com/cybernews-summaries/ab746e304ca994537cd37838aacbc85b/ Checkmarx Warns of Unknown Threat Actor Targeting Developers with Malicious npm Packages |... threat actornpm packagescheckmarxwarnsunknown https://cyberinsider.com/threat-actor-claims-sale-of-318-million-otelier-records/ Threat Actor Claims Sale of 318 Million Otelier Records Jan 21, 2025 - Threat actor "Ay4me" is selling 318 million records on BreachForums, allegedly stolen from Otelier, a cloud-based hotel management platform. threat actorclaimssalemillionrecords https://www.huntress.com/threat-library/threat-actors/solar-spider Solar Spider Threat Actor Profile: TTPs, IOCs & Attacks | Huntress A profile of Solar Spider, a financially motivated eCrime group known for phishing attacks on banks using the JSOutProx RAT. threat actorsolarspiderprofilettps https://www.paubox.com/blog/threat-actor-hazy-hawk-hijacks-abandoned-cloud-resources Threat actor 'Hazy Hawk' hijacks abandoned cloud resources A threat actor known as Hazy Hawk is hijacking abandoned cloud resources from reputable organizations by exploiting DNS misconfigurations. threat actorcloud resourceshazyhawkabandoned https://securitybrief.asia/story/cybersecurity-firm-group-ib-tracks-major-new-threat-actor-gambleforce Cybersecurity firm Group-IB tracks major new threat actor GambleForce Threat actor GambleForce has struck 24 organisations in 8 countries in 3 months, exploiting SQL vulnerabilities to steal sensitive data. threat actorcybersecurityfirmgroupib https://strobes.co/vi/threat-actors/APT30/ APT30 - Threat Actor Profile & Exploited CVEs | Strobes VI | Strobes VI APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not threat actorprofileexploitedcvesstrobes https://www.crowdstrike.com/en-us/blog/meet-crowdstrikes-adversary-of-the-month-for-october-dungeon-spider/ DUNGEON SPIDER | Threat Actor Profile | CrowdStrike DUNGEON SPIDER is a group of eCrime hackers that conduct opportunistic targeting aimed at deploying the Locky ransomware. Learn about their targets and methods. threat actordungeonspiderprofilecrowdstrike https://thecyberwire.com/newsletters/research-briefing/4/48 Sandworm deploys new ransomware against Ukraine. Chinese threat actor uses USB sticks to spread... CYBERCOM and DARPA announce new pilot program. threat actorusb stickssandwormnewransomware https://iplogger.org/de/blog/tag/threat-actor/ threat-actor ::description_blog_tag threat actor https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel TA558 Threat Actor Targets Hospitality & Travel | Proofpoint US Jun 30, 2023 - Learn about TA558, the financially-motivated threat actor targeting hospitality, hotel, and travel organizations. Find out what our researchers have learned. threat actortargetshospitalitytravelproofpoint https://moderniqs.com/app/data_collection_threat_actor_profile_synthesizer/ Threat actor profile synthesizer for threat analysis The threat actor profile synthesizer helps you collect vital data on threat actors, their tactics, and incidents to enhance your security insights. threat actorprofilesynthesizeranalysis https://groups.oasis-open.org/discussion/september-2024-monthly-meeting-uploaded September 2024 Monthly Meeting uploaded | OASIS Threat Actor Context (TAC) TC Submitter's message TAC:Please join us for our call on Oct. 25th.Jane Ginn -- Jane Ginn Document Name: September 2024 Monthly MeetingDescri monthly meetingthreat actorseptemberuploadedoasis https://www.redhotcyber.com/post/coinbase-usa-threat-actor-dichiara-di-vendere-un-database-di-600-000-utenti/ Coinbase USA: Threat Actor dichiara di vendere un database di 600.000 utenti Sep 8, 2025 - Recentemente Threat Actors ha pubblicato all'interno di un forum underground la violazione del database di Coinbase di 600 000 utenti. threat actorcoinbaseusadivendere https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack |... A North Korea-nexus threat actor targeted the popular axios NPM package in a massive supply chain attack. supply chain attacknorth koreathreat actornpm packagenexus https://www.hendryadrian.com/inside-the-intelligence-center-financially-driven-chinese-threat-actor-silkspecter-targeting-black-friday-shoppers/ Inside the Intelligence Center: Financially Driven Chinese Threat Actor SilkSpecter Targeting Black... Oct 14, 2025 - In October 2024, EclecticIQ analysts identified a phishing campaign targeting e-commerce shoppers in Europe and the USA, attributed to a Chinese threat actor... the intelligencethreat actorinsidecenterfinancially https://dailysecurityreview.com/threat-actors/water-saci-threat-actor-evolves-tactics-with-sophisticated-infection-chain/ Water Saci Threat Actor Evolves Tactics with Sophisticated Infection Chain - Threat Actors Dec 5, 2025 - Water Saci advances its attack methods, exploiting WhatsApp to spread malware using HTA files and PDFs. threat actorwaterevolvestacticssophisticated https://www.bitdefender.com/en-gb/blog/businessinsights/deep-dive-into-unfading-sea-haze-a-new-threat-actor-in-the-south-china-sea Deep Dive Into Unfading Sea Haze: A New Threat Actor in the South China Sea In a recent investigation by Bitdefender Labs, a series of cyberattacks targeting high-level organizations in South China Sea countries revealed a previously... in the southdeep divethreat actorseahaze https://www.securitymagazine.com/articles/93589-threat-actor-ta505-exploiting-zerologon-to-attack-and-gain-account-control-privileges Threat actor TA505 exploiting ZeroLogon to attack and gain account control privileges | 2020-10-12... Microsoft recently warned that more cybercriminals have started to incorporate exploit code for the ZeroLogon vulnerability in their attacks. Threat actor... threat actorexploitingattackgainaccount https://www.cybertransactiongateway.com/security-bug-in-stealc-malware-panel-let-researchers-spy-on-threat-actor-operations/ Security Bug in StealC Malware Panel Let Researchers Spy on Threat Actor Operations - Cyber... Cybersecurity researchers have disclosed a cross-site scripting (XSS) vulnerability in the web-based control panel used by operators of the StealC information... threat actorsecuritybugstealcmalware https://www.pcrisk.com/internet-threat-news/33743-threat-actor-storm-0501-deploys-ransomware-in-cloud-environments Threat Actor Storm-0501 Deploys Ransomware In Cloud Environments threat actorcloud environmentsstormransomware https://www.malwarebytes.com/glossary/threat-actor Threat actor | Malwarebytes Glossary In cybersecurity, a threat actor is a group or person behind a malicious incident. As it is sometimes unclear whether an... threat actormalwarebytesglossary https://unit42.paloaltonetworks.com/new-windows-based-malware-family-airstalk/?pdf=download&lg=en&_wpnonce=d4b794fb6b Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack Nov 18, 2025 - A nation-state attacker is using novel Airstalk malware in supply chain attacks to exfiltrate browser data. Airstalk misuses the AirWatch API. supply chain attacknation statethreat actorsuspecteduses https://blog.netmanageit.com/threat-actor-profile-interlock-ransomware/ Threat Actor Profile: Interlock Ransomware Aug 15, 2025 - NetmanageIT OpenCTI - opencti.netmanageit.com threat actorprofileinterlockransomware https://www.channelpronetwork.com/2020/07/22/mcafee-report-shows-threat-actor-evolution-during-pandemic/ McAfee Report Shows Threat Actor Evolution During Pandemic - The ChannelPro Network Jul 22, 2020 - Key Findings Cybercriminals leverage pandemic as entry mechanism into systems across the globe McAfee Advanced Programs Group releases daily COVID-19 threat... the channelpro networkthreat actormcafeereportshows https://thehackernews.com/2023/02/new-threat-actor-wip26-targeting.html New Threat Actor WIP26 Targeting Telecom Service Providers in the Middle East Cybersecurity experts are cautioning of a new, previously unreported threat actor located in the Middle East that is targeting telecommunications s telecom service providersin the middlethreat actornewtargeting https://www.thestack.technology/purpleurchin-freejacking-sysdig-research-cryptomining/ Mystery threat actor PURPLEURCHIN in "abnormal" freejacking campaign Apr 4, 2025 - Security researchers at Sysdig say that they have identified a previously unreported threat actor running an "abnormal" cryptomining campaign threat actormysteryabnormalcampaign https://www.coalitioninc.com/en-gb/blog/security-labs/sim-swapping-extortion Threat Actor Claims 100% Success With SIM-Swapping Extortion SIM-swapping extortion attacks are on the rise due to self-service password resets, which help threat actors bypass interaction with their victims. threat actorsim swappingclaimssuccessextortion https://www.endorlabs.com/learn/teampcp-isnt-done?ref=alphasec.io TeamPCP Isn't Done: Threat Actor Behind Trivy and KICS Compromises Now Hits LiteLLM's 95 Million... Two backdoored versions of litellm (1.82.7 and 1.82.8) shipped with a full credential harvester, Kubernetes lateral movement toolkit, and persistent backdoor. threat actorteampcpdonebehindtrivy https://www.helpnetsecurity.com/2023/10/11/exploited-cve-2023-22515/ Critical Atlassian Confluence vulnerability exploited by state-backed threat actor - Help Net... Oct 16, 2023 - A critical flaw in Atlassian Confluence Data Center and Server (CVE-2023-22515) has been exploited by a state-backed threat actor. atlassian confluenceby statethreat actorcriticalvulnerability https://www.newstalk.com/news/ticketmaster-owner-confirms-data-hack-by-criminal-threat-actor-1731007 Ticketmaster owner confirms data hack by 'criminal threat actor' | Newstalk A group of hackers claimed to have stolen data belonging to more than 500 million global Ticketmaster customers threat actorticketmasterownerdatahack https://dig.watch/updates/storm-0324-a-threat-actor-targets-microsoft-teams-for-phishing-campaigns Storm-0324: A threat actor targets Microsoft Teams for phishing campaigns | Digital Watch... Sep 14, 2023 - The phishing lures can potentially open the door for follow-on attacks, according to Microsoft's security researchers. threat actormicrosoft teamsphishing campaignsdigital watchstorm https://www.ictsecuritymagazine.com/tag/cyber-threat-actor/ cyber threat actor - ICT Security Magazine cyber threatict securityactormagazine