Name Guesses
Some names in the paper's reports match no actor in the registry. A program labels each one (actor, malware, tool or not an entity) by comparing it with the names the sources already list, and for a probable actor it names the closest known actor. To measure how far to trust it, we hid each known name in turn and asked it to recover the label. Those results come first, and they are modest.
How Good Are the Guesses
The method was scored on 64 names whose answer a source already lists, each with its own entry hidden. The label was right for 45 of them.
70% of labels were right
The method is 2 points above the answer that always gives the most common label, and 3 points below a version that uses only the shape of the name. The names are few, so a gap of a few points is within noise. No guess reaches the High band.
Confidence
Each actor or malware guess carries a confidence: the share of scored names with a similar score that the method labelled correctly, using a calibration made without that name. High means 0.85 or more and medium means 0.70 or more. A band is used only when enough scored names reached it. A guess that would fall in a band that is not used is shown one band lower, with its confidence held just under that band's threshold. A guess that rests on no measured signal is always low.
| Band | Scored names | Correct | Share correct |
|---|---|---|---|
| High | 0 | 0 | n/a |
| Medium | 0 | 0 | n/a |
| Low | 64 | 45 | 70% |
By Label
Precision is the share of names given a label that truly carry it. Recall is the share of names that truly carry the label and were given it. No known name is labelled tool or not an entity in enough numbers to test, so guesses with those labels are shown as unvalidated and carry no confidence.
| Label | Known names | Guessed | Precision | Recall |
|---|---|---|---|---|
| Actor | 44 | 61 | 71% | 98% |
| Malware | 20 | 3 | 67% | 10% |
| Tool unvalidated | 0 | 0 | n/a | n/a |
| Not an entity unvalidated | 0 | 0 | n/a | n/a |
Confusion
Rows are the known label and columns are the label the method gave.
| Known label | Actor | Malware | Tool | Not an entity |
|---|---|---|---|---|
| Actor | 43 | 1 | 0 | 0 |
| Malware | 18 | 2 | 0 | 0 |
| Tool | 0 | 0 | 0 | 0 |
| Not an entity | 0 | 0 | 0 | 0 |
Matches to a Known Actor
For a name labelled actor, the method also looks for the closest known actor. Of the 44 known actor names, 27 have another name in the registry that a match could find. A kind of match is shown on a guess only when it was right at least half the time here.
| Kind of match | Proposed | Right | Share right | Shown |
|---|---|---|---|---|
| Same name apart from a suffix or a plural | 1 | 1 | 100% | Yes |
| One name contains the other | 0 | 0 | n/a | No |
| A close spelling | 6 | 0 | 0% | No |
Signals
A signal is one thing the program checks about a name. A signal is kept only when the model does worse without it. The model separates actor from malware. In a guess, a positive weight supports it and a negative weight argues against it.
cluster_idkeptThe name follows a numbered cluster pattern such as UNC1234 or APT-C-15.
fires on 7, mostly actor, right 100%, pushes toward actor, strength 0.9
Kept: the model does worse without it.
vendor_suffixkeptThe name ends in a vendor naming word such as Panda, Bear or Team, or starts with Water.
fires on 4, mostly actor, right 100%, pushes toward actor, strength 0.7
Kept: the model does worse without it.
malware_wordkeptThe name ends in a word that usually names malware, such as RAT, Spy or Loader.
fires on 3, mostly malware, right 100%, pushes toward malware, strength 1.0
Kept: the model does worse without it.
actor_resemblancekeptThe name is a close spelling of, or contains, the name of a known actor.
fires on 7, mostly actor, right 100%, pushes toward actor, strength 0.8
Kept: the model does worse without it.
software_resemblancekeptThe name is a close spelling of the name of known malware or a known tool.
fires on 4, mostly malware, right 75%, pushes toward malware, strength 0.8
Kept: the model does worse without it.
cooc_actorkeptThe paper lists the name in the same report row as an actor the resolver knows.
fires on 3, mostly malware, right 100%, pushes toward malware, strength 1.1
Kept: the model does worse without it.
cve_actordroppedA report that uses the name cites a rare CVE that other reports tie to a known actor.
fires on 9, mostly actor, right 89%
Dropped: removing it did not make the model worse.
non_latindroppedThe name is written in a script other than Latin.
fires on 0
Dropped: it fires on fewer than 3 ground-truth names, too few to measure.
title_malware_ctxdroppedReport titles write the name next to a word for malware, as in 'Name stealer' or 'Name ransomware'.
fires on 6, mostly malware, right 67%
Dropped: removing it did not make the model worse.
title_actor_ctxdroppedReport titles write the name next to a word for an actor, as in 'Name threat actor' or 'Name APT'.
fires on 10, mostly actor, right 80%
Dropped: removing it did not make the model worse.
exact_name_listednot measuredEvery ground-truth name is labeled because a source lists it, so leaving that source out removes the signal, and keeping it would make the test circular. A guess that rests on it is shown as unvalidated.
Limitations
- The ground truth has fewer than 10 names labeled tool or not-an-entity, so guesses with those labels are shown as unvalidated.
- The ground-truth names are ones that a source lists, so they are better known than a typical unresolved name.
- Signals were chosen on the same 64 names that score them, so the figures are likely a little optimistic. Confidence is calibrated without each name in turn, which removes a second source of the same bias.
- No guess is shown as high confidence. The band needs at least 20 held-out names with 85% or more right, and 15 qualified, of which 15 were right.
- No guess is shown as medium confidence. The band needs at least 20 held-out names with 70% or more right, and 15 qualified, of which 15 were right.
- Three fixed rules set some labels without any measurement: a placeholder word such as "unclassified", the word "operation" or "campaign", and an alias that a source lists for an actor and never for software. Those guesses are shown as unvalidated.
- Names that differ only by a suffix or a plural can look like the same actor when they are not. A proposed actor is a lead to check, not an identification.
The Guesses
95 names resolve to no actor, the most often seen first.
The bar is measured confidence, from 0 to 100%. Ticks mark the Medium (70%) and High (85%) thresholds.
- Winnti Umbrella 592 reports
Actor Low, 69% pending confirmation
Evidence (1)
- The name contains 'Winnti', the distinctive part of 'Winnti Group', a name of the actor Winnti Group. +0.7 supports the guess
- Operation Armageddon 24 reports
Not an entity Unvalidated pending confirmation
Evidence (2)
- The name begins or ends with 'operation' or 'campaign', which names an operation, not an actor. context only
- The name matches the actor Star Blizzard (as 'Armageddon') after removing the word 'operation'. context only
- COBALT GIPSY 19 reports
Actor Low, 69% pending confirmation
Evidence (1)
- The name contains 'Cobalt', the distinctive part of 'Cobalt Group', a name of the actor Cobalt Group. +0.7 supports the guess
- Kimsuki 19 reports
Actor Low, 31% pending confirmation
Evidence (2)
- The name is 1 edit away from 'Kimsuky', a name of the actor Kimsuky. +0.7 supports the guess
- The name is 1 edit away from 'Kimsuky', a malware listed by Malpedia. -0.7 argues against it
- Timberworm 19 reports
Actor Unvalidated pending confirmation
Evidence (2)
- MISP, ETDA and Malpedia list this exact name as an actor alias. context only
- The name ends in 'worm', a word that usually names malware. -1.0 argues against it
- nso group 5 reports
Actor Low, 69% pending confirmation
Evidence (4)
- The name uses the vendor naming word 'group', which appears in names of tracked groups. +0.7 supports the guess
- A report that uses this name cites CVE-2016-4655, which the dataset's other reports tie to Stealth Falcon. context only
- 7 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- 38 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- LOTUS PANDA 4 reports
Actor Unvalidated pending confirmation
Evidence (2)
- MISP, ETDA, Malpedia and Microsoft list this exact name as an actor alias. context only
- The name uses the vendor naming word 'panda', which appears in names of tracked groups. +0.7 supports the guess
- grand theft auto panda 3 reports
Actor Low, 69% pending confirmation
Evidence (2)
- The name uses the vendor naming word 'panda', which appears in names of tracked groups. +0.7 supports the guess
- A report that uses this name cites CVE-2012-1856, which the dataset's other reports tie to Patchwork. context only
- Oktropys 3 reports
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- uac-0056 3 reports
Actor Unvalidated pending confirmation
Evidence (3)
- ATT&CK, MISP, ETDA and Malpedia list this exact name as an actor alias. context only
- The name follows the cluster-ID pattern UAC-<number>, which vendors use for groups they track by number. +0.9 supports the guess
- 4 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- chessmaster 2 reports
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2017-5689, which the dataset's other reports tie to Lazarus Group. context only
- iron group 2 reports
Actor Unvalidated pending confirmation
Evidence (2)
- MISP, ETDA and Malpedia list this exact name as an actor alias. context only
- The name uses the vendor naming word 'group', which appears in names of tracked groups. +0.7 supports the guess
- kovcoreg 2 reports
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- newsbeef 2 reports
Actor Unvalidated pending confirmation
Evidence (1)
- MISP, ETDA and Malpedia list this exact name as an actor alias. context only
- outlaw 2 reports
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- shadow force 2 reports
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Sphinx (APT-C-15) 2 reports
Actor Low, 69% pending confirmation
Closest known actor: Sphinx
Evidence (1)
- The name matches the actor Sphinx (as 'Sphinx') after taking the part outside the brackets. +0.8 supports the guess
- thrip 2 reports
Actor Unvalidated pending confirmation
Evidence (1)
- ATT&CK, MISP, ETDA and Malpedia list this exact name as an actor alias. context only
- 3ve 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 85th gtsss 1 report
Malware Low, 31% pending confirmation
Evidence (2)
- A report in the paper's dataset lists this name together with APT28. +1.1 supports the guess
- A report that uses this name cites CVE-2020-0688, which the dataset's other reports tie to Threat Group-3390. context only
- a 공격 그룹 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- a41apt 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- aleksandr 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- appin security group 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'group', which appears in names of tracked groups. +0.7 supports the guess
- apt sidewinder 1 report
Actor Low, 31% pending confirmation
Closest known actor: Sidewinder
Evidence (2)
- The name matches the actor Sidewinder (as 'Sidewinder') after removing the leading 'apt'. +0.8 supports the guess
- The name matches the malware 'SideWinder' listed by Malpedia after removing the leading 'apt'. -0.8 argues against it
- apt-c-01 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name follows the cluster-ID pattern APT-C-NN, which vendors use for groups they track by number. +0.9 supports the guess
- apt-c-47 1 report
Actor Low, 69% pending confirmation
Evidence (2)
- The name follows the cluster-ID pattern APT-C-NN, which vendors use for groups they track by number. +0.9 supports the guess
- The name is 1 edit away from 'APT-K-47', a name of the actor Mysterious Elephant. +0.7 supports the guess
- apt-c-59 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name follows the cluster-ID pattern APT-C-NN, which vendors use for groups they track by number. +0.9 supports the guess
- black mafia 1 report
Actor Low, 31% pending confirmation
Evidence (1)
- The name is 2 edits away from 'BlackMagic', a malware listed by Malpedia. -0.6 argues against it
- black peace 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- blackenergy gang 1 report
Actor Low, 31% pending confirmation
Closest known actor: Sandworm Team
Evidence (2)
- The name matches the actor Sandworm Team (as 'BlackEnergy (Group)') after removing the word 'gang'. +0.8 supports the guess
- The name matches the malware 'BlackEnergy' listed by ATT&CK and Malpedia after removing the word 'gang'. -0.8 argues against it
- blue termit 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name is 1 edit away from 'Blue Termite', a name of the actor Blue Termite. +0.7 supports the guess
- c-23 1 report
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- c.rufus security team 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'team', which appears in names of tracked groups. +0.7 supports the guess
- clouddragon 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- cosmic banker 1 report
Malware Low, 31% pending confirmation
Evidence (1)
- The name ends in 'banker', a word that usually names malware. +1.0 supports the guess
- edbitss 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- emotet gang 1 report
Actor Low, 31% pending confirmation
Evidence (1)
- The name matches the malware 'Emotet' listed by ATT&CK and Malpedia after removing the word 'gang'. -0.8 argues against it
- fhappi 1 report
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2014-6271, which the dataset's other reports tie to Threat Group-3390. context only
- french intelligence 1 report
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2011-4369, which the dataset's other reports tie to SNOWGLOBE. context only
- gholee6 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- ghost dragon 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- great 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- hafnuim 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name is 1 edit away from 'HAFNIUM', a name of the actor HAFNIUM. +0.7 supports the guess
- inception attackers 1 report
Actor Low, 69% pending confirmation
Closest known actor: Inception
Evidence (2)
- The name matches the actor Inception (as 'Inception') after removing the word 'attackers'. +0.8 supports the guess
- A report that uses this name cites CVE-2012-1856, which the dataset's other reports tie to APT30. context only
- isis-linked hackers 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- jolly roger’s patrons 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- kelvinsecurityteam 1 report
Actor Low, 69% pending confirmation
Evidence (2)
- The name uses the vendor naming word 'team', which appears in names of tracked groups. +0.7 supports the guess
- A report that uses this name cites CVE-2019-11510, which the dataset's other reports tie to APT29. context only
- keyboys 1 report
Actor Low, 31% pending confirmation
Closest known actor: Tropic Trooper
Evidence (2)
- The name matches the actor Tropic Trooper (as 'KeyBoy') after removing a plural 's'. +0.8 supports the guess
- The name matches the malware 'KeyBoy' listed by ATT&CK and Malpedia after removing a plural 's'. -0.8 argues against it
- king kong elephant 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'elephant', which appears in names of tracked groups. +0.7 supports the guess
- leery turtle 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- lucky elephant 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'elephant', which appears in names of tracked groups. +0.7 supports the guess
- luminousmoth 1 report
Actor Unvalidated pending confirmation
Evidence (2)
- ATT&CK, MISP, ETDA, Malpedia and Microsoft list this exact name as an actor alias. context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- mirrorthief 1 report
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2019-2215, which the dataset's other reports tie to Sidewinder. context only
- mykings 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- negg 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- nilephish 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- operation falcon 1 report
Not an entity Unvalidated pending confirmation
Evidence (1)
- The name begins or ends with 'operation' or 'campaign', which names an operation, not an actor. context only
- operation kingphish 1 report
Not an entity Unvalidated pending confirmation
Evidence (1)
- The name begins or ends with 'operation' or 'campaign', which names an operation, not an actor. context only
- operation oceansalt 1 report
Not an entity Unvalidated pending confirmation
Evidence (2)
- The name begins or ends with 'operation' or 'campaign', which names an operation, not an actor. context only
- The name matches the malware 'OceanSalt' listed by ATT&CK and Malpedia after removing the word 'operation'. context only
- operation transparent tribe 1 report
Not an entity Unvalidated pending confirmation
Evidence (2)
- The name begins or ends with 'operation' or 'campaign', which names an operation, not an actor. context only
- The name matches the actor Transparent Tribe (as 'Transparent Tribe') after removing the word 'operation'. context only
- ozie team 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'team', which appears in names of tracked groups. +0.7 supports the guess
- praying mantis 1 report
Actor Low, 69% pending confirmation
Evidence (2)
- The name contains 'Mantis', a name of the actor APT-C-23. +0.7 supports the guess
- A report that uses this name cites CVE-2019-18935, which the dataset's other reports tie to Blue Mockingbird. context only
- quantum ransomware 1 report
Malware Low, 69% pending confirmation
Evidence (2)
- The name ends in 'ransomware', a word that usually names malware. +1.0 supports the guess
- A report in the paper's dataset lists this name together with Play. +1.1 supports the guess
- raqqah 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- reconhellcat 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- red hacker alliance 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- redoctober 1 report
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- right sector 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- romcom threat actor 1 report
Actor Low, 69% pending confirmation
Closest known actor: RomCom
Evidence (1)
- The name matches the actor RomCom (as 'RomCom') after removing the words 'actor' and 'threat'. +0.8 supports the guess
- russian gru 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- sectora05 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- sectorb06 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- shadow chaser 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- shiqiang 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- shun wang technologies 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- silverhawk 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- soraj bear 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'bear', which appears in names of tracked groups. +0.7 supports the guess
- sun team folder 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- sunshop digital quartermaster 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name contains 'Sunshop', the distinctive part of 'Sunshop Group', a name of the actor APT19. +0.7 supports the guess
- tag-26 1 report
Actor Low, 69% pending confirmation
Evidence (2)
- The name follows the cluster-ID pattern TAG-<number>, which vendors use for groups they track by number. +0.9 supports the guess
- The name is 1 edit away from 'ATG26', a name of the actor Turla. +0.6 supports the guess
- tarh andishan 1 report
Actor Unvalidated pending confirmation
Evidence (1)
- MISP, ETDA and Malpedia list this exact name as an actor alias. context only
- teleport crew 1 report
Actor Low, 31% pending confirmation
Evidence (1)
- The name matches the malware 'Teleport' listed by Malpedia after removing the word 'crew'. -0.8 argues against it
- TopHat 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- uac-0098 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name follows the cluster-ID pattern UAC-<number>, which vendors use for groups they track by number. +0.9 supports the guess
- ucid902 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- unc2727 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name follows the cluster-ID pattern UNC<number>, which vendors use for groups they track by number. +0.9 supports the guess
- unclassified 1 report
Not an entity Unvalidated pending confirmation
Evidence (2)
- The name is a placeholder word such as 'unclassified', not a name. context only
- A report that uses this name cites CVE-2010-2568, which the dataset's other reports tie to APT28. context only
- valkyrie-x security research group 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'group', which appears in names of tracked groups. +0.7 supports the guess
- water kappa 1 report
Actor Low, 69% pending confirmation
Evidence (2)
- The name uses the vendor naming word 'water', which appears in names of tracked groups. +0.7 supports the guess
- A report that uses this name cites CVE-2020-1380, which the dataset's other reports tie to APT37. context only
- water pamola 1 report
Actor Low, 69% pending confirmation
Evidence (1)
- The name uses the vendor naming word 'water', which appears in names of tracked groups. +0.7 supports the guess
- zebra2104 1 report
Actor Low, 67% pending confirmation
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2021-40444, which the dataset's other reports tie to APT28. context only
- عقارب ليبيا 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 伪猎者apt组织 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 海莲花 1 report
Actor Low, 67% pending confirmation
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
Seen in Titles
A phrase that 3 or more titles repeat, from 2 or more publishers, may be a name the sources have not caught up with. This list holds 130 such phrases, found in 29,406 titles. Each phrase goes through the same guesser as the names above, so every label is a guess.
A publisher is the organization a report lists, or the website it links to when none is listed. Only titles this site already shows are read, and nothing else from a report is used.
- RedLine 58 reports from 27 publishers
Actor Low, 67% pending confirmation
Seen 2016-06-20 to 2026-04-07
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 46 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Basta 57 reports from 28 publishers
Actor Low, 67% pending confirmation
Seen 2022-04-26 to 2026-04-09
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 30 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- NSO 53 reports from 19 publishers
Actor Low, 67% pending confirmation
Seen 2016-08-24 to 2026-05-01
Example titles (3)
Evidence (4)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2016-4655, which the dataset's other reports tie to Stealth Falcon. context only
- 7 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- 38 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- Lumma 36 reports from 26 publishers
Actor Low, 67% pending confirmation
Seen 2023-02-27 to 2026-04-23
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 28 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- ClickFix 27 reports from 21 publishers
Actor Low, 31% pending confirmation
Seen 2024-10-17 to 2026-09-08
Example titles (3)
Evidence (2)
- The name is 1 edit away from 'IClickFix', a malware listed by Malpedia. -0.7 argues against it
- 2 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- QuickNote 27 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2021-08-04 to 2026-07-21
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Quasar 26 reports from 13 publishers
Actor Low, 67% pending confirmation
Seen 2017-01-30 to 2026-05-04
Example titles (3)
- Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities 2026-05-04
- GitHub - quasar/Quasar: Remote Administration Tool for Windows 2026-04-06
- Quasar Open-Source Remote Administration Tool | CISA 2026-04-06
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 17 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Rabbit 21 reports from 8 publishers
Actor Low, 67% pending confirmation
Seen 2017-08-24 to 2026-04-29
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Orcus 16 reports from 8 publishers
Actor Low, 67% pending confirmation
Seen 2016-07-21 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 13 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Revenge 15 reports from 10 publishers
Actor Low, 67% pending confirmation
Seen 2017-03-15 to 2026-04-09
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 10 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- LummaC2 14 reports from 10 publishers
Actor Low, 67% pending confirmation
Seen 2023-01-06 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 8 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Nokoyawa 14 reports from 6 publishers
Actor Low, 67% pending confirmation
Seen 2022-03-09 to 2023-05-22
Example titles (3)
- IcedID Macro Ends in Nokoyawa Ransomware The DFIR Report, 2023-05-22
- IcedID Macro Ends in Nokoyawa Ransomware 2023-05-22
- Nevada Ransomware, Nokoyawa Variant | ThreatLabz 2023-03-06
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 10 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Gh0st 13 reports from 9 publishers
Actor Low, 67% pending confirmation
Seen 2011-07-27 to 2025-08-05
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 10 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Mimic 12 reports from 9 publishers
Actor Low, 67% pending confirmation
Seen 2016-01-24 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- PrintNightmare 11 reports from 6 publishers
Actor Low, 67% pending confirmation
Seen 2021-08-11 to 2022-06-30
Example titles (3)
- Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit 2022-06-30
- Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit 2022-06-30
- Russian State-Sponsored Cyber Actors Gain Network Access by Exploiting Default Multifactor Authentication Protocols and “PrintNightmare” Vulnerability | CISA 2022-03-15
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- OverWatch 10 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2021-09-17 to 2022-05-11
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Campo 9 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2021-03-21 to 2021-08-05
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 5 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Spring4Shell 9 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2022-03-31 to 2022-04-20
Example titles (3)
- Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners 2022-04-20
- Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet Malware 2022-04-08
- CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware 2022-04-08
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Eternity 9 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-05-12 to 2022-10-05
Example titles (3)
Evidence (3)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 5 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- Injector 9 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2017-10-09 to 2026-04-06
Example titles (3)
- GitHub - ryhanson/phishery: An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector 2026-04-06
- OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan 2026-04-06
- DotRunPEX - Demystifying New Virtualized .NET Injector used in the Wild 2023-03-15
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- WizardOpium 9 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2019-11-01 to 2020-06-03
Example titles (3)
- The WizardOpium LPE- Exploiting CVE-2019-1458 2020-06-03
- The zero-day exploits of Operation WizardOpium 2020-05-28
- The zero-day exploits of Operation WizardOpium _ Securelist Kaspersky, 2020-05-28
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SecurityScorecard 9 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2021-06-18 to 2026-04-06
Example titles (3)
- Inside a North Korean Phishing Operation Targeting DevOps Employees - SecurityScorecard 2026-04-06
- SecurityScorecard Discovers new botnet, ‘Zhadnost,’ responsible for Ukraine DDoS attacks 2022-03-10
- Operation Phantom Circuit: North Korea's Global Data Exfiltration Campaign - SecurityScorecard 2025-01-29
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Colibri 8 reports from 5 publishers
Actor Low, 67% pending confirmation
Seen 2022-02-13 to 2022-11-30
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 8 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Netfilter 8 reports from 5 publishers
Actor Low, 67% pending confirmation
Seen 2021-03-20 to 2025-05-19
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 6 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- BackConnect 8 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2017-11-21 to 2025-12-10
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- ChessMaster 8 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2017-07-27 to 2018-03-29
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- A report that uses this name cites CVE-2017-5689, which the dataset's other reports tie to Lazarus Group. context only
- CryptXXX 8 reports from 4 publishers
Actor Low, 31% pending confirmation
Seen 2016-05-05 to 2016-08-10
Example titles (3)
- CryptXXX - CrypMIC – intensywnie dystrybuowany ransomware w ramach exploit-kitów 2016-08-10
- CryptXXX \ CrypMIC – intensywnie dystrybuowany ransomware w ramach exploit-kitów 2016-08-10
- Malware-Traffic-Analysis.net - 2016-05-09 - pseudo-Darkleech Angler EK from 185.118.66[.]154 sends Bedep/CryptXXX ransomware 2016-05-09
Evidence (2)
- The name is 1 edit away from 'CryptXXXX', a malware listed by Malpedia. -0.7 argues against it
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Trouble 8 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2020-09-24 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Bandit 7 reports from 6 publishers
Actor Low, 67% pending confirmation
Seen 2019-10-24 to 2023-07-31
Example titles (3)
- Bandit Stealer Garbled 2023-07-31
- Breaking into the Bandit Stealer Malware Infrastructure 2023-07-11
- Bandit Stealer | ThreatLabz 2023-06-03
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Strela 7 reports from 6 publishers
Actor Low, 67% pending confirmation
Seen 2014-11-12 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 7 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Spook 7 reports from 5 publishers
Actor Low, 67% pending confirmation
Seen 2021-10-05 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- InPage 7 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2016-11-23 to 2018-11-29
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Maui 7 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2022-07-06 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 7 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Oski 7 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2021-01-07 to 2022-02-01
Example titles (3)
- Mars Stealer Oski refactoring 2022-02-01
- Mars Stealer: Oski refactoring 2022-02-01
- Oski Stealer : A Credential Theft Malware 2021-01-16
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 5 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- BlackNET 7 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2019-12-25 to 2026-04-06
Example titles (3)
Evidence (2)
- The name is 1 edit away from 'BackNet', a malware listed by Malpedia. -0.7 argues against it
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Hermetic 6 reports from 5 publishers
Actor Low, 67% pending confirmation
Seen 2022-02-25 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 6 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- RATatouille 6 reports from 5 publishers
Actor Low, 67% pending confirmation
Seen 2019-08-28 to 2025-06-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- HCrypt 6 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2021-03-16 to 2022-01-23
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- InSideCopy 6 reports from 4 publishers
Actor Low, 69% pending confirmation
Seen 2021-07-02 to 2021-07-07
Example titles (3)
Evidence (1)
- The name is 2 edits away from 'SideCopy', a name of the actor SideCopy. +0.6 supports the guess
- Parallax 6 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2020-02-13 to 2023-02-28
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- ADSelfService 6 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2021-09-08 to 2021-11-08
Example titles (3)
- Threat actor DEV-0322 exploiting ZOHO ManageEngine ADSelfService Plus 2021-11-08
- Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer PaloAlto, 2021-11-07
- Targeted Attack Campaign Against ManageEngine ADSelfService Plus Delivers Godzilla Webshells, NGLite Trojan and KdcSponge Stealer 2021-11-07
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Haron 6 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2021-05-10 to 2021-09-07
Example titles (3)
Evidence (2)
- The name is 1 edit away from 'Charon', a malware listed by Malpedia. -0.6 argues against it
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Mischa 6 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2016-05-19 to 2016-12-15
Example titles (3)
Evidence (2)
- The name is 1 edit away from 'Misha', a malware listed by Malpedia. -0.6 argues against it
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Rorschach 6 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2023-04-04 to 2023-04-19
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- CyberThreatIntel 6 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2019-10-10 to 2021-03-27
Example titles (3)
- CyberThreatIntel/Additional Analysis/Terraloader/2021-03-25/Analysis.md at master · StrangerealIntel/CyberThreatIntel 2021-03-27
- CyberThreatIntel/China/APT/Chimera/Analysis.md at master · StrangerealIntel/CyberThreatIntel Github (StrangerealIntel), 2020-10-11
- CyberThreatIntel/Additional Analysis/UnknownTA/2020-09-07/Analysis.md at master · StrangerealIntel/CyberThreatIntel 2020-09-07
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- StrangerealIntel 6 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2019-10-10 to 2021-03-27
Example titles (3)
- CyberThreatIntel/Additional Analysis/Terraloader/2021-03-25/Analysis.md at master · StrangerealIntel/CyberThreatIntel 2021-03-27
- CyberThreatIntel/China/APT/Chimera/Analysis.md at master · StrangerealIntel/CyberThreatIntel Github (StrangerealIntel), 2020-10-11
- CyberThreatIntel/Additional Analysis/UnknownTA/2020-09-07/Analysis.md at master · StrangerealIntel/CyberThreatIntel 2020-09-07
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- NukeSped 5 reports from 5 publishers
Actor Low, 67% pending confirmation
Seen 2021-06-22 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Castling 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2022-03-21 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- DarkCloud 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2018-03-06 to 2025-03-31
Example titles (3)
- DarkCloud 2025-03-31
- DarkCloud Infostealer Being Distributed via Spam Emails 2023-05-23
- DarkCloud Stealer Triage 2022-10-01
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- DCSync 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2026-04-06 to 2026-08-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- InterPlanetary 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2019-06-11 to 2023-06-28
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- KovCoreG 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2019-10-01
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- PRB 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2018-05-12 to 2018-06-19
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 5 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- PureLogs 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2025-07-02 to 2026-07-27
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- React2Shell 5 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2025-12-04 to 2025-12-19
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- FreeMilk 5 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2017-10-05 to 2018-10-03
Example titles (3)
- APT37- Final1stspy Reaping the FreeMilk 2018-10-03
- APT37 Final1stspy Reaping the FreeMilk Intezer, 2018-10-03
- FreeMilk: A Highly Targeted Spear Phishing Campaign 2017-10-05
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- HUI 5 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2018-12-01 to 2023-08-02
Example titles (3)
- HUI Loader — Malware Analysis Note 2023-08-02
- BRONZE STARLIGHT Ransomware Operations Use HUI Loader 2022-06-23
- HUI Loaderの分析 - JPCERT/CC Eyes 2022-05-16
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- PowerFall 5 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2020-08-12 to 2020-09-02
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SockDetour 5 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-02-24 to 2022-02-25
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- TrickBoot 5 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2020-12-03 to 2026-04-06
Example titles (3)
Evidence (1)
- The name is 1 edit away from 'TrickBot', a malware listed by ATT&CK and Malpedia. -0.7 argues against it
- CuckooBees 5 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-05-04 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Xtreme 5 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2012-06-21 to 2017-08-02
Example titles (3)
- Malspam delivers Xtreme RAT 8-1-2017 2017-08-02
- Malware.lu - Xtreme RAT analysis 2012-07-22
- Colombians major target of email campaigns delivering Xtreme RAT 2015-12-03
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 5 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Yanbian 5 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2018-11-26 to 2021-04-07
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 5 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- DCShadow 4 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2022-08-15 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- HackingTeam 4 reports from 4 publishers
Actor Low, 69% pending confirmation
Seen 2014-04-21 to 2018-01-16
Example titles (3)
- Skygofree: Following in the footsteps of HackingTeam 2018-01-16
- Skygofree- Following in the footsteps of HackingTeam 2018-01-16
- Skygofree_ Following in the footsteps of HackingTeam - Securelist Kaspersky, 2018-01-16
Evidence (1)
- The name uses the vendor naming word 'team', which appears in names of tracked groups. +0.7 supports the guess
- KeyBoys 4 reports from 4 publishers
Actor Low, 31% pending confirmation
Possibly the same as Tropic Trooper
Seen 2017-11-02 to 2026-04-06
Example titles (3)
- The KeyBoys are back in town 2026-04-06
- The KeyBoys are back in town 2017-11-03
- The KeyBoys are back in town PWC, 2017-11-02
Evidence (2)
- The name matches the actor Tropic Trooper (as 'KeyBoy') after removing a plural 's'. +0.8 supports the guess
- The name matches the malware 'KeyBoy' listed by ATT&CK and Malpedia after removing a plural 's'. -0.8 argues against it
- MacProStorage02 4 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2018-02-01 to 2019-06-25
Example titles (3)
- MacProStorage02:_2019CLF:Bitdefender-Whitepaper-Hard-creat3095-A4-v2-en_EN:Bitdefender-Whitepaper-Hard-creat3095-A4-v2-en_EN.indd Bitdefender Brand Department Dan-Mihai Iorgulescu-Stavri, 2019-06-25
- MacProStorage02:_Final:Bitdefender-WhitePaper-APTBluePrint-CREAT3496-31M1416s-en_EN:Bitdefender-WhitePaper-APTBluePrint-CREAT3496-31M1416s-en_EN.indd Bitdefender Dan-Mihai Iorgulescu-Stavri, 2019-06-04
- MacProStorage02:_2019CLF:Bitdefender-Whitepaper-Hard-creat3095-A4-v2-en_EN:Bitdefender-Whitepaper-Hard-creat3095-A4-v2-en_EN.indd 2019-04-12
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- MuddyC3 4 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2019-06-25 to 2021-01-13
Example titles (3)
- Reviving MuddyC3 Used by MuddyWater (IRAN) APT 2021-01-13
- Reviving MuddyC3 Used by MuddyWater (IRAN) APT 2021-01-13
- Reviving MuddyC3 Used by MuddyWater (IRAN) APT Shells.Systems, 2020-01-13
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- PupyRAT 4 reports from 4 publishers
Malware Low, 31% pending confirmation
Seen 2017-02-15 to 2020-01-23
Example titles (3)
Evidence (1)
- The name ends in 'rat', a word that usually names malware. +1.0 supports the guess
- Shady 4 reports from 4 publishers
Actor Low, 31% pending confirmation
Seen 2011-08-08 to 2026-04-06
Example titles (3)
- Operation Shady RAT - Threat Group Cards: A Threat Actor Encyclopedia 2026-04-06
- Operation Shady RAT 2026-04-06
- Shady RAT Vanity Fair, 2013-09-25
Evidence (2)
- The name is 1 edit away from 'Shade', a malware listed by Malpedia. -0.6 argues against it
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- SneakyPastes 4 reports from 4 publishers
Actor Low, 67% pending confirmation
Seen 2019-04-10 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- BadUSB 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2020-09-01 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- BlackWater 4 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2019-05-20 to 2026-04-06
Example titles (3)
Evidence (2)
- The name is 2 edits away from 'BlackMatter', a malware listed by Malpedia. -0.6 argues against it
- 2 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Clandestine Wolf 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2015-06-23 to 2015-07-05
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Cobian 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2017-08-31 to 2017-09-01
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- EITest 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2017-01-17 to 2017-09-01
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- FakeSecurity 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2019-11-08 to 2020-12-09
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- IPfuscation 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-03-29 to 2022-03-30
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- LagTime 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2019-07-23 to 2020-11-26
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Lime 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2018-08-27 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- PetitPotam 4 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2021-08-20 to 2026-04-06
Example titles (3)
Evidence (1)
- The name is 2 edits away from 'PetitPotato', a malware listed by Malpedia. -0.6 argues against it
- Prynt 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-04-21 to 2022-09-01
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- ServiceDesk 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2021-12-02
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SmoothOperator 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2023-03-29 to 2023-04-01
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SSHBearDoor 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2016-01-03 to 2026-04-06
Example titles (3)
- BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry 2026-04-06
- BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry 2016-01-06
- BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry ESET, 2016-01-03
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- TopHat 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2018-01-26 to 2026-04-06
Example titles (3)
- The TopHat Campaign: Attacks Within The Middle East Region Using Popular Third-Party Services 2026-04-06
- unit42-the-tophat-campaign-attacks-within-the-middle-east-region-using-popular-third-party-services Palo Alto, 2018-01-26
- The TopHat Campaign- Attacks Within The Middle East Region Using Popular Third-Party Services 2018-01-26
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Water Pamola 4 reports from 3 publishers
Actor Low, 69% pending confirmation
Seen 2021-04-28 to 2022-04-04
Example titles (3)
- Confirmation of damage to domestic e-commerce sites, actual situation of Web skimming attacks and examples of countermeasures that Rack thinks (Water Pamola) 2022-04-04
- Water Pamola Attacked Online Shops Via Malicious Orders Trend Micro, 2021-04-28
- Water Pamola Attacked Online Shops Via Malicious Orders 2021-04-28
Evidence (1)
- The name uses the vendor naming word 'water', which appears in names of tracked groups. +0.7 supports the guess
- Xeno 4 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2024-02-23 to 2024-07-06
Example titles (3)
- GitHub - moom825/xeno-rat: Xeno-RAT is an open-source remote access tool (RAT) developed in C#, providing a comprehensive set of features for remote system management. Has features such as HVNC, live microphone, reverse proxy, and much much more! 2024-07-06
- Good Game, Gone Bad: Xeno RAT Spread Via .gg Domains and GitHub 2024-06-25
- Xeno RAT: A New Remote Access Trojan with Advance Capabilities - CYFIRMA 2024-02-23
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Avos 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2021-12-22 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- BlueCrab 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2021-01-28 to 2021-02-01
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 2 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Haskers 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-04-14
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- LemonCat 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2021-07-22 to 2021-07-29
Example titles (3)
- When coin miners evolve, Part 2- Hunting down LemonDuck and LemonCat attacks 2021-07-29
- When coin miners evolve, Part 2: Hunting down LemonDuck and LemonCat attacks 2021-07-29
- When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure | Microsoft Security Blog 2021-07-22
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- PlainSight 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2023-01-26 to 2023-01-29
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Rehashed 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2017-09-05 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 4 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- ShortAndMalicious 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-11-08 to 2023-09-19
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- TransferXL 4 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-05-19 to 2022-05-20
Example titles (3)
- Bumblebee Malware from TransferXL URLs 2022-05-20
- Bumblebee Malware from TransferXL URLs - SANS ISC 2022-05-19
- Bumblebee Malware from TransferXL URLs 2022-05-19
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Atlas RedOctober 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2014-12-10
Example titles (3)
- Cloud Atlas- RedOctober APT is back in style 2014-12-10
- Cloud Atlas: RedOctober APT is back in style - Securelist Kaspersky, 2014-12-10
- Cloud Atlas: RedOctober APT is back in style 2014-12-10
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- CCleanup 3 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2017-09-18
Example titles (3)
- CCleanup- A Vast Number of Machines at Risk 2017-09-18
- CCleanup: A Vast Number of Machines at Risk 2017-09-18
- CCleanup Symantec, 2017-09-18
Evidence (1)
- The name is 1 edit away from 'CleanUp', a malware listed by Malpedia. -0.7 argues against it
- CKing 3 reports from 3 publishers
Actor Low, 31% pending confirmation
Seen 2018-10-01 to 2020-05-14
Example titles (3)
Evidence (1)
- The name is 1 edit away from 'Cring', a malware listed by Malpedia. -0.6 argues against it
- CryWiper 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-12-01 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Dissident NSO 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2016-08-24 to 2026-04-06
Example titles (3)
- The Million Dollar Dissident: NSO Group's iPhone Zero-Days Used Against A UAE Human Rights Defender - The Citizen Lab 2026-04-06
- The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender - The Citizen Lab 2016-08-26
- The Million Dollar Dissident: NSO Group's iPhone Zero-Days used against a UAE Human Rights Defender Citizen Lab, 2016-08-24
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- DRBControl 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2020-02-18
Example titles (3)
- Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations 2020-02-18
- Operation DRBControl: Uncovering a Cyberespionage Campaign Targeting Gambling Companies in Southeast Asia 2020-02-18
- Uncovering DRBControl- Inside the Cyberespionage Campaign Targeting Gambling Operations 2020-02-18
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- DriveGuard 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-02-15
Example titles (3)
- Guard Your Drive from DriveGuard- Moses Staff Campaigns Against Israeli Organizations Span Several Months 2022-02-15
- Guard Your Drive from DriveGuard: Moses Staff Campaigns Against Israeli Organizations Span Several Months fortinet, 2022-02-15
- Guard Your Drive from DriveGuard: Moses Staff Campaigns Against Israeli Organizations Span Several Months | FortiGuard Labs 2022-02-15
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- ElephantRAT 3 reports from 3 publishers
Malware Low, 31% pending confirmation
Seen 2021-02-01 to 2021-02-17
Example titles (3)
- blog.vincss.net-RE020 ElephantRAT Kunming version our latest discovered RAT of Panda and the similarities with recent 2021-02-17
- [RE020] ElephantRAT (Kunming version)- our latest discovered RAT of Panda and the similarities with recently Smanager RAT 2021-02-17
- VinCSS Blog_ [RE020] ElephantRAT (Kunming version)_ our latest discovered RAT of Panda and the similarities with recently Smanager RAT VinCSS, 2021-02-01
Evidence (1)
- The name ends in 'rat', a word that usually names malware. +1.0 supports the guess
- FriarFox 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2021-02-25 to 2026-04-06
Example titles (3)
- TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations | Proofpoint UK 2026-04-06
- proofpoint.com-TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organiz Microsoft, 2021-02-25
- TA413 Leverages New FriarFox Browser Extension to Target the Gmail Accounts of Global Tibetan Organizations 2021-02-25
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- KitKat 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2014-09-23 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- KMSPico 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2021-12-02 to 2021-12-04
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Kraken Cryptor 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2018-09-14 to 2018-10-30
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- MyKings 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2019-12-16 to 2021-10-12
Example titles (3)
- The King is Dead, Long Live MyKings! (Part 1 of 2) 2021-10-12
- The King is Dead, Long Live MyKings! (Part 1 of 2) 2021-10-12
- SophosLabs Uncut MyKings Report RSA, 2019-12-16
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- NetSupportManager 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-04-11 to 2026-04-06
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- NoName 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2023-04-04 to 2024-06-27
Example titles (3)
- AzzaSec & NoName Join Forces: Threat To Ukraine's Allies? 2024-06-27
- A Blog with NoName 2023-04-04
- A Blog with NoName 2023-04-04
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SCANdalous 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2020-07-13 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SettingContent 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2018-07-19 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SpyAgent 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2022-10-11 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- StrongPity3 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2020-06-29
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- SugarGh0st 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2023-11-30 to 2024-06-25
Example titles (3)
- SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques 2024-06-25
- SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques 2024-06-21
- New SugarGh0st RAT targets Uzbekistan government and South Korea Cisco, 2023-11-30
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Tempting Cedar 3 reports from 3 publishers
Actor Low, 67% pending confirmation
Seen 2018-02-21
Example titles (3)
- Avast tracks down Tempting Cedar Spyware 2018-02-21
- Avast tracks down Tempting Cedar Spyware RSA, 2018-02-21
- Avast tracks down Tempting Cedar Spyware 2018-02-21
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- Aura 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2025-07-29 to 2025-10-29
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- C2aaS 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2018-04-13 to 2022-08-04
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- ChainVeil 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2026-06-16 to 2026-07-17
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- ChinaZ 3 reports from 2 publishers
Actor Low, 31% pending confirmation
Seen 2019-01-07 to 2026-04-06
Example titles (3)
- ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups 2026-04-06
- ChinaZ Revelations- Revealing ChinaZ Relationships with other Chinese Threat Actor Groups 2019-01-07
- ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups 2019-01-07
Evidence (1)
- The name is 1 edit away from 'Chinad', a malware listed by Malpedia. -0.6 argues against it
- Kardon 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2018-06-19 to 2018-06-23
Example titles (3)
- Malware Analysis- Kardon Loader 2018-06-23
- Kardon Loader Looks for Beta Testers | NETSCOUT 2018-06-19
- Kardon Loader Looks for Beta Testers 2018-06-19
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- M00nD3V 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2020-06-30 to 2020-07-10
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- MacProStorage 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2017-02-21 to 2021-05-18
Example titles (3)
- MacProStorage-T3:4Work:Bitdefender-PR-Whitepaper-creat4279-en_EN:Bitdefender-PR-Whitepaper-creat4279-en_EN.indd 2021-05-18
- MacProStorage:_2017Final:Bitdefender-Whitepaper-APT-Mac-A4-en_EN:Bitdefender-Whitepaper-APT-Mac-A4-en_EN.indd Bitdefender, 2017-02-21
- MacProStorage-T3:4Work:Bitdefender-WhitePaper-RDPA-CREA4155-en_EN:Bitdefender-WhitePaper-RDPA-CREA4155-en_EN.indd 2019-12-18
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- NCC 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2020-06-23 to 2026-09-04
Example titles (3)
- NCC Group Monthly Threat Pulse – Review of July 2026 2026-09-04
- TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access – NCC Group Research NCC Group, 2021-11-08
- WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research NCC Group, 2020-06-23
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for an actor, such as 'threat actor' or 'APT'. context only
- RestyLink 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-05-11 to 2026-04-06
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- SLServer 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2016-04-18 to 2016-05-14
Example titles (3)
- Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaign Citizen Lab, 2016-05-14
- Between Hong Kong and Burma_ Tracking UP007 and SLServer Espionage Campaigns - The Citizen Lab 2016-04-20
- Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaigns - The Citizen Lab Citizen Lab, 2016-04-18
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- Socketless 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-02-24 to 2022-02-25
Example titles (3)
Evidence (2)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- 3 report titles write this name next to a word for malware, such as 'stealer' or 'loader'. context only
- TA02 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2022-01-27
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only
- ThreeDollars 3 reports from 2 publishers
Actor Low, 67% pending confirmation
Seen 2018-02-23
Example titles (3)
Evidence (1)
- No measured signal fired, so this is only the most common label in the ground truth (actor, 44 of 64 names). context only