Threat Actors

Profiles for actors tracked across more than one threat brief. Each card blends open-source intelligence with what Vega has observed in its reporting.

reported in Vega briefs 7 actors
ShinyHunters actor figure

ShinyHunters

5 briefs

Motivation

Financially motivated — data theft & extortion

First seen

2020

Also known as

Bling LibraUNC6240UNC6661UNC6671Sp1d3rhunters

Actor IOCs (157)

ShinyHunters is a financially motivated data-theft and extortion collective that rose to prominence in 2020 by breaching dozens of companies and selling stolen databases on underground forums such as RaidForums and, later, BreachForums. Rather than encrypting victims, the group specializes in mass data exfiltration followed by public extortion via its own data-leak site. Google's Threat Intelligence Group tracks the financially motivated cluster behind the current wave as UNC6240, with related vishing and SaaS-theft activity attributed to clusters UNC6661 and UNC6671. Recent operations have pivoted from bulk database dumps toward targeted social engineering — help-desk vishing, victim-branded SSO/Okta phishing pages, and OAuth/connected-app abuse — to plunder SaaS platforms like Salesforce, SharePoint, DocuSign and Google Workspace before extortion.

Sources: Wikipedia · Malpedia

Targeted sectors

BankingCommercial FacilitiesEducationFinancial ServicesInformation TechnologyInsuranceTechnologyHealthcareHospitalityMedia & EntertainmentRetailTelecommunications

Targeted regions

AustraliaCanadaNetherlandsUnited KingdomUnited StatesFrance
Famous Chollima actor figure

Famous Chollima

3 briefs

Motivation

Financially motivated — state-sponsored revenue generation (DPRK)

First seen

2018

Also known as

UNC5267Jasper SleetWagemoleWage MoleWageMole

Actor IOCs (16)

Famous Chollima is a North Korean state-sponsored cluster best known for the fraudulent remote IT worker scheme, in which operatives use stolen or fabricated identities, AI-enhanced profiles and facilitator-run "laptop farms" to get hired as remote software developers and IT contractors at Western companies. Wages are funneled back to the DPRK regime, and the access gained on the job is increasingly used for data theft, source-code exfiltration and extortion after dismissal. The same cluster runs "Contagious Interview" fake-recruiter campaigns that deliver malware such as BeaverTail and InvisibleFerret to job seekers. Mandiant tracks the IT worker activity as UNC5267, Microsoft as Jasper Sleet, and Palo Alto Unit 42 as Wagemole.

Sources: Malpedia · Google Cloud (UNC5267)

Targeted sectors

AutomotiveBankingEnergyGovernmentHealthcareLogistics & Supply Chain ManagementManufacturingMedia & EntertainmentSocial MediaTechnologyTransportationTravel and HospitalityCryptocurrencyDefenseFinancial ServicesProfessional ServicesSoftware Development

Targeted regions

CanadaGermanyJapanPLPTSKSpainUnited KingdomUnited StatesAustraliaSouth Korea
MuddyWater actor figure

MuddyWater

3 briefs

Motivation

Espionage — Iranian state-sponsored (MOIS)

First seen

2017

Also known as

SeedwormStatic KittenMango SandstormMERCURYTEMP.ZagrosTemp ZagrosTA450Earth VetalaBoggy Serpens

Actor IOCs (57)

MuddyWater is an Iranian cyber-espionage group that US and UK authorities have attributed to Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017, it targets government, telecommunications, energy and critical-infrastructure organizations, mainly across the Middle East but increasingly in Europe, Asia and North America. The group relies on spear-phishing and, more recently, ClickFix and Microsoft Teams social engineering to deploy legitimate remote-management tools (such as Atera, ScreenConnect and SimpleHelp) alongside custom backdoors, and it uses DLL sideloading, credential theft and public file-sharing services for exfiltration. It has also carried out destructive and false-flag operations disguised as ransomware. Symantec tracks the group as Seedworm, CrowdStrike as Static Kitten, and Microsoft as Mango Sandstorm (formerly MERCURY).

Sources: MITRE ATT&CK · Malpedia · CISA Advisory AA22-055A

Targeted sectors

AutomotiveAviationBankingConstructionEducationElectronicsFinancial ServicesGovernmentHealthcareManufacturingMedia & EntertainmentProfessional ServicesPublic SectorSocial MediaTransportationTravel and HospitalityCritical InfrastructureDefenseEnergyOil & GasTelecommunications

Targeted regions

CanadaIsraelJapanPLSKSpainUnited KingdomUnited StatesEuropeIraqJordanPakistanSaudi ArabiaTurkeyUnited Arab Emirates
Scattered Spider actor figure

Scattered Spider

3 briefs

Motivation

Financially motivated — social engineering & ransomware

First seen

2022

Also known as

UNC3944Octo TempestMuddled Libra0ktapusOktapusScatter SwineStorm-0875Star Fraud

Actor IOCs (13)

Scattered Spider is a financially motivated, loosely organized collective of mostly native-English-speaking actors associated with the broader online community known as "The Com." Active since at least 2022, the group is best known for advanced social engineering — IT help-desk vishing, MFA-fatigue push bombing, and SIM-swapping — to defeat multi-factor authentication and seize initial access at large enterprises. After entry they register attacker-controlled MFA devices, abuse RMM tooling, federate rogue identity providers, and move laterally through cloud and on-prem estates before exfiltrating data and deploying ransomware (historically ALPHV/BlackCat, more recently DragonForce). Mandiant tracks the group as UNC3944, Microsoft as Octo Tempest, and Palo Alto Unit 42 as Muddled Libra.

Sources: Wikipedia · Malpedia

Targeted sectors

BankingFinancial ServicesInsuranceTechnologyBusiness Process OutsourcingGaming & CasinosHospitalityManufacturingRetailTelecommunications

Targeted regions

AustraliaCanadaNetherlandsUnited KingdomUnited StatesSingapore
TeamPCP actor figure

TeamPCP

3 briefs

Motivation

Credential theft & destructive supply-chain compromise

First seen

2026

Also known as

Mini Shai-HuludCanisterWorm (linked)

Actor IOCs (48)

TeamPCP is the threat actor behind a series of open-source software supply-chain compromises first widely documented in early 2026, including attacks on Aqua Security's Trivy, Checkmarx, the Bitwarden CLI, Telnyx, the SAP CAP npm ecosystem, and the TanStack/UiPath npm packages. Dubbed "Mini Shai-Hulud" for echoing the earlier Shai-Hulud npm worm, the group backdoors packages with npm preinstall hooks that fetch the Bun runtime and execute obfuscated stealers, harvesting developer and CI/CD credentials — including, in later waves, OIDC tokens read directly from GitHub Actions runner memory and password-vault data. Payloads self-propagate by republishing the victim's own packages and, in the TanStack wave, install a destructive daemon that wipes the user's home directory when the stolen GitHub token is revoked. As a recently-identified cluster, TeamPCP does not yet have established Wikipedia or Malpedia profiles; the supporting research lives in the related briefs below.

Targeted sectors

Financial ServicesTechnologyDevOps & CloudSoftware Development

Targeted regions

IranIsraelGlobal
Akira actor figure

Akira

2 briefs

Motivation

Financially motivated — Ransomware-as-a-Service

First seen

2023

Also known as

Storm-1567Howling ScorpiusGOLD SAHARA

Actor IOCs (78)

Akira is a ransomware-as-a-service operation that emerged in March 2023 and quickly became one of the most active extortion brands, using a retro 1980s-styled leak site and a double-extortion model. Affiliates gain initial access primarily through compromised VPN credentials (often accounts lacking MFA) and exploitation of edge appliances, then exfiltrate data and deploy Windows and Linux/ESXi encryptors. Akira shares notable code and operational overlaps with the former Conti ecosystem and has collected tens of millions of dollars in ransom payments across hundreds of victims.

Sources: Wikipedia · Malpedia

Targeted sectors

AgricultureEducationFinancial ServicesHealthcareManufacturingTechnologyConstructionCritical InfrastructureProfessional Services

Targeted regions

AustraliaCanadaGermanyUnited KingdomUnited States
Qilin actor figure

Qilin

2 briefs

Motivation

Financially motivated — Ransomware-as-a-Service

First seen

2022

Also known as

Agenda RansomwareAgendaWater Galura

Actor IOCs (24)

Qilin (also tracked as Agenda) is a Russia-linked ransomware-as-a-service operation active since mid-2022, running a double-extortion model: data is stolen and a victim-shaming data-leak site is used to pressure payment alongside encryption. Its affiliates deploy cross-platform Rust and Go encryptors against Windows, Linux and VMware ESXi hosts. Through 2025-2026 Qilin became one of the most prolific RaaS brands, absorbing affiliates as rival programs collapsed and drawing attention for high-impact intrusions against healthcare and other critical-service providers.

Sources: Wikipedia

Targeted sectors

HealthcareCritical InfrastructureEducationFinancial ServicesGovernmentManufacturingProfessional Services

Targeted regions

AustraliaCanadaFranceGermanyUnited KingdomUnited States

Related Briefs & Detections

Hunt these actors across your environment with Vega detections.

Hunt with Vega →