Threat Actors

Profiles for actors tracked across more than one threat brief. Each card blends open-source intelligence with what Vega has observed in its reporting.

reported in Vega briefs 5 actors
ShinyHunters actor figure

ShinyHunters

4 briefs

Motivation

Financially motivated — data theft & extortion

First seen

2020

Also known as

Bling LibraUNC6240UNC6661UNC6671Sp1d3rhunters

Actor IOCs (31)

ShinyHunters is a financially motivated data-theft and extortion collective that rose to prominence in 2020 by breaching dozens of companies and selling stolen databases on underground forums such as RaidForums and, later, BreachForums. Rather than encrypting victims, the group specializes in mass data exfiltration followed by public extortion via its own data-leak site. Google's Threat Intelligence Group tracks the financially motivated cluster behind the current wave as UNC6240, with related vishing and SaaS-theft activity attributed to clusters UNC6661 and UNC6671. Recent operations have pivoted from bulk database dumps toward targeted social engineering — help-desk vishing, victim-branded SSO/Okta phishing pages, and OAuth/connected-app abuse — to plunder SaaS platforms like Salesforce, SharePoint, DocuSign and Google Workspace before extortion.

Sources: Wikipedia · Malpedia

Targeted sectors

BankingCommercial FacilitiesEducationFinancial ServicesInformation TechnologyInsuranceTechnologyHealthcareHospitalityMedia & EntertainmentRetailTelecommunications

Targeted regions

AustraliaCanadaNetherlandsUnited KingdomUnited StatesFrance
Scattered Spider actor figure

Scattered Spider

3 briefs

Motivation

Financially motivated — social engineering & ransomware

First seen

2022

Also known as

UNC3944Octo TempestMuddled Libra0ktapusOktapusScatter SwineStorm-0875Star Fraud

Actor IOCs (13)

Scattered Spider is a financially motivated, loosely organized collective of mostly native-English-speaking actors associated with the broader online community known as "The Com." Active since at least 2022, the group is best known for advanced social engineering — IT help-desk vishing, MFA-fatigue push bombing, and SIM-swapping — to defeat multi-factor authentication and seize initial access at large enterprises. After entry they register attacker-controlled MFA devices, abuse RMM tooling, federate rogue identity providers, and move laterally through cloud and on-prem estates before exfiltrating data and deploying ransomware (historically ALPHV/BlackCat, more recently DragonForce). Mandiant tracks the group as UNC3944, Microsoft as Octo Tempest, and Palo Alto Unit 42 as Muddled Libra.

Sources: Wikipedia · Malpedia

Targeted sectors

BankingFinancial ServicesInsuranceTechnologyBusiness Process OutsourcingGaming & CasinosHospitalityManufacturingRetailTelecommunications

Targeted regions

AustraliaCanadaNetherlandsUnited KingdomUnited StatesSingapore
TeamPCP actor figure

TeamPCP

3 briefs

Motivation

Credential theft & destructive supply-chain compromise

First seen

2026

Also known as

Mini Shai-HuludCanisterWorm (linked)

Actor IOCs (48)

TeamPCP is the threat actor behind a series of open-source software supply-chain compromises first widely documented in early 2026, including attacks on Aqua Security's Trivy, Checkmarx, the Bitwarden CLI, Telnyx, the SAP CAP npm ecosystem, and the TanStack/UiPath npm packages. Dubbed "Mini Shai-Hulud" for echoing the earlier Shai-Hulud npm worm, the group backdoors packages with npm preinstall hooks that fetch the Bun runtime and execute obfuscated stealers, harvesting developer and CI/CD credentials — including, in later waves, OIDC tokens read directly from GitHub Actions runner memory and password-vault data. Payloads self-propagate by republishing the victim's own packages and, in the TanStack wave, install a destructive daemon that wipes the user's home directory when the stolen GitHub token is revoked. As a recently-identified cluster, TeamPCP does not yet have established Wikipedia or Malpedia profiles; the supporting research lives in the related briefs below.

Targeted sectors

Financial ServicesTechnologyDevOps & CloudSoftware Development

Targeted regions

IranIsraelGlobal
Akira actor figure

Akira

2 briefs

Motivation

Financially motivated — Ransomware-as-a-Service

First seen

2023

Also known as

Storm-1567Howling ScorpiusGOLD SAHARA

Actor IOCs (78)

Akira is a ransomware-as-a-service operation that emerged in March 2023 and quickly became one of the most active extortion brands, using a retro 1980s-styled leak site and a double-extortion model. Affiliates gain initial access primarily through compromised VPN credentials (often accounts lacking MFA) and exploitation of edge appliances, then exfiltrate data and deploy Windows and Linux/ESXi encryptors. Akira shares notable code and operational overlaps with the former Conti ecosystem and has collected tens of millions of dollars in ransom payments across hundreds of victims.

Sources: Wikipedia · Malpedia

Targeted sectors

AgricultureEducationFinancial ServicesHealthcareManufacturingTechnologyConstructionCritical InfrastructureProfessional Services

Targeted regions

AustraliaCanadaGermanyUnited KingdomUnited States
Qilin actor figure

Qilin

2 briefs

Motivation

Financially motivated — Ransomware-as-a-Service

First seen

2022

Also known as

Agenda RansomwareAgendaWater Galura

Actor IOCs (24)

Qilin (also tracked as Agenda) is a Russia-linked ransomware-as-a-service operation active since mid-2022, running a double-extortion model: data is stolen and a victim-shaming data-leak site is used to pressure payment alongside encryption. Its affiliates deploy cross-platform Rust and Go encryptors against Windows, Linux and VMware ESXi hosts. Through 2025-2026 Qilin became one of the most prolific RaaS brands, absorbing affiliates as rival programs collapsed and drawing attention for high-impact intrusions against healthcare and other critical-service providers.

Sources: Wikipedia

Targeted sectors

HealthcareCritical InfrastructureEducationFinancial ServicesGovernmentManufacturingProfessional Services

Targeted regions

AustraliaCanadaFranceGermanyUnited KingdomUnited States

Related Briefs & Detections

Hunt these actors across your environment with Vega detections.

Hunt with Vega →