Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,713 entities
1337 GTWK
Technical ID: 1337_GTWK
APT GROUP
This is a Linux malware program consisting of several modules, parts of which were likely programmed using AI. It consists of a rootkit and an agent capable of executing malicious code.
APT GROUP
Malware family tracked by Malpedia. ID: win.potemkin
APT GROUPespionageadvanced
According to Gen Threat Labs, VoidStealer is a Malware-as-a-Service infostealer that targets browser credentials and is the first observed malware in the wild to employ a novel debugger-based Application-Bound Encryption bypass technique. It attaches to the browser process as a debugger and sets hardware breakpoints at specific code locations to extract the v20_master_key directly from browser memory during startup, without requiring privilege escalation or code injection. The technique is adapted from the open-source ElevationKatz project and specifically targets Chromium-based browsers such as Chrome and Edge. As a fallback, VoidStealer also implements a traditional process injection method to invoke the browser's internal decryption interface when the debugger approach is unavailable.
APT GROUP
UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and Mullvad exit nodes, utilizing over 200 IP addresses. Notably, several attacker hostnames, including a Kali Linux machine, were leaked during lateral movement, indicating hands-on-keyboard intrusion.
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures and sophisticated malware, including DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK. They compromised a legitimate domain to enhance their phishing efforts and employed at least 50 domains throughout the campaign. The actor demonstrated target research through personalized email addresses and subject lines, indicating a non-native English speaker. Their activities suggest a financial crime motive, with extensive use of obfuscation and fileless malware to evade detection.
Updated: 2026-08-03
View profile →
APT GROUPespionageadvanced
UAT-7810 is an APT actor responsible for maintaining the LapDogs ORB network and developing custom malware, including the backdoors SHORTLEASH and LONGLEASH, as well as DOGLEASH and JARLEASH. They exploit known vulnerabilities in unpatched Ruckus wireless routers and have been observed using infrastructure to host malicious payloads across various hardware platforms. Forensic analysis has revealed their use of multiple IP addresses for hosting and deploying malware, including a test binary named LEASHTEST for functionality checks on MIPS devices. Talos assesses UAT-7810 as a China-nexus threat actor, providing infrastructure to secondary APTs while maintaining distinct objectives.
🇨🇳 CN
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
UAT-11795 is a sophisticated, Russian-speaking, financially motivated adversary conducting malicious campaigns targeting users in the U.S. and Europe since June 2025. The actor employs CastleStealer and Remcos RAT as alternative payload implants. Their operations indicate a focus on financial gain through targeted attacks.
🇷🇺 RU
Updated: 2026-08-03
View profile →
Launched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on today’s cybercriminal landscape. This alliance brings together three of the most notorious English-speaking cybercriminal groups: Scattered Spider, LAPSUS$ and ShinyHunters. In just a few months, this organization has multiplied spectacular attacks against leading companies, stealing billions of pieces of data and perfecting the art of digital extortion.
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack chain from initial access to data destruction. It exploited CVE-2025-3248 against an exposed Langflow instance for initial access, then compromised MinIO using default credentials and manipulated MySQL for privilege escalation. The operation culminated in the encryption of over 1,300 configuration records in Nacos, with the encryption key lost, rendering the data unrecoverable. JADEPUFFER exemplifies a shift towards machine-speed extortion, where traditional security models are outpaced by automated threats.
Updated: 2026-08-03
View profile →
APT GROUPespionageadvanced
Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online gambling sector and domestic security. They rapidly exploited CVE-2025-55182 using automated scanning, reconnaissance commands, and multi-vulnerability campaigns. Their activities have been linked to infrastructure associated with the exploitation of trojanized platforms and malware deployment, including SNOWLIGHT and VShell.
🇨🇳 CN
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows systems while avoiding the CIS region. The group rebranded its ransomware as Beast in June 2024, enhancing its toolset to include support for Linux and VMware ESXi, and incorporating extensive use of NirSoft tools. The latest iteration, GodDamn, showcases advanced defensive evasion techniques, including the use of the PoisonX malicious driver component. Hyadina operates as a ransomware-as-a-service, collaborating with affiliates to execute attacks.
Updated: 2026-08-03
View profile →
APT GROUPespionageadvanced
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS. The group employs a modular command-and-control framework built on a shared .NET foundation, utilizing multiple compilation formats to create an anti-analysis layer. Their operations demonstrate a high operational tempo and a disciplined approach to target selection, particularly during campaigns like "Operation Epic Fury." By decoupling core infrastructure from mission-specific modules, Cavern Manticore enhances operational agility while complicating detection efforts for defenders.
🇮🇷 IR
Updated: 2026-08-03
View profile →
APT GROUPespionageadvanced
Armored Likho is an APT group targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. Their operations blend financially motivated campaigns with cyber-espionage, utilizing obfuscated, modular RATs and infostealers designed to evade dynamic analysis. They employ spear-phishing emails with deceptive themes to gain initial access, distributing malicious attachments that mimic legitimate content. Their toolkit includes BusySnake Stealer and AquilaRAT, with a focus on evolving TTPs and leveraging AI tools for payload generation.
Updated: 2026-08-03
View profile →
According to Group-IB, TriBack Loader is a custom shellcode loader used to deliver and execute secondary payloads in memory on targeted Windows systems. It operates through DLL sideloading, where a signed legitimate binary loads a malicious DLL that decrypts an encrypted companion file using a two-stage decryption routine consisting of byte reversal and rolling XOR with an offset. The decrypted shellcode is then executed via Win32 callback APIs such as InitOnceExecuteOnce, TimerQueue callbacks, or the undocumented EtwpCreateEtwThread, each chosen to evade detection by endpoint security products. Four observed variants indicate it is produced by a custom builder, with each variant rotating the callback API used for execution while maintaining the same decryption scheme and reflective loader mechanism for deploying final payloads.
APT GROUP
According to Proofpoint, ZimReaper is a JavaScript-based malware family delivered via a half-click cross-site scripting exploit (CVE-2025-66376) targeting Zimbra Collaboration Suite webmail servers, requiring only that the victim open or preview a malicious email in the webmail client. The exploit uses a tag-splitting technique where CSS "@import" directives fragment HTML tags to bypass Zimbra's client-side HTML sanitizer, allowing arbitrary JavaScript execution in the context of the authenticated webmail session. Once executed, ZimReaper steals the CSRF token, auto-filled credentials, and two-factor authentication codes from the browser, creates an app-specific password named "ZimbraWeb" for persistent IMAP/POP3/SMTP access, and exfiltrates stolen data via DNS queries and HTTP POST. The malware also enumerates the Global Address List and exfiltrates the last 90 days of the victim's emails in a TGZ archive, using obfuscation layers including XOR-encrypted payloads that evolved over the course of the campaign.
APT GROUP
According to its author, this is a C-based malware research framework designed to demonstrate advanced multi-stage system compromise techniques on Windows.
APT GROUP
According to Rapid7, ModeloRAT is a Python-based remote access trojan framework previously tied to the KongTuke group's browser extension campaigns, which in this incident was delivered through Microsoft Teams social engineering using a portable WinPython environment to bypass traditional detections. Its capabilities center on a long-running HTTP C2 beacon that can load DLLs via rundll32, launch additional Python modules, execute PowerShell commands, install MSI packages, handle persistence, and self-update or remove, while supporting supplementary modules for reverse shells, SOCKS proxying, and HTTP tunneling. The Python modules are obfuscated and run through pythonw.exe to avoid visible console windows, with all communication blended into normal-looking web traffic over port 80.
APT GROUP
According to Zscaler, MacSync (also tracked as MacSync Stealer) is a macOS information stealer likely developed by a Russian-speaking threat actor, as evidenced by Russian-language comments found in its third-stage AppleScript payload. It is distributed through a multi-stage ClickFix campaign that abuses shared Claude chats, ultimately delivering the core stealer via osascript, which leaves no file trace on disk. Its capabilities include stealing keychain data, browser credentials, cookies, and autofill information from Chromium- and Gecko-based browsers, harvesting cryptocurrency wallet data (both browser extensions and desktop applications), and collecting sensitive files such as cloud keys, shell history, and high-value documents, all of which are compressed and exfiltrated in 10MB HTTP PUT chunks. The malware also implements persistence by appending a curl command to ~/.zshrc, prompts the user for full disk access, and may drop additional trojanized payloads targeting hardware-wallet users.
APT GROUP
Jackskid is a Mirai-derived Linux/IoT DDoS botnet, first publicly documented by Foresiet in November 2025 and tracked by CNCERT/SecrSS as RCtea. It encrypts its configuration with a custom RC4 cipher post-processed by an LCG (key DEADBEEF CAFEBABE E0A4CBD6 BADC0DE5) and negotiates per-session ChaCha20 keys via XXTEA (passphrase FrshPckBnnnSplit). The same RC4+LCG modification appears in Aisuru, indicating a shared code lineage, and the family sits within the CatDDoS-derivative ecosystem. Later builds add ENS-based C2 resolution, an anti-competition module (0clKiller) backed by a NETLINK process monitor, and a pivot toward Android/ADB-exposed TV boxes. Jackskid and several related botnets were disrupted by law enforcement in March 2026.
APT GROUPespionageadvanced
Mysterious Elephant is an APT group active since 2023 that primarily targets government and foreign affairs entities across South Asia, especially Pakistan, Bangladesh, Sri Lanka, Nepal, and Afghanistan. In its early-2025 campaign it shifted toward spear-phishing and custom/customized tools—including the BabShell reverse shell and MemLoader HidenDesk/Edge loaders—to deploy RATs like Remcos and VRat, while also using WhatsApp-specific exfiltration tools to steal shared documents, images, and archives. The group shares code and infrastructure with other APT clusters (Origami Elephant, Confucius, SideWinder), reflecting ongoing tool reuse and collaboration among South Asian threat actors.
Updated: 2026-08-03
View profile →
APT GROUP
According to Kaspersky, this malware sticks out as performing a large set of operations in memory with the help of the malloc, memmove and memcmp function calls.
APT GROUP
According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling". In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.
APT GROUP
Malware family tracked by Malpedia. ID: win.warlock
Malware family tracked by Malpedia. ID: win.unidentified_003
Updated: 2016-12-29
View profile →
APT GROUPfinancialhigh
According to PCrisk, Trigona is ransomware that encrypts files and appends the "._locked" extension to filenames. Also, it drops the "how_to_decrypt.hta" file that opens a ransom note. An example of how Trigona renames files: it renames "1.jpg" to "1.jpg._locked", "2.png" to "2.png._locked", and so forth. It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.
APT GROUP
Malware family tracked by Malpedia. ID: win.termite
APT GROUPespionageadvanced
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company> A decryptor was released on 2022-02-07 by AVAST
APT GROUP
Malware family tracked by Malpedia. ID: win.taidoor
APT GROUPfinancialhigh
Ransomware, written in Delphi.
APT GROUPfinancialhigh
Ransomware, written in .NET.
APT GROUP
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.sarcoma
APT GROUP
Malware family tracked by Malpedia. ID: win.safepay
APT GROUP
Malware family tracked by Malpedia. ID: win.rtm_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.reynolds
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
A ransomware written in Rust.
APT GROUPfinancialhigh
According to ESET Research, PromptLock is first known AI-powered ransomware. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.
APT GROUP
Malware family tracked by Malpedia. ID: win.polyvice
← PreviousPage 1 / 268Next →