Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
Malware family tracked by Malpedia. ID: win.unidentified_098
Malware family tracked by Malpedia. ID: win.unidentified_097
Keylogger.
Updated: 2025-10-15
View profile →
Wiper, using EldoS RawDisk for low level access to disks.
Check Point Research observed this malware being used by Sidewinder.
APT GROUPespionageadvanced
According to Antiy CERT, this is a C++ backdoor that was first discovered in an attack by Confucius in September 2020. Its main functions include creating scheduled tasks, retrieving process information, retrieving network adapter information, retrieving disk drive information, uploading files, downloading files, executing files, and providing shell access.
Avast found this unidentified RAT, which abuses a code-signing certificate by the Philippine Navy. It is statically linked against OpenSSL 1.1.1g.
Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
Updated: 2023-07-24
View profile →
APT GROUPespionageadvanced
Downloader used in suspected APT attack against Vietnam.
Updated: 2023-07-24
View profile →
APT GROUPfinancialhigh
Ransomware written in Nim.
Symantec describes this family as an unidentified tool set used to target a range of organizations in South East Asia. The campaign was first noticed in September 2020.
A RAT written in .NET, potentially used by Transparent Tribe.
Malware family tracked by Malpedia. ID: win.unidentified_083
This Trojan is a full-featured RAT capable of executing common tasks such as command execution and downloading/uploading files. This is implemented through a couple dozen C++ classes such as CMFile, CMFile, CMProcess, TFileDownload, TDrive, TProcessInfo, TSock, etc. The first stage custom installer utilizes the same classes. The Trojan uses HTTP Server API to filter HTTPS packets at port 443 and parse commands. It is also used by attackers to gather a target’s data, make lateral movements and create SOCKS tunnels to their C2 using the Earthworm tunneler.Given that the Trojan is an HTTPS server itself, the SOCKS tunnel is used for targets without an external IP, so the C2 is able to send commands.
Suspected Zebrocy loader written in Nim.
Malware family tracked by Malpedia. ID: win.unidentified_077
Malware family tracked by Malpedia. ID: win.unidentified_076
Unpacked http_dll.dat from the blog post.
Updated: 2023-07-24
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_074
Malware family tracked by Malpedia. ID: win.unidentified_073
MSI-based loader that has been observed as a stager for win.metamorfo.
Malware family tracked by Malpedia. ID: win.unidentified_071
Unidentified downloader, possibly related to KONNI.
Zeus derivate, no known public references.
Malware family tracked by Malpedia. ID: win.unidentified_068
Malware family tracked by Malpedia. ID: win.unidentified_067
This .net executable can receive commands from c2 sever, upload and download files according to the returned content, perform an uninstall, or modify the registry to achieve persistence across reboots. At the end, it downloads a Python-based RAT, called PeppyRAT.
Was previously wrongly tagged as PoweliksDropper, now looking for additional context.
Updated: 2019-07-31
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_058
Unnamed portscanner as used in the Australian Parliament Hack (Feb 2019).
Malware family tracked by Malpedia. ID: win.unidentified_053
Updated: 2018-09-12
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_052
Updated: 2018-08-23
View profile →
APT GROUPespionageadvanced
RAT written in Delphi used by Patchwork APT.
Malware family tracked by Malpedia. ID: win.unidentified_045
Updated: 2018-06-13
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_044
Updated: 2018-05-17
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_042
Malware family tracked by Malpedia. ID: win.unidentified_041
Updated: 2018-03-16
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_039
Updated: 2017-11-16
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_038
Updated: 2017-11-16
View profile →
Malware family tracked by Malpedia. ID: win.unidentified_037
Updated: 2017-11-16
View profile →