Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
APT GROUPespionageadvanced
[Aoqin Dragon](https://attack.mitre.org/groups/G1007) is a suspected Chinese cyber espionage threat group that has been active since at least 2013. [Aoqin Dragon](https://attack.mitre.org/groups/G1007) has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between [Aoqin Dragon](https://attack.mitre.org/groups/G1007) and UNC94, based on malware, infrastructure, and targets.(Citation: SentinelOne Aoqin Dragon June 2022)
🇨🇳 CNT1036T1203T1083
Updated: 2026-08-07
View profile →
APT GROUPespionageadvanced
Antlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan. This persistent campaign has lasted over the course of at least 18 months.
🇨🇳 CN
Updated: 2026-08-07
View profile →
APT GROUPfinancialhigh
Publicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial regulators and institutions. These campaigns used macro-enabled Microsoft documents to deliver the PowerShell Empire post-exploitation framework. ANTHROPOID SPIDER likely enabled a breach that allegedly involved fraudulent transfers over the SWIFT network.
Updated: 2026-08-07
View profile →
APT GROUPhacktivism
Since January 23, 2023, a threat actor identifying as "Anonymous Sudan" has been conducting denial of service (DDoS) attacks against multiple organizations in Sweden. This group claims to be "hacktivists," politically motivated hackers from Sudan. According to Truesec’s report, the threat actor has nothing to do with the online activists collectively known as Anonymous.
Updated: 2026-08-07
View profile →
APT GROUP
Anonymous KSA is a Saudi hacking group that has executed cyber attacks targeting Indian institutions, including a significant breach of UIDAI's data storage units, leading to access to sensitive information and system disruption. The group claims these actions are in response to India's normalization of ties with Israel and its treatment of Palestinians. They have called for support for the Palestinian cause and accountability for the damage caused by their operations. The group's TTPs include targeting government agencies and leveraging public sentiment to justify their actions.
Updated: 2026-08-07
View profile →
APT GROUP
Anonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electronic screens, and network television. The Ministry of State Security claims that Anonymous 64 is linked to a cyber unit within Taiwan's defense ministry and identifies three active-duty military personnel as its members. The MSS alleges that the group is involved in an influence operation within China, using hacktivism as a cover. The accusations suggest that Anonymous 64 engages in sabotage activities, prompting authorities to call for public reporting of such actions.
TW
Updated: 2026-08-07
View profile →
APT GROUPespionageadvanced
Angry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Russia and Belarus. Their attacks typically involve spear-phishing emails with malicious attachments, such as RAR archives, and utilize a known payload, the Lumma stealer, for data exfiltration. The group employs a compact infrastructure and has been linked to espionage activities, particularly in sectors like aviation and pharmaceuticals. Their operations have shown a focus on collecting sensitive information, including cryptowallet files and user credentials.
🇷🇺 RU
Updated: 2026-08-07
View profile →
Threat actor tracked by Malpedia.
Updated: 2026-08-07
View profile →
APT GROUPespionageadvanced
Amaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exhibiting similar tooling and operational patterns. The group demonstrated technical maturity by rapidly operationalizing CVE-2025-8088, a vulnerability in WinRAR, shortly after its public disclosure. Check Point Research has identified multiple campaigns targeting Cambodia, Thailand, Laos, Indonesia, Singapore, and the Philippines, with operations typically focused on one or two countries at a time. The overlaps in technical and operational indicators strongly suggest that Amaranth-Dragon is either affiliated with or part of the broader APT-41 ecosystem.
🇨🇳 CN
Updated: 2026-08-07
View profile →
APT GROUPhacktivism
ALTOUFAN TEAM is a politically motivated hacktivist group with anti-Zionism, anti-monarchy, and pro-14-February movement sentiments. They have targeted government agencies and organizations in Bahrain and Israel, claiming to support political causes in the region. The group has employed techniques such as credential theft to compromise systems, as demonstrated by their attack on Bahrain's Social Insurance Organization. ALTOUFAN maintains a presence on social media platforms to disseminate their messages and showcase their activities.
Updated: 2026-08-07
View profile →
APT GROUPfinancialhigh
ALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia. They have been involved in data breaches of companies in various sectors, such as real estate and retail, compromising sensitive information like customer names, bank account numbers, and transaction details. ALTDOS uses tactics like ransomware attacks, data exfiltration, and dumping data publicly or for sale on underground forums. The group has been known to demand ransom payments from victims, but also leaks data if demands are not met.
Updated: 2026-08-07
View profile →
APT GROUP
Altahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for a number of cyberattacks, including DDoS attacks against Israeli websites, a hack of the Israel Airports Authority website, and a cyberattack on the Orot Yosef power plant in Israel.
IQ
Updated: 2026-08-07
View profile →
APT GROUPfinancialhigh
ALPHA SPIDER is a threat actor known for developing and operating the Alphv ransomware as a service. They have been observed using novel offensive techniques, such as exploiting software vulnerabilities and leveraging legitimate administration tools for malicious activities. ALPHA SPIDER affiliates have demonstrated persistence in exfiltrating data and have shown the ability to bypass security measures like DNS-based filtering and multifactor authentication. Despite lacking specific operational security measures, defenders have opportunities to detect and respond to ALPHA SPIDER's operations effectively.
Updated: 2026-08-07
View profile →
APT GROUP
[ALLANITE](https://attack.mitre.org/groups/G1000) is a suspected Russian cyber espionage group, that has primarily targeted the electric utility sector within the United States and United Kingdom. The group's tactics and techniques are reportedly similar to [Dragonfly](https://attack.mitre.org/groups/G0035), although [ALLANITE](https://attack.mitre.org/groups/G1000)s technical capabilities have not exhibited disruptive or destructive abilities. It has been suggested that the group maintains a presence in ICS for the purpose of gaining understanding of processes and to maintain persistence. (Citation: Dragos)
T0852T0865T0817
Updated: 2026-08-07
View profile →
APT GROUPfinancialhigh
Aggressive Inventory Zombies is a threat actor involved in a large-scale phishing and pig-butchering network targeting retail brands and cryptocurrency users. They create fraudulent sites using a popular website template that scrapes product details from legitimate e-commerce platforms and integrate chat services for phishing. Financial ties to India have been identified, and collaboration with Stark Industries has led to the dismantling of parts of their infrastructure, revealing the network's breadth. AIZ is also linked to Entropy ransomware infections, which were preceded by detections of Cobalt Strike beacons and Dridex malware.
Updated: 2026-08-07
View profile →
APT GROUPespionageadvanced
AeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States. Their objective appears to be conducting commercial and competitive cyber espionage. They employ spear-phishing as a delivery mechanism, using weaponized documents with embedded remote template injection techniques and malicious VBA macro code. The attacks have been ongoing since September 2022, with multiple phases identified in the attack chain. The origin and precise objective of AeroBlade remain unknown.
Updated: 2026-08-07
View profile →
APT GROUPfinancialhigh
Adrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen data for sale. They describe themselves as a group of independent cybersecurity experts and researchers. Adrastea has been linked to ransomware operations, data leak platforms, and network access groups. The actor has been known to exploit critical vulnerabilities in target organizations' infrastructure to gain access to sensitive data.
Updated: 2026-08-07
View profile →
APT GROUPespionageadvanced
Actor240524 is a newly identified APT group that targeted Azerbaijani and Israeli diplomats through spear-phishing emails to steal sensitive data. The group employs a Trojan program known as ABCloader and ABCsync, demonstrating capabilities to steal secrets and modify file data. Their operations appear to focus on undermining the cooperative relationship between Azerbaijan and Israel. Actor240524 utilizes various countermeasures to obscure their attack tactics and techniques.
Updated: 2026-08-07
View profile →
APT GROUP
1937CN is a Chinese hacking group that has been active since at least 2013. The group is known for targeting Vietnamese organizations, including government agencies, businesses, and media outlets. 1937CN has been linked to a number of high-profile cyberattacks, including the hacking of Vietnam Airlines in 2016 and the defacement of Vietnamese government websites in 2015.
🇨🇳 CN
Updated: 2026-08-07
View profile →
ZynorRAT
Technical ID: win.zynor_rat
MALWARE
Malware family identifying win.zynor_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-05
View profile →
Zyklon
Technical ID: win.zyklon
MALWARE
According to FireEye, Zyklon or Zyklon HTTP is a publicly available, full-featured backdoor capable of keylogging, password harvesting, downloading and executing additional plugins, conducting distributed denial-of-service (DDoS) attacks, and self-updating and self-removal. The malware may communicate with its command and control (C2) server over The Onion Router (Tor) network if configured to do so. The malware can download several plugins, some of which include features such as cryptocurrency mining and password recovery, from browsers and email software. Zyklon also provides a very efficient mechanism to monitor the spread and impact.
Updated: 2023-09-22
View profile →
ZxxZ
Technical ID: win.zxxz
HAZY TIGER
MALWAREespionageadvanced
Cisco Talos attributes this backdoor with moderate confidence to the Bitter APT.
Also known as: MuuyDownloader
Updated: 2025-06-05
View profile →
ZXShell
Technical ID: win.zxshell
APT41EMISSARY PANDALeviathan
MALWAREespionageadvanced
According to FireEye, ZXSHELL is a backdoor that can be downloaded from the internet, particularly Chinese hacker websites. The backdoor can launch port scans, run a keylogger, capture screenshots, set up an HTTP or SOCKS proxy, launch a reverse command shell, cause SYN floods, and transfer/delete/run files. The publicly available version of the tool provides a graphical user interface that malicious actors can use to interact with victim backdoors. Simplified Chinese is the language used for the bundled ZXSHELL documentation.
Also known as: Sensocode
Updated: 2025-05-21
View profile →
Zupdax
Technical ID: win.zupdax
MALWARE
Malware family identifying win.zupdax. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-25
View profile →
ZUpdater
Technical ID: win.zupdater
MALWARE
Malware family identifying win.zupdater. Origin and technical characteristics tracked via Malpedia.
Also known as: Zpevdo
Updated: 2019-08-19
View profile →
Zumanek
Technical ID: win.zumanek
MALWARE
According to ESET, this malware family was active exclusively in Brazil until the middle of 2020. It s identified by its method for obfuscating strings. It creates a function for each character of the alphabet and then concatenates the result of calling the correct functions in sequence.
Updated: 2022-01-05
View profile →
ZStealer
Technical ID: win.zstealer
MALWARE
Information Stealer used by Void Balaur.
Also known as: Z*Stealer
Updated: 2021-12-22
View profile →
Zlob
Technical ID: win.zlob
MALWARE
Malware family identifying win.zlob. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-14
View profile →
Zloader
Technical ID: win.zloader
MALWAREfinancialhigh
This family describes the (initially small) loader, which downloads Zeus OpenSSL. In June 2016, a new loader was dubbed DEloader by Fortinet. It has some functions borrowed from Zeus 2.0.8.9 (e.g. the versioning, nrv2b, binstorage-labels), but more importantly, it downloaded a Zeus-like banking trojan (-> Zeus OpenSSL). Furthermore, the loader shared its versioning with the Zeus OpenSSL it downloaded. The initial samples from May 2016 were small (17920 bytes). At some point, visualEncrypt/Decrypt was added, e.g. in v1.11.0.0 (September 2016) with size 27648 bytes. In January 2017 with v1.15.0.0, obfuscation was added, which blew the size up to roughly 80k, and the loader became known as Zloader aka Terdot. These changes may be related to the Moskalvzapoe Distribution Network, which started the distribution of it at the same time. Please note that IBM X-Force decided to call win.zloader/win.zeus_openssl "Zeus Sphinx", after mentioning it as "a new version of Zeus Sphinx" in their initial post in August 2016. Malpedia thus lists the alias "Zeus XSphinx" for win.zeus_openssl - the X to refer to IBM X-Force.
Also known as: DELoader • SILENTNIGHT • Terdot
Updated: 2025-02-25
View profile →
ZiyangRAT
Technical ID: win.ziyangrat
MALWARE
Malware family identifying win.ziyangrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-27
View profile →
ZitMo
Technical ID: win.zitmo
MALWARE
Malware family identifying win.zitmo. Origin and technical characteristics tracked via Malpedia.
Also known as: ZeuS-in-the-Mobile
Updated: 2021-05-25
View profile →
ZingoStealer
Technical ID: win.zingo_stealer
MALWARE
An information stealer written in .NET.
Also known as: Ginzo
Updated: 2024-05-06
View profile →
ZhMimikatz
Technical ID: win.zhmimikatz
Cleaver
MALWARE
Malware family identifying win.zhmimikatz. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-01-20
View profile →
ZhCat
Technical ID: win.zhcat
MALWARE
Malware family identifying win.zhcat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-17
View profile →
zgRAT
Technical ID: win.zgrat
MALWARE
zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets. Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on.
Updated: 2024-05-14
View profile →
Zezin
Technical ID: win.zezin
MALWARE
Malware family identifying win.zezin. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-02
View profile →
Zeus Sphinx
Technical ID: win.zeus_sphinx
MALWARE
This family describes the vanilla Zeus-variant that includes TOR (and Polipo proxy). It has an almost 90% overlap with Zeus v2.0.8.9. Please note that IBM X-Force decided to call win.zloader/win.zeus_openssl "Zeus Sphinx", after mentioning it as "a new version of Zeus Sphinx" in their initial post in August 2016. Malpedia thus lists the alias "Zeus XSphinx" for win.zeus_openssl - the X to refer to IBM X-Force. Zeus Sphinx on the one hand has the following versioning ("slow increase") - 2015/09 v1.0.1.0 (Zeus Sphinx size: 1.5 MB) - 2016/02 v1.0.1.2 (Zeus Sphinx size: 1.5 MB) - 2016/04 v1.0.2.0 (Zeus Sphinx size: 1.5 MB) Zeus OpenSSL on the other hand has the following versioning ("fast increase") - 2016/05 v1.5.4.0 (Zeus OpenSSL size: 1.2 MB) - 2017/01 v1.14.8.0 (Zeus OpenSSL size: 1.8 MB) - 2017/01 v1.15.0.0 (Zeus OpenSSL size: 2.2 MB)
Updated: 2022-09-21
View profile →
Zeus OpenSSL
Technical ID: win.zeus_openssl
MALWARE
This family describes the Zeus-variant that includes a version of OpenSSL and usually is downloaded by Zloader. In June 2016, the version 1.5.4.0 (PE timestamp: 2016.05.11) appeared, downloaded by Zloader (known as DEloader at that time). OpenSSL 1.0.1p is statically linked to it, thus its size is roughly 1.2 MB. In subsequent months, that size increased up to 1.6 MB. In January 2017, with version 1.14.8.0, OpenSSL 1.0.2j was linked to it, increasing the size to 1.8 MB. Soon after also in January 2017, with version v1.15.0.0 the code was obfuscated, blowing up the size of the binary to 2.2 MB. Please note that IBM X-Force decided to call win.zloader/win.zeus_openssl "Zeus Sphinx", after mentioning it as "a new version of Zeus Sphinx" in their initial post in August 2016. Malpedia thus lists the alias "Zeus XSphinx" for win.zeus_openssl - the X to refer to IBM X-Force. Zeus Sphinx on the one hand has the following versioning ("slow increase") - 2015/09 v1.0.1.0 (Zeus Sphinx size: 1.5 MB) - 2016/02 v1.0.1.2 (Zeus Sphinx size: 1.5 MB) - 2016/04 v1.0.2.0 (Zeus Sphinx size: 1.5 MB) Zeus OpenSSL on the other hand has the following versioning ("fast increase") - 2016/05 v1.5.4.0 (Zeus OpenSSL size: 1.2 MB) - 2017/01 v1.14.8.0 (Zeus OpenSSL size: 1.8 MB) - 2017/01 v1.15.0.0 (Zeus OpenSSL size: 2.2 MB)
Also known as: XSphinx
Updated: 2020-04-01
View profile →
Zeus MailSniffer
Technical ID: win.zeus_mailsniffer
MALWARE
Malware family identifying win.zeus_mailsniffer. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →
ZeusAction
Technical ID: win.zeus_action
MALWARE
Malware family identifying win.zeus_action. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-01
View profile →
← PreviousPage 121 / 269Next →