Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Unidentified 023
Technical ID: win.unidentified_023
MALWARE
Malware family identifying win.unidentified_023. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →Unidentified 022 (Ransom)
Technical ID: win.unidentified_022_ransom
MALWARE
Malware family identifying win.unidentified_022_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →MALWARE
Malware family identifying win.unidentified_020_cia_vault7. Origin and technical characteristics tracked via Malpedia.
Unidentified 013 (Korean)
Technical ID: win.unidentified_013_korean_malware
MALWARE
Malware family identifying win.unidentified_013_korean_malware. Origin and technical characteristics tracked via Malpedia.
Unidentified 006
Technical ID: win.unidentified_006
MALWARE
Malware family identifying win.unidentified_006. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →Unidentified 003
Technical ID: win.unidentified_003
MALWARE
Malware family identifying win.unidentified_003. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-29
View profile →Unidentified 001
Technical ID: win.unidentified_001
MALWARE
Malware family identifying win.unidentified_001. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-29
View profile →UnderminerEK
Technical ID: win.underminer_ek
MALWARE
Malware family identifying win.underminer_ek. Origin and technical characteristics tracked via Malpedia.
Umbral
Technical ID: win.umbral
MALWAREfinancialhigh
Umbral is a data-stealing Trojan that targets Windows systems. It spreads through phishing emails and malicious attachments. Once installed, Umbral can steal a variety of data, including usernames, passwords, online banking credentials, and confidential files. It can also change computer settings and execute harmful commands. Umbral is a serious security threat and should be removed immediately if found.
Uiwix
Technical ID: win.uiwix
MALWARE
Malware family identifying win.uiwix. Origin and technical characteristics tracked via Malpedia.
UDPoS
Technical ID: win.udpos
MALWARE
Malware family identifying win.udpos. Origin and technical characteristics tracked via Malpedia.
UACMe
Technical ID: win.uacme
MALWARE
A toolkit maintained by hfiref0x which incorporates numerous UAC bypass techniques for Windows 7 - Windows 10. Typically, components of this tool are stripped out and reused by malicious actors.
Also known as: Akagi
tRat
Technical ID: win.trat
MALWARE
tRat is a modular RAT written in Delphi and has appeared in campaigns in September and October of 2018.
T-Cmd
Technical ID: win.t_cmd
MALWARE
Malware family identifying win.t_cmd. Origin and technical characteristics tracked via Malpedia.
Also known as: t_cmd
Tyupkin
Technical ID: win.tyupkin
MALWARE
Malware family identifying win.tyupkin. Origin and technical characteristics tracked via Malpedia.
Typhon Stealer
Technical ID: win.typhon_stealer
MALWARE
According to PCrisk, Typhon is a stealer-type malware written in the C# programming language. Newer versions of this program are called Typhon Reborn (TyphonReborn). Malware within this classification is designed to extract data from infected systems. The older variants of Typhon have a broader range of functionalities, while Typhon Reborn versions are streamlined stealers.
Also known as: Typhon Reborn V2
MALWARE
Malware family identifying win.typehash. Origin and technical characteristics tracked via Malpedia.
Also known as: SkinnyD
MALWARE
TYPEFRAME is a RAT.
It supports ~25 commands that include operations on the victim’s filesystem, manipulation with its configuration, modification of the system's firewall, the download and execution of additional tools from the attacker’s C&C and the uninstall via a self-delete batch. The commands are indexed by 16-bit integers, starting with the value 0x8000.
The RAT uses RC4 for decryption of its binary configuration. It has a statically linked OpenSSL 0.9.8k library used for SSL communication.
MALWARE
Malware family identifying win.twodash. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.turnedup. Origin and technical characteristics tracked via Malpedia.
Also known as: Notestuk
MALWARE
Malware family identifying win.turla_silentmoon. Origin and technical characteristics tracked via Malpedia.
Also known as: BigBoss • Cacao • GoldenSky • HyperStack
MALWARE
Malware family identifying win.turla_rpc. Origin and technical characteristics tracked via Malpedia.
Turkojan
Technical ID: win.turkojan
MALWARE
Malware family identifying win.turkojan. Origin and technical characteristics tracked via Malpedia.
turian
Technical ID: win.turian
MALWARE
According to Mitre, Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.
Tuoni
Technical ID: win.tuoni
MALWAREespionageadvanced
According to its Github repo, Tuoni is a sophisticated, cross-platform red teaming framework designed to enhance cybersecurity education and training through large-scale cyber defense exercises. Developed using Java for robustness, Docker for versatility, and featuring an intuitive web browser interface, it supports and streamlines cyber exercises. With its modular, extendable plugin system, Tuoni offers Red Teamers the flexibility to tailor its capabilities for specific educational and exercise needs. Its user-friendly interface facilitates easy operation and efficient reporting, essential in training environments. Tuoni embodies a commitment to power, adaptability, and collaboration, aimed at empowering Red Teamers with a tool that meets the dynamic demands of modern cyber defense education.
TunnelSpecter
Technical ID: win.tunnelspecter
MALWARE
Malware family identifying win.tunnelspecter. Origin and technical characteristics tracked via Malpedia.
TUNNELFISH
Technical ID: win.tunnelfish
MALWARE
Malware family identifying win.tunnelfish. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
TsunamiKit is a multi-stage malware toolkit written in Python and .NET.
The execution chain consists of several modules—including TsunamiLoader, TsunamiInjector, TsunamiInstaller, TsunamiPayload and the core TsunamiClient. The name is derived from the developer's recurring use of "Tsunami" in its components, e.g. "C# Tsunami Dist Version 3.0.0" or "Tsunami Stable\Tsunami Payload".
The primary purpose of the core module depends on the variant. It either carries out information theft by exfiltrating browser data, or monetize its presence by dropping cryptocurrency miners like XMRig and NBMiner. It also fingerprints the compromised system and uses the Tor network for command-and-control (C&C) communication.
While it was delivered by the InvisibleFerret malware in November 2024, older samples dating back to November 2021 suggest TsunamiKit is a pre-existing dark web project adapted by the APT actors.
MALWARE
Malware family identifying win.tsunami. Origin and technical characteristics tracked via Malpedia.
Tsifiri
Technical ID: win.tsifiri
MALWARE
Malware family identifying win.tsifiri. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →TrustConnect RAT
Technical ID: win.trustconnect
MALWARE
TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool. It gives attackers full control of infected systems through a web dashboard, allowing them to manage compromised devices, run commands, transfer files, collect system data, initiate remote desktop sessions, and record screens via standard SSL/TLS-protected web APIs.
DocConnect RAT is an upgraded and reengineered version of TrustConnect RAT. It fixes earlier security and detection weaknesses (such as poor credential storage, weak persistence, and detectable command-and-control mechanisms) while adding new capabilities, including an interactive multi-session terminal, stronger process protection against termination, a fake Windows Update overlay for deception, and a PDF-based lure and delivery system.
Trump Ransom
Technical ID: win.trump_ransom
MALWARE
Malware family identifying win.trump_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →troystealer
Technical ID: win.troystealer
MALWARE
Malware family identifying win.troystealer. Origin and technical characteristics tracked via Malpedia.
TroubleGrabber
Technical ID: win.troublegrabber
MALWARE
Malware family identifying win.troublegrabber. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Tropidoor is an advanced HTTP/S Remote Access Trojan (RAT) written as a C project, which exhibits significant code overlap with the PostNapTea RAT. In November 2024, it was deployed in campaigns targeting developers via fake recruiters as part of a social engineering campaign distributing trojanized open-source projects on platforms like Bitbucket. It is a final-stage payload in a multi-stage execution chain, which also deployed an obfuscated BeaverTail malware.
The RAT uses RSA and AES for encryption and decryption of network traffic. Communication with the C2 uses specific HTTP POST parameters, including tropi2p, gumi, s_width, and letter, with the first parameter loosely inspiring its code name. It stores its configuration in a binary format and resolves required Windows APIs during runtime via the Fowler–Noll–Vo (FNV) hash function. Many of its characteristic strings are XOR encrypted.
A key technical feature is its custom implementation of various Windows administrative and reconnaissance commands. By implementing this functionality internally, the RAT avoids executing the legitimate Windows binaries, making its command execution activities harder to detect by behavioral monitoring tools. Custom implemented commands include functionality equivalent to standard utilities like:
arp
dir
ipconfig
kill
net
netsh
netstat
nslookup
ping
reg
rm
sc
schtasks
systeminfo
tracert
wmic logicaldisk
wmic process
MALWARE
Malware family identifying win.troll_stealer. Origin and technical characteristics tracked via Malpedia.
Troldesh
Technical ID: win.troldesh
MALWAREfinancialhigh
According to Malwarebyte, Ransomware is a type of malware that prevents users from accessing their system or personal files and demands ransom payment in order to regain access. Ransom.Troldesh is spread by malspam, typically in the form of attached .zip files. This ransomware sometimes uses a CMS on a compromised site to host downloads.
Also known as: Shade
MALWARE
Trochilus is a C++ written RAT, which is available on GitHub.
GitHub Repo:
- https://github.com/m0n0ph1/malware-1/tree/master/Trochilus
- https://github.com/5loyd/trochilus
MALWARE
Malware attacking commonly used in Industrial Control Systems (ICS) Triconex Safety Instrumented System (SIS) controllers.
Also known as: Trisis • HatMan