Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Unidentified 023
Technical ID: win.unidentified_023
MALWARE
Malware family identifying win.unidentified_023. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →
Unidentified 022 (Ransom)
Technical ID: win.unidentified_022_ransom
MALWARE
Malware family identifying win.unidentified_022_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →
Unidentified 020 (Vault7)
Technical ID: win.unidentified_020_cia_vault7
Longhorn
MALWARE
Malware family identifying win.unidentified_020_cia_vault7. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-02
View profile →
Unidentified 013 (Korean)
Technical ID: win.unidentified_013_korean_malware
MALWARE
Malware family identifying win.unidentified_013_korean_malware. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →
Unidentified 006
Technical ID: win.unidentified_006
MALWARE
Malware family identifying win.unidentified_006. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →
Unidentified 003
Technical ID: win.unidentified_003
MALWARE
Malware family identifying win.unidentified_003. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-29
View profile →
Unidentified 001
Technical ID: win.unidentified_001
MALWARE
Malware family identifying win.unidentified_001. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-29
View profile →
UnderminerEK
Technical ID: win.underminer_ek
MALWARE
Malware family identifying win.underminer_ek. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-01
View profile →
Umbral
Technical ID: win.umbral
MALWAREfinancialhigh
Umbral is a data-stealing Trojan that targets Windows systems. It spreads through phishing emails and malicious attachments. Once installed, Umbral can steal a variety of data, including usernames, passwords, online banking credentials, and confidential files. It can also change computer settings and execute harmful commands. Umbral is a serious security threat and should be removed immediately if found.
Updated: 2023-07-24
View profile →
Uiwix
Technical ID: win.uiwix
MALWARE
Malware family identifying win.uiwix. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-20
View profile →
UFR Stealer
Technical ID: win.ufrstealer
MALWARE
Information stealer.
Also known as: Usteal
Updated: 2019-02-22
View profile →
UDPoS
Technical ID: win.udpos
MALWARE
Malware family identifying win.udpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-29
View profile →
UACMe
Technical ID: win.uacme
MALWARE
A toolkit maintained by hfiref0x which incorporates numerous UAC bypass techniques for Windows 7 - Windows 10. Typically, components of this tool are stripped out and reused by malicious actors.
Also known as: Akagi
Updated: 2019-05-17
View profile →
tRat
Technical ID: win.trat
MALWARE
tRat is a modular RAT written in Delphi and has appeared in campaigns in September and October of 2018.
Updated: 2024-05-14
View profile →
T-Cmd
Technical ID: win.t_cmd
MALWARE
Malware family identifying win.t_cmd. Origin and technical characteristics tracked via Malpedia.
Also known as: t_cmd
Updated: 2022-07-13
View profile →
Tyupkin
Technical ID: win.tyupkin
MALWARE
Malware family identifying win.tyupkin. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-27
View profile →
Typhon Stealer
Technical ID: win.typhon_stealer
MALWARE
According to PCrisk, Typhon is a stealer-type malware written in the C# programming language. Newer versions of this program are called Typhon Reborn (TyphonReborn). Malware within this classification is designed to extract data from infected systems. The older variants of Typhon have a broader range of functionalities, while Typhon Reborn versions are streamlined stealers.
Also known as: Typhon Reborn V2
Updated: 2023-05-02
View profile →
TypeHash
Technical ID: win.typehash
Tonto Team
MALWARE
Malware family identifying win.typehash. Origin and technical characteristics tracked via Malpedia.
Also known as: SkinnyD
Updated: 2020-10-08
View profile →
TYPEFRAME
Technical ID: win.typeframe
Lazarus Group
MALWARE
TYPEFRAME is a RAT. It supports ~25 commands that include operations on the victim’s filesystem, manipulation with its configuration, modification of the system's firewall, the download and execution of additional tools from the attacker’s C&C and the uninstall via a self-delete batch. The commands are indexed by 16-bit integers, starting with the value 0x8000. The RAT uses RC4 for decryption of its binary configuration. It has a statically linked OpenSSL 0.9.8k library used for SSL communication.
Updated: 2023-12-11
View profile →
TwoDash
Technical ID: win.twodash
Turla
MALWARE
Malware family identifying win.twodash. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-12
View profile →
TURNEDUP
Technical ID: win.turnedup
APT33
MALWARE
Malware family identifying win.turnedup. Origin and technical characteristics tracked via Malpedia.
Also known as: Notestuk
Updated: 2020-08-21
View profile →
Turla SilentMoon
Technical ID: win.turla_silentmoon
Turla
MALWARE
Malware family identifying win.turla_silentmoon. Origin and technical characteristics tracked via Malpedia.
Also known as: BigBoss • Cacao • GoldenSky • HyperStack
Updated: 2022-12-01
View profile →
TurlaRPC
Technical ID: win.turla_rpc
Turla
MALWARE
Malware family identifying win.turla_rpc. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-01
View profile →
Turkojan
Technical ID: win.turkojan
MALWARE
Malware family identifying win.turkojan. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-24
View profile →
turian
Technical ID: win.turian
MALWARE
According to Mitre, Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.
Updated: 2023-06-09
View profile →
Tuoni
Technical ID: win.tuoni
MALWAREespionageadvanced
According to its Github repo, Tuoni is a sophisticated, cross-platform red teaming framework designed to enhance cybersecurity education and training through large-scale cyber defense exercises. Developed using Java for robustness, Docker for versatility, and featuring an intuitive web browser interface, it supports and streamlines cyber exercises. With its modular, extendable plugin system, Tuoni offers Red Teamers the flexibility to tailor its capabilities for specific educational and exercise needs. Its user-friendly interface facilitates easy operation and efficient reporting, essential in training environments. Tuoni embodies a commitment to power, adaptability, and collaboration, aimed at empowering Red Teamers with a tool that meets the dynamic demands of modern cyber defense education.
Updated: 2024-05-14
View profile →
TunnelSpecter
Technical ID: win.tunnelspecter
MALWARE
Malware family identifying win.tunnelspecter. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-06-05
View profile →
TUNNELFISH
Technical ID: win.tunnelfish
MALWARE
Malware family identifying win.tunnelfish. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-19
View profile →
TsunamiKit
Technical ID: win.tsunamikit
WageMole
MALWAREespionageadvanced
TsunamiKit is a multi-stage malware toolkit written in Python and .NET. The execution chain consists of several modules—including TsunamiLoader, TsunamiInjector, TsunamiInstaller, TsunamiPayload and the core TsunamiClient. The name is derived from the developer's recurring use of "Tsunami" in its components, e.g. "C# Tsunami Dist Version 3.0.0" or "Tsunami Stable\Tsunami Payload". The primary purpose of the core module depends on the variant. It either carries out information theft by exfiltrating browser data, or monetize its presence by dropping cryptocurrency miners like XMRig and NBMiner. It also fingerprints the compromised system and uses the Tor network for command-and-control (C&C) communication. While it was delivered by the InvisibleFerret malware in November 2024, older samples dating back to November 2021 suggest TsunamiKit is a pre-existing dark web project adapted by the APT actors.
Updated: 2025-11-21
View profile →
tsunami
Technical ID: win.tsunami
Lazarus Group
MALWARE
Malware family identifying win.tsunami. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-21
View profile →
Tsifiri
Technical ID: win.tsifiri
MALWARE
Malware family identifying win.tsifiri. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →
TrustConnect RAT
Technical ID: win.trustconnect
MALWARE
TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool. It gives attackers full control of infected systems through a web dashboard, allowing them to manage compromised devices, run commands, transfer files, collect system data, initiate remote desktop sessions, and record screens via standard SSL/TLS-protected web APIs. DocConnect RAT is an upgraded and reengineered version of TrustConnect RAT. It fixes earlier security and detection weaknesses (such as poor credential storage, weak persistence, and detectable command-and-control mechanisms) while adding new capabilities, including an interactive multi-session terminal, stronger process protection against termination, a fake Windows Update overlay for deception, and a PDF-based lure and delivery system.
Trump Ransom
Technical ID: win.trump_ransom
MALWARE
Malware family identifying win.trump_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
troystealer
Technical ID: win.troystealer
MALWARE
Malware family identifying win.troystealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-17
View profile →
TroubleGrabber
Technical ID: win.troublegrabber
MALWARE
Malware family identifying win.troublegrabber. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-17
View profile →
Tropidoor
Technical ID: win.tropidoor
WageMole
MALWAREespionageadvanced
Tropidoor is an advanced HTTP/S Remote Access Trojan (RAT) written as a C project, which exhibits significant code overlap with the PostNapTea RAT. In November 2024, it was deployed in campaigns targeting developers via fake recruiters as part of a social engineering campaign distributing trojanized open-source projects on platforms like Bitbucket. It is a final-stage payload in a multi-stage execution chain, which also deployed an obfuscated BeaverTail malware. The RAT uses RSA and AES for encryption and decryption of network traffic. Communication with the C2 uses specific HTTP POST parameters, including tropi2p, gumi, s_width, and letter, with the first parameter loosely inspiring its code name. It stores its configuration in a binary format and resolves required Windows APIs during runtime via the Fowler–Noll–Vo (FNV) hash function. Many of its characteristic strings are XOR encrypted. A key technical feature is its custom implementation of various Windows administrative and reconnaissance commands. By implementing this functionality internally, the RAT avoids executing the legitimate Windows binaries, making its command execution activities harder to detect by behavioral monitoring tools. Custom implemented commands include functionality equivalent to standard utilities like: arp dir ipconfig kill net netsh netstat nslookup ping reg rm sc schtasks systeminfo tracert wmic logicaldisk wmic process
Updated: 2025-10-20
View profile →
Troll Stealer
Technical ID: win.troll_stealer
Kimsuky
MALWARE
Malware family identifying win.troll_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-09
View profile →
Troldesh
Technical ID: win.troldesh
MALWAREfinancialhigh
According to Malwarebyte, Ransomware is a type of malware that prevents users from accessing their system or personal files and demands ransom payment in order to regain access. Ransom.Troldesh is spread by malspam, typically in the form of attached .zip files. This ransomware sometimes uses a CMS on a compromised site to host downloads.
Also known as: Shade
Updated: 2023-05-02
View profile →
Trochilus RAT
Technical ID: win.trochilus_rat
APT31GALLIUMStone Panda
MALWARE
Trochilus is a C++ written RAT, which is available on GitHub. GitHub Repo: - https://github.com/m0n0ph1/malware-1/tree/master/Trochilus - https://github.com/5loyd/trochilus
Updated: 2022-09-20
View profile →
Triton
Technical ID: win.triton
XENOTIME
MALWARE
Malware attacking commonly used in Industrial Control Systems (ICS) Triconex Safety Instrumented System (SIS) controllers.
Also known as: Trisis • HatMan
Updated: 2023-01-19
View profile →
← PreviousPage 129 / 269Next →