Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Trigona
Technical ID: win.trigona
MALWAREfinancialhigh
According to PCrisk, Trigona is ransomware that encrypts files and appends the "._locked" extension to filenames. Also, it drops the "how_to_decrypt.hta" file that opens a ransom note. An example of how Trigona renames files: it renames "1.jpg" to "1.jpg._locked", "2.png" to "2.png._locked", and so forth. It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.
Updated: 2024-03-04
View profile →
TrickBot
Technical ID: win.trickbot
TA505UNC1878WIZARD SPIDER
MALWAREfinancialhigh
A financial Trojan believed to be a derivative of Dyre: the bot uses very similar code, web injects, and operational tactics. Has multiple modules including VNC and Socks5 Proxy. Uses SSL for C2 communication. - Q4 2016 - Detected in wild Oct 2016 - 1st Report 2017 - Trickbot primarily uses Necurs as vehicle for installs. Jan 2018 - Use XMRIG (Monero) miner Feb 2018 - Theft Bitcoin Mar 2018 - Unfinished ransomware module Q3/4 2018 - Trickbot starts being spread through Emotet. Infection Vector 1. Phish > Link MS Office > Macro Enabled > Downloader > Trickbot 2. Phish > Attached MS Office > Macro Enabled > Downloader > Trickbot 3. Phish > Attached MS Office > Macro enabled > Trickbot installed
Also known as: Trickster • TheTrick • TrickLoader
Updated: 2025-06-18
View profile →
TreasureHunter
Technical ID: win.treasurehunter
MALWARE
Malware family identifying win.treasurehunter. Origin and technical characteristics tracked via Malpedia.
Also known as: huntpos
Updated: 2018-05-14
View profile →
TransferLoader
Technical ID: win.transferloader
MALWARE
Malware family identifying win.transferloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-25
View profile →
TransBox
Technical ID: win.transbox
MALWARE
According to Trend Micro, this is a backdoor abusing the Dropbox API, used by threat actor Earth Yako.
Updated: 2023-02-17
View profile →
ToxicEye
Technical ID: win.toxiceye
MALWAREfinancialhigh
ToxicEye is a ransomware that spreads through phishing emails. The malware encrypts system files with AES-256 and demands a ransom in Bitcoin.
Updated: 2025-02-25
View profile →
TOUGHPROGRESS
Technical ID: win.toughprogress
APT41
MALWARE
According to Google Threat Intelligence Group, this malware uses Google Calendar events for command and control (C2).
Updated: 2025-06-02
View profile →
TOUCHSHIFT
Technical ID: win.touchshift
MALWARE
Malware family identifying win.touchshift. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-13
View profile →
TOUCHMOVE
Technical ID: win.touchmove
Lazarus Group
MALWARE
Malware family identifying win.touchmove. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-27
View profile →
TorLoader
Technical ID: win.tor_loader
MALWARE
Downloader, delivered via a lure with fake exploits published on Github.
Updated: 2023-07-11
View profile →
TorrentLocker
Technical ID: win.torrentlocker
MALWARE
Malware family identifying win.torrentlocker. Origin and technical characteristics tracked via Malpedia.
Also known as: Teerac
Updated: 2021-09-19
View profile →
Torisma
Technical ID: win.torisma
Lazarus Group
MALWARE
Torisma is a complex HTTP(S) downloader, that can serve as an orchestrator handling the execution of additional payloads from the C&C server. It uses VEST-32 for encryption and decryption of network traffic between the client and the server. Typically, it uses these parameter names for its HTTP POST requests: ACTION, CODE, CACHE, REQUEST, RES. It sends the victim's MAC address in the initial request. The response of the server informing the client about a successful authentication is "Your request has been accepted. ClientID: {f9102bc8a7d81ef01ba}". The client then requests additional data from the server, that decrypts to shellcode and its data parameters, and is executed. The client also creates a named pipe, \\.\pipe\fb4d1181bb09b484d058768598b, that allows inter-process communication with the executed shellcode. Torisma was usually downloaded by NedDnLoader, and deployed in the Operation DreamJob campaigns starting around Q4 2019.
Updated: 2024-11-29
View profile →
Topinambour
Technical ID: win.topinambour
MALWARE
Malware family identifying win.topinambour. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-26
View profile →
Tonnerre
Technical ID: win.tonnerre
Infy
MALWARE
Malware family identifying win.tonnerre. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-12-22
View profile →
TONESHELL
Technical ID: win.toneshell
MUSTANG PANDA
MALWARE
Malware family identifying win.toneshell. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-23
View profile →
TONERJAM
Technical ID: win.tonerjam
MALWARE
According to Symantec, Grager was deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of the backdoor revealed that it used the Graph API to communicate with a C&C server hosted on Microsoft OneDrive. Grager was downloaded from a typosquatted URL mimicking the open-source file archiver 7-Zip.
Updated: 2024-10-29
View profile →
TONEDEAF
Technical ID: win.tonedeaf
APT34
MALWARE
TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS. Supported commands include system information collection, file upload, file download, and arbitrary shell command execution. When executed, this variant of TONEDEAF wrote encrypted data to two temporary files – temp.txt and temp2.txt – within the same directory of its execution.
Updated: 2021-04-10
View profile →
tomiris
Technical ID: win.tomiris
MALWARE
Malware family identifying win.tomiris. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
TOLLBOOTH
Technical ID: win.tollbooth
MALWARE
Malware family identifying win.tollbooth. Origin and technical characteristics tracked via Malpedia.
Also known as: HijackServer IIS
Updated: 2025-10-22
View profile →
TokyoX
Technical ID: win.tokyox
MALWARE
Malware family identifying win.tokyox. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-18
View profile →
Tofsee
Technical ID: win.tofsee
MALWARE
According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining cryptocurrency, sending emails, stealing various account credentials, updating itself, and more. Cyber criminals mainly use this program as an email-oriented tool (they target users' email accounts), however, having Tofsee installed can also lead to many other problems.
Also known as: Gheg
Updated: 2023-10-17
View profile →
Tmanger
Technical ID: win.tmanger
TA428
MALWARE
Malware family identifying win.tmanger. Origin and technical characteristics tracked via Malpedia.
Also known as: LuckyBack
Updated: 2024-10-15
View profile →
TitanStealer
Technical ID: win.titan_stealer
MALWARE
The stealer is written in Go and capable of stealing a variety of information from infected Windows machines, including credential data from browsers and crypto wallets, FTP client details, screenshots, system information, and grabbed files.
Updated: 2023-09-04
View profile →
Tiop
Technical ID: win.tiop
MALWARE
Malware family identifying win.tiop. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
TinyTurla
Technical ID: win.tiny_turla
Turla
MALWARE
Talos describes this as a malware family with very scoped functionality and thus a small code footprint, likely used as a second chance backdoor.
Updated: 2023-10-05
View profile →
TinyZbot
Technical ID: win.tinyzbot
Cleaver
MALWARE
Malware family identifying win.tinyzbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
TinyTyphon
Technical ID: win.tinytyphon
Dropping Elephant
MALWARE
Malware family identifying win.tinytyphon. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-06
View profile →
TinyTurlaNG
Technical ID: win.tinyturla_ng
Turla
MALWARE
Cisco Talos states that TinyTurla-NG is a small “last chance” backdoor that is left behind to be used when all other unauthorized access/backdoor mechanisms have failed or been detected on the infected systems. TinyTurla-NG was seen as early as December 2023 targeting a Polish non-governmental organization (NGO) working on improving Polish democracy and supporting Ukraine during the Russian invasion.
Also known as: TTNG
Updated: 2024-10-21
View profile →
TinyNuke
Technical ID: win.tinynuke
MALWAREfinancialhigh
TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server. It was for sale on underground marketplaces for $2500 in 2016. The program's author claimed the malware was written from scratch, but that it functioned similarly to the ZeuS banking trojan in that it could steal passwords and inject arbitrary content when victims visited banking Web sites. However, he then proceeded to destroy his own reputation on hacker forums by promoting his development too aggressively. As a displacement activity, he published his source code on Github. XBot is an off-spring of TinyNuke, but very similar to its ancestor.
Also known as: NukeBot • Nuclear Bot • MicroBankingTrojan • Xbot
Updated: 2022-08-28
View profile →
TinyMet
Technical ID: win.tinymet
AnunakTA505
MALWARE
TinyMet is a meterpreter stager.
Also known as: TiniMet
Updated: 2023-08-03
View profile →
TinyLoader
Technical ID: win.tinyloader
Tiny Spider
MALWARE
Malware family identifying win.tinyloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-24
View profile →
TinyFluff
Technical ID: win.tinyfluff
MALWARE
TinyFluff is a dropper developed by the OldGremlin group. In one of their March '22 campaigns, TinyFluff included a JavaScript RAT with a time-independent DGA.
Updated: 2023-07-12
View profile →
Tinba
Technical ID: win.tinba
MALWAREfinancialhigh
F-Secure notes that TinyBanker or short Tinba is usually distributed through malvertising (advertising content that leads the user to sites hosting malicious threats), exploit kits and spam email campaigns. According to news reports, Tinba has been found targeting bank customers in the United States and Europe. If Tinba successfully infects a device, it can steal banking and personal information through webinjects. To do this, the malware monitors the user's browser activity and if specific banking portals are visited, Tinba injects code to present the victim with fake web forms designed to mimic the legitimate web site. The malware then tricks them into entering their personal information, log-in credentials, etc in the legitimate-looking page. Tinba may also display socially-engineered messages to lure or pressure the user into entering their information on the fake page; for example, a message may be shown which attempts to convince the victim that funds were accidentally deposited to his account and must be refunded immediately.
Also known as: Zusy • TinyBanker • Illi
Updated: 2022-06-09
View profile →
TimbreStealer
Technical ID: win.timbre_stealer
MALWARE
Malware family identifying win.timbre_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-09
View profile →
tildeb
Technical ID: win.tildeb
Equation Group
MALWARE
Standalone implant. Potentially tied to a framework called PATROLWAGON.
Updated: 2021-09-19
View profile →
Tiger RAT
Technical ID: win.tiger_rat
Silent Chollima
MALWAREfinancialhigh
This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware". The third stage payload was created via the second stage payload, is interactively executed in the operation and exists in both x64 and x86 versions. Most of them use Internet Explorer or Google Chrome icons and corresponding file names to disguise themselves as legitimate internet browsers. The malware decrypts the embedded payload at runtime. It uses an embedded 16-byte XOR key to decrypt the base64 encoded payload. The decrypted payload is another portable executable file that runs in memory. Before getting decrypted with a hardcoded XOR key, the backdoor also checks for sandbox environment. The backdoor has some code overlap with a know malware family PEBBLEDASH, attributed to Lazarus/LABYRINTH CHOLLIMA.
Updated: 2024-08-15
View profile →
TigerLite
Technical ID: win.tigerlite
Silent Chollima
MALWARE
TigerLite is a TCP downloader. It creates mutexes like "qtrgads32" or "Microsoft32". It uses RC4 with the key "MicrosoftCorporationValidation@#$%^&*()!US" for decryption of its character strings, and a custom algorithm for encryption and decryption of network traffic. It supports from 5 up to 8 commands with the following identifiers: 1111, 1234, 2099/3333, 4444, 8877, 8888, 9876, 9999. The commands mostly perform various types of execution - either of code received from the server, or native Windows commands, with their output collected and sent back to the server. TigerLite is an intermediate step of a multi-stage attack, in which Tiger RAT is usually the next step. This malware was observed in attacks against South Korean entities in H1 2021.
Updated: 2024-08-15
View profile →
Tidepool
Technical ID: win.tidepool
Mirage
MALWARE
Malware family identifying win.tidepool. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-25
View profile →
Thunker
Technical ID: win.thunker
MALWARE
Malware family identifying win.thunker. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
ThunderX
Technical ID: win.thunderx
MALWAREfinancialhigh
Ransomware.
Also known as: Ranzy Locker
Updated: 2022-01-24
View profile →
← PreviousPage 130 / 269Next →