Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
ThumbThief
Technical ID: win.thumbthief
MALWARE
Malware family identifying win.thumbthief. Origin and technical characteristics tracked via Malpedia.
ThreeByte
Technical ID: win.threebyte
IXESHE
MALWARE
Malware family identifying win.threebyte. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
ThinMon
Technical ID: win.thinmon
DarkHotel
MALWARE
Malware family identifying win.thinmon. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-25
View profile →
ThemeForestRAT
Technical ID: win.theme_forest_rat
Lazarus Group
MALWARE
Malware family identifying win.theme_forest_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: TALLSHIP
Updated: 2026-01-05
View profile →
Thanatos Ransomware
Technical ID: win.thanatos_ransom
MALWARE
Malware family identifying win.thanatos_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-05
View profile →
Thanatos
Technical ID: win.thanatos
MALWARE
Malware family identifying win.thanatos. Origin and technical characteristics tracked via Malpedia.
Also known as: Alphabot
Updated: 2017-01-05
View profile →
TFlower
Technical ID: win.tflower
MALWAREfinancialhigh
TFlower is a new ransomware targeting mostly corporate networks discovered in August, 2019. It is reportedly installed on networks by attackers after they gain access via RDP. TFlower displays a console showing activity being performed by the ransomware when it encrypts a machine, further indicating that this ransomware is triggered by the attacker post compromise, similar to Samsam/Samas in terms of TTP. Once encryption is started, the ransomware will conduct a status report to an apparently hard-coded C2. Shadow copies are deleted and the Windows 10 repair environment is disabled by this ransomware. This malware also will terminate any running Outlook.exe process so that the mail files can be encrypted. This ransomware does not add an extention to encrypted files, but prepends the marker "*tflower" and what may be the encrypted encryption key for the file to each affected file. Once encryption is completed, another status report is sent to the C2 server.
Updated: 2021-03-04
View profile →
Tetra Loader
Technical ID: win.tetra_loader
MALWARE
According to Cisco Talos, this is loader is written in Rust and was observed to stage Cobalt Strike Beacons and VShell.
Updated: 2025-05-26
View profile →
TeslaCrypt
Technical ID: win.teslacrypt
MALWAREfinancialhigh
According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers. Amongst other types of target files, it tries to infect typical gaming files: game saves, user profiles, recoded replays etc. That said, TeslaCrypt does not encrypt files that are larger than 268 MB. Recently,
Also known as: cryptesla
Updated: 2023-06-09
View profile →
TerraTV
Technical ID: win.terra_tv
VENOM SPIDER
MALWARE
TerraTV is a custom DLL designed to hijack legit TeamViewer applications. It was discovered and documented by QuoINT. It has been attributed to Golden Chickens malware as a service group.
Also known as: Taurus Loader TeamViewer Module
Updated: 2021-07-26
View profile →
TerraStealer
Technical ID: win.terra_stealer
VENOM SPIDERFIN6
MALWARE
According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email clients, web browsers, and file transfer utilities. Attributed to Golden Chickens.
Also known as: StealerOne • SONE • Taurus Loader Stealer Module
Updated: 2025-05-12
View profile →
TerraRecon
Technical ID: win.terra_recon
VENOM SPIDER
MALWARE
According to QuoINT TerraRecon is a reconnaissance tool, looking for a specific piece of hardware and software targeting retail and payment services sectors. Attributed to Golden Chickens.
Also known as: Taurus Loader Reconnaissance Module
Updated: 2020-07-24
View profile →
TerraLoader
Technical ID: win.terra_loader
MALWARE
Malware family identifying win.terra_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-25
View profile →
TerraPreter
Technical ID: win.terrapreter
MALWARE
Malware family identifying win.terrapreter. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-25
View profile →
Terralogger
Technical ID: win.terralogger
VENOM SPIDER
MALWAREfinancialhigh
TerraLogger is a standalone keylogger malware developed by Golden Chickens, a financially motivated threat actor. It uses a common low-level keyboard hook to record keystrokes and writes the logs to local files. The malware is typically delivered as an OCX file and employs initial execution checks before proceeding. Upon execution, it opens a file handle to log keystrokes and implements its keylogger using a SetWindowsHookExA hook. Keystrokes are written to the open log file, with special characters handled accordingly. Five distinct TerraLogger samples were identified, reflecting minor updates and active development.
Updated: 2025-05-19
View profile →
Termite
Technical ID: win.termite
MALWARE
Malware family identifying win.termite. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-06-27
View profile →
Terminator RAT
Technical ID: win.terminator_rat
MALWARE
Malware family identifying win.terminator_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: Fakem RAT
Updated: 2018-01-21
View profile →
Tendyron
Technical ID: win.tendyron_dropper
TA410
MALWARE
Malware family identifying win.tendyron_dropper. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-15
View profile →
TempStealer
Technical ID: win.temp_stealer
MALWARE
According to Cyble, this is a stealer targeting several crypto currency wallets along browser data.
Updated: 2022-11-21
View profile →
TEMPLEDOOR
Technical ID: win.templedoor
UNC1860
MALWARE
Malware family identifying win.templedoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
Tempedreve
Technical ID: win.tempedreve
MALWARE
Malware family identifying win.tempedreve. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-20
View profile →
TellYouThePass
Technical ID: win.tellyouthepass
MALWAREfinancialhigh
According to PCrisk, Tellyouthepass is one of many ransomware-type programs used to block access to files by encryption and keep them in this state unless a ransom is paid. The program renames all encrypted files by adding the ".locked" extension and creates a ransom message in a text file called "README.html". For example, "1.jpg" is renamed by Tellyouthepass to "1.jpg.locked". According to cyber criminals, this ransomware encrypts data using RSA-1024 and AES-256 cryptography algorithms.
Updated: 2023-06-09
View profile →
TelePowerBot
Technical ID: win.telepowerbot
MALWARE
Malware family identifying win.telepowerbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-02-03
View profile →
Teleport
Technical ID: win.teleport
TA505
MALWARE
Cisco Talos reports that this is a data exfiltration tool used by TA505.
Updated: 2022-12-12
View profile →
Telemiris
Technical ID: win.telemiris
MALWARE
Malware family identifying win.telemiris. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-26
View profile →
TelegramGrabber
Technical ID: win.telegram_grabber
Charming Kitten
MALWARE
Malware family identifying win.telegram_grabber. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-25
View profile →
TeleDoor
Technical ID: win.teledoor
TeleBotsSandworm
MALWARE
Malware family identifying win.teledoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
TeleBot
Technical ID: win.telebot
TeleBotsSandworm
MALWARE
Malware family identifying win.telebot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-25
View profile →
TelB
Technical ID: win.telb
MALWARE
According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
Updated: 2020-09-21
View profile →
TelAndExt
Technical ID: win.telandext
MALWARE
According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
Updated: 2020-09-21
View profile →
TefoSteal
Technical ID: win.tefosteal
MALWARE
Malware family identifying win.tefosteal. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-14
View profile →
TEARDROP
Technical ID: win.teardrop
UNC2452
MALWARE
TEARDROP is a memory only dropper that runs as a service, spawns a thread and reads from the file “gracious_truth.jpg”, which likely has a fake JPG header. Next it checks that HKU\SOFTWARE\Microsoft\CTF exists, decodes an embedded payload using a custom rolling XOR algorithm and manually loads into memory an embedded payload using a custom PE-like file format. TEARDROP does not have code overlap with any previously seen malware. FireEye believe that this was used to execute a customized Cobalt Strike BEACON.
Updated: 2022-08-02
View profile →
TeamSpy
Technical ID: win.teamspy
MALWARE
Malware family identifying win.teamspy. Origin and technical characteristics tracked via Malpedia.
Also known as: TVSPY • TeamViewerENT • TVRAT
Updated: 2022-10-14
View profile →
TeamBot
Technical ID: win.teambot
MALWARE
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer. This is achieved by sideloading another DLL among the legit TeamViewer.
Also known as: FINTEAM
Updated: 2023-07-24
View profile →
TDTESS
Technical ID: win.tdtess
Rocket Kitten
MALWARE
Malware family identifying win.tdtess. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-14
View profile →
tDiscoverer
Technical ID: win.tdiscoverer
APT29
MALWARE
F-Secure described tDiscoverer (also known as HammerDuke) as interesting because it is written in .NET, and even more so because of its occasional use of Twitter as a C&C communication channel. Some HammerDuke variants only contain a hardcoded C&C server address from which they will retrieve commands, but other HammerDuke variants will first use a custom algorithm to generate a Twitter account name based on the current date. If the account exists, HammerDuke will then search for tweets from that account with links to image files that contain embedded commands for the toolset to execute.
Also known as: HAMMERTOSS • HammerDuke
Updated: 2023-03-14
View profile →
TClient
Technical ID: win.tclient
Pirate Panda
MALWARE
Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
Also known as: FIRESHADOW
Updated: 2020-06-05
View profile →
Taurus Stealer
Technical ID: win.taurus_stealer
MALWARE
According to Zscaler, Taurus is a stealer that surfaced in June 2020. It is being developed by the author(s) that previously created Predator the Thief. The name overlaps partly with the StealerOne / Terra* family (also aliased Taurus Loader) but appears to be a completely disjunct project.
Updated: 2023-08-07
View profile →
Tarsip
Technical ID: win.tarsip
Comment Crew
MALWARE
Malware family identifying win.tarsip. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
TargetCompany
Technical ID: win.targetcompany
MALWAREfinancialhigh
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company> A decryptor was released on 2022-02-07 by AVAST
Also known as: Fargo • Mallox • Tohnichi
Updated: 2025-04-25
View profile →
← PreviousPage 131 / 269Next →