Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.tapaoux. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-05-03
View profile →Tandfuy
Technical ID: win.tandfuy
MALWARE
Malware family identifying win.tandfuy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →TamperedChef
Technical ID: win.tampered_chef
MALWARE
Malware family identifying win.tampered_chef. Origin and technical characteristics tracked via Malpedia.
Taleret
Technical ID: win.taleret
MALWARE
Malware family identifying win.taleret. Origin and technical characteristics tracked via Malpedia.
TAINTEDSCRIBE
Technical ID: win.taintedscribe
MALWARE
Malware family identifying win.taintedscribe. Origin and technical characteristics tracked via Malpedia.
taidoor
Technical ID: win.taidoor
MALWARE
Malware family identifying win.taidoor. Origin and technical characteristics tracked via Malpedia.
Also known as: simbot
MALWARE
Malware family identifying win.tabmsgsql. Origin and technical characteristics tracked via Malpedia.
T34loader
Technical ID: win.t34loader
MALWARE
Malware family identifying win.t34loader. Origin and technical characteristics tracked via Malpedia.
Szribi
Technical ID: win.szribi
MALWARE
Malware family identifying win.szribi. Origin and technical characteristics tracked via Malpedia.
Also known as: Srizbi
MALWARE
SystemBC is a multiplatform proxy malware active since August 2019. It creates SOCKS5 network tunnels in the victim’s network and connects to its C2 server using a custom, RC4-encrypted protocol. It can also download and execute additional malware, with payloads either written to disk or mapped into memory. The SystemBC kit, including the C2 panel, server, and malware executables, is sold in underground forums.
Also known as: Coroxy • DroxiDat
SysScan
Technical ID: win.sysscan
MALWARE
Malware family identifying win.sysscan. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →Sysrv-hello
Technical ID: win.sysrv_hello
MALWARE
Sysrv is a Golang written Cryptojacking malware. There are Windows and Linux variants.
Sysraw Stealer
Technical ID: win.sysraw_stealer
MALWARE
Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe". PDB strings suggest the name "Clipsa" though. First stage connects to /WPCoreLog/, the second one to /WPSecurity/. Its behavior suggest that it is an info stealer. It creates a rather large amount of files in a subdirectory (e.g. data) named "1?[-+].dat" and POSTs them.
Also known as: Clipsa
MALWARE
Malware family identifying win.syskit. Origin and technical characteristics tracked via Malpedia.
Also known as: IvizTech • MANGOPUNCH
SysJoker
Technical ID: win.sysjoker
MALWARE
Sysjoker is a backdoor malware that was first discovered in December 2021 by Intezer. It is sophisticated and written from scratch in C++. Sysjoker is a cross-platform malware that has Linux, Windows, and macOS variants. Possible attack vectors for Sysjoker are email attachments, malicious advertisements, and trojanized software.
MALWARE
Malware family identifying win.sysget. Origin and technical characteristics tracked via Malpedia.
Syscon
Technical ID: win.syscon
MALWARE
SYSCON is a Remote Access Trojan used in a targeted champing against US government agencies. It has been recently observed in conjunction with CARROTBAT and CARROTBALL downloaders and it uses the File Transfer Protocol as Command and Control channel. Use of the family is attributed by Unit 42 to the Konni Group.
MALWARE
Malware family identifying win.sys10. Origin and technical characteristics tracked via Malpedia.
Synth Loader
Technical ID: win.synth_loader
MALWARE
Malware family identifying win.synth_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →MALWARE
Malware family identifying win.synflooder. Origin and technical characteristics tracked via Malpedia.
Sync-Scheduler
Technical ID: win.sync_scheduler
MALWARE
According to Cyfirma, Sync-Scheduler is a dedicated document stealer that targets Word documents, Excel Spreadsheets, PowerPoint presentations, PDFs and ZIP compress files. The malware is written in C++ and equipped with anti-analysis and defense evasion techniques. It uses obfuscation in its code and terminates itself if it detects an analysis environment.
SyncCrypt
Technical ID: win.synccrypt
MALWARE
Malware family identifying win.synccrypt. Origin and technical characteristics tracked via Malpedia.
SynAck
Technical ID: win.synack
MALWARE
Malware family identifying win.synack. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.sykipot. Origin and technical characteristics tracked via Malpedia.
Also known as: getkys • Wkysol
MALWARE
Malware family identifying win.sword. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to ESET, this is a wiper written in Go, that was deployed against an Ukrainian organization on January 25th 2023 through Group Policy, which suggests that the attackers had taken control of the victim’s Active Directory environment.
Also known as: JaguarBlade
swen
Technical ID: win.swen
MALWARE
Malware family identifying win.swen. Origin and technical characteristics tracked via Malpedia.
SweetSpecter
Technical ID: win.sweetspecter
MALWARE
Malware family identifying win.sweetspecter. Origin and technical characteristics tracked via Malpedia.
SwaetRAT
Technical ID: win.swaet_rat
MALWARE
Malware family identifying win.swaet_rat. Origin and technical characteristics tracked via Malpedia.
SVCStealer
Technical ID: win.svcstealer
MALWARE
According to Broadcom, SVCStealer is an information stealer written in C++, targeting devices running an windows operating system. It collects sensitive information from the infected device such as system information, credentials, cryptocurrency wallets, data stored in browsers, screenshots, data from messaging applications such as Telegram or VPN apps. The collected information is compressed into a .zip archive and extracted to botnet C2 servers.
SVCReady
Technical ID: win.svcready
MALWARE
According to PCrisk, SVCReady collects information about the infected system such as username, computer name, time zone, computer manufacturer, BIOS, and firmware. Also, it gathers lists of running processes and installed software. SVCReady sends collected data to the C2 server. Additionally, SVCReady attempts to maintain its foothold on the system by creating a scheduled task.
surtr
Technical ID: win.surtr
MALWAREfinancialhigh
According to PCrisk, Surtr is ransomware. Malware of this type encrypts files (and renames them) and generates a ransom note. Surtr appends the decryptmydata@mailfence.com email address and the ".SURT" extension to filenames.
SuppoBox
Technical ID: win.suppobox
MALWARE
Malware family identifying win.suppobox. Origin and technical characteristics tracked via Malpedia.
Also known as: Bayrob • Nivdort • pizd
MALWARE
Supper is a 64-bit Windows backdoor and tunnelling utility first observed in the wild in July 2024. This malware operates as both a Remote Access Trojan (RAT) and a SOCKS5 proxy, offering threat actors persistent access to infected systems and the ability to route arbitrary traffic through victim environments.
Once executed, it establishes a TCP connection to its primary C2 endpoint, i.e. hardcoded in the file, over port 443. A fallback mechanism allows the malware to retrieve alternate C2 IP addresses from an encoded file, %temp%/s01bafg, ensuring resilience in case the primary server is unavailable. The malware supports up to 16,384 concurrent sessions over a single TCP connection, each uniquely identified via a 16-bit session ID.
Communication begins with an unencrypted 300-byte handshake payload that includes a static bot identifier (0x00691155), system metadata (hostname, domain, OS version, integrity level), and a fixed flag. Following this, all network traffic is wrapped in a 12-byte obfuscated header and an encrypted payload (8 bytes) which consists of two encrypted IP addresses. The header is transformed using two hardcoded XOR keys: 0x4d4d4d4d4d4d4d4d and 0x4d4d4d4d. Payload encryption is performed with a non-standard, stateful XOR cipher, where each byte of the message is encrypted based on a calculated offset and a cycling key (xored with 0x4d4d4d4d) derived from the header.
It supports a range of C2 commands, including remote shell execution, session teardown, SOCKS5 proxy operations, self-deletion, and dynamic updating of fallback IPs. When executing commands, Supper spawns a hidden cmd.exe instance and forwards command outputs back to the C2 server after encryption. As a proxy, it accepts operator-specified connection requests, establishes TCP sessions to external targets, and forwards data between the target and the attacker, all managed under the session multiplexing framework.
If instructed or if a C2 session fails, the malware can delete itself using cmd.exe or schtasks.exe, often masquerading the operation under the guise of a scheduled task named "GoogleUpdateTask". The file used to store fallback C2 IPs (%temp%/s01bafg) is updated by the malware using its encryption routine.
Also known as: SocksShell • ZAPCAT
SUPERNOVA
Technical ID: win.supernova
MALWAREespionageadvanced
According to CISA, SUPERNOVA is a malicious webshell backdoor that allows a remote operator to dynamically inject C# source code into a web portal to subsequently inject code. APT actors use SUPERNOVA to perform reconnaissance, conduct domain mapping, and steal sensitive information and credentials.
SuperBear RAT
Technical ID: win.superbear
MALWARE
Malware family identifying win.superbear. Origin and technical characteristics tracked via Malpedia.
SunSeed
Technical ID: win.sunseed
MALWARE
According to Proofpoint, this is a Lua-based malware likely used by a nation-state sponsored attacker used to target European government personnel involved in managing the logistics of refugees fleeing Ukraine.
SunOrcal
Technical ID: win.sunorcal
MALWARE
Malware family identifying win.sunorcal. Origin and technical characteristics tracked via Malpedia.
sunnyday
Technical ID: win.sunnyday
MALWARE
Malware family identifying win.sunnyday. Origin and technical characteristics tracked via Malpedia.
SunCrypt
Technical ID: win.suncrypt
MALWAREfinancialhigh
According to PCrisk, Suncrypt ransomware prevents victims from accessing files by encryption. It also renames all encrypted files and creates a ransom message. It renames encrypted files by appending a string of random characters as the new extension.