Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Tapaoux
Technical ID: win.tapaoux
DarkHotel
MALWARE
Malware family identifying win.tapaoux. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-05-03
View profile →
Tandfuy
Technical ID: win.tandfuy
MALWARE
Malware family identifying win.tandfuy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
TamperedChef
Technical ID: win.tampered_chef
MALWARE
Malware family identifying win.tampered_chef. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-12-30
View profile →
Taleret
Technical ID: win.taleret
MALWARE
Malware family identifying win.taleret. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
TAINTEDSCRIBE
Technical ID: win.taintedscribe
MALWARE
Malware family identifying win.taintedscribe. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-23
View profile →
taidoor
Technical ID: win.taidoor
MALWARE
Malware family identifying win.taidoor. Origin and technical characteristics tracked via Malpedia.
Also known as: simbot
Updated: 2022-03-07
View profile →
TabMsgSQL
Technical ID: win.tabmsgsql
Comment Crew
MALWARE
Malware family identifying win.tabmsgsql. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
T34loader
Technical ID: win.t34loader
MALWARE
Malware family identifying win.t34loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-02
View profile →
Szribi
Technical ID: win.szribi
MALWARE
Malware family identifying win.szribi. Origin and technical characteristics tracked via Malpedia.
Also known as: Srizbi
Updated: 2025-05-26
View profile →
SystemBC
Technical ID: win.systembc
Vanilla Tempest
MALWARE
SystemBC is a multiplatform proxy malware active since August 2019. It creates SOCKS5 network tunnels in the victim’s network and connects to its C2 server using a custom, RC4-encrypted protocol. It can also download and execute additional malware, with payloads either written to disk or mapped into memory. The SystemBC kit, including the C2 panel, server, and malware executables, is sold in underground forums.
Also known as: Coroxy • DroxiDat
Updated: 2025-09-23
View profile →
SysScan
Technical ID: win.sysscan
MALWARE
Malware family identifying win.sysscan. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Sysrv-hello
Technical ID: win.sysrv_hello
MALWARE
Sysrv is a Golang written Cryptojacking malware. There are Windows and Linux variants.
Updated: 2022-09-06
View profile →
Sysraw Stealer
Technical ID: win.sysraw_stealer
MALWARE
Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe". PDB strings suggest the name "Clipsa" though. First stage connects to /WPCoreLog/, the second one to /WPSecurity/. Its behavior suggest that it is an info stealer. It creates a rather large amount of files in a subdirectory (e.g. data) named "1?[-+].dat" and POSTs them.
Also known as: Clipsa
Updated: 2019-08-07
View profile →
SysKit
Technical ID: win.syskit
APT35Tortoiseshell
MALWARE
Malware family identifying win.syskit. Origin and technical characteristics tracked via Malpedia.
Also known as: IvizTech • MANGOPUNCH
Updated: 2021-07-29
View profile →
SysJoker
Technical ID: win.sysjoker
MALWARE
Sysjoker is a backdoor malware that was first discovered in December 2021 by Intezer. It is sophisticated and written from scratch in C++. Sysjoker is a cross-platform malware that has Linux, Windows, and macOS variants. Possible attack vectors for Sysjoker are email attachments, malicious advertisements, and trojanized software.
Updated: 2024-01-05
View profile →
SysGet
Technical ID: win.sysget
DragonOK
MALWARE
Malware family identifying win.sysget. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-29
View profile →
Syscon
Technical ID: win.syscon
MALWARE
SYSCON is a Remote Access Trojan used in a targeted champing against US government agencies. It has been recently observed in conjunction with CARROTBAT and CARROTBALL downloaders and it uses the File Transfer Protocol as Command and Control channel. Use of the family is attributed by Unit 42 to the Konni Group.
Updated: 2020-02-04
View profile →
Sys10
Technical ID: win.sys10
Naikon
MALWARE
Malware family identifying win.sys10. Origin and technical characteristics tracked via Malpedia.
Synth Loader
Technical ID: win.synth_loader
MALWARE
Malware family identifying win.synth_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
SynFlooder
Technical ID: win.synflooder
Cleaver
MALWARE
Malware family identifying win.synflooder. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
Sync-Scheduler
Technical ID: win.sync_scheduler
MALWARE
According to Cyfirma, Sync-Scheduler is a dedicated document stealer that targets Word documents, Excel Spreadsheets, PowerPoint presentations, PDFs and ZIP compress files. The malware is written in C++ and equipped with anti-analysis and defense evasion techniques. It uses obfuscation in its code and terminates itself if it detects an analysis environment.
Updated: 2025-01-15
View profile →
SyncCrypt
Technical ID: win.synccrypt
MALWARE
Malware family identifying win.synccrypt. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-14
View profile →
SynAck
Technical ID: win.synack
MALWARE
Malware family identifying win.synack. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-08-15
View profile →
sykipot
Technical ID: win.sykipot
Samurai Panda
MALWARE
Malware family identifying win.sykipot. Origin and technical characteristics tracked via Malpedia.
Also known as: getkys • Wkysol
Updated: 2022-03-07
View profile →
Sword
Technical ID: win.sword
Comment Crew
MALWARE
Malware family identifying win.sword. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
SwiftSlicer
Technical ID: win.swiftslicer
Sandworm
MALWARE
According to ESET, this is a wiper written in Go, that was deployed against an Ukrainian organization on January 25th 2023 through Group Policy, which suggests that the attackers had taken control of the victim’s Active Directory environment.
Also known as: JaguarBlade
Updated: 2023-04-25
View profile →
swen
Technical ID: win.swen
MALWARE
Malware family identifying win.swen. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-31
View profile →
SweetSpecter
Technical ID: win.sweetspecter
MALWARE
Malware family identifying win.sweetspecter. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-06-05
View profile →
SwaetRAT
Technical ID: win.swaet_rat
MALWARE
Malware family identifying win.swaet_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-01-07
View profile →
SVCStealer
Technical ID: win.svcstealer
MALWARE
According to Broadcom, SVCStealer is an information stealer written in C++, targeting devices running an windows operating system. It collects sensitive information from the infected device such as system information, credentials, cryptocurrency wallets, data stored in browsers, screenshots, data from messaging applications such as Telegram or VPN apps. The collected information is compressed into a .zip archive and extracted to botnet C2 servers.
Updated: 2026-01-05
View profile →
SVCReady
Technical ID: win.svcready
MALWARE
According to PCrisk, SVCReady collects information about the infected system such as username, computer name, time zone, computer manufacturer, BIOS, and firmware. Also, it gathers lists of running processes and installed software. SVCReady sends collected data to the C2 server. Additionally, SVCReady attempts to maintain its foothold on the system by creating a scheduled task.
Updated: 2023-06-09
View profile →
surtr
Technical ID: win.surtr
MALWAREfinancialhigh
According to PCrisk, Surtr is ransomware. Malware of this type encrypts files (and renames them) and generates a ransom note. Surtr appends the decryptmydata@mailfence.com email address and the ".SURT" extension to filenames.
Updated: 2023-06-09
View profile →
SuppoBox
Technical ID: win.suppobox
MALWARE
Malware family identifying win.suppobox. Origin and technical characteristics tracked via Malpedia.
Also known as: Bayrob • Nivdort • pizd
Updated: 2024-05-17
View profile →
Supper
Technical ID: win.supper
Vanilla Tempest
MALWARE
Supper is a 64-bit Windows backdoor and tunnelling utility first observed in the wild in July 2024. This malware operates as both a Remote Access Trojan (RAT) and a SOCKS5 proxy, offering threat actors persistent access to infected systems and the ability to route arbitrary traffic through victim environments. Once executed, it establishes a TCP connection to its primary C2 endpoint, i.e. hardcoded in the file, over port 443. A fallback mechanism allows the malware to retrieve alternate C2 IP addresses from an encoded file, %temp%/s01bafg, ensuring resilience in case the primary server is unavailable. The malware supports up to 16,384 concurrent sessions over a single TCP connection, each uniquely identified via a 16-bit session ID. Communication begins with an unencrypted 300-byte handshake payload that includes a static bot identifier (0x00691155), system metadata (hostname, domain, OS version, integrity level), and a fixed flag. Following this, all network traffic is wrapped in a 12-byte obfuscated header and an encrypted payload (8 bytes) which consists of two encrypted IP addresses. The header is transformed using two hardcoded XOR keys: 0x4d4d4d4d4d4d4d4d and 0x4d4d4d4d. Payload encryption is performed with a non-standard, stateful XOR cipher, where each byte of the message is encrypted based on a calculated offset and a cycling key (xored with 0x4d4d4d4d) derived from the header. It supports a range of C2 commands, including remote shell execution, session teardown, SOCKS5 proxy operations, self-deletion, and dynamic updating of fallback IPs. When executing commands, Supper spawns a hidden cmd.exe instance and forwards command outputs back to the C2 server after encryption. As a proxy, it accepts operator-specified connection requests, establishes TCP sessions to external targets, and forwards data between the target and the attacker, all managed under the session multiplexing framework. If instructed or if a C2 session fails, the malware can delete itself using cmd.exe or schtasks.exe, often masquerading the operation under the guise of a scheduled task named "GoogleUpdateTask". The file used to store fallback C2 IPs (%temp%/s01bafg) is updated by the malware using its encryption routine.
Also known as: SocksShell • ZAPCAT
Updated: 2026-01-14
View profile →
SUPERNOVA
Technical ID: win.supernova
MALWAREespionageadvanced
According to CISA, SUPERNOVA is a malicious webshell backdoor that allows a remote operator to dynamically inject C# source code into a web portal to subsequently inject code. APT actors use SUPERNOVA to perform reconnaissance, conduct domain mapping, and steal sensitive information and credentials.
Updated: 2023-10-05
View profile →
SuperBear RAT
Technical ID: win.superbear
MALWARE
Malware family identifying win.superbear. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-04
View profile →
SunSeed
Technical ID: win.sunseed
MALWARE
According to Proofpoint, this is a Lua-based malware likely used by a nation-state sponsored attacker used to target European government personnel involved in managing the logistics of refugees fleeing Ukraine.
Updated: 2022-04-15
View profile →
SunOrcal
Technical ID: win.sunorcal
MALWARE
Malware family identifying win.sunorcal. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-21
View profile →
sunnyday
Technical ID: win.sunnyday
MALWARE
Malware family identifying win.sunnyday. Origin and technical characteristics tracked via Malpedia.
SunCrypt
Technical ID: win.suncrypt
MALWAREfinancialhigh
According to PCrisk, Suncrypt ransomware prevents victims from accessing files by encryption. It also renames all encrypted files and creates a ransom message. It renames encrypted files by appending a string of random characters as the new extension.
Updated: 2023-06-09
View profile →
← PreviousPage 132 / 269Next →