Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
SUNBURST
Technical ID: win.sunburst
APT 29UNC2452
MALWARE
FireEye describes SUNBURST as a trojanized SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. After an initial dormant period of up to two weeks, it uses a DGA to generate specific subdomains for a set C&C domain. The backdoor retrieves and executes commands, that include the ability to transfer files, execute files, profile the system, reboot the machine, and disable system services. The C2 traffic to the malicious domains is designed to mimic normal SolarWinds API communications: Orion Improvement Program (OIP) protocol. The backdoor uses multiple obfuscated blocklists to identify forensic and anti-virus tools running as processes, services, and drivers. Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website.
Also known as: Solorigate
Updated: 2023-05-25
View profile →
SUGARUSH
Technical ID: win.sugarush
MALWARE
According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.
Updated: 2022-08-19
View profile →
SUGARRUSH
Technical ID: win.sugarrush
MALWARE
According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.
Updated: 2022-08-19
View profile →
SUGARDUMP
Technical ID: win.sugardump
MALWARE
According to Mandiant, SUGARDUMP is a credential harvesting utility, capable of password collection from Chromium-based browsers. There are also versions to exfiltrate data via SMTP and HTTP.
Updated: 2022-08-19
View profile →
Sugar
Technical ID: win.sugar
MALWAREfinancialhigh
Ransomware, written in Delphi.
Updated: 2022-02-19
View profile →
SUCEFUL
Technical ID: win.suceful
MALWARE
Malware family identifying win.suceful. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-27
View profile →
Subzero
Technical ID: win.subzero
Denim Tsunami
MALWARE
Malware family identifying win.subzero. Origin and technical characteristics tracked via Malpedia.
Also known as: Corelump • Jumplump
Updated: 2026-01-16
View profile →
Stuxnet
Technical ID: win.stuxnet
MALWARE
Malware family identifying win.stuxnet. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-05
View profile →
StrongPity
Technical ID: win.strongpity
PROMETHIUMStrongPity
MALWARE
According to Mitre, StrongPity is an information stealing malware used by PROMETHIUM.
Updated: 2023-06-09
View profile →
StrikeSuit Gift
Technical ID: win.strikesuit_gift
APT32
MALWARE
Malware family identifying win.strikesuit_gift. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-11
View profile →
StrifeWater RAT
Technical ID: win.strifewater_rat
MosesStaff
MALWARE
Malware family identifying win.strifewater_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
Stresspaint
Technical ID: win.stresspaint
MALWARE
Malware family identifying win.stresspaint. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-21
View profile →
StrelaStealer
Technical ID: win.strelastealer
MALWARE
According to PCRisk, StrelaStealer seeks to extract email account log-in credentials. At the time of writing, this program targets Microsoft Outlook and Mozilla Thunderbird email clients. Following successful infiltration, StrelaStealer searches for "logins.json" (account/password) and "key4.db" (password database) within the "%APPDATA%\Thunderbird\Profiles\" directory - by doing so, it can acquire the credentials for Thunderbird. Alternatively, if Outlook credentials are targeted - StrelaStealer seeks out the Windows Registry from where it can retrieve the program's key and "IMAP User", "IMAP Server", as well as the "IMAP Password" values. Since the latter is kept in an encrypted form, the malicious program employs the Windows CryptUnprotectData feature to decrypt it prior to exfiltration.
Updated: 2025-10-15
View profile →
STRATOFEAR
Technical ID: win.stratofear
MALWARE
Malware family identifying win.stratofear. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-26
View profile →
Stration
Technical ID: win.stration
MALWARE
Malware family identifying win.stration. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
STOWAWAY
Technical ID: win.stowaway
MALWARE
According to Mandiant, STOWAWAY is a publicly available backdoor and proxy. The project supports several types of communication like SSH, socks5. Backdoor component supports upload and download of files, remote shell and basic information gathering.
Updated: 2025-12-15
View profile →
Stormwind
Technical ID: win.stormwind
Evilnum
MALWARE
Malware family identifying win.stormwind. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-14
View profile →
StormKittyRAT
Technical ID: win.stormkitty_rat
MALWARE
According to unpac.me, StormKitty is a Remote Access Trojan (RAT), written in C#, primarily designed to perform extensive system reconnaissance and data collection. It leverages Windows Management Instrumentation for execution and conducts a thorough discovery of system information, including querying the registry, identifying system owners and users, and discovering network configurations. StormKitty is also capable of collecting data from information repositories and performing file and directory discovery. For defense evasion, it employs techniques such as obfuscating files or information and checks for virtualization or sandbox environments to avoid detection. These capabilities enable StormKitty to maintain persistence and gather sensitive information from compromised systems.
Updated: 2025-05-02
View profile →
STOP
Technical ID: win.stop
MALWAREfinancialhigh
STOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.
Also known as: KeyPass • Djvu
Updated: 2025-05-02
View profile →
StoneDrill
Technical ID: win.stonedrill
Charming Kitten
MALWARE
Malware family identifying win.stonedrill. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-19
View profile →
STONEBOAT
Technical ID: win.stoneboat
MALWARE
According to Mandiant, STONEBOAT is an installer for DICELOADER. It is written in .NET and drops its payload in-memory.
Updated: 2023-12-12
View profile →
Stinger
Technical ID: win.stinger
MALWARE
Malware family identifying win.stinger. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-19
View profile →
StegoLoader
Technical ID: win.stegoloader
MALWARE
Malware family identifying win.stegoloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-28
View profile →
SteamHide
Technical ID: win.steamhide
MALWARE
Malware written in .NET that hides in Steam profile pictures. Tries to evade virtualization through detection if it is executed within VMWare or VirtualBox.
Updated: 2023-09-04
View profile →
Stealth Soldier
Technical ID: win.stealth_soldier
MALWAREespionageadvanced
Check Point Research observed a wave of highly-targeted espionage attacks in Libya that utilize a new custom modular backdoor. Stealth Soldier malware is an undocumented backdoor that primarily operates surveillance functions such as file exfiltration, screen and microphone recording, keystroke logging and stealing browser information.
Updated: 2023-06-09
View profile →
StealthWorker Go
Technical ID: win.stealthworker
MALWARE
According to Fortinet, StealthWorker is a brute-force malware that has been linked to a compromised e-commerce website with an embedded skimmer that steals personal information and payment details. Before hackers can embed a skimmer, however, the first requirement is for hackers to gain access to their target’s backend. Hacker’s commonly take advantage of vulnerabilities in the Content Management System (CMS) or its plugins to gain entry into the target’s system. Another, simpler option is to use brute force attacks. Though quite slow, this method is still effective against administrators using weak or commonly used passwords.
Updated: 2022-11-09
View profile →
STEALHOOK
Technical ID: win.stealhook
OilRig
MALWARE
Malware family identifying win.stealhook. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-04
View profile →
Stealer0x3401
Technical ID: win.stealer_0x3401
APT31
MALWARE
According to PTSecurity, this stealer harvests system information which is then RC4 encrypted and Base64 encoded before sending it to the C2 server.
Updated: 2022-08-15
View profile →
Stealerium
Technical ID: win.stealerium
MALWARE
According to SecurityScorecard, Stealerium is an open-source stealer available on GitHub. The malware steals information from browsers, cryptocurrency wallets, and applications such as Discord, Pidgin, Outlook, Telegram, Skype, Element, Signal, Tox, Steam, Minecraft, and VPN clients. The binary also gathers data about the infected host, such as the running processes, Desktop and webcam screenshots, Wi-Fi networks, the Windows product key, and the public and private IP address. The stealer employs multiple anti-analysis techniques, such as detecting virtual machines, sandboxes, and malware analysis tools and checking if the process is being debugged. The malware also embedded a keylogger module and a clipper module that replaces cryptocurrency wallet addresses with the threat actor’s addresses if the victim makes a transaction. The stolen information is sent to a Discord channel using a Discord Webhook.
Updated: 2025-09-09
View profile →
Stealc
Technical ID: win.stealc
MALWARE
Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline. Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.
Updated: 2026-01-20
View profile →
StealBit
Technical ID: win.stealbit
MALWARE
This is a stealer used by LockBit 2.0.
Also known as: Corrempa
Updated: 2022-09-26
View profile →
STATICPLUGIN
Technical ID: win.staticplugin
MUSTANG PANDA
MALWARE
According to Google, this is a digitally signed downloader written in Delphi, used for in-memory deployment of Mustang Panda's PlugX.
Updated: 2025-08-26
View profile →
Statc
Technical ID: win.statc
MALWAREfinancialhigh
This malicious software gains access to a victim’s data by appearing like an authentic Google advertisement. Once the victim clicks on the advertisement, their operating system is infected with malicious code that steals sensitive data like credentials from web browsers, credit card information, and cryptocurrency wallet details. Unauthorized access to a victim’s computer system can have enormous personal and professional repercussions. Victims become easy targets for identity theft, cryptojacking, and other forms of malware attacks. At the enterprise level, a Statc Stealer breach can result in financial loss, reputational damage, legal liabilities, and regulatory penalties.
Also known as: Statc Stealer • Static Stealer
Updated: 2025-05-23
View profile →
STASHLOG
Technical ID: win.stashlog
MALWARE
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
Updated: 2022-05-09
View profile →
StartPage
Technical ID: win.startpage
MALWARE
Potentially unwanted program that changes the startpage of browsers to induce ad impressions.
Also known as: Easy Television Access Now
Updated: 2019-02-27
View profile →
StarsyPound
Technical ID: win.starsypound
Comment Crew
MALWARE
Malware family identifying win.starsypound. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
StarLoader
Technical ID: win.starloader
Sowbug
MALWARE
Malware family identifying win.starloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-21
View profile →
StarCruft
Technical ID: win.starcruft
APT37
MALWARE
Malware family identifying win.starcruft. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
Stampedo
Technical ID: win.stampedo
MALWARE
Malware family identifying win.stampedo. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
StallionRAT
Technical ID: win.stallion_rat
YoroTrooper
MALWARE
According to BI.ZONE, StallionRAT allows attackers to execute arbitrary commands, load additional files, and exfiltrate collected data. The malware uses a Telegram bot as their C2 server.
Updated: 2026-01-19
View profile →
← PreviousPage 133 / 269Next →