Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
StalinLocker
Technical ID: win.stalin_locker
MALWARE
Malware family identifying win.stalin_locker. Origin and technical characteristics tracked via Malpedia.
Also known as: StalinScreamer
Stabuniq
Technical ID: win.stabuniq
MALWARE
Malware family identifying win.stabuniq. Origin and technical characteristics tracked via Malpedia.
MALWARE
SSLoad is a Rust-based downloader that first emerged in January 2024 and is used to deliver secondary payloads. Early versions of the malware used a first-stage DLL that connected to a Telegram channel named 'SSLoad' to retrieve another URL. It then downloaded a compressed PE file using a hardcoded User-Agent (SSLoad/1.x) and Content-Type over HTTP. The downloaded file was then decompressed and executed directly in memory. The malware has since undergone several updates, including changes to the command-and-control (C2) communication and the supporting executables that load the malware. Recent versions of the malware bypass the first-stage DLL by loading SSLoad directly onto the victim's machine.
MALWARE
Malware family identifying win.sslmm. Origin and technical characteristics tracked via Malpedia.
SSHNET
Technical ID: win.sshnet
MALWARE
Malware family identifying win.sshnet. Origin and technical characteristics tracked via Malpedia.
MALWARE
sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.
Also known as: DAVESHELL
SquirtDanger
Technical ID: win.squirtdanger
MALWARE
According to PaloAlto, SquirtDanger is a commodity botnet malware family that comes equipped with a number of characteristics and capabilities. The malware is written in C# (C Sharp) and has multiple layers of embedded code. Once run on the system, it will persist via a scheduled task that is set to run every minute. SquirtDanger uses raw TCP connections to a remote command and control (C2) server for network communications.
Squirrelwaffle
Technical ID: win.squirrelwaffle
MALWARE
According to Sophos, Squirrelwaffle is a malware loader that is distributed as a malicious Office document in spam campaigns. It provides attackers with an initial foothold in a victim’s environment and a channel to deliver and infect systems with other malware. When a recipient opens a Squirrelwaffle-infected document and enables macros, a visual basic script typically downloads and executes malicious files and scripts, giving further control of the computer to an attacker. Squirrelwaffle operators also use DocuSign to try and trick the user into enabling macros in Office documents.
Also known as: DatopLoader
SquidLoader
Technical ID: win.squidloader
MALWARE
Malware family identifying win.squidloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
A backdoor, capable of providing shell access, loading additional payloads, interacting remotely with the file system and processes, and taking screenshots.
Also known as: SpyGlace
SpyEye
Technical ID: win.spyeye
MALWARE
SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari. Originated in Russia, it was available in dark forums for $500+ claiming to be the "The Next Zeus Malware". It performed many functionalities typical from bankers trojan such as keyloggers, auto-fill credit card modules, email backups, config files (encrypted), http access, Pop3 grabbers and FTP grabbers. SpyEye allowed hackers to steal money from online bank accounts and initiate transactions even while valid users are logged into their bank account.
MALWARE
Malware family identifying win.spyder_patchwork. Origin and technical characteristics tracked via Malpedia.
Spyder
Technical ID: win.spyder
MALWARE
Malware family identifying win.spyder. Origin and technical characteristics tracked via Malpedia.
SpyBot
Technical ID: win.spybot
MALWARE
Malware family identifying win.spybot. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-26
View profile →Spora
Technical ID: win.spora_ransom
MALWARE
Malware family identifying win.spora_ransom. Origin and technical characteristics tracked via Malpedia.
splitloader
Technical ID: win.splitloader
MALWARE
Malware family identifying win.splitloader. Origin and technical characteristics tracked via Malpedia.
Splinter
Technical ID: win.splinter
MALWARE
According to Unit 42, Splinter is a post-exploitation red team tool, written in Rust.
MALWARE
Malware family identifying win.spider_rat. Origin and technical characteristics tracked via Malpedia.
Spicy Hot Pot
Technical ID: win.spicyhotpot
MALWARE
Malware family identifying win.spicyhotpot. Origin and technical characteristics tracked via Malpedia.
SPICA
Technical ID: win.spica
MALWARE
Malware family identifying win.spica. Origin and technical characteristics tracked via Malpedia.
SPHijacker
Technical ID: win.sphijacker
MALWARE
According to Trend Micro, this is a tool designed to disable security products, adopting two approaches to achieve this purpose. One approach terminates the security product process by using a vulnerable driver, zamguard64.sys, published by Zemana (vulnerability designated as CVE-2018-5713). Meanwhile, another approach disables process launching by using a new technique that they named stack rumbling.
MALWARE
Malware family identifying win.spedear. Origin and technical characteristics tracked via Malpedia.
Spectre Rat
Technical ID: win.spectre
MALWARE
Mixed RAT and Botnet malware sold in underground forums. In march 2021 it was advertised with the Spectre 2.0, it reached version 3 in June 2021 and then quickly version 4. This crimeware tool was being abused in malicious campaigns targeting European users in September 2021.
MALWARE
Malware family identifying win.spectralviper. Origin and technical characteristics tracked via Malpedia.
Spereal
Technical ID: win.spearal
MALWARE
Malware family identifying win.spearal. Origin and technical characteristics tracked via Malpedia.
Spartacus
Technical ID: win.spartacus
MALWAREfinancialhigh
Spartacus is ransomware written in .NET and emerged in the first half of 2018.
MALWARE
Malware family identifying win.sparrow_door. Origin and technical characteristics tracked via Malpedia.
SparkRAT
Technical ID: win.spark_rat
MALWARE
SparkRAT is a cross-platform, open-source Remote Administration Tool (RAT) written in Go and released on GitHub in 2022. Compatible with Windows, macOS, and Linux systems, it offers extensive remote access capabilities, including file and process management, file transfer, remote desktop monitoring, system information collection, and command execution via terminal access.
Sparksrv
Technical ID: win.sparksrv
MALWARE
Malware family identifying win.sparksrv. Origin and technical characteristics tracked via Malpedia.
Sparkle
Technical ID: win.sparkle
MALWARE
Malware family identifying win.sparkle. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.spark. Origin and technical characteristics tracked via Malpedia.
MALWARE
SPACESHIP searches for files with a specified set of file extensions and copies them to
a removable drive. FireEye believes that SHIPSHAPE is used to copy SPACESHIP to a removable drive,
which could be used to infect another victim computer, including an air-gapped computer. SPACESHIP is
then used to steal documents from the air-gapped system, copying them to a removable drive inserted
into the SPACESHIP-infected system
MALWARE
According to ESET, Spacecolon is a collection of malware written in Delphi, consisting of ScRansom, ScHackTool, ScInstaller, ScService, and ScPatcher.
MALWARE
Malware family identifying win.soundbite. Origin and technical characteristics tracked via Malpedia.
Also known as: denis
SoundBill
Technical ID: win.soundbill
MALWARE
According to Cisco Talos, this is a customized shellcode loader that has been observed to stage Mimikatz and CobaltStrike.
MALWARE
SoulSearcher is a second-stage loader responsible for executing the Soul backdoor main module and parsing its configuration. SoulSearcher has multiple variants based on where the configuration and payload are located and on the type of configuration.
Soul
Technical ID: win.soul
MALWARE
Malware family identifying win.soul. Origin and technical characteristics tracked via Malpedia.
Also known as: SoulSearcher
MALWARE
Malware family identifying win.sorgu. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.sorefang. Origin and technical characteristics tracked via Malpedia.
soraya
Technical ID: win.soraya
MALWARE
Malware family identifying win.soraya. Origin and technical characteristics tracked via Malpedia.