Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
StalinLocker
Technical ID: win.stalin_locker
MALWARE
Malware family identifying win.stalin_locker. Origin and technical characteristics tracked via Malpedia.
Also known as: StalinScreamer
Updated: 2020-03-02
View profile →
Stabuniq
Technical ID: win.stabuniq
MALWARE
Malware family identifying win.stabuniq. Origin and technical characteristics tracked via Malpedia.
SSLoad
Technical ID: win.ssload
TA578
MALWARE
SSLoad is a Rust-based downloader that first emerged in January 2024 and is used to deliver secondary payloads. Early versions of the malware used a first-stage DLL that connected to a Telegram channel named 'SSLoad' to retrieve another URL. It then downloaded a compressed PE file using a hardcoded User-Agent (SSLoad/1.x) and Content-Type over HTTP. The downloaded file was then decompressed and executed directly in memory. The malware has since undergone several updates, including changes to the command-and-control (C2) communication and the supporting executables that load the malware. Recent versions of the malware bypass the first-stage DLL by loading SSLoad directly onto the victim's machine.
Updated: 2024-11-05
View profile →
SslMM
Technical ID: win.sslmm
Naikon
MALWARE
Malware family identifying win.sslmm. Origin and technical characteristics tracked via Malpedia.
SSHNET
Technical ID: win.sshnet
MALWARE
Malware family identifying win.sshnet. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-18
View profile →
sRDI
Technical ID: win.srdi
APT29Lazarus Group
MALWARE
sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.
Also known as: DAVESHELL
Updated: 2024-08-29
View profile →
SquirtDanger
Technical ID: win.squirtdanger
MALWARE
According to PaloAlto, SquirtDanger is a commodity botnet malware family that comes equipped with a number of characteristics and capabilities. The malware is written in C# (C Sharp) and has multiple layers of embedded code. Once run on the system, it will persist via a scheduled task that is set to run every minute. SquirtDanger uses raw TCP connections to a remote command and control (C2) server for network communications.
Updated: 2023-06-09
View profile →
Squirrelwaffle
Technical ID: win.squirrelwaffle
MALWARE
According to Sophos, Squirrelwaffle is a malware loader that is distributed as a malicious Office document in spam campaigns. It provides attackers with an initial foothold in a victim’s environment and a channel to deliver and infect systems with other malware. When a recipient opens a Squirrelwaffle-infected document and enables macros, a visual basic script typically downloads and executes malicious files and scripts, giving further control of the computer to an attacker. Squirrelwaffle operators also use DocuSign to try and trick the user into enabling macros in Office documents.
Also known as: DatopLoader
Updated: 2022-07-19
View profile →
SquidLoader
Technical ID: win.squidloader
MALWARE
Malware family identifying win.squidloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-07-03
View profile →
SpyGrace
Technical ID: win.spygrace
APT-C-60
MALWARE
A backdoor, capable of providing shell access, loading additional payloads, interacting remotely with the file system and processes, and taking screenshots.
Also known as: SpyGlace
Updated: 2024-12-16
View profile →
SpyEye
Technical ID: win.spyeye
MALWARE
SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari. Originated in Russia, it was available in dark forums for $500+ claiming to be the "The Next Zeus Malware". It performed many functionalities typical from bankers trojan such as keyloggers, auto-fill credit card modules, email backups, config files (encrypted), http access, Pop3 grabbers and FTP grabbers. SpyEye allowed hackers to steal money from online bank accounts and initiate transactions even while valid users are logged into their bank account.
Updated: 2021-06-29
View profile →
Spyder Patchwork
Technical ID: win.spyder_patchwork
QUILTED TIGER
MALWARE
Malware family identifying win.spyder_patchwork. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-08-29
View profile →
Spyder
Technical ID: win.spyder
MALWARE
Malware family identifying win.spyder. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-03-21
View profile →
SpyBot
Technical ID: win.spybot
MALWARE
Malware family identifying win.spybot. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-26
View profile →
Spora
Technical ID: win.spora_ransom
MALWARE
Malware family identifying win.spora_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
splitloader
Technical ID: win.splitloader
MALWARE
Malware family identifying win.splitloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-25
View profile →
Splinter
Technical ID: win.splinter
MALWARE
According to Unit 42, Splinter is a post-exploitation red team tool, written in Rust.
Updated: 2025-01-15
View profile →
SPIDERPIG RAT
Technical ID: win.spider_rat
BlackTech
MALWARE
Malware family identifying win.spider_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-30
View profile →
Spicy Hot Pot
Technical ID: win.spicyhotpot
MALWARE
Malware family identifying win.spicyhotpot. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-23
View profile →
SPICA
Technical ID: win.spica
MALWARE
Malware family identifying win.spica. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
SPHijacker
Technical ID: win.sphijacker
MALWARE
According to Trend Micro, this is a tool designed to disable security products, adopting two approaches to achieve this purpose. One approach terminates the security product process by using a vulnerable driver, zamguard64.sys, published by Zemana (vulnerability designated as CVE-2018-5713). Meanwhile, another approach disables process launching by using a new technique that they named stack rumbling.
Updated: 2023-05-04
View profile →
Spedear
Technical ID: win.spedear
Thrip
MALWARE
Malware family identifying win.spedear. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-25
View profile →
Spectre Rat
Technical ID: win.spectre
MALWARE
Mixed RAT and Botnet malware sold in underground forums. In march 2021 it was advertised with the Spectre 2.0, it reached version 3 in June 2021 and then quickly version 4. This crimeware tool was being abused in malicious campaigns targeting European users in September 2021.
Updated: 2024-06-24
View profile →
SPECTRALVIPER
Technical ID: win.spectralviper
Rebel Jackal
MALWARE
Malware family identifying win.spectralviper. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-26
View profile →
Spereal
Technical ID: win.spearal
MALWARE
Malware family identifying win.spearal. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-16
View profile →
Spartacus
Technical ID: win.spartacus
MALWAREfinancialhigh
Spartacus is ransomware written in .NET and emerged in the first half of 2018.
Updated: 2020-01-21
View profile →
SparrowDoor
Technical ID: win.sparrow_door
GhostEmperor
MALWARE
Malware family identifying win.sparrow_door. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-29
View profile →
SparkRAT
Technical ID: win.spark_rat
MALWARE
SparkRAT is a cross-platform, open-source Remote Administration Tool (RAT) written in Go and released on GitHub in 2022. Compatible with Windows, macOS, and Linux systems, it offers extensive remote access capabilities, including file and process management, file transfer, remote desktop monitoring, system information collection, and command execution via terminal access.
Updated: 2025-10-15
View profile →
Sparksrv
Technical ID: win.sparksrv
MALWARE
Malware family identifying win.sparksrv. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-01-23
View profile →
Sparkle
Technical ID: win.sparkle
MALWARE
Malware family identifying win.sparkle. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-05-17
View profile →
Spark
Technical ID: win.spark
Molerats
MALWARE
Malware family identifying win.spark. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-09
View profile →
SPACESHIP
Technical ID: win.spaceship
APT 30
MALWARE
SPACESHIP searches for files with a specified set of file extensions and copies them to a removable drive. FireEye believes that SHIPSHAPE is used to copy SPACESHIP to a removable drive, which could be used to infect another victim computer, including an air-gapped computer. SPACESHIP is then used to steal documents from the air-gapped system, copying them to a removable drive inserted into the SPACESHIP-infected system
Updated: 2022-08-25
View profile →
SpaceColon
Technical ID: win.spacecolon
CosmicBeetle
MALWARE
According to ESET, Spacecolon is a collection of malware written in Delphi, consisting of ScRansom, ScHackTool, ScInstaller, ScService, and ScPatcher.
Updated: 2024-10-18
View profile →
SOUNDBITE
Technical ID: win.soundbite
APT32
MALWARE
Malware family identifying win.soundbite. Origin and technical characteristics tracked via Malpedia.
Also known as: denis
Updated: 2020-11-11
View profile →
SoundBill
Technical ID: win.soundbill
MALWARE
According to Cisco Talos, this is a customized shellcode loader that has been observed to stage Mimikatz and CobaltStrike.
Updated: 2025-08-21
View profile →
SoulSearcher
Technical ID: win.soulsearcher
SharpPanda
MALWARE
SoulSearcher is a second-stage loader responsible for executing the Soul backdoor main module and parsing its configuration. SoulSearcher has multiple variants based on where the configuration and payload are located and on the type of configuration.
Updated: 2025-10-15
View profile →
Soul
Technical ID: win.soul
MALWARE
Malware family identifying win.soul. Origin and technical characteristics tracked via Malpedia.
Also known as: SoulSearcher
Updated: 2025-10-15
View profile →
Sorgu
Technical ID: win.sorgu
Leafminer
MALWARE
Malware family identifying win.sorgu. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-21
View profile →
SoreFang
Technical ID: win.sorefang
APT 29
MALWARE
Malware family identifying win.sorefang. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-04
View profile →
soraya
Technical ID: win.soraya
MALWARE
Malware family identifying win.soraya. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-07
View profile →
← PreviousPage 134 / 269Next →