Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Sorano
Technical ID: win.sorano
MALWARE
Malware family identifying win.sorano. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-20
View profile →
Somnia
Technical ID: win.somnia
MALWARE
Malware family identifying win.somnia. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-13
View profile →
SombRAT
Technical ID: win.sombrat
[Unnamed group]
MALWARE
Malware family identifying win.sombrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-28
View profile →
SolidBit
Technical ID: win.solidbit
MALWAREfinancialhigh
Ransomware, written in .NET.
Updated: 2022-08-08
View profile →
solarmarker
Technical ID: win.solarmarker
MALWARE
Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities, mainly delivered through search engine optimization (SEO) manipulation to convince users to download malicious documents. Some of SolarMarker’s capabilities include the exfiltration of auto-fill data, saved passwords and saved credit card information from victims’ web browsers. Besides capabilities typical for infostealers, SolarMarker has additional capabilities such as file transfer and execution of commands received from a C2 server. The malware invests significant effort into defense evasion, which consists of techniques like signed files, huge files, impersonation of legitimate software installations and obfuscated PowerShell scripts.
Also known as: Jupyter • Polazert • Yellow Cockatoo
Updated: 2025-12-30
View profile →
Solarbot
Technical ID: win.solarbot
MALWARE
Malware family identifying win.solarbot. Origin and technical characteristics tracked via Malpedia.
Also known as: Napolar
Updated: 2020-02-26
View profile →
Solar
Technical ID: win.solar
OilRig
MALWARE
Malware family identifying win.solar. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-06
View profile →
SodaMaster
Technical ID: win.sodamaster
Stone Panda
MALWARE
This is a RAT that is usually loaded with one or more shellcode and/or reflective DLL injection techniques. The RAT uses RC4 or a hardcoded RSA key for traffic encryption/decryption. Its communication can either happen via a raw TCP socket or a HTTP POST request. Depending on the version, the RAT may remotely execute DLLs or shellcode.
Also known as: dfls • HEAVYPOT • DelfsCake
Updated: 2025-03-21
View profile →
SocksBot
Technical ID: win.socksbot
Anunak
MALWARE
Malware family identifying win.socksbot. Origin and technical characteristics tracked via Malpedia.
Also known as: BIRDDOG • Nadrac
Updated: 2023-01-19
View profile →
Socks5 Systemz
Technical ID: win.socks5_systemz
MALWARE
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
Updated: 2024-12-06
View profile →
Sockbot
Technical ID: win.sockbot
MALWARE
Sockbot is a customized and in Go written fork of the Ligolo reverse tunneling open-source tool. Several modification were performed by the threat actors who rewrote that code, e.g. execution checks, hardcoded values. Ligolo: https://github.com/sysdream/ligolo
Updated: 2022-08-08
View profile →
Socelars
Technical ID: win.socelars
MALWARE
Socelars is an infostealer with main focus on: * Facebook Stealer (ads/manager) * Cookie Stealer | AdsCreditCard {Amazon}
Updated: 2022-12-29
View profile →
Sobig
Technical ID: win.sobig
MALWARE
Malware family identifying win.sobig. Origin and technical characteristics tracked via Malpedia.
Also known as: Palyh
Updated: 2019-05-20
View profile →
Sobaken
Technical ID: win.sobaken
MALWARE
According to ESET, this RAT was derived from (the open-source) Quasar RAT.
Updated: 2018-07-24
View profile →
SNS Locker
Technical ID: win.snslocker
MALWARE
Malware family identifying win.snslocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-06-02
View profile →
SnowFlake Stealer
Technical ID: win.snowflake_stealer
MALWARE
Information stealer, written in Rust.
Updated: 2023-08-07
View profile →
Snojan
Technical ID: win.snojan
MALWARE
Malware family identifying win.snojan. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-23
View profile →
SnipVex
Technical ID: win.snipvex
MALWARE
SnipVex is a virus that infects files with .exe extension via prepending itself to the host. It is written in .NET. It has a clipbanker as payload.
Updated: 2025-05-19
View profile →
Snifula
Technical ID: win.snifula
MALWARE
Malware family identifying win.snifula. Origin and technical characteristics tracked via Malpedia.
Also known as: Ursnif
Updated: 2024-11-25
View profile →
SNEEPY
Technical ID: win.sneepy
MALWARE
Malware family identifying win.sneepy. Origin and technical characteristics tracked via Malpedia.
Also known as: ByeByeShell
Updated: 2017-11-17
View profile →
SnatchLoader
Technical ID: win.snatch_loader
MALWARE
A downloader trojan with some infostealer capabilities focused on the browser. Previously observed as part of RigEK campaigns.
Updated: 2020-10-08
View profile →
SnatchCrypto
Technical ID: win.snatchcrypto
Lazarus Group
MALWARE
Malware observed in the SnatchCrypto campaign, attributed by Kaspersky Labs to BlueNoroff with high confidence.
Also known as: BackbitingTea • msoRAT
Updated: 2025-11-05
View profile →
Snatch
Technical ID: win.snatch
MALWAREfinancialhigh
Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.
Updated: 2022-03-18
View profile →
SNAPPYBEE
Technical ID: win.snappybee
Earth Estries
MALWARE
Malware family identifying win.snappybee. Origin and technical characteristics tracked via Malpedia.
Also known as: Deed RAT • POISONPLUG.DEED
Updated: 2026-01-27
View profile →
SnakeDisk
Technical ID: win.snake_disk
MUSTANG PANDA
MALWARE
According to X-Force, SnakeDisk is a USB worm, dropping further payloads
Updated: 2025-09-23
View profile →
Snake
Technical ID: win.snake
MALWAREfinancialhigh
Snake Ransomware is a Golang ransomware reportedly containing obfuscation not typically seen in Golang ransomware. This malware will remove shadow copies and kill processes related to SCADA/ICS devices, virtual machines, remote management tools, network management software, and others. After this, encryption of files on the device commences, while skipping Windows system folders and various system files. A random 5 character string is appended to encrypted files. According to Bleeping Computer, this ransomware takes an especially long time to encrypt files on a targeted machine. This ransomware is reported to target an entire network, rather than individual workstations.
Also known as: EKANS • SNAKEHOSE
Updated: 2022-08-28
View profile →
Sn0wsLogger
Technical ID: win.sn0wslogger
MALWARE
Malware family identifying win.sn0wslogger. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-29
View profile →
Smrss32
Technical ID: win.smrss32
MALWAREfinancialhigh
Ransomware.
Updated: 2018-11-19
View profile →
Smominru
Technical ID: win.smominru
MALWARE
Malware family identifying win.smominru. Origin and technical characteristics tracked via Malpedia.
Also known as: Ismo
Updated: 2018-02-07
View profile →
SmokeLoader
Technical ID: win.smokeloader
SMOKY SPIDERUAC-0006
MALWARE
The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.
Also known as: Dofoil • Sharik • Smoke • Smoke Loader
Updated: 2025-09-17
View profile →
SMOKEDHAM
Technical ID: win.smokedham
MALWARE
According to Mandiant, SMOKEDHAM is dropped through a powershell script that contains the (C#) source code for this backdoor, which is stored in an encrypted variable. The dropper dynamically defines a cmdlet and .NET class for the backdoor, meaning the compiled code is only found in memory.
Updated: 2025-02-19
View profile →
SMAUG
Technical ID: win.smaug
MALWAREfinancialhigh
According to PCrisk, Smaug ransomware is available for download on the dark web: it is for sale as Ransomware as a Service (RaaS). Therefore, cyber criminals who purchase it can perform ransomware attacks without having to develop malware of this type. Smaug is designed to encrypt files, rename them and create a ransom message.
Updated: 2023-06-09
View profile →
SmartLoader
Technical ID: win.smartloader
MALWARE
Malware family identifying win.smartloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-18
View profile →
SmartEyes
Technical ID: win.smarteyes
MALWARE
Malware family identifying win.smarteyes. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-29
View profile →
SManager
Technical ID: win.smanager
MALWARE
Malware family identifying win.smanager. Origin and technical characteristics tracked via Malpedia.
Also known as: PhantomNet
Updated: 2023-10-07
View profile →
Smackdown
Technical ID: win.smackdown
MALWARE
Malware family identifying win.smackdown. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-19
View profile →
smac
Technical ID: win.smac
MALWARE
Malware family identifying win.smac. Origin and technical characteristics tracked via Malpedia.
Also known as: speccom
Updated: 2020-05-23
View profile →
SLUB
Technical ID: win.slub
MALWARE
Malware family identifying win.slub. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-16
View profile →
SlowStepper
Technical ID: win.slowstepper
MALWARE
According to ESET, SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components, programmed in C++, Python, and Go.
Updated: 2025-01-27
View profile →
SlothfulMedia
Technical ID: win.slothfulmedia
PowerPool
MALWARE
According to MITRE, SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.
Also known as: QueenOfClubs
Updated: 2023-06-09
View profile →
← PreviousPage 135 / 269Next →