Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
SloppyMIO
Technical ID: win.sloppy_mio
MALWARE
According to HarfangLab, SloppyMIO is written in C#. It retrieves its configuration steganographically from images whose URLs are obtained via a Dead Drop Resolver (DDR) backed by GitHub. From these images, it extracts a XOR key, Telegram bot token and chat ID, and module URLs from an LSB-hidden payload. The malware can fetch and cache multiple modules from remote storage, run arbitrary commands, collect and exfiltrate files and deploy further malware with persistence via scheduled tasks. SloppyMIO beacons status messages, polls for commands and sends exfiltrated files over to a specified operator leveraging the Telegram Bot API for command-and-control.
slnrat
Technical ID: win.slnrat
MALWARE
Malware family identifying win.slnrat. Origin and technical characteristics tracked via Malpedia.
Sliver
Technical ID: win.sliver
MALWARE
According to VK9 Seecurity, Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants (slivers) that can run on virtually every architecture out there, and securely manage these connections through a central server. Sliver supports multiple callback protocols including DNS, TCP, and HTTP(S) to make egress simple, even when those pesky blue teams block your domains. You can even have multiple operators (players) simultaneously commanding your sliver army.
MALWARE
According to Proofpoint, SlipScreen is a first stage loader and has variants written in Rust and in C++. Its crypter is updated for each campaign, making static detection difficult.
Slingshot
Technical ID: win.slingshot
MALWARE
- 2012 first sighted
- Attack vector via compromised Mikrotik routers where victims get infection when they connect to Mikrotik router admin software - Winbox
- 2018 when discovered by Kaspersky Team
Infection Vector
- Infected Mikrotik Router > Malicious DLL (IP4.dll) in Router > User connect via winbox > Malicious DLL downloaded on computer
MALWARE
According to CERT-UA, this is a malware developed using the C++ programming language. The main functional purpose is the production of screenshots.
MALWARE
Malware family identifying win.slickshoes. Origin and technical characteristics tracked via Malpedia.
Slave
Technical ID: win.slave
MALWARE
Malware family identifying win.slave. Origin and technical characteristics tracked via Malpedia.
Skyplex
Technical ID: win.skyplex
MALWARE
Malware family identifying win.skyplex. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →Skynet
Technical ID: win.skynet
MALWARE
Malware family identifying win.skynet. Origin and technical characteristics tracked via Malpedia.
Skuld
Technical ID: win.skuld
MALWARE
Skuld, also known as TMPN Stealer, is an information-stealing malware written in Golang (Go) that emerged in May 2023.
Also known as: TMPN
MALWARE
Malware family identifying win.skipper. Origin and technical characteristics tracked via Malpedia.
Also known as: Kotel
MALWARE
A Microsoft SQL Server backdoor
SkinnyBoy
Technical ID: win.skinnyboy
MALWARE
Malware family identifying win.skinnyboy. Origin and technical characteristics tracked via Malpedia.
Skimer
Technical ID: win.skimer
MALWARE
Malware family identifying win.skimer. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.sisfader. Origin and technical characteristics tracked via Malpedia.
Sinowal
Technical ID: win.sinowal
MALWARE
Malware family identifying win.sinowal. Origin and technical characteristics tracked via Malpedia.
Also known as: Theola • Quarian • Mebroot • Anserin • Torpig
SimpleFileMover
Technical ID: win.simplefilemover
MALWARE
Malware family identifying win.simplefilemover. Origin and technical characteristics tracked via Malpedia.
Simda
Technical ID: win.simda
MALWARE
Malware family identifying win.simda. Origin and technical characteristics tracked via Malpedia.
Also known as: iBank
Siluhdur
Technical ID: win.siluhdur
MALWARE
Malware family identifying win.siluhdur. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →Silon
Technical ID: win.silon
MALWARE
Malware family identifying win.silon. Origin and technical characteristics tracked via Malpedia.
SilentSweeper
Technical ID: win.silent_sweeper
MALWARE
Malware family identifying win.silent_sweeper. Origin and technical characteristics tracked via Malpedia.
SILENTUPLOADER
Technical ID: win.silentuploader
MALWARE
According to Mandiant, SILENTUPLOADER is an uploader written in MSIL that is dropped by DOSTEALER and is designed to work specifically in tandem with it. It checks for files in a specified folder every 30 seconds and uploads them to a remote server.
SilentGh0st
Technical ID: win.silentgh0st
MALWARE
Malware family identifying win.silentgh0st. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to PCrisk, Truebot, also known as Silence.Downloader, is a malicious program that has botnet and loader/injector capabilities. This malware can add victims' devices to a botnet and cause chain system infections (i.e., download/install additional malicious programs/components).
There is significant variation in Truebot's infection chains and distribution. It is likely that the attackers using this malicious software will continue to make such changes.
Also known as: TrueBot
MALWARE
Malware family identifying win.sihost. Origin and technical characteristics tracked via Malpedia.
SigLoader
Technical ID: win.sigloader
MALWARE
Malware family identifying win.sigloader. Origin and technical characteristics tracked via Malpedia.
Siggen6
Technical ID: win.siggen6
MALWARE
Malware family identifying win.siggen6. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →SiestaGraph
Technical ID: win.siesta_graph
MALWARE
Malware family identifying win.siesta_graph. Origin and technical characteristics tracked via Malpedia.
Also known as: DRAFTGRAPH
MALWARE
Malware family identifying win.sierras. Origin and technical characteristics tracked via Malpedia.
Also known as: Destover
SiennaPurple
Technical ID: win.sienna_purple
MALWAREfinancialhigh
Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
Also known as: HolyLocker • H0lyGh0st
SiennaBlue
Technical ID: win.sienna_blue
MALWAREfinancialhigh
Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
Also known as: HolyLocker • H0lyGh0st
MALWARE
Malware family identifying win.sidewinder. Origin and technical characteristics tracked via Malpedia.
SideWalk
Technical ID: win.sidewalk
MALWARE
Shellcode-based malware family that according to ESET Research was likely written by the same authors as win.crosswalk.
Also known as: ScrambleCross
MALWARE
Malware family identifying win.sidetwist. Origin and technical characteristics tracked via Malpedia.
Shylock
Technical ID: win.shylock
MALWARE
Malware family identifying win.shylock. Origin and technical characteristics tracked via Malpedia.
Also known as: Caphaw
Shurl0ckr
Technical ID: win.shurl0ckr
MALWARE
Malware family identifying win.shurl0ckr. Origin and technical characteristics tracked via Malpedia.
Shurk Steal
Technical ID: win.shurk
MALWARE
Malware family identifying win.shurk. Origin and technical characteristics tracked via Malpedia.
Shujin
Technical ID: win.shujin
MALWARE
Malware family identifying win.shujin. Origin and technical characteristics tracked via Malpedia.