Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
ShrinkLocker
Technical ID: win.shrinklocker
MALWARE
Malware family identifying win.shrinklocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-25
View profile →
ShortLeash
Technical ID: win.shortleash
MALWAREespionageadvanced
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.
Updated: 2025-06-24
View profile →
SHIPSHAPE
Technical ID: win.shipshape
APT 30
MALWAREespionageadvanced
SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.
Updated: 2022-08-25
View profile →
Shim RAT
Technical ID: win.shimrat
Mofang
MALWARE
Malware family identifying win.shimrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
Shifu
Technical ID: win.shifu
MALWAREfinancialhigh
Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.
Updated: 2022-02-14
View profile →
Sheriff
Technical ID: win.sheriff
MALWARE
According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine. It uses the Dropbox API for C2 and data exfiltration.
Updated: 2025-04-10
View profile →
ShellLocker
Technical ID: win.shelllocker
MALWAREfinancialhigh
PCRIsk states that ShellLocker is a ransomware-type virus developed using .NET framework. It was first discovered by Jakub Kroustek and is virtually identical to another ransomware virus called Exotic. Following infiltration, this virus encrypts stored data (video, audio, etc.) and renames encrypted files using the "[random_characters].L0cked" pattern (e.g., "sample.jpg" might be renamed to "gd&=AA0fgoi.L0cked"). Following successful encryption, ShellLocker opens a pop-up window containing ransom-demand message.
Updated: 2022-11-15
View profile →
ShellClient RAT
Technical ID: win.shellclient
MALWARE
Malware family identifying win.shellclient. Origin and technical characteristics tracked via Malpedia.
Also known as: GhostShell
Updated: 2021-11-19
View profile →
SHEETCREEP
Technical ID: win.sheetcreep
MALWARE
According to Zscaler, SHEETCREEP is a lightweight backdoor written in C# that uses Google Sheets for C2 communication.
Updated: 2026-01-29
View profile →
SHATTEREDGLASS
Technical ID: win.shatteredglass
Silent Chollima
MALWAREfinancialhigh
Kaspersky Labs observed Andariel to drop this ransomware in one case within a series of attacks carried out against targets in South Korea in April 2021.
Also known as: Unidentified 081
Updated: 2024-08-01
View profile →
SharpRhino
Technical ID: win.sharp_rhino
MALWARE
Malware family identifying win.sharp_rhino. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-19
View profile →
SharPyShell
Technical ID: win.sharpyshell
APT41
MALWARE
SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at runtime. SharPyShell supports only C# web applications that runs on .NET Framework >= 2.0 VB is not supported atm.
Also known as: ASPSHELL
Updated: 2025-07-22
View profile →
SharpWMI
Technical ID: win.sharpwmi
MALWARE
According to its Github repository, SharpWMI is a C# implementation of various WMI functionality.
Updated: 2026-01-16
View profile →
SHARPSTATS
Technical ID: win.sharpstats
MuddyWater
MALWARE
Malware family identifying win.sharpstats. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-23
View profile →
SharpStage
Technical ID: win.sharpstage
Molerats
MALWARE
The SharpStage backdoor is a .NET malware with backdoor capabilities. Its name is a derivative of the main activity class called “Stage_One”. SharpStage can take screenshots, run arbitrary commands and downloads additional payloads. It exfiltrates data from the infected machine to a dropbox account by implementing a dropbox client in its code. SharpStage was seen used by the Molerats group in targeted attacks in the middle east.
Also known as: LastConn
Updated: 2022-02-09
View profile →
SharpMapExec
Technical ID: win.sharpmapexec
MALWARE
This tool is made to simplify penetration testing of networks and to create a Swiss-army knife that is made for running on Windows which is often a requirement during insider threat simulation engagements.
Updated: 2021-12-01
View profile →
SHARPKNOT
Technical ID: win.sharpknot
Silent Chollima
MALWARE
Malware family identifying win.sharpknot. Origin and technical characteristics tracked via Malpedia.
Also known as: Bitrep
Updated: 2018-04-13
View profile →
SharpHound
Technical ID: win.sharphound
MALWARE
According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
Updated: 2026-01-16
View profile →
SharpBeacon
Technical ID: win.sharpbeacon
MALWARE
.NET reimplementation of Cobalt Strike beacon/stager
Updated: 2021-11-10
View profile →
Shark
Technical ID: win.shark
MALWARE
Malware family identifying win.shark. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-11-09
View profile →
shareip
Technical ID: win.shareip
UPS
MALWARE
Malware family identifying win.shareip. Origin and technical characteristics tracked via Malpedia.
Also known as: remotecmd
Updated: 2018-04-17
View profile →
SHAPESHIFT
Technical ID: win.shapeshift
APT33
MALWARE
Malware family identifying win.shapeshift. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-29
View profile →
Shakti
Technical ID: win.shakti
MALWARE
Malware family identifying win.shakti. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
ShadyHammock
Technical ID: win.shady_hammock
MALWARE
Malware family identifying win.shady_hammock. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-25
View profile →
Shadow RAT
Technical ID: win.shadow_rat
MALWARE
Malware family identifying win.shadow_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-13
View profile →
ShadowPad
Technical ID: win.shadowpad
APT17APT23APT41DAGGER PANDA+4 more
MALWARE
Malware family identifying win.shadowpad. Origin and technical characteristics tracked via Malpedia.
Also known as: POISONPLUG.SHADOW • XShellGhost
Updated: 2026-01-27
View profile →
shadowhammer
Technical ID: win.shadowhammer
Operation ShadowHammer
MALWARE
Malware family identifying win.shadowhammer. Origin and technical characteristics tracked via Malpedia.
Also known as: DAYJOB
Updated: 2021-09-19
View profile →
Sfile
Technical ID: win.sfile
MALWAREfinancialhigh
Ransomware
Also known as: Morseop • Escal
Updated: 2022-06-09
View profile →
SessionManager
Technical ID: win.session_manager
Gelsemium
MALWARE
A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the network behind.
Updated: 2022-07-05
View profile →
ServHelper
Technical ID: win.servhelper
TA505
MALWARE
ServHelper is written in Delphi and according to ProofPoint best classified as a backdoor. ProofPoint noticed two distinct variant - "tunnel" and "downloader" (citation): "The 'tunnel' variant has more features and focuses on setting up reverse SSH tunnels to allow the threat actor to access the infected host via Remote Desktop Protocol (RDP). Once ServHelper establishes remote desktop access, the malware contains functionality for the threat actor to 'hijack' legitimate user accounts or their web browser profiles and use them as they see fit. The 'downloader' variant is stripped of the tunneling and hijacking functionality and is used as a basic downloader."
Updated: 2022-12-20
View profile →
Serpico
Technical ID: win.serpico
MALWARE
Malware family identifying win.serpico. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Serpent Stealer
Technical ID: win.serpent
MALWARE
Malware family identifying win.serpent. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-02
View profile →
SerialVlogger
Technical ID: win.serialvlogger
APT41
MALWARE
This malware is protected using VMProtect and related to the loading of KEYPLUG.
Updated: 2022-11-18
View profile →
Sepulcher
Technical ID: win.sepulcher
TA413
MALWARE
Malware family identifying win.sepulcher. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-25
View profile →
SepSys
Technical ID: win.sepsys
MALWAREfinancialhigh
Ransomware.
Also known as: Silvertor Ransomware
Updated: 2020-10-15
View profile →
SendSafe
Technical ID: win.sendsafe
MALWARE
Malware family identifying win.sendsafe. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-11
View profile →
SelfMake Loader
Technical ID: win.selfmake
BlackTech
MALWARE
Malware family identifying win.selfmake. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-30
View profile →
Sekhmet
Technical ID: win.sekhmet
MALWAREfinancialhigh
According to PCrisk, Sekhmet is ransomware. This malicious program operates by encrypting data and demanding ransom payments for decryption. During the encryption process, all affected files are appended with an extension, consisting of random characters (e.g. ".HrUSsw", ".WNgh", ".NdWfEr", etc.).
Updated: 2023-06-09
View profile →
seinup
Technical ID: win.seinup
MALWARE
Malware family identifying win.seinup. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-04
View profile →
Seduploader
Technical ID: win.seduploader
APT28
MALWARE
simple tool to facilitate download and persistence of a next-stage tool; collects system information and metadata probably in an attempt to tell sandbox-environments apart from real targets on the server-side; uses domains of search engines like Google to check for Internet connectivity; XOR-based string obfuscation with a 16-byte key
Also known as: jhuhugit • jkeyskw • downrage • carberplike • GAMEFISH
Updated: 2024-07-10
View profile →
← PreviousPage 137 / 269Next →