Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Sedreco
Technical ID: win.sedreco
APT28
MALWARE
Malware family identifying win.sedreco. Origin and technical characteristics tracked via Malpedia.
Also known as: azzy • eviltoss
Updated: 2022-05-04
View profile →
SeDll
Technical ID: win.sedll
Leviathan
MALWARE
Malware family identifying win.sedll. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
SectopRAT
Technical ID: win.sectop_rat
MALWARE
SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.
Also known as: 1xxbot • ArechClient
Updated: 2025-06-20
View profile →
SecondHandTea
Technical ID: win.secondhandtea
Lazarus Group
MALWAREfinancialhigh
SecondHandTea is a full-featured Remote Access Trojan (RAT), closely related to BackbitingTea, the flagship backdoor used in the DangerousPassword campaigns (also known as SnatchCrypto). Both malware families appear to share a common codebase and are compiled within the same build environment. While they share most core functionality and supported commands, SecondHandTea differs from BackbitingTea variants in several technical aspects: - Configuration file paths - Network libraries: OpenSSL 1.1.0f vs. wolfSSL or Winsock TCP/IP - Encryption algorithms: AES-256 vs. RC4 - Compression methods: LZ4 vs. ZIP These differences suggest active development and customization efforts tailored to specific operational needs. The malware's name was inferred from its internal filename: SecondT_x64.exe. Between H2 2022 and Q1 2023, SecondHandTea was observed in targeted attacks against entities involved in cryptotrading and blockchain technology, indicating a continued focus on financially motivated cyber operations.
Updated: 2025-09-15
View profile →
SeaSalt
Technical ID: win.seasalt
Comment Crew
MALWARE
Malware family identifying win.seasalt. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
SEADADDY
Technical ID: win.seadaddy
APT29
MALWARE
Backdoor written in Python 2, deployed with PyInstaller.
Also known as: SeaDuke • Seadask
Updated: 2022-03-14
View profile →
SDBbot
Technical ID: win.sdbbot
TA505
MALWARE
Malware family identifying win.sdbbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-17
View profile →
ScrubCrypt
Technical ID: win.scrubcrypter
MALWARE
ScrubCrypt is the rebranded "Jlaive" crypter, with a unique capability of .BAT packing
Updated: 2023-05-17
View profile →
ScreenLocker
Technical ID: win.screenlocker
MALWARE
Malware family identifying win.screenlocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
ScreenCap
Technical ID: win.screencap
MALWAREespionageadvanced
SentinelOne describes this malware as capable of doing screen capture and keylogging. It is uses by a threat cluster they named WIP19, targeting telecommunications and IT service providers in the Middle East and Asia.
Updated: 2022-10-24
View profile →
Scranos
Technical ID: win.scranos
MALWARE
Malware family identifying win.scranos. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-21
View profile →
ScoutC2
Technical ID: win.scoutc2
MALWARE
Malware family identifying win.scoutc2. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-21
View profile →
Scout
Technical ID: win.scout
Lazarus Group
MALWARE
A downloader that uses Windows messages to control its execution flow.
Updated: 2023-10-20
View profile →
Scote
Technical ID: win.scote
TopHatDustySky
MALWARE
Malware family identifying win.scote. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-26
View profile →
ScoringMathTea
Technical ID: win.scoring_math_tea
Lazarus Group
MALWARE
According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine. Its first appearance dates to late 2022, when its dropper was uploaded to VirusTotal. Soon after, it was seen in the wild, and since then in multiple attacks attributed to Lazarus’ Operation DreamJob campaigns, which makes it the attacker’s payload of choice for already three years. It uses compromised servers for C&C communication, with the server part usually stored under the WordPress folder containing design templates or plugins.
Updated: 2025-11-21
View profile →
Scieron
Technical ID: win.scieron
MALWARE
The Chinese threat actor has used a custom backdoor dubbed "Scieron" over years in several campaigns according to SentinelLABS.
Updated: 2022-09-20
View profile →
Schneiken
Technical ID: win.schneiken
MALWARE
Schneiken is a VBS 'Double-dropper'. It comes with two RATs embedded in the code (Dunihi and Ratty). Entire code is Base64 encoded.
Updated: 2018-04-27
View profile →
Scavenger
Technical ID: win.scavenger
MALWARE
Scavenger is a stealthy, two-stage malware family first observed in July 2025 following a targeted supply chain attack on the NPM ecosystem. The infection began with a phishing campaign that leveraged a typo-squatted domain (npnjs.com) to impersonate the legitimate NPM login page. The adversaries abused NPM's web-based login flow—akin to device code phishing—to trick a package maintainer into generating an automation access token, which does not expire and can bypass 2FA under certain configurations. With the stolen credentials, the attackers injected malicious payloads into several trusted NPM packages, including eslint-config-prettier, by modifying their install scripts to execute a DLL loader. This first-stage loader, compiled in Visual Studio, performs anti-VM checks, dynamic API resolution using CRC32 hashing, indirect syscalls to bypass EDR, and string decryption routines. If the environment passes these checks, it executes a second-stage infostealer that targets browser data—particularly from Chromium—such as extension state, cached content, and visited URLs. The malware communicates with its command and control infrastructure using libcurl and XXTEA-encrypted payloads over HTTP(S), implementing challenge-response integrity checks during session initialization. Development artifacts like a leftover PDB path and operational overlaps have linked Scavenger to other campaigns, including one involving an infected BeamNG game binary, further suggesting a broader and evolving threat infrastructure.
Also known as: scavenger • SCVNGR • scvngr
Updated: 2025-07-29
View profile →
ScareCrow
Technical ID: win.scarecrow
MALWARE
Based on the leaked Conti source code.
Updated: 2022-12-19
View profile →
Scarab Ransomware
Technical ID: win.scarab_ransom
MALWARE
Malware family identifying win.scarab_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
Scarabey
Technical ID: win.scarabey
MALWAREfinancialhigh
Ransomware with ransomnote in Russian and encryption extension .scarab.
Also known as: MVP • Scarab-Russian • Scarab
Updated: 2019-08-19
View profile →
ScanPOS
Technical ID: win.scanpos
MALWARE
Malware family identifying win.scanpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-19
View profile →
Scano
Technical ID: win.scano
MALWARE
Malware family identifying win.scano. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-29
View profile →
ScanLine
Technical ID: win.scanline
Volt Typhoon
MALWARE
According to CISA, this is a command-line port scanning utility from Foundstone. It is used to scan for open UDP and TCP ports, grab banners from open ports, resolve IP addresses to host names, and bind to specified ports and IP addresses.
Updated: 2024-02-08
View profile →
Sathurbot
Technical ID: win.sathurbot
MALWARE
Malware family identifying win.sathurbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-03
View profile →
Satellite Turla
Technical ID: win.satellite_turla
Turla
MALWARE
Malware family identifying win.satellite_turla. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-11-17
View profile →
Satana
Technical ID: win.satana
MALWAREfinancialhigh
According to bitdefender, Satana is an aggressive ransomware for Windows that encrypts the computer’s master boot record (MBR) and prevents it from starting.
Updated: 2023-06-09
View profile →
Satan
Technical ID: win.satan
MALWAREfinancialhigh
Ransomware.
Also known as: 5ss5c • DBGer • Lucky Ransomware
Updated: 2020-01-16
View profile →
Satacom
Technical ID: win.satacom
MALWARE
Malware family identifying win.satacom. Origin and technical characteristics tracked via Malpedia.
Also known as: CurlyGate • LegionLoader • RobotDropper
Updated: 2025-02-04
View profile →
Sasfis
Technical ID: win.sasfis
MALWARE
Sasfis acts mostly as a downloader that has been observed to download Asprox and FakeAV. According to a VirusBulletin article from 2012, it is likely authored by the same group as SmokeLoader.
Also known as: Oficla
Updated: 2018-11-28
View profile →
Sarhust
Technical ID: win.sarhust
MALWARE
Malware family identifying win.sarhust. Origin and technical characteristics tracked via Malpedia.
Also known as: ENDCMD • Hussarini
Updated: 2020-06-30
View profile →
Sarcoma
Technical ID: win.sarcoma
MALWARE
Malware family identifying win.sarcoma. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-23
View profile →
SappyCache
Technical ID: win.sappycache
MALWARE
Malware family identifying win.sappycache. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
SapphireStealer
Technical ID: win.sapphire_stealer
MALWARE
Malware family identifying win.sapphire_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-01
View profile →
SapphireMiner
Technical ID: win.sapphire_miner
MALWARE
Malware family identifying win.sapphire_miner. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-31
View profile →
SantaStealer
Technical ID: win.santa_stealer
MALWARE
According to Rapid7, this malware collects and exfiltrates sensitive documents, credentials, wallets, and data from a broad range of applications, and aims to operate entirely in-memory to avoid file-based detection. Stolen data is then compressed, split into 10 MB chunks, and sent to a C2 server over unencrypted HTTP.
Updated: 2026-01-05
View profile →
Sanny
Technical ID: win.sanny
MALWARE
Malware family identifying win.sanny. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-08
View profile →
SamSam
Technical ID: win.samsam
Boss Spider
MALWAREfinancialhigh
According to PCrisk, Samsam is high-risk ransomware designed to infect unpatched servers and encrypt files stored on computers networked to the infected server.
Also known as: Samas
Updated: 2023-05-24
View profile →
SamoRAT
Technical ID: win.samo_rat
MALWARE
According to PCrisk, SamoRAT is a Remote Access Trojan (RAT), a type of malware that allows the cyber criminals responsible to monitor and control the infected computer. In most cases, RATs are used to steal sensitive information and/or install other malware onto the infected computer.
Updated: 2023-05-25
View profile →
Sality
Technical ID: win.sality
Salty Spider
MALWARE
F-Secure states that the Sality virus family has been circulating in the wild as early as 2003. Over the years, the malware has been developed and improved with the addition of new features, such as rootkit or backdoor functionality, and so on, keeping it an active and relevant threat despite the relative age of the malware. Modern Sality variants also have the ability to communicate over a peer-to-peer (P2P) network, allowing an attacker to control a botnet of Sality-infected machines. The combined resources of the Sality botnet may also be used by its controller(s) to perform other malicious actions, such as attacking routers. Infection Sality viruses typically infect executable files on local, shared and removable drives. In earlier variants, the Sality virus simply added its own malicious code to the end of the infected (or host) file, a technique known as prepending. The viral code that Sality inserts is polymorphic, a form of complex code that is intended to make analysis more difficult. Earlier Sality variants were regarded as technically sophisticated in that they use an Entry Point Obscuration (EPO) technique to hide their presence on the system. This technique means that the virus inserts a command somewhere in the middle of an infected file's code, so that when the system is reading the file to execute it and comes to the command, it forces the system to 'jump' to the malware's code and execute that instead. This technique was used to make discovery and disinfection of the malicious code harder. Payload Once installed on the computer system, Sality viruses usually also execute a malicious payload. The specific actions performed depend on the specific variant in question, but generally Sality viruses will attempt to terminate processes, particularly those related to security programs. The virus may also attempt to open connections to remote sites, download and run additional malicious files, and steal data from the infected machine.
Updated: 2023-11-14
View profile →
← PreviousPage 138 / 269Next →