Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Salgorea
Technical ID: win.salgorea
APT32
MALWARE
Malware family identifying win.salgorea. Origin and technical characteristics tracked via Malpedia.
Also known as: BadCake
Updated: 2020-05-06
View profile →
SalatStealer
Technical ID: win.salatstealer
MALWAREespionageadvanced
Crypto Stealer written in GO. Targets browsers, crypto wallets and telegram clients (Telegram Desktop, Kotatogram). Can capture webcam and microphone and stream it on to c2 server.
Updated: 2025-12-15
View profile →
Sakula RAT
Technical ID: win.sakula_rat
APT 26Hurricane Panda
MALWARE
Sakula / Sakurel is a trojan horse that opens a back door and downloads potentially malicious files onto the compromised computer.
Also known as: Sakurel
Updated: 2024-05-21
View profile →
Saitama Backdoor
Technical ID: win.saitama
OilRig
MALWARE
This in .Net witten backdoor abuses the DNS protocoll for its C2 communication. Also other techniques (e.g. long random sleeps, compression) are used to become more stealthy.
Also known as: AMATIAS • Saitama
Updated: 2023-02-03
View profile →
Saint Bot
Technical ID: win.saint_bot
MALWARE
Malware family identifying win.saint_bot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-25
View profile →
SaiGon
Technical ID: win.saigon
MALWAREfinancialhigh
FireEye reports SaiGon as a variant of ISFB v3 (versions documented are tagged 3.50.132) that is more a generic backdoor than being focused on enabling banking fraud.
Updated: 2020-09-01
View profile →
SAGE
Technical ID: win.sage_ransom
MALWARE
Malware family identifying win.sage_ransom. Origin and technical characteristics tracked via Malpedia.
Also known as: Saga
Updated: 2019-07-20
View profile →
Sagerunex
Technical ID: win.sagerunex
LOTUS PANDA
MALWARE
According to Symantec, Sagerunex is a backdoor that is fairly resilient and implements multiple forms of communication with its command-and-control (C&C) server. Its logs are encrypted and the encryption algorithm used is AES256-CBC with 8192 rounds of SHA256 for key derivation based on a hardcoded key. It supports multiple modes methods for communicating via HTTP (proxy-aware).
Updated: 2026-01-05
View profile →
SafePay
Technical ID: win.safepay
MALWARE
Malware family identifying win.safepay. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-15
View profile →
SafeNet
Technical ID: win.safenet
MALWARE
Malware family identifying win.safenet. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-01-22
View profile →
Saefko
Technical ID: win.saefko
MALWARE
Malware family identifying win.saefko. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-09
View profile →
Sadogo
Technical ID: win.sadogo
MALWAREfinancialhigh
Ransomware.
Updated: 2020-04-20
View profile →
SADBRIDGE
Technical ID: win.sadbridge
MALWARE
According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various injection techniques to execute malicious payloads. SADBRIDGE abuses legitimate applications such as x64dbg.exe and MonitoringHost.exe to load malicious DLLs like x64bridge.dll and HealthServiceRuntime.dll, which leads to subsequent stages and shellcodes.
Updated: 2025-01-02
View profile →
Ryuk Stealer
Technical ID: win.ryuk_stealer
MALWARE
Information Stealer that searches for sensitive documents and uploads its results to an FTP server. Skips files with known Ryuk extensions.
Also known as: Sidoh
Updated: 2021-09-02
View profile →
Ryuk
Technical ID: win.ryuk
FIN6GRIM SPIDERUNC1878WIZARD SPIDER
MALWAREfinancialhigh
Ryuk is a ransomware which encrypts its victim's files and asks for a ransom via bitcoin to release the original files. It is has been observed being used to attack companies or professional environments. Cybersecurity experts figured out that Ryuk and Hermes ransomware shares pieces of codes. Hermes is commodity ransomware that has been observed for sale on dark-net forums and used by multiple threat actors.
Updated: 2024-06-12
View profile →
RustyClaw
Technical ID: win.rusty_claw
RomCom
MALWARE
According to Proofpoint, RustyClaw is a downloader written in Rust
Updated: 2025-11-25
View profile →
RustyRocket
Technical ID: win.rustyrocket
MALWARE
Written in Rust and designed for both Windows and Linux environments, RustyRocket enables WorldLeaks affiliates to steal data through heavily obfuscated, multi-layered encrypted tunnels that can be exceptionally difficult to detect using traditional network monitoring.
Rustonotto
Technical ID: win.rustonotto
APT37
MALWAREespionageadvanced
Rustonotto, active since June 2025, is a Rust-compiled malware, representing the first known instance of APT37 leveraging Rust-based malware to target Windows systems.
Also known as: CHILLYCHINO
Updated: 2025-09-09
View profile →
Rustock
Technical ID: win.rustock
MALWARE
Malware family identifying win.rustock. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
RustBucket
Technical ID: win.rustbucket
Lazarus Group
MALWARE
Malware family identifying win.rustbucket. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-11
View profile →
Rurktar
Technical ID: win.rurktar
MALWARE
Malware family identifying win.rurktar. Origin and technical characteristics tracked via Malpedia.
Also known as: RCSU
Updated: 2017-08-31
View profile →
RURansom
Technical ID: win.ruransom
MALWAREfinancialhigh
RURansom shows characteristics of typical ransomware, but despite its name, TrendMicro's assumptions after analysis showed that this malware is more a wiper than ransomware, because the irreversible destruction of encrypted files.
Updated: 2022-05-04
View profile →
Running RAT
Technical ID: win.runningrat
MALWARE
NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files. When the trojan is loaded onto a system, it executes the first DLL. This is used to disable anti-malware solutions, unpack and execute the main RAT DLL, and gain persistence. The trojan installs a Windows batch file dx.bat that attempts to kill the daumcleaner.exe task, a Korean security program. The file then attempts to remove itself. Once the second DLL is loaded into memory, the first DLL overwrites the IP address for the control server to change the address the trojan communicates with. The second DLL gathers information about the victim's system, including its operating system and driver and processor information. The RAT can log user keystrokes, copy the clipboard, delete files, compress files, clear event logs, shut down the machine, and more. The second DLL also uses several anti-bugging techniques.
Also known as: running_rat
Updated: 2024-11-15
View profile →
Rumish
Technical ID: win.rumish
MALWARE
Malware family identifying win.rumish. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
Rugmi
Technical ID: win.rugmi
MALWARE
Malware family identifying win.rugmi. Origin and technical characteristics tracked via Malpedia.
Also known as: Penguish
Updated: 2025-04-09
View profile →
Ruckguv
Technical ID: win.ruckguv
MALWARE
Malware family identifying win.ruckguv. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-01
View profile →
Rubeus
Technical ID: win.rubeus
MALWARE
Rubeus is a C# toolset for raw Kerberos interaction and abuses.
Updated: 2026-01-16
View profile →
rtpos
Technical ID: win.rtpos
MALWARE
Malware family identifying win.rtpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-01
View profile →
RTM Locker
Technical ID: win.rtm_locker
MALWARE
Malware family identifying win.rtm_locker. Origin and technical characteristics tracked via Malpedia.
Also known as: Read The Manual Locker
Updated: 2023-11-13
View profile →
RTM
Technical ID: win.rtm
MALWARE
RTM Banker also known as Redaman was first blogged about in February 2017 by ESET. The malware is written in Delphi and shows some similarities (like process list) with Buhtrap. It uses a slightly modified version of RC4 to encrypt its strings, network data, configuration and modules, according to ESET.
Also known as: Redaman
Updated: 2022-04-04
View profile →
Rozena
Technical ID: win.rozena
MALWARE
Malware family identifying win.rozena. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-12
View profile →
Royal Ransom
Technical ID: win.royal_ransom
MALWAREfinancialhigh
Ransomware
Updated: 2026-01-12
View profile →
Royal DNS
Technical ID: win.royal_dns
Mirage
MALWAREespionageadvanced
RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
Updated: 2021-04-29
View profile →
RoyalCli
Technical ID: win.royalcli
Mirage
MALWARE
RoyalCli is a backdoor which appears to be an evolution of BS2005 and uses familiar encryption and encoding routines. The name RoyalCli was chosen by us due to a debugging path left in the binary. RoyalCli and BS2005 both communicate with the attacker's command and control (C2) through Internet Explorer (IE) by using the COM interface IWebBrowser2.
Updated: 2021-04-29
View profile →
Rovnix
Technical ID: win.rovnix
MALWARE
Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves. It is part of the Carberp source code leak (https://github.com/nyx0/Rovnix). Rovnix has been used to protect Gozi ISFB, ReactorBot and Rerdom (at least).
Also known as: Mayachok • Cidox • BkLoader
Updated: 2022-05-25
View profile →
Rover
Technical ID: win.rover
MALWARE
Malware family identifying win.rover. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-04
View profile →
RotorCrypt
Technical ID: win.rotorcrypt
MALWAREfinancialhigh
Ransomware that was discovered over the last months of 2016 and likely based on Gomasom, another ransomware family.
Also known as: Rotor • RotoCrypt
Updated: 2019-04-07
View profile →
Roshtyak
Technical ID: win.roshtyak
MALWARE
A DLL backdoor distributed by Raspberry Robin. According to Avast Decoded, Roshtyak belongs to one of the best-protected malware strains they have ever seen.
Updated: 2025-03-27
View profile →
Roseam
Technical ID: win.roseam
Wekby
MALWARE
Malware family identifying win.roseam. Origin and technical characteristics tracked via Malpedia.
Also known as: PisLoader
Updated: 2024-11-29
View profile →
Rorschach Ransomware
Technical ID: win.rorschach
MALWARE
Malware family identifying win.rorschach. Origin and technical characteristics tracked via Malpedia.
Also known as: BabLock
Updated: 2023-04-25
View profile →
← PreviousPage 139 / 269Next →