Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUPespionageadvanced
Tropidoor is an advanced HTTP/S Remote Access Trojan (RAT) written as a C project, which exhibits significant code overlap with the PostNapTea RAT. In November 2024, it was deployed in campaigns targeting developers via fake recruiters as part of a social engineering campaign distributing trojanized open-source projects on platforms like Bitbucket. It is a final-stage payload in a multi-stage execution chain, which also deployed an obfuscated BeaverTail malware.
The RAT uses RSA and AES for encryption and decryption of network traffic. Communication with the C2 uses specific HTTP POST parameters, including tropi2p, gumi, s_width, and letter, with the first parameter loosely inspiring its code name. It stores its configuration in a binary format and resolves required Windows APIs during runtime via the Fowler–Noll–Vo (FNV) hash function. Many of its characteristic strings are XOR encrypted.
A key technical feature is its custom implementation of various Windows administrative and reconnaissance commands. By implementing this functionality internally, the RAT avoids executing the legitimate Windows binaries, making its command execution activities harder to detect by behavioral monitoring tools. Custom implemented commands include functionality equivalent to standard utilities like:
arp
dir
ipconfig
kill
net
netsh
netstat
nslookup
ping
reg
rm
sc
schtasks
systeminfo
tracert
wmic logicaldisk
wmic process
APT GROUP
Malware family tracked by Malpedia. ID: win.troll_stealer
APT GROUPfinancialhigh
According to Malwarebyte, Ransomware is a type of malware that prevents users from accessing their system or personal files and demands ransom payment in order to regain access. Ransom.Troldesh is spread by malspam, typically in the form of attached .zip files. This ransomware sometimes uses a CMS on a compromised site to host downloads.
APT GROUP
Trochilus is a C++ written RAT, which is available on GitHub.
GitHub Repo:
- https://github.com/m0n0ph1/malware-1/tree/master/Trochilus
- https://github.com/5loyd/trochilus
APT GROUP
Malware attacking commonly used in Industrial Control Systems (ICS) Triconex Safety Instrumented System (SIS) controllers.
APT GROUPfinancialhigh
A financial Trojan believed to be a derivative of Dyre: the bot uses very similar code, web injects, and operational tactics. Has multiple modules including VNC and Socks5 Proxy. Uses SSL for C2 communication.
- Q4 2016 - Detected in wild
Oct 2016 - 1st Report
2017 - Trickbot primarily uses Necurs as vehicle for installs.
Jan 2018 - Use XMRIG (Monero) miner
Feb 2018 - Theft Bitcoin
Mar 2018 - Unfinished ransomware module
Q3/4 2018 - Trickbot starts being spread through Emotet.
Infection Vector
1. Phish > Link MS Office > Macro Enabled > Downloader > Trickbot
2. Phish > Attached MS Office > Macro Enabled > Downloader > Trickbot
3. Phish > Attached MS Office > Macro enabled > Trickbot installed
APT GROUP
Malware family tracked by Malpedia. ID: win.treasurehunter
APT GROUP
tRat is a modular RAT written in Delphi and has appeared in campaigns in September and October of 2018.
APT GROUP
Malware family tracked by Malpedia. ID: win.transferloader
APT GROUP
According to Trend Micro, this is a backdoor abusing the Dropbox API, used by threat actor Earth Yako.
APT GROUPfinancialhigh
ToxicEye is a ransomware that spreads through phishing emails. The malware encrypts system files with AES-256 and demands a ransom in Bitcoin.
APT GROUP
According to Google Threat Intelligence Group, this malware uses Google Calendar events for command and control (C2).
APT GROUP
Malware family tracked by Malpedia. ID: win.touchshift
APT GROUP
Malware family tracked by Malpedia. ID: win.touchmove
APT GROUP
Downloader, delivered via a lure with fake exploits published on Github.
APT GROUP
Torisma is a complex HTTP(S) downloader, that can serve as an orchestrator handling the execution of additional payloads from the C&C server.
It uses VEST-32 for encryption and decryption of network traffic between the client and the server.
Typically, it uses these parameter names for its HTTP POST requests: ACTION, CODE, CACHE, REQUEST, RES. It sends the victim's MAC address in the initial request.
The response of the server informing the client about a successful authentication is "Your request has been accepted. ClientID: {f9102bc8a7d81ef01ba}". The client then requests additional data from the server, that decrypts to shellcode and its data parameters, and is executed. The client also creates a named pipe, \\.\pipe\fb4d1181bb09b484d058768598b, that allows inter-process communication with the executed shellcode.
Torisma was usually downloaded by NedDnLoader, and deployed in the Operation DreamJob campaigns starting around Q4 2019.
APT GROUP
Malware family tracked by Malpedia. ID: win.topinambour
APT GROUP
Malware family tracked by Malpedia. ID: win.tonnerre
APT GROUP
Malware family tracked by Malpedia. ID: win.toneshell
APT GROUP
According to Symantec, Grager was deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of the backdoor revealed that it used the Graph API to communicate with a C&C server hosted on Microsoft OneDrive. Grager was downloaded from a typosquatted URL mimicking the open-source file archiver 7-Zip.
APT GROUP
TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS. Supported commands include system information collection, file upload, file download, and arbitrary shell command execution. When executed, this variant of TONEDEAF wrote encrypted data to two temporary files – temp.txt and temp2.txt – within the same directory of its execution.
APT GROUP
Malware family tracked by Malpedia. ID: win.tomiris
APT GROUP
Malware family tracked by Malpedia. ID: win.tollbooth
APT GROUP
Malware family tracked by Malpedia. ID: win.tokyox
APT GROUP
According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining cryptocurrency, sending emails, stealing various account credentials, updating itself, and more.
Cyber criminals mainly use this program as an email-oriented tool (they target users' email accounts), however, having Tofsee installed can also lead to many other problems.
APT GROUP
Malware family tracked by Malpedia. ID: win.tmanger
APT GROUP
The stealer is written in Go and capable of stealing a variety of information from infected Windows machines, including credential data from browsers and crypto wallets, FTP client details, screenshots, system information, and grabbed files.
APT GROUP
Malware family tracked by Malpedia. ID: win.tiop
APT GROUP
Talos describes this as a malware family with very scoped functionality and thus a small code footprint, likely used as a second chance backdoor.
APT GROUP
Malware family tracked by Malpedia. ID: win.tinyzbot
APT GROUP
Malware family tracked by Malpedia. ID: win.tinytyphon
APT GROUP
Cisco Talos states that TinyTurla-NG is a small “last chance” backdoor that is left behind to be used when all other unauthorized access/backdoor mechanisms have failed or been detected on the infected systems. TinyTurla-NG was seen as early as December 2023 targeting a Polish non-governmental organization (NGO) working on improving Polish democracy and supporting Ukraine during the Russian invasion.
APT GROUPfinancialhigh
TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server. It was for sale on underground marketplaces for $2500 in 2016. The program's author claimed the malware was written from scratch, but that it functioned similarly to the ZeuS banking trojan in that it could steal passwords and inject arbitrary content when victims visited banking Web sites. However, he then proceeded to destroy his own reputation on hacker forums by promoting his development too aggressively. As a displacement activity, he published his source code on Github. XBot is an off-spring of TinyNuke, but very similar to its ancestor.
APT GROUP
Malware family tracked by Malpedia. ID: win.tinyloader
APT GROUP
TinyFluff is a dropper developed by the OldGremlin group. In one of their March '22 campaigns, TinyFluff included a JavaScript RAT with a time-independent DGA.
APT GROUPfinancialhigh
F-Secure notes that TinyBanker or short Tinba is usually distributed through malvertising (advertising content that leads the user to sites hosting malicious threats), exploit kits and spam email campaigns. According to news reports, Tinba has been found targeting bank customers in the United States and Europe.
If Tinba successfully infects a device, it can steal banking and personal information through webinjects. To do this, the malware monitors the user's browser activity and if specific banking portals are visited, Tinba injects code to present the victim with fake web forms designed to mimic the legitimate web site. The malware then tricks them into entering their personal information, log-in credentials, etc in the legitimate-looking page.
Tinba may also display socially-engineered messages to lure or pressure the user into entering their information on the fake page; for example, a message may be shown which attempts to convince the victim that funds were accidentally deposited to his account and must be refunded immediately.
APT GROUP
Malware family tracked by Malpedia. ID: win.timbre_stealer
APT GROUP
Standalone implant. Potentially tied to a framework called PATROLWAGON.
APT GROUPfinancialhigh
This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware". The third stage payload was created via the second stage payload, is interactively executed in the operation and exists in both x64 and x86 versions. Most of them use Internet Explorer or Google Chrome icons and corresponding file names to disguise themselves as legitimate internet browsers. The malware decrypts the embedded payload at runtime. It uses an embedded 16-byte XOR key to decrypt the base64 encoded payload. The decrypted payload is another portable executable file that runs in memory. Before getting decrypted with a hardcoded XOR key, the backdoor also checks for sandbox environment.
The backdoor has some code overlap with a know malware family PEBBLEDASH, attributed to Lazarus/LABYRINTH CHOLLIMA.