Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Raccoon
Technical ID: win.raccoon
MALWARE
Raccoon Stealer is a malware reportedly sold for $75 a week or $200 a month. It gathers personal information including passwords, browser cookies and autofill data, as well as cryptowallet details. Additionally, Raccoon Stealer records system information such as IP addresses and geo-location data.
Also known as: Mohazo • RaccoonStealer • Racealer • Racoon
Updated: 2025-05-19
View profile →
r980
Technical ID: win.r980
MALWARE
Malware family identifying win.r980. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
r77
Technical ID: win.r77
MALWARE
According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys & values * Services * TCP & UDP connections * Junctions, named pipes, scheduled tasks
Also known as: r77 Rootkit
Updated: 2025-03-21
View profile →
QvoidStealer
Technical ID: win.qvoidstealer
MALWARE
Malware family identifying win.qvoidstealer. Origin and technical characteristics tracked via Malpedia.
Also known as: Qvoid-Token-Grabber
Updated: 2022-07-13
View profile →
Qulab
Technical ID: win.qulab
MALWARE
Qulab is an AutoIT Malware focusing on stealing & clipping content from victim's machines.
Updated: 2019-03-27
View profile →
QuiteRAT
Technical ID: win.quiterat
Silent Chollima
MALWARE
QuiteRAT is a simple remote access trojan written with the help of Qt libraries. After sending preliminary system information to its C&C server, it expects a response containing either a supported command code or an actual Windows command (like systeminfo or ipconfig with parameters) to execute. It was deployed in a campaign exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966).
Also known as: Acres
Updated: 2023-08-28
View profile →
QuirkyLoader
Technical ID: win.quirkyloader
MALWARE
According to X-Force, this is a loader module written in .NET languages for which ahead-of-time (AOT) compilation is used.
Updated: 2025-08-22
View profile →
QuietSieve
Technical ID: win.quietsieve
Gamaredon Group
MALWARE
According to Microsoft, this is a heavily obfuscated .NET malware, primarily geared towards the exfiltration of data from the compromised host. But it can also receive and execute a remote payload from the operator.
Updated: 2025-06-20
View profile →
QUIETCANARY
Technical ID: win.quietcanary
Turla
MALWARE
Malware family identifying win.quietcanary. Origin and technical characteristics tracked via Malpedia.
Also known as: Kapushka • Tunnus
Updated: 2023-12-04
View profile →
QUICKMUTE
Technical ID: win.quickmute
Tonto Team
MALWARE
QuickMute is a malware developed using the C/C++ programming language. Functionally provides download, RC4 decryption, and in-memory launch of the payload (waiting for a PE file with the export function "HttpsVictimMain"). To communicate with the management server, a number of protocols are provided, in particular: TCP, UDP, HTTP, HTTPS.
Updated: 2022-07-13
View profile →
QuickHeal
Technical ID: win.quickheal
MALWARE
Malware family identifying win.quickheal. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-16
View profile →
Quasar RAT
Technical ID: win.quasar_rat
APT33Dropping ElephantStone PandaThe Gorgon Group
MALWARE
Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.
Also known as: CinaRAT • QuasarRAT • Yggdrasil
Updated: 2026-01-21
View profile →
QUARTERRIG
Technical ID: win.quarterrig
APT29
MALWAREespionageadvanced
A stager used by APT29 to download and run CobaltStrike. Here, MUSKYBEAT refers to the in-memory dropper component, while STATICNOISE is the final payload / downloader.
Also known as: MUSKYBEAT • STATICNOISE
Updated: 2023-10-18
View profile →
QuanPinLoader
Technical ID: win.quan_pin_loader
Lazarus Group
MALWARE
According to ESET Research, this is a loader that has the Mandarin Chinese symbol (yang in the Pinyin transliteration) as an icon in the resources. It also contains the string SampleIMESimplifiedQuanPin.txt, which suggests that it is probably based on the open-source project Sample IME, a TSF-based input method editor demo.
Updated: 2025-11-21
View profile →
QuantLoader
Technical ID: win.quantloader
Guru Spider
MALWARE
Malware family identifying win.quantloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
QtBot
Technical ID: win.qtbot
MALWARE
Malware family identifying win.qtbot. Origin and technical characteristics tracked via Malpedia.
Also known as: qtproject
Updated: 2017-11-07
View profile →
QHost
Technical ID: win.qhost
MALWARE
According to F-Secure, this is a network worm with backdoor capabilities, which spreads itself under Win32 systems. The worm was reported in-the-wild in July-August, 2000. The worm itself is a Win32 executable file and about 120K long, written in MS Visual C++.
Also known as: Tolouge
Updated: 2024-09-11
View profile →
QakBot
Technical ID: win.qakbot
GOLD CABIN
MALWAREfinancialhigh
QBot is a modular information stealer also known as Qakbot or Pinkslipbot. It has been active for years since 2007. It has historically been known as a banking Trojan, meaning that it steals financial data from infected systems, and a loader using C2 servers for payload targeting and download.
Also known as: Oakboat • Pinkslipbot • Qbot • Quakbot
Updated: 2025-03-10
View profile →
Qadars
Technical ID: win.qadars
MALWARE
Malware family identifying win.qadars. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-05
View profile →
Qaccel
Technical ID: win.qaccel
MALWARE
Malware family identifying win.qaccel. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
PyXie
Technical ID: win.pyxie
MALWARE
Full-featured Python RAT compiled into an executable. PyXie RAT functionality includes: * Man-in-the-middle (MITM) Interception * Web-injects * Keylogging * Credential harvesting * Network Scanning * Cookie theft * Clearing logs * Recording video * Running arbitrary payloads * Monitoring USB drives and exfiltrating data * WebDav server * Socks5 proxy * Virtual Network Connection (VNC) * Certificate theft * Inventorying software * Enumerating the domain with Sharphound
Also known as: PyXie RAT
Updated: 2022-05-25
View profile →
PyLocky
Technical ID: win.pylocky
MALWAREfinancialhigh
PyLocky is a ransomware that tries to pass off as Locky in its ransom note. It is written in Python and packaged with PyInstaller.
Also known as: Locky Locker
Updated: 2020-12-23
View profile →
Pykspa
Technical ID: win.pykspa
MALWARE
According to Akamai, Pykspa is a worm that spreads via Skype by sending messages to other Skype users with download links. Once downloaded, Pykspa extracts personal information and communicates with its command and control servers (C2) using a domain generation algorithm (DGA).
Updated: 2025-09-12
View profile →
Py2exe built worm propagating via USB drives, having wiper features embedded in the logic (based on today's date being later than 2016-04-03 and existence of a file C:\txt.txt)
pwnpos
Technical ID: win.pwnpos
MALWARE
Malware family identifying win.pwnpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-05
View profile →
PwndLocker
Technical ID: win.pwndlocker
MALWAREfinancialhigh
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.
Also known as: ProLock
Updated: 2022-01-25
View profile →
PvzOut
Technical ID: win.pvzout
Cleaver
MALWARE
Malware family identifying win.pvzout. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
puzzlemaker
Technical ID: win.puzzlemaker
[Unnamed group]
MALWARE
The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS. One of these files (%SYSTEM%\WmiPrvMon.exe) is registered as a service and is used as a launcher for the second executable. This second executable (%SYSTEM%\wmimon.dll) has the functionality of a remote shell and can be considered the main payload of the attack.
Updated: 2021-07-20
View profile →
Putabmow
Technical ID: win.putabmow
MALWARE
Malware family identifying win.putabmow. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
Pushdo
Technical ID: win.pushdo
MALWARE
Pushdo is usually classified as a "downloader" trojan - meaning its true purpose is to download and install additional malicious software. There are dozens of downloader trojan families out there, but Pushdo is actually more sophisticated than most, but that sophistication lies in the Pushdo control server rather than the trojan.
Updated: 2021-02-25
View profile →
PurpleWave
Technical ID: win.purplewave
MALWARE
ZScaler reported on a new Infostealer called PurpleWave, which is written in C++ and silently installs itself onto a user’s system. It connects to a command and control (C&C) server to send system information and installs new malware onto the infected system. The author of this malware is advertising and selling PurpleWave stealer on Russian cybercrime forums for 5,000 RUB (US$68) with lifetime updates and 4,000 RUB (US$54) with only two updates.
Updated: 2022-11-15
View profile →
purpleink
Technical ID: win.purpleink
MALWARE
Malware family identifying win.purpleink. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-09
View profile →
PurpleFox
Technical ID: win.purplefox
MALWARE
Purple Fox uses msi.dll function, 'MsiInstallProductA', to download and execute its payload. The payload is a .msi file that contains encrypted shellcode including 32-bit and 64-bit versions. once executed the system will be restarted and uses the 'PendingFileRenameOperations' registry to rename it's components. Upon restart the rootkit capability of Purple Fox is invoked. It creates a suspended svchost process and injects a DLL that will create a driver with the rootkit capability. The latest version of Purple Fox abuses open-source code to enable it's rootkit components, which includes hiding and protecting its files and registry entries. It also abuses a file utility software to hide its DLL component, which deters reverse engineering.
Updated: 2024-02-02
View profile →
PureRAT
Technical ID: win.pure_rat
MALWARE
According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion techniques. They have named it ‘Resolver’ due to its heavy reliance on runtime resolution mechanisms and dynamic resource handling, which make static and behavioral analysis significantly more difficult.
Also known as: PureHVNC • ResolverRAT
Updated: 2025-11-13
View profile →
PureLogs Stealer
Technical ID: win.purelogs
MALWARE
PureLogs, also known as PureLog Stealer, is an infostealer malware from the Pure family that aims to steal sensitive information from infected devices.
Updated: 2026-01-27
View profile →
PureLocker
Technical ID: win.purelocker
MALWAREfinancialhigh
ransomware
Updated: 2019-11-20
View profile →
PureCrypter
Technical ID: win.purecrypter
MALWARE
According to zscaler, PureCrypter is a fully-featured loader being sold since at least March 2021 The malware has been observed distributing a variety of remote access trojans and information stealers The loader is a .NET executable obfuscated with SmartAssembly and makes use of compression, encryption and obfuscation to evade antivirus software products PureCrypter features provide persistence, injection and defense mechanisms that are configurable in Google’s Protocol Buffer message format
Updated: 2025-08-29
View profile →
pupy
Technical ID: win.pupy
APT33APT35OilRigRocket Kitten
MALWARE
Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python. Pupy can be loaded from various loaders, including PE EXE, reflective DLL, Linux ELF, pure python, powershell and APK. Most of the loaders bundle an embedded python runtime, python library modules in source/compiled/native forms as well as a flexible configuration. They bootstrap a python runtime environment mostly in-memory for the later stages of pupy to run in. Pupy can communicate using various transports, migrate into processes, load remote python code, python packages and python C-extensions from memory.
Also known as: Patpoopy
Updated: 2024-09-27
View profile →
Punkey POS
Technical ID: win.punkey_pos
MALWARE
Malware family identifying win.punkey_pos. Origin and technical characteristics tracked via Malpedia.
Also known as: poscardstealer • pospunk • punkeypos
Updated: 2023-02-21
View profile →
PULSEPACK
Technical ID: win.pulsepack
MALWARE
Malware family identifying win.pulsepack. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-03
View profile →
← PreviousPage 143 / 269Next →