Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Pulsar RAT
Technical ID: win.pulsar_rat
MALWARE
According to Broadcom, Pulsar RAT is a derivation of Quasar RAT, which has miscellaneous functionality including keylogging, cryptocurrency wallet clipping, infostealing, file management, remote shell and command execution, among others. The data theft capabilities of this malware include collection and exfiltration of sensitive information such as credentials, cookies, cryptowallets, session files and data stored in the system web browsers, etc.
MALWARE
Malware family identifying win.pulsartea. Origin and technical characteristics tracked via Malpedia.
PubNubRAT
Technical ID: win.pubnubrat
MALWARE
Malware family identifying win.pubnubrat. Origin and technical characteristics tracked via Malpedia.
PUBLOAD
Technical ID: win.pubload
MALWARE
Malware family identifying win.pubload. Origin and technical characteristics tracked via Malpedia.
Also known as: ClaimLoader • PUBLOAD
MALWARE
According to Seqrite, this is a loader for a follow-up side-loaded and in memory-staged Cobalt Strike Beacon. It uses API hashing (SDBM) and pulls the next stage from Google Drive using hardcoded access credentials.
MALWARE
Malware family identifying win.pteranodon. Origin and technical characteristics tracked via Malpedia.
Also known as: Pterodo
PC Surveillance System
Technical ID: win.pss
MALWARE
Citizenlab notes that PC Surveillance System (PSS) is a commercial spyware product offered by Cyberbit and marketed to intelligence and law enforcement agencies.
Also known as: PSS
MALWARE
Malware family identifying win.pslogger. Origin and technical characteristics tracked via Malpedia.
Also known as: ECCENTRICBANDWAGON
PsiX
Technical ID: win.psix
MALWAREfinancialhigh
According to Matthew Mesa, this is a modular bot. The name stems from the string PsiXMainModule in binaries until mid of September 2018.
In binaries, apart from BotModule and MainModule, references to the following Modules have be observed:
BrowserModule
BTCModule
ComplexModule
KeyLoggerModule
OutlookModule
ProcessModule
RansomwareModule
SkypeModule
Also known as: PsiXBot
PseudoManuscrypt
Technical ID: win.pseudo_manuscrypt
MALWARE
According to PCrisk, PseudoManuscrypt is the name of the malware that spies on victims. It is similar to another malware called Manuscrypt. We have discovered PseudoManuscrypt while checking installers for pirated software (one of the examples is a fake pirated installer for SolarWinds - a network monitoring software).
Prynt Stealer
Technical ID: win.prynt_stealer
MALWARE
Malware family identifying win.prynt_stealer. Origin and technical characteristics tracked via Malpedia.
ProtonBot
Technical ID: win.protonbot
MALWARE
Malware family identifying win.protonbot. Origin and technical characteristics tracked via Malpedia.
Proto8RAT
Technical ID: win.proto8_rat
MALWARE
Malware family identifying win.proto8_rat. Origin and technical characteristics tracked via Malpedia.
proteus
Technical ID: win.proteus
MALWARE
Malware family identifying win.proteus. Origin and technical characteristics tracked via Malpedia.
PromptLock
Technical ID: win.prompt_lock
MALWAREfinancialhigh
According to ESET Research, PromptLock is first known AI-powered ransomware. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.
Prometheus
Technical ID: win.prometheus
MALWAREfinancialhigh
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Prometei
Technical ID: win.prometei
MALWARE
According to Lior Rochberger, Cybereason, prometei is a modular and multi-stage cryptocurrency botnet. It was discovered in July 2020, Cybereason Nocturnus team found evidence that this Prometei has been evolved since 2016. There are Linux and Windows versions of this malware.
ProjectWood
Technical ID: win.project_wood
MALWARE
Malware family identifying win.project_wood. Origin and technical characteristics tracked via Malpedia.
Project Hook POS
Technical ID: win.project_hook
MALWARE
Malware family identifying win.project_hook. Origin and technical characteristics tracked via Malpedia.
PRIVATELOG
Technical ID: win.privatelog
MALWARE
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
PrivateLoader
Technical ID: win.privateloader
MALWARE
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads. The loader implements anti-analysis techniques, fingerprints the compromised host and reports statistics to its C2 server.
PrincessLocker
Technical ID: win.princess_locker
MALWARE
Malware family identifying win.princess_locker. Origin and technical characteristics tracked via Malpedia.
Prilex
Technical ID: win.prilex
MALWARE
Malware family identifying win.prilex. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.prikormka. Origin and technical characteristics tracked via Malpedia.
Prestige
Technical ID: win.prestige
MALWAREfinancialhigh
According to PCrisk, Prestige is ransomware - malware that prevents victims from accessing (opening) their files by encrypting them. Additionally, Prestige appends the ".enc" extension to filenames and drops the "README" file containing a ransom note. An example of how this ransomware modifies filenames: it renames "1.jpg" to "1.jpg.enc", "2.png" to "2.png.enc", and so forth.
Predator The Thief
Technical ID: win.predator
MALWARE
Predator is a feature-rich information stealer. It is sold on hacking forums as a bundle which includes: Payload builder and Command and Control web panel. It is able to grab passwords from browsers, replace cryptocurrency wallets, and take photos from the web-camera. It is developed by using a modular approach so that criminals may add more sophisticated tools on top of the it.
prb_backdoor
Technical ID: win.prb_backdoor
MALWARE
Malware family identifying win.prb_backdoor. Origin and technical characteristics tracked via Malpedia.
MALWARE
QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor. Its payloads are often saved to C:\windows\temp\
Also known as: QUICKRIDE.POWER
Powersniff
Technical ID: win.powersniff
MALWARE
A malware of the gozi group, developed on the base of isfb. It uses Office Macros and PowerShell in documents distributed in e-mail messages.
Also known as: PUNCHBUGGY
MALWARE
Malware family identifying win.powershellrunner. Origin and technical characteristics tracked via Malpedia.
PowerPool
Technical ID: win.powerpool
MALWARE
Malware family identifying win.powerpool. Origin and technical characteristics tracked via Malpedia.
PowerLoader
Technical ID: win.powerloader
MALWARE
Malware family identifying win.powerloader. Origin and technical characteristics tracked via Malpedia.
powerkatz
Technical ID: win.powerkatz
MALWARE
Malware family identifying win.powerkatz. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.powerduke. Origin and technical characteristics tracked via Malpedia.
PowerCat
Technical ID: win.powercat
MALWARE
Malware family identifying win.powercat. Origin and technical characteristics tracked via Malpedia.
MALWARE
.NET variant of ps1.powerton.
Poweliks
Technical ID: win.poweliks
MALWARE
Malware family identifying win.poweliks. Origin and technical characteristics tracked via Malpedia.
Povlsomware
Technical ID: win.povlsomware
MALWAREfinancialhigh
According to Trend Micro, Povlsomware (Ransom.MSIL.POVLSOM.THBAOBA) is a proof-of-concept (POC) ransomware first released in November 2020 which, according to their Github page, is used to “securely” test the ransomware protection capabilities of security vendor products.
Poulight Stealer
Technical ID: win.poulight_stealer
MALWARE
Malware family identifying win.poulight_stealer. Origin and technical characteristics tracked via Malpedia.
Also known as: Poullight
MALWAREespionageadvanced
PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project.
In 2022-2023, it was deployed against targets like a newspaper organization, agriculture-related entity or a software vendor. The initial access was usually achieved by exploiting vulnerabilities in widely-used software in South Korea.
It collects various information about the victim’s computer, such as computer name, product name, OS details, system uptime, CPU information, system locale, time zone, network status, and malware configuration.
PostNapTea uses AES for encryption and decryption ot network traffic. There is a constant prefix SIGNBT occuring in its HTTP POST requests. The prefix is concatenated with 2 characters that identify the communication stage:
• LG: logging into the C&C server
• KE: acknowledging the succesful login to the C&C
• FI: sending the status of a failed operation
• SR: sending the status of a successful operation
• GC: getting the next command
There are five classes that represent command groups:
• CCButton: for file manipulation and screen capturing
• CCBitmap: for network commands, implementing functionality of Windows commands often abused by attackers, like sc, reg, arp, net, ver, wmic, ping, whoami, netstat, tracert, lookup, ipconfig,
systeminfo, and netsh advfirewall.
• CCComboBox: for file system management
• CCList: for process management
• CCBrush: for control of the malware itself
It stores its configuration in JSON format. It resolves the Windows APIs it requires during runtime, via the Fowler–Noll–Vo (FNV) hash function.
Its internal name in the version-information resource is usually ppcsnap.dll or pconsnap.dll, which loosely inspired its code name.
Also known as: SIGNBT