Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Pulsar RAT
Technical ID: win.pulsar_rat
MALWARE
According to Broadcom, Pulsar RAT is a derivation of Quasar RAT, which has miscellaneous functionality including keylogging, cryptocurrency wallet clipping, infostealing, file management, remote shell and command execution, among others. The data theft capabilities of this malware include collection and exfiltration of sensitive information such as credentials, cookies, cryptowallets, session files and data stored in the system web browsers, etc.
Updated: 2026-01-06
View profile →
PulsarTea
Technical ID: win.pulsartea
Lazarus Group
MALWARE
Malware family identifying win.pulsartea. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-28
View profile →
PubNubRAT
Technical ID: win.pubnubrat
MALWARE
Malware family identifying win.pubnubrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-30
View profile →
PUBLOAD
Technical ID: win.pubload
MALWARE
Malware family identifying win.pubload. Origin and technical characteristics tracked via Malpedia.
Also known as: ClaimLoader • PUBLOAD
Updated: 2025-09-23
View profile →
Pterois
Technical ID: win.pterois
Swan Vector
MALWARE
According to Seqrite, this is a loader for a follow-up side-loaded and in memory-staged Cobalt Strike Beacon. It uses API hashing (SDBM) and pulls the next stage from Google Drive using hardcoded access credentials.
Updated: 2025-11-13
View profile →
Pteranodon
Technical ID: win.pteranodon
Gamaredon GroupOperation Armageddon
MALWARE
Malware family identifying win.pteranodon. Origin and technical characteristics tracked via Malpedia.
Also known as: Pterodo
Updated: 2025-11-26
View profile →
PC Surveillance System
Technical ID: win.pss
MALWARE
Citizenlab notes that PC Surveillance System (PSS) is a commercial spyware product offered by Cyberbit and marketed to intelligence and law enforcement agencies.
Also known as: PSS
Updated: 2018-02-07
View profile →
PSLogger
Technical ID: win.pslogger
Lazarus Group
MALWARE
Malware family identifying win.pslogger. Origin and technical characteristics tracked via Malpedia.
Also known as: ECCENTRICBANDWAGON
Updated: 2022-11-21
View profile →
PsiX
Technical ID: win.psix
MALWAREfinancialhigh
According to Matthew Mesa, this is a modular bot. The name stems from the string PsiXMainModule in binaries until mid of September 2018. In binaries, apart from BotModule and MainModule, references to the following Modules have be observed: BrowserModule BTCModule ComplexModule KeyLoggerModule OutlookModule ProcessModule RansomwareModule SkypeModule
Also known as: PsiXBot
Updated: 2022-11-28
View profile →
PseudoManuscrypt
Technical ID: win.pseudo_manuscrypt
MALWARE
According to PCrisk, PseudoManuscrypt is the name of the malware that spies on victims. It is similar to another malware called Manuscrypt. We have discovered PseudoManuscrypt while checking installers for pirated software (one of the examples is a fake pirated installer for SolarWinds - a network monitoring software).
Updated: 2025-09-25
View profile →
Prynt Stealer
Technical ID: win.prynt_stealer
MALWARE
Malware family identifying win.prynt_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-07
View profile →
ProtonBot
Technical ID: win.protonbot
MALWARE
Malware family identifying win.protonbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-24
View profile →
Proto8RAT
Technical ID: win.proto8_rat
MALWARE
Malware family identifying win.proto8_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-26
View profile →
proteus
Technical ID: win.proteus
MALWARE
Malware family identifying win.proteus. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-31
View profile →
PromptLock
Technical ID: win.prompt_lock
MALWAREfinancialhigh
According to ESET Research, PromptLock is first known AI-powered ransomware. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.
Updated: 2026-02-03
View profile →
Prometheus
Technical ID: win.prometheus
MALWAREfinancialhigh
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Updated: 2022-03-02
View profile →
Prometei
Technical ID: win.prometei
MALWARE
According to Lior Rochberger, Cybereason, prometei is a modular and multi-stage cryptocurrency botnet. It was discovered in July 2020, Cybereason Nocturnus team found evidence that this Prometei has been evolved since 2016. There are Linux and Windows versions of this malware.
Updated: 2024-10-24
View profile →
ProjectWood
Technical ID: win.project_wood
MALWARE
Malware family identifying win.project_wood. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-02
View profile →
Project Hook POS
Technical ID: win.project_hook
MALWARE
Malware family identifying win.project_hook. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-29
View profile →
PRIVATELOG
Technical ID: win.privatelog
MALWARE
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
Updated: 2022-05-09
View profile →
PrivateLoader
Technical ID: win.privateloader
MALWARE
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads. The loader implements anti-analysis techniques, fingerprints the compromised host and reports statistics to its C2 server.
Updated: 2025-01-07
View profile →
PrincessLocker
Technical ID: win.princess_locker
MALWARE
Malware family identifying win.princess_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-14
View profile →
Prilex
Technical ID: win.prilex
MALWARE
Malware family identifying win.prilex. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-16
View profile →
Prikormka
Technical ID: win.prikormka
Groundbait
MALWARE
Malware family identifying win.prikormka. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-01
View profile →
Prestige
Technical ID: win.prestige
MALWAREfinancialhigh
According to PCrisk, Prestige is ransomware - malware that prevents victims from accessing (opening) their files by encrypting them. Additionally, Prestige appends the ".enc" extension to filenames and drops the "README" file containing a ransom note. An example of how this ransomware modifies filenames: it renames "1.jpg" to "1.jpg.enc", "2.png" to "2.png.enc", and so forth.
Updated: 2023-05-25
View profile →
Predator The Thief
Technical ID: win.predator
MALWARE
Predator is a feature-rich information stealer. It is sold on hacking forums as a bundle which includes: Payload builder and Command and Control web panel. It is able to grab passwords from browsers, replace cryptocurrency wallets, and take photos from the web-camera. It is developed by using a modular approach so that criminals may add more sophisticated tools on top of the it.
Updated: 2021-04-12
View profile →
prb_backdoor
Technical ID: win.prb_backdoor
MALWARE
Malware family identifying win.prb_backdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
PowerRatankba
Technical ID: win.power_ratankba
Lazarus Group
MALWARE
QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor. Its payloads are often saved to C:\windows\temp\
Also known as: QUICKRIDE.POWER
Updated: 2020-03-11
View profile →
Powersniff
Technical ID: win.powersniff
MALWARE
A malware of the gozi group, developed on the base of isfb. It uses Office Macros and PowerShell in documents distributed in e-mail messages.
Also known as: PUNCHBUGGY
Updated: 2020-06-03
View profile →
PowerShellRunner
Technical ID: win.powershellrunner
Turla
MALWARE
Malware family identifying win.powershellrunner. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-05-30
View profile →
PowerPool
Technical ID: win.powerpool
MALWARE
Malware family identifying win.powerpool. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-07
View profile →
PowerLoader
Technical ID: win.powerloader
MALWARE
Malware family identifying win.powerloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
powerkatz
Technical ID: win.powerkatz
MALWARE
Malware family identifying win.powerkatz. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-04-03
View profile →
PowerDuke
Technical ID: win.powerduke
APT 29
MALWARE
Malware family identifying win.powerduke. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-28
View profile →
PowerCat
Technical ID: win.powercat
MALWARE
Malware family identifying win.powercat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-16
View profile →
POWERBAND
Technical ID: win.powerband
APT33
MALWARE
.NET variant of ps1.powerton.
Updated: 2020-02-14
View profile →
Poweliks
Technical ID: win.poweliks
MALWARE
Malware family identifying win.poweliks. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-23
View profile →
Povlsomware
Technical ID: win.povlsomware
MALWAREfinancialhigh
According to Trend Micro, Povlsomware (Ransom.MSIL.POVLSOM.THBAOBA) is a proof-of-concept (POC) ransomware first released in November 2020 which, according to their Github page, is used to “securely” test the ransomware protection capabilities of security vendor products.
Updated: 2021-11-27
View profile →
Poulight Stealer
Technical ID: win.poulight_stealer
MALWARE
Malware family identifying win.poulight_stealer. Origin and technical characteristics tracked via Malpedia.
Also known as: Poullight
Updated: 2021-04-21
View profile →
PostNapTea
Technical ID: win.postnaptea
Lazarus Group
MALWAREespionageadvanced
PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project. In 2022-2023, it was deployed against targets like a newspaper organization, agriculture-related entity or a software vendor. The initial access was usually achieved by exploiting vulnerabilities in widely-used software in South Korea. It collects various information about the victim’s computer, such as computer name, product name, OS details, system uptime, CPU information, system locale, time zone, network status, and malware configuration. PostNapTea uses AES for encryption and decryption ot network traffic. There is a constant prefix SIGNBT occuring in its HTTP POST requests. The prefix is concatenated with 2 characters that identify the communication stage: • LG: logging into the C&C server • KE: acknowledging the succesful login to the C&C • FI: sending the status of a failed operation • SR: sending the status of a successful operation • GC: getting the next command There are five classes that represent command groups: • CCButton: for file manipulation and screen capturing • CCBitmap: for network commands, implementing functionality of Windows commands often abused by attackers, like sc, reg, arp, net, ver, wmic, ping, whoami, netstat, tracert, lookup, ipconfig, systeminfo, and netsh advfirewall. • CCComboBox: for file system management • CCList: for process management • CCBrush: for control of the malware itself It stores its configuration in JSON format. It resolves the Windows APIs it requires during runtime, via the Fowler–Noll–Vo (FNV) hash function. Its internal name in the version-information resource is usually ppcsnap.dll or pconsnap.dll, which loosely inspired its code name.
Also known as: SIGNBT
Updated: 2025-10-31
View profile →
← PreviousPage 144 / 269Next →