Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
PoSlurp
Technical ID: win.poslurp
FIN8
MALWARE
Malware family identifying win.poslurp. Origin and technical characteristics tracked via Malpedia.
Also known as: PUNCHTRACK
Updated: 2021-03-24
View profile →
PoshC2
Technical ID: win.poshc2
APT33
MALWARE
PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python3 implants with payloads written in PowerShell v2 and v4, C++ and C# source code, a variety of executables, DLLs and raw shellcode in addition to a Python3 payload. These enable C2 functionality on a wide range of devices and operating systems, including Windows, *nix and OSX.
Updated: 2024-11-25
View profile →
poscardstealer
Technical ID: win.poscardstealer
MALWARE
Malware family identifying win.poscardstealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-11
View profile →
PortStarter
Technical ID: win.portstarter
Vanilla Tempest
MALWARE
Malware family identifying win.portstarter. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-09
View profile →
portless
Technical ID: win.portless
MALWARE
Malware family identifying win.portless. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-19
View profile →
PortDoor
Technical ID: win.portdoor
MALWARE
Malware family identifying win.portdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-06
View profile →
Popcorn Time
Technical ID: win.popcorn_time
MALWARE
Malware family identifying win.popcorn_time. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
PoorWeb
Technical ID: win.poorweb
APT37
MALWARE
Malware family identifying win.poorweb. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-07
View profile →
POORTRY
Technical ID: win.poortry
MALWARE
According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode signature. This malware has been observed being used by UNC3944.
Updated: 2025-07-07
View profile →
PoohMilk Loader
Technical ID: win.poohmilk
APT37
MALWARE
Malware family identifying win.poohmilk. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-16
View profile →
Pony
Technical ID: win.pony
Cobalt
MALWARE
According to KnowBe4, Pony Stealer is a password stealer that can decrypt or unlock passwords for over 110 different applications including VPN, FTP, email, instant messaging, web browsers and much more. Pony Stealer is very dangerous and once it infects a PC it will turn the device into a botnet, allowing it to use the PCs it infects to infect other PCs.
Also known as: Siplog • Fareit
Updated: 2024-06-05
View profile →
PolyVice
Technical ID: win.polyvice
MALWARE
Malware family identifying win.polyvice. Origin and technical characteristics tracked via Malpedia.
Also known as: Chily
Updated: 2024-02-08
View profile →
Polyglot
Technical ID: win.polyglot_ransom
MALWARE
Malware family identifying win.polyglot_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
PolyglotDuke
Technical ID: win.polyglotduke
APT29
MALWARE
Malware family identifying win.polyglotduke. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
PolPo
Technical ID: win.polpo
EMISSARY PANDA
MALWARE
Malware family identifying win.polpo. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-15
View profile →
Poldat
Technical ID: win.poldat
Samurai PandaStone Panda
MALWARE
Malware family identifying win.poldat. Origin and technical characteristics tracked via Malpedia.
Also known as: Zlib • KABOB
Updated: 2020-01-15
View profile →
Poison RAT
Technical ID: win.poison_rat
MALWARE
Malware family identifying win.poison_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-12
View profile →
Poison Ivy
Technical ID: win.poison_ivy
GALLIUMMoleratsMustang PandaNightshade Panda+4 more
MALWARE
Malware family identifying win.poison_ivy. Origin and technical characteristics tracked via Malpedia.
Also known as: SPIVY • pivy • poisonivy
Updated: 2025-05-21
View profile →
POISONPLUG
Technical ID: win.poisonplug
APT41
MALWARE
According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities. The malware is capable of registry or service persistence, self-removal, plug-in execution, and network connection forwarding. POISONPLUG has been observed using social platforms to host encoded C&C commands.
Also known as: Barlaiy
Updated: 2025-01-30
View profile →
Poco RAT
Technical ID: win.poco_rat
MALWARE
Malware family identifying win.poco_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-12-08
View profile →
PocoDown
Technical ID: win.pocodown
APT28
MALWARE
uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure overlap with X-Agent, probably in use since mid-2018
Also known as: Blitz • PocoDownloader
Updated: 2020-03-25
View profile →
PNGLoad
Technical ID: win.png_load
MALWARE
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or PowHeartBeat. PNGLoad has capabilities to download and execute additional payloads from a C&C server, which is likely how the attackers have deployed PNGLoad on systems compromised with PowHeartBeat. PNGLoad is a loader that uses bytes from PNG files to create a payload to execute. It is a 64-bit .NET executable - obfuscated with .NET Reactor - that masquerades as legitimate software.
Updated: 2022-09-10
View profile →
pngdowner
Technical ID: win.pngdowner
APT2Putter Panda
MALWARE
Malware family identifying win.pngdowner. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-01
View profile →
Plurox
Technical ID: win.plurox
MALWARE
Malware family identifying win.plurox. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-09-25
View profile →
PlugX
Technical ID: win.plugx
APT 22APT 26APT31APT41+16 more
MALWAREespionageadvanced
RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully. Once the device is infected, an attacker can remotely execute several kinds of commands on the affected system. Notable features of this malware family are the ability to execute commands on the affected machine to retrieve: machine information capture the screen send keyboard and mouse events keylogging reboot the system manage processes (create, kill and enumerate) manage services (create, start, stop, etc.); and manage Windows registry entries, open a shell, etc. The malware also logs its events in a text log file.
Also known as: Destroy RAT • Kaba • Korplug • Sogu • TIGERPLUG
Updated: 2026-01-28
View profile →
ployx
Technical ID: win.ployx
MALWARE
Malware family identifying win.ployx. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-19
View profile →
Ploutus ATM
Technical ID: win.ploutus_atm
MALWARE
Malware family identifying win.ploutus_atm. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-16
View profile →
PLEAD
Technical ID: win.plead
BlackTech
MALWARE
PLEAD is a RAT used by the actor BlackTech. FireEye uses the synonyms GOODTIMES for the RAT module and DRAWDOWN for the respective downloader.
Also known as: DRAWDOWN • GOODTIMES • Linopid
Updated: 2021-03-02
View profile →
playwork
Technical ID: win.playwork
MALWARE
Malware family identifying win.playwork. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-13
View profile →
PLAY
Technical ID: win.play
MALWAREfinancialhigh
According to PCrisk, PLAY is the name of a ransomware-type program. Malware categorized as such operates by encrypting data and demanding ransoms for the decryption. After we executed a sample of this ransomware on our test machine, it encrypted files and appended their filenames with a ".PLAY" extension. For example, a file titled "1.jpg" appeared as "1.jpg.PLAY", "2.png" as "2.png.PLAY", etc. Once the encryption process was completed, PLAY created a text file named "ReadMe.txt" on the desktop.
Also known as: PlayCrypt
Updated: 2026-01-12
View profile →
PLAINTEE
Technical ID: win.plaintee
RANCOR
MALWARE
Malware family identifying win.plaintee. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
Pkybot
Technical ID: win.pkybot
MALWARE
Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref: fortinet). In the beginning of 2015, webinject capability was added according to /Kleissner/Kafeine/iSight using the infamous ATS.
Also known as: Pykbot • TBag • Bublik
Updated: 2018-02-15
View profile →
PittyTiger RAT
Technical ID: win.pittytiger_rat
MALWARE
Malware family identifying win.pittytiger_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-19
View profile →
Pitou
Technical ID: win.pitou
MALWARE
According to TG Soft, Pitou has beeen released on April 2014. It maybe an evolution of the rootkit "Srzizbi" developed on 2008. Pitou is a spambot, the main goal is send spam form the computer of victim.
Updated: 2024-09-04
View profile →
pirpi
Technical ID: win.pirpi
UPS
MALWARE
Malware family identifying win.pirpi. Origin and technical characteristics tracked via Malpedia.
Also known as: SHOTPUT • CookieCutter
Updated: 2020-05-23
View profile →
PirateStealer
Technical ID: win.pirate_stealer
MALWARE
Infostealer
Updated: 2023-10-09
View profile →
PipeSnoop
Technical ID: win.pipesnoop
MALWARE
Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.
Also known as: TOFUPIPE
Updated: 2024-10-18
View profile →
PipeMon
Technical ID: win.pipemon
Winnti Umbrella
MALWARE
Malware family identifying win.pipemon. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-23
View profile →
PipeMagic
Technical ID: win.pipemagic
MALWARE
Malware family identifying win.pipemagic. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-25
View profile →
pipcreat
Technical ID: win.pipcreat
MALWARE
Malware family identifying win.pipcreat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-11
View profile →
← PreviousPage 145 / 269Next →