Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
PingBack
Technical ID: win.pingback
MALWARE
Malware family identifying win.pingback. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-05
View profile →
PINEGROVE
Technical ID: win.pinegrove
APT41
MALWARE
Malware family identifying win.pinegrove. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-13
View profile →
PinchDuke
Technical ID: win.pinchduke
APT29
MALWARE
According to F-Secure, the PinchDuke information stealer gathers system configuration information, steals user credentials, and collects user files from the compromised host transferring these via HTTP(S) to a C&C server. F-Secure believes that PinchDuke’s credential stealing functionality is based on the source code of the Pinch credential stealing malware (also known as LdPinch) that was developed in the early 2000s and has later been openly distributed on underground forums.
Updated: 2022-11-15
View profile →
PILLOWMINT
Technical ID: win.pillowmint
Anunak
MALWARE
According to FireEye, PILLOWMINT is a Point-of-Sale malware tool used to scrape track 1 and track 2 payment card data from memory. Scraped payment card data is encrypted and stored in the registry and as plaintext in a file (T1074: Data Staged) Contains additional backdoor capabilities including: Running processes Downloading and executing files (T1105: Remote File Copy) Downloading and injecting DLLs (T1055: Process Injection) Communicates with a command and control (C2) server over HTTP using AES encrypted messages (T1071: Standard Application Layer Protocol) (T1032: Standard Cryptographic Protocol)
Updated: 2023-05-23
View profile →
Pikabot
Technical ID: win.pikabot
MALWARE
Introducing Pikabot, an emerging malware family that comprises a downloader/installer, a loader, and a core backdoor component. Despite being in the early stages of development, it already demonstrates advanced techniques in evasion, injection, and anti-analysis. Notably, the loader component incorporates an array of sophisticated anti-debugging and anti-VM measures inspired by the open-source Al-Khaser project, while leveraging steganography to conceal its payload. Additionally, Pikabot utilizes a proprietary C2 framework and supports a diverse range of commands, encompassing host enumeration and advanced secondary payload injection options.
Updated: 2025-11-25
View profile →
Pierogi
Technical ID: win.pierogi
Molerats
MALWARE
Malware family identifying win.pierogi. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-04
View profile →
PIEHOP
Technical ID: win.piehop
MALWARE
According to Mandiant, PIEHOP is a disruption tool written in Python and packaged with PyInstaller version 2.1+ that has the capability to connect to a user supplied remote MSSQL server for uploading files and issuing remote commands to a RTU. PIEHOP expects its main function to be called via another Python file, supplying either the argument control=True or upload=True. At a minimum, it requires the following arguments: oik, user, and pwd, and if called with control=True, it must also be supplied with iec104.
Updated: 2023-05-26
View profile →
PICKPOCKET
Technical ID: win.pickpocket
APT34
MALWAREespionageadvanced
PICKPOCKET is a credential theft tool that dumps the user's website login credentials from Chrome, Firefox, and Internet Explorer to a file. This tool was previously observed solely utilized by APT34.
Updated: 2021-06-29
View profile →
PicassoLoader
Technical ID: win.picasso_loader
Ghostwriter
MALWARE
Malware family identifying win.picasso_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-26
View profile →
PhotoLoader
Technical ID: win.photoloader
MALWARE
A loader used to deliver IcedID, fetching a fake image from which payloads are extracted.
Also known as: GZIPLOADER
Updated: 2024-04-03
View profile →
PHOTOLITE
Technical ID: win.photolite
MALWAREfinancialhigh
PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e. for example it does not have any functionality to exfiltrate the host information. This new variant is observed as a follow-on payload in a TA542 Emotet campaign back in November'22. contains a static URL to download a "Bot Pack" file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud.
Updated: 2023-08-14
View profile →
PHOTOFORK
Technical ID: win.photofork
MALWARE
PHOTOFORK is a downloader which is a modified version of GZIPLOADER. It was first detected in February 2023 and was distributed by TA581 along with an unattributed threat activity cluster that facilitated initial access. In this version, the configuration file is no longer encrypted using a simple XOR algorithm with a 64-byte key. Instead, it uses a custom algorithm previously used by the Standard core loader. This algorithm decrypts DLL strings that are needed to resolve handles to the necessary DLLs later on. The strings are decrypted using an algorithm that splits the data into DWORDs and XORs it against a random key. The main objective of PHOTOFORK remains the same as GZIPLOADER, i.e. to deliver an encrypted bot and core DLL loader (forked) that loads the Forked ICEDID bot into memory using a custom PE format.
Updated: 2024-12-11
View profile →
Phorpiex
Technical ID: win.phorpiex
MALWARE
Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers. The name Trik is derived from PDB strings.
Also known as: Trik • phorphiex
Updated: 2023-11-13
View profile →
PHOREAL
Technical ID: win.phoreal
APT32
MALWARE
Phoreal is a very simple backdoor that is capable of creating a reverse shell, performing simple file I/O and top-level window enumeration. It communicates to a list of four preconfigured C2 servers via ICMP on port 53
Also known as: Rizzo
Updated: 2022-03-08
View profile →
Phonk
Technical ID: win.phonk
MALWARE
Malware family identifying win.phonk. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-27
View profile →
Phoenix Locker
Technical ID: win.phoenix_locker
MALWARE
Malware family identifying win.phoenix_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-03-07
View profile →
Phoenix Keylogger
Technical ID: win.phoenix_keylogger
MALWARE
Keylogger, information stealer.
Updated: 2022-09-19
View profile →
Phobos
Technical ID: win.phobos
MALWAREfinancialhigh
MalwareBytes states that Phobos is one of the ransomware families that are distributed via hacked Remote Desktop (RDP) connections. This isn't surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost efficient dissemination vector for threat groups.
Updated: 2025-07-21
View profile →
Philadephia Ransom
Technical ID: win.philadelphia_ransom
MALWARE
Malware family identifying win.philadelphia_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
Phemedrone Stealer
Technical ID: win.phemedrone_stealer
MALWARE
Malware family identifying win.phemedrone_stealer. Origin and technical characteristics tracked via Malpedia.
Also known as: Ov3r_Stealer
Updated: 2025-12-15
View profile →
Phantom Stealer
Technical ID: win.phantom_stealer
MALWARE
According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
Updated: 2025-12-08
View profile →
PhantomVAI
Technical ID: win.phantomvai
MALWARE
PhantomVAI Loader is a malicious multi-stage infection chain used to distribute the Katz Stealer information-stealing malware or other malicious payloads.
Also known as: Caminho • Katz Stealer Loader • VMDetectLoader
Updated: 2026-01-05
View profile →
PhantomCore
Technical ID: win.phantomcore
MALWAREfinancialhigh
According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare. It has been active since 2023 and is known for consistently targeting Russia. PhantomCore collects the victim’s information, including the public IP address, to gain detailed insights into the target before deploying the final-stage payload or executing additional commands on the compromised system. PhantomCore is known to deploy ransomware payloads such as LockBit and Babuk, inflicting significant damage on the victim’s systems.
Updated: 2025-12-08
View profile →
PhanDoor
Technical ID: win.phandoor
Lazarus GroupSilent Chollima
MALWARE
Malware family identifying win.phandoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-28
View profile →
pgift
Technical ID: win.pgift
Pitty Panda
MALWARE
Information gathering and downloading tool used to deliver second stage malware to the infected system
Also known as: ReRol
Updated: 2018-01-25
View profile →
Petya
Technical ID: win.petya
MALWARE
Malware family identifying win.petya. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-30
View profile →
PetrWrap
Technical ID: win.petrwrap
MALWAREfinancialhigh
The PetrWrap Trojan is written in C and compiled in MS Visual Studio. It carries a sample of the Petya ransomware v3 inside its data section and uses Petya to infect the victim’s machine. What’s more, PetrWrap implements its own cryptographic routines and modifies the code of Petya in runtime to control its execution. This allows the criminals behind PetrWrap to hide the fact that they are using Petya during infection.
Updated: 2023-07-22
View profile →
PetitPotato
Technical ID: win.petit_potato
Silent Chollima
MALWARE
Malware family identifying win.petit_potato. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-27
View profile →
Peppy RAT
Technical ID: win.peppy_rat
Operation C-Major
MALWARE
Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson appearances. Peppy communicates to its C&C over HTTP and utilizes SQLite for much of its internal functionality and tracking of exfiltrated files. The primary purpose of Peppy may be the automated exfiltration of potentially interesting files and keylogs. Once Peppy successfully communicates to its C&C, the keylogging and exfiltration of files using configurable search parameters begins. Files are exfiltrated using HTTP POST requests.
Updated: 2024-11-29
View profile →
PennyWise Stealer
Technical ID: win.pennywise
MALWARE
Malware family identifying win.pennywise. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-05
View profile →
Penco
Technical ID: win.penco
MALWARE
Malware family identifying win.penco. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
Pelmeni
Technical ID: win.pelmeni
Turla
MALWARE
Wrapper for Kazuar.
Updated: 2024-07-17
View profile →
Pekraut
Technical ID: win.pekraut
MALWARE
Malware family identifying win.pekraut. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-06
View profile →
PeddleCheap
Technical ID: win.peddlecheap
Equation Group
MALWARE
PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks. In May 2020, ESET mentioned that they found mysterious samples of PeddleCheap packed with a custom packer so far exclusively attributed to Winnti.
Updated: 2022-01-05
View profile →
PEBBLEDASH
Technical ID: win.pebbledash
MALWARE
Malware family identifying win.pebbledash. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-23
View profile →
PcShare
Technical ID: win.pcshare
Pirate Panda
MALWARE
PcShare is a open-source backdoor which has been seen modified and used by Chinese threat actors, mainly attacking countries in South East Asia.
Updated: 2022-07-29
View profile →
PayloadBIN
Technical ID: win.payloadbin
Evil Corp
MALWARE
Malware family identifying win.payloadbin. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-01
View profile →
Pay2Key
Technical ID: win.pay2key
MALWARE
Malware family identifying win.pay2key. Origin and technical characteristics tracked via Malpedia.
Also known as: Cobalt
Updated: 2021-05-13
View profile →
PathWiper
Technical ID: win.pathwiper
MALWARE
According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly. It identifies connected storage media, creates one thread per drive and volume for every path recorded and overwrites artifacts with randomly generated bytes. The wiper also reads multiple file systems attributes from NTFS and overwrites them as well. PathWiper additionally destroys files on disk by overwriting them with randomized bytes.
Updated: 2025-06-05
View profile →
PATHLOADER
Technical ID: win.pathloader
MALWARE
Malware family identifying win.pathloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-25
View profile →
← PreviousPage 146 / 269Next →