Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Passlock
Technical ID: win.passlock
MALWAREfinancialhigh
Ransomware.
Updated: 2020-02-10
View profile →
PartyTicket
Technical ID: win.partyticket
MALWAREfinancialhigh
PartyTicket is a Go-written ransomware, which was described as a poorly designed one by Zscaler. According to Brett Stone-Gross this malware is likely intended to be a diversion from the Hermetic wiper (aka. KillDisk.NCV, DriveSlayer) attack.
Also known as: Elections GoRansom • HermeticRansom • SonicVote
Updated: 2024-04-23
View profile →
Parite
Technical ID: win.parite
MALWARE
According to Microsoft, Parite is a family of polymorphic file infectors that targets computers running Microsoft Windows. The virus infects .exe and .scr executable files on the local file system and on writeable network shares. In turn, the infected executable files perform operations that cause other .exe and .scr files to become infected.
Updated: 2025-02-10
View profile →
parasite_http
Technical ID: win.parasite_http
MALWARE
Malware family identifying win.parasite_http. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-13
View profile →
Parallax RAT
Technical ID: win.parallax
MALWARE
Parallax is a Remote Access Trojan used by attackers to gain access to a victim's machine. It was involved in one of the many infamous "coronamalware" campaigns. Basically, the attackers abused the COVID-19 pandemic news to lure victims into opening themed emails spreading parallax.
Also known as: ParallaxRAT
Updated: 2025-04-28
View profile →
Paradise
Technical ID: win.paradise
MALWAREfinancialhigh
Ransomware.
Updated: 2023-12-27
View profile →
Paradies Clipper
Technical ID: win.paradies_clipper
MALWARE
Malware family identifying win.paradies_clipper. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-09
View profile →
Pantegana
Technical ID: win.pantegana
MALWARE
A multi-platform RAT written in Go.
Updated: 2025-10-15
View profile →
Pandora RAT
Technical ID: win.pandora_rat
MALWARE
Malware family identifying win.pandora_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: Pandora hVNC RAT
Updated: 2022-08-05
View profile →
Pandora
Technical ID: win.pandora
MALWAREfinancialhigh
Pandora ransomware was obtained by vx-underground at 2022-03-14.
Updated: 2022-09-20
View profile →
Panda Stealer
Technical ID: win.panda_stealer
MALWARE
According to PCrisk, Panda is the name of a malicious program, which is classified as a stealer. It is a new variant of CollectorStealer. The aim of this malware is to extract and exfiltrate sensitive and personal information from infected devices. Panda primarily targets data relating to cryptocurrency wallets. This piece of malicious software has been observed being actively distributed via spam campaigns - large-scale operations during which thousands of scam emails are sent. The spam mail proliferating Panda stealer heavily targeted users from the United States, Germany, Japan, and Australia. The deceptive email letters concerned business-related topics (e.g., fake product quote requests, etc.). Panda stealer is a dangerous program, and as such - its infections must be removed immediately upon detection.
Updated: 2024-05-14
View profile →
PandaBanker
Technical ID: win.pandabanker
MALWAREfinancialhigh
According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*). Fox IT discovered it in February 2016. This banking trojan uses the infamous ATS (Automatic Transfer System/Scripts) to automate online bank portal actions. The baseconfig (c2, crypto material, botnet name, version) is embedded in the malware itself. It then obtains a dynamic config from the c2, with further information about how to grab the webinjects and additional modules, such as vnc, backsocks and grabber. Panda does have some DGA implemented, but according to Arbor, a bug prevents it from using it.
Also known as: ZeusPanda
Updated: 2022-01-25
View profile →
paladin
Technical ID: win.paladin
Pitty Panda
MALWARE
Paladin RAT is a variant of Gh0st RAT used by PittyPanda active since at least 2011.
Updated: 2018-09-30
View profile →
PadCrypt
Technical ID: win.padcrypt
MALWARE
Malware family identifying win.padcrypt. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
Ozone RAT
Technical ID: win.ozone
MALWARE
Malware family identifying win.ozone. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-03
View profile →
OZH RAT
Technical ID: win.ozh_rat
MALWARE
Malware family identifying win.ozh_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-29
View profile →
OxtaRAT
Technical ID: win.oxtarat
MALWARE
Malware family identifying win.oxtarat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-17
View profile →
Owowa
Technical ID: win.owowa
MALWARE
Kaspersky describes this as a OWA add-on that has credential stealing capabilities.
Updated: 2025-05-02
View profile →
Owlproxy
Technical ID: win.owlproxy
MALWARE
Malware family identifying win.owlproxy. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-05
View profile →
owaauth
Technical ID: win.owaauth
MALWARE
Malware family identifying win.owaauth. Origin and technical characteristics tracked via Malpedia.
Also known as: luckyowa
Updated: 2020-05-23
View profile →
OvidiyStealer
Technical ID: win.ovidiystealer
MALWARE
Malware family identifying win.ovidiystealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-03
View profile →
Overlay RAT
Technical ID: win.overlay_rat
MALWARE
Malware family identifying win.overlay_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-20
View profile →
OutSteel
Technical ID: win.outsteel
MALWARE
According to MITRE, OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Ember Bear since at least March 2021.
Updated: 2023-06-09
View profile →
Outlook Backdoor
Technical ID: win.outlook_backdoor
Turla
MALWARE
Malware family identifying win.outlook_backdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: FACADE
Updated: 2020-07-24
View profile →
OutCrypt
Technical ID: win.outcrypt
MALWAREfinancialhigh
Ransomware.
Updated: 2020-08-05
View profile →
Ousaban
Technical ID: win.ousaban
MALWARE
Malware family identifying win.ousaban. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-05
View profile →
Osno
Technical ID: win.osno
MALWARE
Malware family identifying win.osno. Origin and technical characteristics tracked via Malpedia.
Also known as: Babax
Updated: 2021-03-31
View profile →
Oski Stealer
Technical ID: win.oski
MALWARE
Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums. It collects different types of data (cryptocurrency wallets, saved passwords, files matching an attacker-defined pattern etc) and it exfiltrates it in a zip file uploaded to the attacker's panel.
Updated: 2025-05-01
View profile →
ORPCBackdoor
Technical ID: win.orpcbackdoor
MALWARE
Malware family identifying win.orpcbackdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-05
View profile →
OriginLogger
Technical ID: win.originlogger
MALWARE
Malware family identifying win.originlogger. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-10
View profile →
OriginBot
Technical ID: win.originbot
MALWARE
OriginBot is a modular information stealer which can also download and execute other malicious payloads.
Also known as: OriginBotnet • OriginLoader
Updated: 2023-12-11
View profile →
Ordinypt
Technical ID: win.ordinypt
MALWAREfinancialhigh
This malware claims to be a ransomware, but it's actually a wiper. After execution, this malware terminates a number of processes such as database processes, likely to allow access to any files that these programs may have held open. Ordinypt will avoid wiping certain files and folders in order to prevent the infected machine from becoming unusable. Affected files are overwritten with null character and receive a random 5 character file extension. Finally, shadow copies are removed and Windows startup repair is disabled to complicate recovery of data from the affected system. The desktop background is changed and a ransom note is dropped for the victim. A C2 check-in occurs to keep track of the file extension used on that specific machine, as well as which BitCoin address was randomly provided for payment to the victim (drawn from a long list stored in the ransomware configuration).
Also known as: GermanWiper • HSDFSDCrypt
Updated: 2023-01-19
View profile →
Orcus RAT
Technical ID: win.orcus_rat
MALWARE
Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016. It has all the features that would be expected from a RAT and probably more. The long list of the commands is documented on their website. But what separates Orcus from the others is its capability to load custom plugins developed by users, as well as plugins that are readily available from the Orcus repository. In addition to that, users can also execute C# and VB.net code on the remote machine in real-time.
Also known as: Schnorchel
Updated: 2023-03-20
View profile →
Orchard
Technical ID: win.orchard
MALWARE
A malware generating DGA domains seeded by the Bitcoin Genesis Block. This family has strong code overlap with win.victorygate.
Also known as: Antavmu
Updated: 2023-05-17
View profile →
OrcaRAT
Technical ID: win.orcarat
MALWARE
OrcaRAT is a Backdoor that targets the Windows platform. It has been reported that a variant of this malware has been used in a targeted attack. It contacts a remote server, sending system information. Moreover, it receives control commands to execute shell commands, and download/upload a file, among other actions.
Updated: 2020-05-23
View profile →
ORANGEADE
Technical ID: win.orangeade
APT 30
MALWARE
FireEye details ORANGEADE as a dropper for the CREAMSICLE malware.
Updated: 2019-04-17
View profile →
OpBlockBuster
Technical ID: win.op_blockbuster
Lazarus Group
MALWARE
Malware family identifying win.op_blockbuster. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-17
View profile →
OpGhoul
Technical ID: win.opghoul
MALWARE
This entry serves as a placeholder of malware observed during Operation Ghoul. The samples will likely be assigned to their respective families. Some families involved and identified were Alina POS (Katrina variant) and TreasureHunter POS.
Updated: 2024-02-08
View profile →
OpenCarrot
Technical ID: win.open_carrot
APT37
MALWARE
Malware family identifying win.open_carrot. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-07
View profile →
OpenSUpdater
Technical ID: win.opensupdater
MALWARE
Malware family identifying win.opensupdater. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-01
View profile →
← PreviousPage 147 / 269Next →