Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
OpcJacker
Technical ID: win.opcjacker
MALWARE
Malware family identifying win.opcjacker. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-25
View profile →
Opachki
Technical ID: win.opachki
MALWARE
Malware family identifying win.opachki. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
OopsIE
Technical ID: win.oopsie
OilRig
MALWARE
Malware family identifying win.oopsie. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
OnlinerSpambot
Technical ID: win.onliner
MALWARE
A spambot that has been observed being used for spreading Ursnif, Zeus Panda, Andromeda or Netflix phishing against Italy and Canada.
Also known as: SBot • Onliner
Updated: 2023-01-25
View profile →
OnionDuke
Technical ID: win.onionduke
APT29
MALWARE
OnionDuke is a new sophisticated piece of malware distributed by threat actors through a malicious exit node on the Tor anonymity network appears to be related to the notorious MiniDuke, researchers at F-Secure discovered. According to experts, since at least February 2014, the threat actors have also distributed the threat through malicious versions of pirated software hosted on torrent websites.
Updated: 2020-07-06
View profile →
Oni
Technical ID: win.oni
MALWAREfinancialhigh
Ransomware.
Updated: 2019-08-14
View profile →
ONHAT
Technical ID: win.onhat
MALWARE
Malware family identifying win.onhat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-26
View profile →
Ondritols
Technical ID: win.ondritols
MALWARE
According to Symantec, this malware has been deployed against IT services companies in the U.S. and Europe. A multi-stage backdoor, the first stage is a downloader that authenticates to Microsoft Graph API and downloads the second stage payload from OneDrive and executes it. The main payload will download a publicly available file from GitHub. It will then create a folder in OneDrive named deviceId_n_<ip address> for each infected machine and upload a file to OneDrive to signal the attackers the status of a new infection.
Also known as: Onedrivetools
Updated: 2024-10-25
View profile →
Olympic Destroyer
Technical ID: win.olympic_destroyer
MALWARE
Malware which seems to have no function other than to disrupt computer systems related to the 2018 Winter Olympic event.
Also known as: SOURGRAPE
Updated: 2024-04-23
View profile →
OLDBAIT
Technical ID: win.oldbait
APT28
MALWAREespionageadvanced
According to FireEye, OLDBAIT is a credential stealer that has been observed to be used by APT28. It targets Internet Explorer, Mozilla Firefox, Eudora, The Bat! (an email client by a Moldovan company), and Becky! (an email client made by a Japanese company). It can use both HTTP or SMTP to exfiltrate data. In some places it is mistakenly named "Sasfis", which however seems to be a completely different and unrelated malware family.
Also known as: Sasfis
Updated: 2022-05-04
View profile →
Okrum
Technical ID: win.okrum
Mirage
MALWARE
a new, previously unknown backdoor that we named Okrum. The malicious actors behind the Okrum malware were focused on the same targets in Slovakia that were previously targeted by Ketrican 2015 backdoors.
Updated: 2021-02-25
View profile →
Odinaff
Technical ID: win.odinaff
MALWARE
Malware family identifying win.odinaff. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-21
View profile →
Oderoor
Technical ID: win.oderoor
MALWARE
Spam bot that was active around 2007 and after, one of the first malware families to use a domain generation algorithm.
Also known as: Bobax • Kraken
Updated: 2024-02-21
View profile →
OddJob
Technical ID: win.oddjob
Equation Group
MALWARE
Malware family identifying win.oddjob. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-01
View profile →
Octowave Loader
Technical ID: win.octowave
MALWAREespionageadvanced
Octowave Loader is a malware loader used to run other families of malware. This is often made up of an MSI or Inno Setup installer for a legitimate piece of software that has been trojanised to include a number of malicious DLLs which inevitably load and run malicious code often stored within a WAV file that is also delivered to an endpoint. In the wild this has been seen delivered through fake software installers and ClickFix / Fake Captcha campaigns. Families of malware deployed often include information stealers, NetSupport RAT, and potentially bots like Danabot.
Updated: 2025-04-01
View profile →
OctoRAT
Technical ID: win.octorat
MALWARE
Malware family identifying win.octorat. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-02-05
View profile →
Octopus
Technical ID: win.octopus
MALWARE
Malware family identifying win.octopus. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-08
View profile →
OctoberSeventh
Technical ID: win.october_seventh
MALWARE
Emanuele De Lucia summarizes that this wiper was sent to potential targets in phishing mails that impersonated ESET as a follow up to a breach of its Israeli distributor Comsecure.
Also known as: ESET Wiper
Updated: 2024-12-16
View profile →
Oceansalt
Technical ID: win.oceansalt
MALWARE
Malware family identifying win.oceansalt. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-19
View profile →
OCEANMAP
Technical ID: win.oceanmap
APT28
MALWARE
Malware family identifying win.oceanmap. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-02
View profile →
ObserverStealer
Technical ID: win.observer_stealer
MALWARE
Malware family identifying win.observer_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-27
View profile →
Obscene
Technical ID: win.obscene
MALWARE
Malware family identifying win.obscene. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-09
View profile →
Oblique RAT
Technical ID: win.oblique_rat
MALWARE
Malware family identifying win.oblique_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-29
View profile →
OATBOAT
Technical ID: win.oatboat
MALWARE
OATBOAT is a loader that loads and executes shellcode payloads.
Updated: 2024-10-25
View profile →
Nyxem
Technical ID: win.nyxem
MALWARE
Malware family identifying win.nyxem. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-29
View profile →
Nymaim2
Technical ID: win.nymaim2
MALWARE
According to bin.re, in April 2018 a new version of Nymaim appeared, that has dropped previous obfuscation, and uses a new wordlist based DGA (Domain Generation Algorithm).
Updated: 2024-09-04
View profile →
Nymaim
Technical ID: win.nymaim
MALWARE
Nymaim is a trojan downloader. It downloads (and runs) other malware on affected systems and was one of the primary malware families hosted on Avalanche. Nymaim is different in that it displays a localized lockscreen while it downloads additional malware. Nymaim is usually delivered by exploit kits and malvertising.
Also known as: nymain
Updated: 2023-08-03
View profile →
N-W0rm
Technical ID: win.nworm
MALWARE
Malware family identifying win.nworm. Origin and technical characteristics tracked via Malpedia.
Also known as: nw0rm • NWorm
Updated: 2022-02-10
View profile →
NVISOSPIT
Technical ID: win.nvisospit
MALWARE
Malware family identifying win.nvisospit. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-23
View profile →
Numando
Technical ID: win.numando
MALWAREfinancialhigh
According to PCrisk, Numando is a banking trojan written in the Delphi programming language. As the malicious program's classification implies, it is designed to steal banking information. Numando primarily targets Brazil, with seldom campaigns occurring in Mexico and Spain.
Updated: 2023-05-25
View profile →
Nullmixer
Technical ID: win.nullmixer
MALWARE
Nullmixer is a dropper/loader for additional malware. It is known to drop a vast amount of different malware, such as info stealers, rats and additional loaders. Samples observed contained up to 8 additional payloads.
Updated: 2024-12-09
View profile →
NuggetPhantom
Technical ID: win.nugget_phantom
MALWARE
NSFOCUS describes PhantomNugget as a modularized malware toolkit, that was spread using EternalBlue. Payloads included a RAT and a XMRig miner.
Updated: 2021-09-20
View profile →
Ntospy
Technical ID: win.ntospy
MALWAREespionageadvanced
Ntospy is a credential stealer leveraging a well-established technique of abusing the Windows Network Provider interface, a method documented as early as 2004 and exemplified by tools like NPPSpy. Posing as a legitimate Network Provider DLL, Ntospy injects itself into the Windows authentication process, hijacking login attempts to harvest user credentials. It achieves this by registering a malicious Network Provider, typically named "credman," which intercepts authentication requests and redirects them to it malicious DLL. Instead of immediately exfiltrating the stolen data, Ntospy employs a form of local storage, writing the captured credentials in cleartext to files disguised as harmless Microsoft Update packages using the .msu file extension. These files are often planted in system directories with believable names like "c:/programdata/package cache/windows10.0-kb5009543-x64.msu," further masking their malicious purpose. Adding to its stealth, Ntospy incorporates obfuscation techniques to evade detection. This includes using seemingly innocuous filenames for its DLL, often mimicking critical system files like "ntoskrnl.dll" to blend in. Some variants even go a step further by encrypting the credential storage file path within the DLL, requiring analysis and decryption to uncover its full functionality.
Updated: 2024-06-05
View profile →
NSPX30
Technical ID: win.nspx30
Blackwood
MALWARE
Malware family identifying win.nspx30. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-05-14
View profile →
nRansom
Technical ID: win.nransom
MALWARE
Malware family identifying win.nransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-26
View profile →
No-Justice
Technical ID: win.no_justice
MALWARE
Malware family identifying win.no_justice. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-11
View profile →
Nozelesn (Decryptor)
Technical ID: win.nozelesn_decryptor
MALWARE
Malware family identifying win.nozelesn_decryptor. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-09
View profile →
NoxPlayer
Technical ID: win.noxplayer
MALWARE
Malware family identifying win.noxplayer. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-11-08
View profile →
Nova Stealer
Technical ID: win.nova
MALWARE
Nova Stealer is a new information stealer that is offered as Malware-as-a-Service by a new French-speaking actor called "Nova Sentinel". Its capabilities include password stealing, browser injections, crypto wallet stealing, discord injections, and screen recordings. Parts of its source code have been made available on GitHub, with certain "Premium" features missing.
Also known as: Malicord
Updated: 2025-08-15
View profile →
Nosu
Technical ID: win.nosu
MALWARE
According to PCrisk, Nosu is the name of a malicious program classified as a stealer. This malware is designed to steal information from infected machines. The Nosu stealer can extract a wide variety of data from devices and installed applications. The most active campaigns associated with Nosu were noted in North and South America, as well as Southeast Asia.
Updated: 2023-05-25
View profile →
← PreviousPage 148 / 269Next →