Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
NorthStar
Technical ID: win.northstar
MALWARE
An open source C2 framework intended for pentest and red teaming activities.
MALWARE
Malware family identifying win.norobot. Origin and technical characteristics tracked via Malpedia.
Also known as: BAITSWITCH
Nopyfy
Technical ID: win.nopyfy
MALWAREfinancialhigh
Ransomware
MALWARE
Malware family identifying win.noopdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: HiddenFace
NonEuclid RAT
Technical ID: win.noneuclid_rat
MALWARE
Malware family identifying win.noneuclid_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: LiberiumRAT • ShadowRoot • SheetRAT
NominatusToxicBattery
Technical ID: win.nominatus_toxic_battery
MALWARE
A wiper that overwrites target files with itself, thus spreading in virus-fashion.
Nokoyawa Ransomware
Technical ID: win.nokoyawa
MALWARE
Malware family identifying win.nokoyawa. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Nokki is a RAT type malware which is believe to evolve from Konni RAT. This malware has been tied to attacks containing politically-motivated lures targeting Russian and Cambodian speaking individuals or organizations. Researchers discovered a tie to the threat actor group known as Reaper also known as APT37.
NodeStealer
Technical ID: win.node_stealer
MALWARE
Malware family identifying win.node_stealer. Origin and technical characteristics tracked via Malpedia.
Nocturnal Stealer
Technical ID: win.nocturnalstealer
MALWARE
Malware family identifying win.nocturnalstealer. Origin and technical characteristics tracked via Malpedia.
nmass malware
Technical ID: win.nmass
MALWARE
It's .NET Rat with harcoded key
MALWARE
RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."
It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
Also known as: Bladabindi • Lime-Worm
NixScare Stealer
Technical ID: win.nixscare
MALWARE
Malware family identifying win.nixscare. Origin and technical characteristics tracked via Malpedia.
Nitrokod
Technical ID: win.nitrokod
MALWARE
A Turkish cryptominer campaign.
Nitrogen Ransomware
Technical ID: win.nitrogen_ransomware
MALWAREfinancialhigh
This ransomware has much in common with the LukaLocker ransomware. [1](https://streamscan.ai/en/ressources/analyse-du-rancongiciel-nitrogen/) Analysis of the files reveals strong correlations between the Nitrogen, LukaLocker and Cactus families.
These similarities lead us to believe that these ransomware families are administered by the same people, or that the files were developed using a common framework. [2](https://www.glimps.re/en/resource/nitrogen-correlation-with-lukalocker-cactus/)
Nitrogen Loader
Technical ID: win.nitrogen
MALWARE
Malware family identifying win.nitrogen. Origin and technical characteristics tracked via Malpedia.
Nitro
Technical ID: win.nitro
MALWAREfinancialhigh
Ransomware family which requires payment in Discord gift cards ("Discord Nitro").
Also known as: Hydra
Nitol
Technical ID: win.nitol
MALWARE
Malware family identifying win.nitol. Origin and technical characteristics tracked via Malpedia.
nitlove
Technical ID: win.nitlove
MALWARE
Malware family identifying win.nitlove. Origin and technical characteristics tracked via Malpedia.
NirCmd
Technical ID: win.nircmd
MALWARE
NirCmd is a benign tool by NirSoft that provides various functionalities. Among these is e.g. a capability to start regedit as SYSTEM, which is sometimes abused for privilege escalation, or other functionality abusable for other malicious purposes. It is also frequently flagged by AV engines.
MALWARE
Malware family identifying win.ninerat. Origin and technical characteristics tracked via Malpedia.
NimBlackout
Technical ID: win.nim_blackout
MALWAREespionageadvanced
According to its author, NimBlackout is an adaptation of the @Blackout project originally developed in C++ by @ZeroMemoryEx, which consists of removing AV/EDRs using the gmer (BYOVD) driver. The main reason for this project was to understand how BYOVD attacks work, and then to provide a valid PoC developed in Nim.
Nimrev
Technical ID: win.nimrev
MALWARE
Backdoor written in Nim.
Nimplant
Technical ID: win.nimplant
MALWARE
Part of Mythic C2, written in Nim.
Considered deprecated, as it is only compatible with Mythic 2.1.
NimGrabber
Technical ID: win.nimgrabber
MALWARE
Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.
Nimbo-C2
Technical ID: win.nimbo_c2
MALWARE
According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework. The agent currently supports Windows x64 and Linux. It's written in Nim, with some usage of .NET (by dynamically loading the CLR to the process).
MALWARE
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.
MALWAREespionageadvanced
NikiTeaR is a sophisticated, custom-developed RAT, which is a rewritten variant of the NikiHTTP (aka NikiTea) RAT.
It supports the following commands:
- srun <EXEC> <ARGS>: Executing arbitrary commands with elevated privileges.
- up/down <FILENAME>: Performing remote file operations (upload/download).
- screen: Capturing screenshots for reconnaissance.
- conn <IP_ADDRESS> <PORT>: Establishing a reverse shell
- memload <EXPORT>: Loading additional DLL into memory.
- die <COMMAND>: Terminates the process and remove trace
It is delivered via a multi-staged execution chain, beginning with a Golang-based dropper that executes a loader, a DLL with the internal name MemLoad_V3.dll, capable of loading DLL reflectively.
Its internal DLL name is httptroy_dll.dll.
To resist analysis, the backdoor is heavily obfuscated; it utilizes custom hashing to conceal Windows API calls, and employs a combined Base64+XOR encryption for C&C traffic and internal character strings, which are dynamically reconstructed at runtime.
MALWARE
NikiHTTP is a versatile backdoor and has multiple capabilities such as download of files, executing them, performing commands, take screenshots and so on.
NightSky
Technical ID: win.nightsky
MALWARE
Malware family identifying win.nightsky. Origin and technical characteristics tracked via Malpedia.
Also known as: Night Sky
NightshadeC2
Technical ID: win.nightshade_c2
MALWAREespionageadvanced
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies from victim systems for both Gecko and Chromium based browsers.
Also known as: CastleRAT
Nightdoor
Technical ID: win.nightdoor
MALWARE
Malware family identifying win.nightdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: NetMM • Suzafk
MALWARE
Malware family identifying win.nightclub. Origin and technical characteristics tracked via Malpedia.
Nibiru
Technical ID: win.nibiru
MALWARE
Malware family identifying win.nibiru. Origin and technical characteristics tracked via Malpedia.
NGLite
Technical ID: win.nglite
MALWARE
According to Unit42, NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.
Ngioweb
Technical ID: win.ngioweb
MALWARE
Malware family identifying win.ngioweb. Origin and technical characteristics tracked via Malpedia.
Also known as: Grobios
NexusLogger
Technical ID: win.nexus_logger
MALWARE
Malware family identifying win.nexus_logger. Origin and technical characteristics tracked via Malpedia.
Nexster Bot
Technical ID: win.nexster_bot
MALWARE
Malware family identifying win.nexster_bot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.new_ct. Origin and technical characteristics tracked via Malpedia.
Also known as: CT