Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
NorthStar
Technical ID: win.northstar
MALWARE
An open source C2 framework intended for pentest and red teaming activities.
Updated: 2022-08-19
View profile →
NOROBOT
Technical ID: win.norobot
Callisto
MALWARE
Malware family identifying win.norobot. Origin and technical characteristics tracked via Malpedia.
Also known as: BAITSWITCH
Updated: 2025-10-22
View profile →
Nopyfy
Technical ID: win.nopyfy
MALWAREfinancialhigh
Ransomware
Updated: 2023-08-21
View profile →
NOOPDOOR
Technical ID: win.noopdoor
MirrorFace
MALWARE
Malware family identifying win.noopdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: HiddenFace
Updated: 2025-02-19
View profile →
NonEuclid RAT
Technical ID: win.noneuclid_rat
MALWARE
Malware family identifying win.noneuclid_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: LiberiumRAT • ShadowRoot • SheetRAT
Updated: 2026-02-17
View profile →
NominatusToxicBattery
Technical ID: win.nominatus_toxic_battery
MALWARE
A wiper that overwrites target files with itself, thus spreading in virus-fashion.
Updated: 2022-11-21
View profile →
Nokoyawa Ransomware
Technical ID: win.nokoyawa
MALWARE
Malware family identifying win.nokoyawa. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
Nokki
Technical ID: win.nokki
APT37
MALWAREespionageadvanced
Nokki is a RAT type malware which is believe to evolve from Konni RAT. This malware has been tied to attacks containing politically-motivated lures targeting Russian and Cambodian speaking individuals or organizations. Researchers discovered a tie to the threat actor group known as Reaper also known as APT37.
Updated: 2025-06-20
View profile →
NodeStealer
Technical ID: win.node_stealer
MALWARE
Malware family identifying win.node_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-21
View profile →
Nocturnal Stealer
Technical ID: win.nocturnalstealer
MALWARE
Malware family identifying win.nocturnalstealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-13
View profile →
nmass malware
Technical ID: win.nmass
MALWARE
It's .NET Rat with harcoded key
Updated: 2021-03-25
View profile →
NjRAT
Technical ID: win.njrat
AQUATIC PANDAEarth LuscaOperation C-MajorThe Gorgon Group
MALWARE
RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives." It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
Also known as: Bladabindi • Lime-Worm
Updated: 2026-02-03
View profile →
NixScare Stealer
Technical ID: win.nixscare
MALWARE
Malware family identifying win.nixscare. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-15
View profile →
Nitrokod
Technical ID: win.nitrokod
MALWARE
A Turkish cryptominer campaign.
Updated: 2022-08-31
View profile →
Nitrogen Ransomware
Technical ID: win.nitrogen_ransomware
MALWAREfinancialhigh
This ransomware has much in common with the LukaLocker ransomware. [1](https://streamscan.ai/en/ressources/analyse-du-rancongiciel-nitrogen/) Analysis of the files reveals strong correlations between the Nitrogen, LukaLocker and Cactus families. These similarities lead us to believe that these ransomware families are administered by the same people, or that the files were developed using a common framework. [2](https://www.glimps.re/en/resource/nitrogen-correlation-with-lukalocker-cactus/)
Updated: 2025-08-18
View profile →
Nitrogen Loader
Technical ID: win.nitrogen
MALWARE
Malware family identifying win.nitrogen. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-21
View profile →
Nitro
Technical ID: win.nitro
MALWAREfinancialhigh
Ransomware family which requires payment in Discord gift cards ("Discord Nitro").
Also known as: Hydra
Updated: 2023-07-02
View profile →
Nitol
Technical ID: win.nitol
MALWARE
Malware family identifying win.nitol. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-20
View profile →
nitlove
Technical ID: win.nitlove
MALWARE
Malware family identifying win.nitlove. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-08-23
View profile →
NirCmd
Technical ID: win.nircmd
MALWARE
NirCmd is a benign tool by NirSoft that provides various functionalities. Among these is e.g. a capability to start regedit as SYSTEM, which is sometimes abused for privilege escalation, or other functionality abusable for other malicious purposes. It is also frequently flagged by AV engines.
Updated: 2023-08-15
View profile →
NineRAT
Technical ID: win.ninerat
Silent Chollima
MALWARE
Malware family identifying win.ninerat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-15
View profile →
NimBlackout
Technical ID: win.nim_blackout
MALWAREespionageadvanced
According to its author, NimBlackout is an adaptation of the @Blackout project originally developed in C++ by @ZeroMemoryEx, which consists of removing AV/EDRs using the gmer (BYOVD) driver. The main reason for this project was to understand how BYOVD attacks work, and then to provide a valid PoC developed in Nim.
Updated: 2023-07-10
View profile →
Nimrev
Technical ID: win.nimrev
MALWARE
Backdoor written in Nim.
Updated: 2021-12-15
View profile →
Nimplant
Technical ID: win.nimplant
MALWARE
Part of Mythic C2, written in Nim. Considered deprecated, as it is only compatible with Mythic 2.1.
Updated: 2023-10-12
View profile →
NimGrabber
Technical ID: win.nimgrabber
MALWARE
Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.
Updated: 2021-12-15
View profile →
Nimbo-C2
Technical ID: win.nimbo_c2
MALWARE
According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework. The agent currently supports Windows x64 and Linux. It's written in Nim, with some usage of .NET (by dynamically loading the CLR to the process).
Updated: 2024-09-13
View profile →
NimbleMamba
Technical ID: win.nimblemamba
Molerats
MALWARE
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.
Updated: 2022-02-09
View profile →
NikiTeaR
Technical ID: win.nikitear
Kimsuky
MALWAREespionageadvanced
NikiTeaR is a sophisticated, custom-developed RAT, which is a rewritten variant of the NikiHTTP (aka NikiTea) RAT. It supports the following commands: - srun <EXEC> <ARGS>: Executing arbitrary commands with elevated privileges. - up/down <FILENAME>: Performing remote file operations (upload/download). - screen: Capturing screenshots for reconnaissance. - conn <IP_ADDRESS> <PORT>: Establishing a reverse shell - memload <EXPORT>: Loading additional DLL into memory. - die <COMMAND>: Terminates the process and remove trace It is delivered via a multi-staged execution chain, beginning with a Golang-based dropper that executes a loader, a DLL with the internal name MemLoad_V3.dll, capable of loading DLL reflectively. Its internal DLL name is httptroy_dll.dll. To resist analysis, the backdoor is heavily obfuscated; it utilizes custom hashing to conceal Windows API calls, and employs a combined Base64+XOR encryption for C&C traffic and internal character strings, which are dynamically reconstructed at runtime.
Updated: 2025-11-19
View profile →
NikiHTTP
Technical ID: win.nikihttp
Kimsuky
MALWARE
NikiHTTP is a versatile backdoor and has multiple capabilities such as download of files, executing them, performing commands, take screenshots and so on.
Updated: 2025-10-28
View profile →
NightSky
Technical ID: win.nightsky
MALWARE
Malware family identifying win.nightsky. Origin and technical characteristics tracked via Malpedia.
Also known as: Night Sky
Updated: 2022-09-20
View profile →
NightshadeC2
Technical ID: win.nightshade_c2
MALWAREespionageadvanced
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies from victim systems for both Gecko and Chromium based browsers.
Also known as: CastleRAT
Updated: 2026-01-12
View profile →
Nighthawk
Technical ID: win.nighthawk
MALWARE
C2 framework.
Updated: 2024-08-29
View profile →
Nightdoor
Technical ID: win.nightdoor
MALWARE
Malware family identifying win.nightdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: NetMM • Suzafk
Updated: 2024-10-29
View profile →
NightClub
Technical ID: win.nightclub
MoustachedBouncer
MALWARE
Malware family identifying win.nightclub. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-11
View profile →
Nibiru
Technical ID: win.nibiru
MALWARE
Malware family identifying win.nibiru. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-19
View profile →
NGLite
Technical ID: win.nglite
MALWARE
According to Unit42, NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.
Updated: 2023-05-25
View profile →
Ngioweb
Technical ID: win.ngioweb
MALWARE
Malware family identifying win.ngioweb. Origin and technical characteristics tracked via Malpedia.
Also known as: Grobios
Updated: 2024-12-09
View profile →
NexusLogger
Technical ID: win.nexus_logger
MALWARE
Malware family identifying win.nexus_logger. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-03-28
View profile →
Nexster Bot
Technical ID: win.nexster_bot
MALWARE
Malware family identifying win.nexster_bot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →
NewCT
Technical ID: win.new_ct
DragonOK
MALWARE
Malware family identifying win.new_ct. Origin and technical characteristics tracked via Malpedia.
Also known as: CT
Updated: 2022-07-29
View profile →
← PreviousPage 149 / 269Next →