Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
NewsReels
Technical ID: win.newsreels
Comment Crew
MALWARE
Malware family identifying win.newsreels. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
NewPosThings
Technical ID: win.newposthings
MALWARE
Malware family identifying win.newposthings. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-19
View profile →
NewPass
Technical ID: win.newpass
APT29Turla
MALWARE
Malware family identifying win.newpass. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-10-17
View profile →
NewCore RAT
Technical ID: win.newcore_rat
Hellsing
MALWARE
Malware family identifying win.newcore_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-25
View profile →
NewBounce
Technical ID: win.newbounce
MALWARE
Malware family identifying win.newbounce. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-15
View profile →
NewBot Loader
Technical ID: win.newbot_loader
MALWARE
Malware family identifying win.newbot_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-18
View profile →
Nevada
Technical ID: win.nevada
MALWARE
Malware family identifying win.nevada. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-02
View profile →
Neutrino POS
Technical ID: win.neutrino_pos
MALWARE
Malware family identifying win.neutrino_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-07-12
View profile →
Neutrino
Technical ID: win.neutrino
MALWARE
Malware family identifying win.neutrino. Origin and technical characteristics tracked via Malpedia.
Also known as: Kasidet
Updated: 2021-09-22
View profile →
Neuron
Technical ID: win.neuron
APT34Turla
MALWARE
Malware family identifying win.neuron. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
NET-STAR
Technical ID: win.net_star
MALWARE
According to Unit 42, NET-STAR is a .NET malware suite designed to target Internet Information Services (IIS) web servers. It was named based on the use of the string in the malware’s program database (PDB) paths. The suite consists of three distinct web-based backdoors, each serving a specific role in the attack chain while maintaining persistence within the target’s IIS environment: A fileless modular backdoor that supports in-memory execution of command-line arguments, arbitrary commands and payloads, a loader for additional Assemblies, and improved version of the Assembly loader that is also equipped with Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypass capabilities.
Updated: 2025-10-15
View profile →
NetWire RC
Technical ID: win.netwire
APT33
MALWARE
Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well. Keylog files are stored on the infected machine in an obfuscated form. The algorithm is: for i in range(0,num_read): buffer[i] = ((buffer[i]-0x24)^0x9D)&0xFF
Also known as: NetWeird • NetWire • Recam
Updated: 2024-11-25
View profile →
NetTraveler
Technical ID: win.nettraveler
NetTraveler
MALWARE
Malware family identifying win.nettraveler. Origin and technical characteristics tracked via Malpedia.
Also known as: TravNet
Updated: 2022-10-06
View profile →
NetSupportManager RAT
Technical ID: win.netsupportmanager_rat
MALWARE
Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago. The purpose of the NetSupport Manager tool is to enable users to receive remote technical support or provide remote computer assistance. However, cyber crooks have hijacked this useful application and misappropriated it to use it in their harmful campaigns. The name of the modified version of the NetSupport Manager has been labeled the NetSupport Manager RAT.
Also known as: NetSupport
Updated: 2026-01-21
View profile →
NetSpy
Technical ID: win.netspy
MALWARE
Freely available network reconnaissance tool.
Updated: 2023-10-11
View profile →
Netrepser
Technical ID: win.netrepser_keylogger
MALWARE
Malware family identifying win.netrepser_keylogger. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-12
View profile →
NetKey
Technical ID: win.netkey
MALWARE
Malware family identifying win.netkey. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-09-06
View profile →
NetFlash
Technical ID: win.netflash
Turla
MALWARE
Malware family identifying win.netflash. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-05
View profile →
NetfilterRootkit
Technical ID: win.netfilter
MALWARE
NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility program. It was first discovered by Karsten Hahn. His team submitted the malware to Microsoft, which allowed Microsoft to start an investigation. After Karsten Hahn published tweets and an article about the rootkit, Microsoft quickly responded with their own article. Their investigation revealed Chinese gamers as targets of the malware. The rootkit redirects traffic to the threat actor's IP. The threat actor can use the driver to spoof their geo-location to cheat, but it also allows account compromise of targeted players. While this particular rootkit is not significant anymore, similar rootkits have been created since that are also signed by Microsoft via the Windows Hardware Compatibility program.
Updated: 2025-05-20
View profile →
NETEAGLE
Technical ID: win.neteagle
APT 30
MALWARE
Malware family identifying win.neteagle. Origin and technical characteristics tracked via Malpedia.
Also known as: Neteagle_Scout • ScoutEagle
Updated: 2022-08-25
View profile →
NetDooka
Technical ID: win.netdooka
MALWARE
A RAT written in .NET, delivered with a driver to protect it from deletion. Observed being dropped by PrivateLoader.
Updated: 2022-05-05
View profile →
NetC
Technical ID: win.netc
Cleaver
MALWARE
Malware family identifying win.netc. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
NESTEGG
Technical ID: win.nestegg
Lazarus Group
MALWARE
NESTEGG is a memory-only backdoor that can proxy commands to other infected systems using a custom routing scheme. It accepts commands to upload and download files, list and delete files, list and terminate processes, and start processes. NESTEGG also creates Windows Firewall rules that allows the backdoor to bind to a specified port number to allow for inbound traffic.
Updated: 2023-08-14
View profile →
neshta
Technical ID: win.neshta
MALWARE
Neshta is a 2005 Belarusian file infector virus written in Delphi. The name of the virus comes from the Belarusian word "nesta" meaning "something."
Updated: 2025-04-14
View profile →
Nerbian RAT
Technical ID: win.nerbian_rat
MALWARE
Proofpoint observed distribution of this RAT since late April 2022, it is written on Go and incorporates code from various open-source Git repositories.
Updated: 2022-05-17
View profile →
Nemty
Technical ID: win.nemty
MALWAREfinancialhigh
Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed through similar ways as Sodinokibi and also noted artfifacts they had seen before in Gandcrab.
Updated: 2022-08-28
View profile →
Nemim
Technical ID: win.nemim
DarkHotel
MALWARE
Malware family identifying win.nemim. Origin and technical characteristics tracked via Malpedia.
Also known as: Nemain
Updated: 2020-09-15
View profile →
Nemesis
Technical ID: win.nemesis
MALWARE
Malware family identifying win.nemesis. Origin and technical characteristics tracked via Malpedia.
Also known as: Project Nemesis
Updated: 2023-07-19
View profile →
Nefilim
Technical ID: win.nefilim
MALWAREfinancialhigh
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
Also known as: Nephilim
Updated: 2022-07-28
View profile →
NedDnLoader
Technical ID: win.neddnloader
Lazarus Group
MALWARE
NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption. It sends detailed information about the victim's environment, like computer name, user name, type and free disk space of all drives, and a list of currently running processes. It uses three typical parameter names for HTTP POST requests: ned, gl, hl. The usual payload downloaded with NedDnLoader is Torisma. The internal DLL name of NedDnLoader is usually Dn.dll, Dn64.dll or DnDll.dll. It is deployed either as a standalone payload or within a trojanized MFC application project. It contains specific RTTI symbols like ".?AVCWininet_Protocol@@" or ".?AVCMFC_DLLApp@@".
Updated: 2023-11-27
View profile →
Necurs
Technical ID: win.necurs
MONTY SPIDER
MALWARE
Malware family identifying win.necurs. Origin and technical characteristics tracked via Malpedia.
Also known as: nucurs
Updated: 2023-10-18
View profile →
Neconyd
Technical ID: win.neconyd
MALWARE
Malware family identifying win.neconyd. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-05-21
View profile →
Nebulae
Technical ID: win.nebulae
Naikon
MALWARE
Malware family identifying win.nebulae. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-06-04
View profile →
nccTrojan
Technical ID: win.ncctrojan
TA428
MALWARE
Malware family identifying win.ncctrojan. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-11
View profile →
NavRAT
Technical ID: win.navrat
Kimsuky
MALWARE
Malware family identifying win.navrat. Origin and technical characteristics tracked via Malpedia.
Also known as: JinhoSpy
Updated: 2022-11-28
View profile →
Nautilus
Technical ID: win.nautilus
APT34Turla
MALWARE
Malware family identifying win.nautilus. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
Narilam
Technical ID: win.narilam
MALWARE
Malware family identifying win.narilam. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
NAPLISTENER
Technical ID: win.naplistener
MALWARE
Malware family identifying win.naplistener. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
NanoLocker
Technical ID: win.nano_locker
MALWARE
Malware family identifying win.nano_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Nanocore RAT
Technical ID: win.nanocore
APT33The Gorgon Group
MALWARE
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
Also known as: Nancrat • NanoCore
Updated: 2025-02-28
View profile →
← PreviousPage 150 / 269Next →