Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
NailaoLocker
Technical ID: win.nailao_locker
MALWAREfinancialhigh
According to Orange Cybwerdefense, NailaoLocker is a ransomware using AES-256-CTR mode, which conveniently logs its encryption activities into a log file.
Updated: 2025-03-05
View profile →
Naikon
Technical ID: win.naikon
Naikon
MALWARE
Malware family identifying win.naikon. Origin and technical characteristics tracked via Malpedia.
Also known as: Sacto
Updated: 2021-08-09
View profile →
Nagini
Technical ID: win.nagini
MALWARE
Malware family identifying win.nagini. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
NACHOCHEESE
Technical ID: win.nachocheese
Lazarus Group
MALWARE
According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.
Also known as: Cyruslish • TWOPENCE • VIVACIOUSGIFT
Updated: 2023-08-31
View profile →
Nabucur
Technical ID: win.nabucur
MALWARE
Malware family identifying win.nabucur. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →
N40
Technical ID: win.n40
MALWARE
Botnet with focus on banks in Latin America and South America. Relies on DLL Sideloading attacks to execute malicious DLL files. Uses legitimate VMWare executable in attacks. As of March 2019, the malware is under active development with updated versions coming out on persistent basis.
Updated: 2019-03-05
View profile →
MZRevenge
Technical ID: win.mzrevenge
MALWARE
Malware family identifying win.mzrevenge. Origin and technical characteristics tracked via Malpedia.
Also known as: MaMo434376
Updated: 2020-03-27
View profile →
Mystic Stealer
Technical ID: win.mystic_stealer
MALWARE
According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40 web browsers and more than 70 browser extensions, also targeting cryptocurrency wallets, Steam, and Telegram. The code is heavily obfuscated making use of polymorphic string obfuscation, hash-based import resolution, and runtime calculation of constants. Mystic implements a custom binary protocol that is encrypted with RC4.
Updated: 2023-07-11
View profile →
MysterySnail
Technical ID: win.mystery_snail
MALWARE
Malware family identifying win.mystery_snail. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-27
View profile →
MyloBot
Technical ID: win.mylobot
MALWARE
According to PCrisk, MyloBot is a high-risk trojan-type virus that allows cyber criminals to control the infected machine. MyloBot can be considered as a botnet, since all infected computers are connected to a single network. Depending on cyber criminals' goals, infected machines might be misused or have additional infections applied.
Also known as: FakeDGA • WillExec
Updated: 2023-11-17
View profile →
MyKings Spreader
Technical ID: win.mykings_spreader
MALWARE
Malware family identifying win.mykings_spreader. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-25
View profile →
MyDoom
Technical ID: win.mydoom
MALWARE
When executed, the worm opens up Windows' Notepad with garbage data in it. When spreading, the infectious email used to distribute the worm copies use variable subjects, bodies and attachment names. The worm encrypts most of the strings in it's UPX-packed body with ROT13 method, i.e. the characters are rotated 13 locations to the right in the abecedary, starting from the beginning if the position is beyond the last letter. Mydoom also performs a Distributed Denial-of-Service attack on www.sco.com. This attack starts on 1st of February. The worm opens up a backdoor to infected computers. This is done by planting a new SHIMGAPI.DLL file to system32 directory and launching it as a child process of EXPLORER.EXE. Mydoom is programmed to stop spreading on February 12th.
Also known as: Novarg • Mimail
Updated: 2025-06-20
View profile →
MyDogs
Technical ID: win.mydogs
Kimsuki
MALWARE
Malware family identifying win.mydogs. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-03
View profile →
Mutabaha
Technical ID: win.mutabaha
MALWARE
Malware family identifying win.mutabaha. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Murofet
Technical ID: win.murofet
MALWARE
According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family. It uses a Domain Generation Algorithm (DGA) to determine the current C2 domain names.
Also known as: Licat
Updated: 2024-09-04
View profile →
murkytop
Technical ID: win.murkytop
Leviathan
MALWARE
a command-line reconnaissance tool. It can be used to execute files as a different user, move, and delete files locally, schedule remote AT jobs, perform host discovery on connected networks, scan for open ports on hosts in a connected network, and retrieve information about the OS, users, groups, and shares on remote hosts.
Updated: 2020-05-23
View profile →
Multigrain POS
Technical ID: win.multigrain_pos
MALWARE
Malware family identifying win.multigrain_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-07
View profile →
MulCom
Technical ID: win.mulcom
MALWARE
Malware family identifying win.mulcom. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-26
View profile →
MuddyC2Go
Technical ID: win.muddyc2go
MuddyWater
MALWARE
Malware family identifying win.muddyc2go. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-08
View profile →
Msupedge
Technical ID: win.msupedge
MALWARE
Malware family identifying win.msupedge. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-09
View profile →
MrPeter
Technical ID: win.mr_peter
MALWARE
Malware family identifying win.mr_peter. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
MrDec
Technical ID: win.mrdec
MALWAREfinancialhigh
Ransomware.
Updated: 2020-03-27
View profile →
MRAC
Technical ID: win.mrac
MALWAREfinancialhigh
Ransomware.
Updated: 2022-02-01
View profile →
MQsTTang
Technical ID: win.mqsttang
MUSTANG PANDA
MALWARE
Malware family identifying win.mqsttang. Origin and technical characteristics tracked via Malpedia.
Also known as: QMAGENT
Updated: 2023-09-08
View profile →
MPKBot
Technical ID: win.mpkbot
Magic HoundRocket Kitten
MALWARE
Malware family identifying win.mpkbot. Origin and technical characteristics tracked via Malpedia.
Also known as: MPK
Updated: 2019-02-17
View profile →
mozart
Technical ID: win.mozart
MALWARE
According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected computer through the DNS protocol. This communication method helps cyber criminals to avoid detection via security software. Mozart is categorized as a malware loader and executes commands that cause download and installation of malicious software.
Updated: 2023-05-26
View profile →
Moure
Technical ID: win.moure
MALWARE
Malware family identifying win.moure. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →
Mount Locker
Technical ID: win.mount_locker
Vanilla Tempest
MALWAREfinancialhigh
According to BlackBerry, MountLocker is a Ransomware-as-a-Service (RaaS), active since July 2020 The MountLocker ransomware was updated during early November 2020 to broaden the targeting of file types and evade security software. Victim’s files are encrypted using ChaCha20, and file encryption keys are encrypted using RSA-2048. The ransomware appears to be somewhat secure; there are no trivial weaknesses allowing for easy key recovery and decryption of data. MountLocker does however use a cryptographically insecure method for key generation that may be prone to attack.
Also known as: DagonLocker • MountLocker • QuantumLocker
Updated: 2025-07-28
View profile →
MostereRAT
Technical ID: win.mostere_rat
MALWARE
According to Fortinet, this malware is written in Easy Programming Language (EPL), a Simplified-Chinese-based programming language designed to be beginner-friendly and easy to understand, especially for native Chinese speakers.
Updated: 2025-09-09
View profile →
Mosquito
Technical ID: win.mosquito
Turla
MALWARE
Malware family identifying win.mosquito. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-19
View profile →
Moserpass
Technical ID: win.moserpass
MALWARE
Malware family identifying win.moserpass. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-04
View profile →
MosaicRegressor
Technical ID: win.mosaic_regressor
MALWARE
Malware family identifying win.mosaic_regressor. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
Morto
Technical ID: win.morto
MALWARE
Malware family identifying win.morto. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
Mortis
Technical ID: win.mortis
MALWARE
Malware family identifying win.mortis. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-05
View profile →
MortalKombat
Technical ID: win.mortalkombat
MALWARE
Malware family identifying win.mortalkombat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-15
View profile →
Morphine
Technical ID: win.morphine
MALWARE
Malware family identifying win.morphine. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-22
View profile →
Morpheus Loader
Technical ID: win.morpheus_loader
MALWARE
Malware family identifying win.morpheus_loader. Origin and technical characteristics tracked via Malpedia.
Morpheus Loader
Technical ID: win.morpheus
MALWAREfinancialhigh
Ransomware. Identical samples (apart from note) operated by Morpheus and HellCat ransomware groups.
Updated: 2025-08-19
View profile →
Moriya
Technical ID: win.moriya
MALWARE
This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that are marked as designated for the malware and respond to them. This forms a covert channel over which attackers are able to issue shell commands and receive back their outputs.
Updated: 2025-05-22
View profile →
MoriAgent
Technical ID: win.moriagent
MuddyWater
MALWARE
Malware family identifying win.moriagent. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-19
View profile →
← PreviousPage 151 / 269Next →