Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
NailaoLocker
Technical ID: win.nailao_locker
MALWAREfinancialhigh
According to Orange Cybwerdefense, NailaoLocker is a ransomware using AES-256-CTR mode, which conveniently logs its encryption activities into a log file.
MALWARE
Malware family identifying win.naikon. Origin and technical characteristics tracked via Malpedia.
Also known as: Sacto
Nagini
Technical ID: win.nagini
MALWARE
Malware family identifying win.nagini. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.
Also known as: Cyruslish • TWOPENCE • VIVACIOUSGIFT
Nabucur
Technical ID: win.nabucur
MALWARE
Malware family identifying win.nabucur. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →N40
Technical ID: win.n40
MALWARE
Botnet with focus on banks in Latin America and South America.
Relies on DLL Sideloading attacks to execute malicious DLL files.
Uses legitimate VMWare executable in attacks.
As of March 2019, the malware is under active development with updated versions coming out on persistent basis.
MZRevenge
Technical ID: win.mzrevenge
MALWARE
Malware family identifying win.mzrevenge. Origin and technical characteristics tracked via Malpedia.
Also known as: MaMo434376
Mystic Stealer
Technical ID: win.mystic_stealer
MALWARE
According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40 web browsers and more than 70 browser extensions, also targeting cryptocurrency wallets, Steam, and Telegram. The code is heavily obfuscated making use of polymorphic string obfuscation, hash-based import resolution, and runtime calculation of constants.
Mystic implements a custom binary protocol that is encrypted with RC4.
MysterySnail
Technical ID: win.mystery_snail
MALWARE
Malware family identifying win.mystery_snail. Origin and technical characteristics tracked via Malpedia.
MyloBot
Technical ID: win.mylobot
MALWARE
According to PCrisk, MyloBot is a high-risk trojan-type virus that allows cyber criminals to control the infected machine. MyloBot can be considered as a botnet, since all infected computers are connected to a single network. Depending on cyber criminals' goals, infected machines might be misused or have additional infections applied.
Also known as: FakeDGA • WillExec
MyKings Spreader
Technical ID: win.mykings_spreader
MALWARE
Malware family identifying win.mykings_spreader. Origin and technical characteristics tracked via Malpedia.
MyDoom
Technical ID: win.mydoom
MALWARE
When executed, the worm opens up Windows' Notepad with garbage data in it. When spreading, the infectious email used to distribute the worm copies use variable subjects, bodies and attachment names.
The worm encrypts most of the strings in it's UPX-packed body with ROT13 method, i.e. the characters are rotated 13 locations to the right in the abecedary, starting from the beginning if the position is beyond the last letter.
Mydoom also performs a Distributed Denial-of-Service attack on www.sco.com. This attack starts on 1st of February.
The worm opens up a backdoor to infected computers. This is done by planting a new SHIMGAPI.DLL file to system32 directory and launching it as a child process of EXPLORER.EXE.
Mydoom is programmed to stop spreading on February 12th.
Also known as: Novarg • Mimail
MALWARE
Malware family identifying win.mydogs. Origin and technical characteristics tracked via Malpedia.
Mutabaha
Technical ID: win.mutabaha
MALWARE
Malware family identifying win.mutabaha. Origin and technical characteristics tracked via Malpedia.
Murofet
Technical ID: win.murofet
MALWARE
According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family. It uses a Domain Generation Algorithm (DGA) to determine the current C2 domain names.
Also known as: Licat
MALWARE
a command-line reconnaissance tool. It can be used to execute files as a different user, move, and delete files locally, schedule remote AT jobs, perform host discovery on connected networks, scan for open ports on hosts in a connected network, and retrieve information about the OS, users, groups, and shares on remote hosts.
Multigrain POS
Technical ID: win.multigrain_pos
MALWARE
Malware family identifying win.multigrain_pos. Origin and technical characteristics tracked via Malpedia.
MulCom
Technical ID: win.mulcom
MALWARE
Malware family identifying win.mulcom. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.muddyc2go. Origin and technical characteristics tracked via Malpedia.
Msupedge
Technical ID: win.msupedge
MALWARE
Malware family identifying win.msupedge. Origin and technical characteristics tracked via Malpedia.
MrPeter
Technical ID: win.mr_peter
MALWARE
Malware family identifying win.mr_peter. Origin and technical characteristics tracked via Malpedia.
MrDec
Technical ID: win.mrdec
MALWAREfinancialhigh
Ransomware.
MALWARE
Malware family identifying win.mqsttang. Origin and technical characteristics tracked via Malpedia.
Also known as: QMAGENT
MALWARE
Malware family identifying win.mpkbot. Origin and technical characteristics tracked via Malpedia.
Also known as: MPK
mozart
Technical ID: win.mozart
MALWARE
According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected computer through the DNS protocol. This communication method helps cyber criminals to avoid detection via security software. Mozart is categorized as a malware loader and executes commands that cause download and installation of malicious software.
Moure
Technical ID: win.moure
MALWARE
Malware family identifying win.moure. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →MALWAREfinancialhigh
According to BlackBerry, MountLocker is a Ransomware-as-a-Service (RaaS), active since July 2020
The MountLocker ransomware was updated during early November 2020 to broaden the targeting of file types and evade security software.
Victim’s files are encrypted using ChaCha20, and file encryption keys are encrypted using RSA-2048.
The ransomware appears to be somewhat secure; there are no trivial weaknesses allowing for easy key recovery and decryption of data. MountLocker does however use a cryptographically insecure method for key generation that may be prone to attack.
Also known as: DagonLocker • MountLocker • QuantumLocker
MostereRAT
Technical ID: win.mostere_rat
MALWARE
According to Fortinet, this malware is written in Easy Programming Language (EPL), a Simplified-Chinese-based programming language designed to be beginner-friendly and easy to understand, especially for native Chinese speakers.
MALWARE
Malware family identifying win.mosquito. Origin and technical characteristics tracked via Malpedia.
Moserpass
Technical ID: win.moserpass
MALWARE
Malware family identifying win.moserpass. Origin and technical characteristics tracked via Malpedia.
MosaicRegressor
Technical ID: win.mosaic_regressor
MALWARE
Malware family identifying win.mosaic_regressor. Origin and technical characteristics tracked via Malpedia.
Morto
Technical ID: win.morto
MALWARE
Malware family identifying win.morto. Origin and technical characteristics tracked via Malpedia.
Mortis
Technical ID: win.mortis
MALWARE
Malware family identifying win.mortis. Origin and technical characteristics tracked via Malpedia.
MortalKombat
Technical ID: win.mortalkombat
MALWARE
Malware family identifying win.mortalkombat. Origin and technical characteristics tracked via Malpedia.
Morphine
Technical ID: win.morphine
MALWARE
Malware family identifying win.morphine. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-22
View profile →Morpheus Loader
Technical ID: win.morpheus_loader
MALWARE
Malware family identifying win.morpheus_loader. Origin and technical characteristics tracked via Malpedia.
Morpheus Loader
Technical ID: win.morpheus
MALWAREfinancialhigh
Ransomware. Identical samples (apart from note) operated by Morpheus and HellCat ransomware groups.
Moriya
Technical ID: win.moriya
MALWARE
This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that are marked as designated for the malware and respond to them. This forms a covert channel over which attackers are able to issue shell commands and receive back their outputs.
MALWARE
Malware family identifying win.moriagent. Origin and technical characteristics tracked via Malpedia.