Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MoonWind
Technical ID: win.moonwind
MALWARE
Malware family identifying win.moonwind. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.moonwalk. Origin and technical characteristics tracked via Malpedia.
Also known as: CurveLast • SneakCross
MOONTAG
Technical ID: win.moontag
MALWARE
The malware, potentially named "MOON_TAG" by its developer as indicated by the strings within, is derived from code shared in a Google Group (https://groups.google.com/g/ph4nt0m/c/2J3_1XPeKD8/m/AYPoWudRcTAJ?pli=1). Each variant discovered possesses capabilities to communicate via the Microsoft Graph API. At this moment, it appears to be in development.
MoonPeak
Technical ID: win.moonpeak
MALWARE
According to Cisco Talos, this RAT is derived from the open source XenoRAT.
MALWARE
MoonBounce is a malware embedded into a modified UEFI firmware. Placed into SPI flash, it can provide persistence across full reinstall and even disk replacements. MoonBounce deploys user-mode malware through in-memory staging with a small footprint.
MontysThree
Technical ID: win.montysthree
MALWARE
Malware family identifying win.montysthree. Origin and technical characteristics tracked via Malpedia.
Also known as: MT3
MonsterV2
Technical ID: win.monsterv2
MALWARE
Malware family identifying win.monsterv2. Origin and technical characteristics tracked via Malpedia.
Also known as: Aurotun Stealer
MALWARE
Malware family identifying win.mongall. Origin and technical characteristics tracked via Malpedia.
Money Message
Technical ID: win.moneymessage
MALWAREfinancialhigh
A new ransomware gang hitting companies in worldwide firstly spotted by Zscaler.
Monero Miner
Technical ID: win.monero_miner
MALWARE
According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero CPU miner called xmrig.
Also known as: CoinMiner
MALWARE
Malware family identifying win.molerat_loader. Origin and technical characteristics tracked via Malpedia.
MALWARE
MoleNet is a .NET downloader malware used by the Molerats group in targeted attacks in the Middle East. Before downloading additional payloads, it first collects information about the infected machine using WMI queries and sends the data to its operators. It was first discovered in 2020, however, Cybereason researchers showed that it has been in use since at least 2019, with infrastructure that operated since 2017.
Mole
Technical ID: win.mole
MALWARE
Malware family identifying win.mole. Origin and technical characteristics tracked via Malpedia.
Mokes
Technical ID: win.mokes
MALWARE
Malware family identifying win.mokes. Origin and technical characteristics tracked via Malpedia.
Moker
Technical ID: win.moker
MALWARE
Malware family identifying win.moker. Origin and technical characteristics tracked via Malpedia.
Moisha Ransomware
Technical ID: win.moisha
MALWAREfinancialhigh
Moisha is a .NET-based ransomware that employs double extortion techniques to encrypt and exfiltrate data from victims. Upon execution, it creates a global mutex to ensure only one instance of the malware runs on the affected system. It then stops services such as backup and antivirus to avoid interference during the encryption process. Moisha disables real-time protection in Microsoft Defender and removes shadow copies using PowerShell and Vssadmin. It encrypts files on the system using RSA and AES encryption algorithms and places a ransom note in the affected directory. The note instructs victims to contact the attackers via a Moisha ID on TOX Messenger to negotiate the ransom. Additionally, Moisha spreads to other machines on the network and self-deletes using PowerShell command line.
Mofksys
Technical ID: win.mofksys
MALWARE
Malware family identifying win.mofksys. Origin and technical characteristics tracked via Malpedia.
ModPOS
Technical ID: win.modpos
MALWARE
Malware family identifying win.modpos. Origin and technical characteristics tracked via Malpedia.
Also known as: straxbot
ModPipe
Technical ID: win.modpipe
MALWARE
ModPipe is point-of-sale (POS) malware capable of accessing sensitive information stored in devices running ORACLE MICROS Restaurant Enterprise Series (RES) 3700 POS – a management software suite used by hundreds of thousands of bars, restaurants, hotels and other hospitality establishments worldwide. ModPipe uses modular architecture consisting of basic components and downloadable modules. One of them – named GetMicInfo – contains an algorithm designed to gather database passwords by decrypting them from Windows registry values. Exfiltrated credentials allow ModPipe's operators access to database contents, including various definitions and configuration, status tables and information about POS transactions.
MoDi RAT
Technical ID: win.modirat
MALWARE
Malware family identifying win.modirat. Origin and technical characteristics tracked via Malpedia.
ModernLoader
Technical ID: win.modern_loader
MALWARE
According to PCrisk, ModernLoader, also known as Avatar Bot and AvatarLoader, is a malicious program that has minimalistic loader and RAT (Remote Access Trojan) functionalities.
Loader-type malware is designed to infect devices with additional malicious programs, while RATs enable remote access/control over infected machines. ModernLoader is capable of executing basic commands and injecting malicious modules into systems.
Also known as: AvatarBot
Mocton
Technical ID: win.mocton
MALWARE
Malware family identifying win.mocton. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →MALWARE
LNK files used to lure and orchestrate execution of various scripts, interacting with the Mocky API service.
MobiRAT
Technical ID: win.mobi_rat
MALWARE
Malware family identifying win.mobi_rat. Origin and technical characteristics tracked via Malpedia.
MM Core
Technical ID: win.mm_core
MALWARE
Malware family identifying win.mm_core. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-06
View profile →MMON
Technical ID: win.mmon
MALWARE
Malware family identifying win.mmon. Origin and technical characteristics tracked via Malpedia.
Also known as: Kaptoxa
MALWARE
According to Proofpoint, MiyaRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. It is possibly authored by the same developer(s) as WmRAT.
Miuref
Technical ID: win.miuref
MALWARE
Malware family identifying win.miuref. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →MALWARE
Malware family identifying win.mistyveal. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable Executable (PE) files. The backdoor is a modification of the open-source Notepad++ binhex plugin v2.0.0.1 where the creation of a thread that executes the malicious code has been added to the DllMain function.
MISTCLOAK
Technical ID: win.mistcloak
MALWARE
Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW.
Also known as: HIUPAN
Mispadu
Technical ID: win.mispadu
MALWAREfinancialhigh
According to ESET Research, Mispadu is an ambitious Latin American banking trojan that utilizes McDonald’s malvertising and extends its attack surface to web browsers. It is used to target the general public and its main goals are monetary and credential theft. In Brazil, ESET has seen it distributing a malicious Google Chrome extension that attempts to steal credit card data and online banking data, and that compromises the Boleto payment system.
Also known as: URSA
Misha
Technical ID: win.misha
MALWARE
Undocumented information stealer targeting multiple browsers and cryptocurrences. Internal project name appears to be "misha".
Misfox
Technical ID: win.misfox
MALWARE
Malware family identifying win.misfox. Origin and technical characteristics tracked via Malpedia.
Also known as: Dromedan • MixFox • ModPack
Updated: 2024-06-05
View profile →MALWARE
Malware family identifying win.misdat. Origin and technical characteristics tracked via Malpedia.
MirrorKey
Technical ID: win.mirrorkey
MALWARE
According to Trend Micro, this is a loader for win.transbox, used by threat actor Earth Yako.
MALWARE
According to Minerva Labs, MirrorBlast malware is a trojan that is known for attacking users’ browsers. It usually pretends to be a legitimate browser add-on however it has now evolved additional capabilities, whereby other malwares are installed simultaneously. Recently, this trojan is thought to have tentative links to TA505 and PYSA groups.
Mirai
Technical ID: win.mirai
MALWARE
Malware family identifying win.mirai. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.miragefox. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.mirage. Origin and technical characteristics tracked via Malpedia.