Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MintStealer
Technical ID: win.mintstealer
MALWARE
Malware family identifying win.mintstealer. Origin and technical characteristics tracked via Malpedia.
MALWARE
miniTYPEFRAME is a variant of TYPEFRAME, a RAT for Windows.
Its functionality is reduced to serve mostly as a proxy module. Its commands are indexed by 16-bit integers, usually in the range 0x8027–0x8044.
MiniStealer
Technical ID: win.ministealer
MALWARE
Malware family identifying win.ministealer. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.minipocket. Origin and technical characteristics tracked via Malpedia.
MiniJunk
Technical ID: win.minijunk
MALWARE
Malware family identifying win.minijunk. Origin and technical characteristics tracked via Malpedia.
MALWARE
The MiniDuke toolset consists of multiple downloader and backdoor components
MINIBUS
Technical ID: win.minibus
MALWARE
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
MiniBrowse
Technical ID: win.minibrowse
MALWARE
Malware family identifying win.minibrowse. Origin and technical characteristics tracked via Malpedia.
MALWARE
miniBlindingCan is an HTTP(S) orchestrator.
It is a variant of the BlindingCan RAT, having the same command parsing logic, but supporting only a small subset of commands available previously. The main operations are the update of the malware configuration, and the download and execution of additional payloads from the attackers' C&C.
The miniBlindingCan malware was used in Operation DreamJob attacks against aerospace and media companies in Q2-Q3 2022.
Also known as: AIRDRY.V2 • EventHorizon
MINIBIKE
Technical ID: win.minibike
MALWARE
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
MALWARE
Malware family identifying win.miniasp. Origin and technical characteristics tracked via Malpedia.
MINEBRIDGE
Technical ID: win.minebridge
MALWARE
Malware family identifying win.minebridge. Origin and technical characteristics tracked via Malpedia.
Also known as: GazGolder
Mindware
Technical ID: win.mindware
MALWAREfinancialhigh
Ransomware, potential rebranding of win.sfile.
MALWARE
Varonis summarizes Mimikatz as an open-source application that allows users to view and save authentication credentials like Kerberos tickets. Benjamin Delpy continues to lead Mimikatz developments, so the toolset works with the current release of Windows and includes the most up-to-date attacks.
Attackers commonly use Mimikatz to steal credentials and escalate privileges: in most cases, endpoint protection software and anti-virus systems will detect and delete it. Conversely, pentesters use Mimikatz to detect and exploit vulnerabilities in your networks so you can fix them.
Mimic Ransomware
Technical ID: win.mimic
MALWAREfinancialhigh
According to PCrisk, Mimic is a ransomware-type program. Malware within this classification is designed to encrypt data and demand ransoms for decryption. Evidence suggests that Mimic is based on the leaked CONTI ransomware builder. Mimic campaigns have been observed targeting English and Russian speaking users.
MALWARE
Malware family identifying win.mim221. Origin and technical characteristics tracked via Malpedia.
Milum
Technical ID: win.milum
MALWARE
In August 2019, Kaspersky Labs discovered a malware they dubbed Milum (naming based on internal file name fragments) when investigating an operation they named WildPressure. It is written in C++ using STL, primarily to parse JSON. Functionality includes bidirectional file transmission and remote command execution.
MALWARE
Malware family identifying win.milkmaid. Origin and technical characteristics tracked via Malpedia.
Milan
Technical ID: win.milan
MALWARE
Malware family identifying win.milan. Origin and technical characteristics tracked via Malpedia.
Mikoponi
Technical ID: win.mikoponi
MALWARE
Malware family identifying win.mikoponi. Origin and technical characteristics tracked via Malpedia.
Midas
Technical ID: win.midas
MALWAREfinancialhigh
This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler). This ransomware features also its own data leak site as part of its double extortion strategy.
MALWARE
This malware written in Delphi is an information stealing malware family dubbed "MICROPSIA". It has s wide range of data theft functionality built in.
Microcin
Technical ID: win.microcin
MALWARE
Malware family identifying win.microcin. Origin and technical characteristics tracked via Malpedia.
MALWARE
Open-source lightweight backdoor for C2 communication.
GitHub: https://github.com/Cr4sh/MicroBackdoor
Micrass
Technical ID: win.micrass
MALWARE
Malware family identifying win.micrass. Origin and technical characteristics tracked via Malpedia.
Miancha
Technical ID: win.miancha
MALWARE
Malware family identifying win.miancha. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →MgBot
Technical ID: win.mgbot
MALWARE
Malware family identifying win.mgbot. Origin and technical characteristics tracked via Malpedia.
Also known as: BLame • MgmBot • POCOSTICK
Mewsei
Technical ID: win.mewsei
MALWARE
Malware family identifying win.mewsei. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →Mevade
Technical ID: win.mevade
MALWARE
A botnet that used Tor .onion links for C&C.
Also known as: Sefnit • SBC
Meterpreter
Technical ID: win.meterpreter
MALWARE
Malware family identifying win.meterpreter. Origin and technical characteristics tracked via Malpedia.
Meteor
Technical ID: win.meteor
MALWARE
A wiper used in an attack against the Iranian train system.
MALWARE
On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available for sale for USD125 per month or USD1000 for unlimited use. The actor claimed it has the same functionality, code, and panel as the Redline stealer, but with several improvements.
Metamorfo
Technical ID: win.metamorfo
MALWAREfinancialhigh
According to BitDefender, Metamorfo is a family of banker Trojans that has been active since mid-2018. It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments. Metamorfo is a potent piece of malware, whose primary capability is theft of banking information and other personal data from the user and exfiltration of it to the C2 server.
Also known as: Casbaneiro
MALWARE
Malware family identifying win.metaljack. Origin and technical characteristics tracked via Malpedia.
Also known as: denesRAT
Mespinoza
Technical ID: win.mespinoza
MALWAREfinancialhigh
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
Also known as: pysa
Merlin
Technical ID: win.merlin
MALWARE
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Merdoor
Technical ID: win.merdoor
MALWARE
Malware family identifying win.merdoor. Origin and technical characteristics tracked via Malpedia.
MercurialGrabber
Technical ID: win.mercurialgrabber
MALWARE
Malware family identifying win.mercurialgrabber. Origin and technical characteristics tracked via Malpedia.
Meow
Technical ID: win.meow
MALWAREfinancialhigh
According to PCrisk, MEOW is ransomware based on other ransomware called CONTI. MEOW encrypts files and appends the ".MEOW" extension to their filenames. It also drops the "readme.txt" file (a ransom note). An example of how MEOW ransomware modifies filenames: it renames "1.jpg" to "1.jpg.MEOW", "2.png" to "2.png.MEOW", and so forth.