Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MeltingClaw
Technical ID: win.meltingclaw
MALWARE
Malware family identifying win.meltingclaw. Origin and technical characteristics tracked via Malpedia.
Melcoz
Technical ID: win.melcoz
MALWARE
Malware family identifying win.melcoz. Origin and technical characteristics tracked via Malpedia.
Mekotio
Technical ID: win.mekotio
MALWARE
Malware family identifying win.mekotio. Origin and technical characteristics tracked via Malpedia.
MeguminTrojan
Technical ID: win.megumin
MALWARE
Megumin Trojan, is a malware focused on multiple fields (DDoS, Miner, Loader, Clipper).
MALWARE
Malware family identifying win.megacreep. Origin and technical characteristics tracked via Malpedia.
MegaCortex
Technical ID: win.megacortex
MALWAREfinancialhigh
Megacortex is a ransomware used in targeted attacks against corporations.
Once the ransomware is run it tries to stop security related services and after that it starts its own encryption process adding a .aes128ctr or .megac0rtx extension to the encrypted files. It is used to be carried from downloaders and trojans, it has no own propagation capabilities.
Meduza Stealer
Technical ID: win.meduza
MALWARE
Malware family identifying win.meduza. Origin and technical characteristics tracked via Malpedia.
MedusaHTTP
Technical ID: win.medusa_http
MALWARE
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
MedusaLocker
Technical ID: win.medusalocker
MALWAREfinancialhigh
A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.
Also known as: AKO Ransomware • AKO Doxware • MedusaReborn
Medusa
Technical ID: win.medusa
MALWAREfinancialhigh
According to Unit 42, Medusa surfaced as a ransomware-as-a-service (RaaS) platform in late 2022 and gained notoriety in early 2023, primarily targeting Windows environments. Medusa should not be confused with a similarly named RaaS, MedusaLocker, which has been available since 2019.
Medre
Technical ID: win.medre
MALWARE
Malware family identifying win.medre. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.mediapi. Origin and technical characteristics tracked via Malpedia.
Also known as: Eyeglass
MALWARE
Malware family identifying win.mechanical. Origin and technical characteristics tracked via Malpedia.
Also known as: GoldStamp
Mebromi
Technical ID: win.mebromi
MALWARE
Malware family identifying win.mebromi. Origin and technical characteristics tracked via Malpedia.
Also known as: MyBios
MBR Locker
Technical ID: win.mbrlocker
MALWAREfinancialhigh
Ransomware overwriting the system's MBR, making it impossible to boot into Windows.
MBRlock
Technical ID: win.mbrlock
MALWAREfinancialhigh
This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
Also known as: DexLocker
MALWAREfinancialhigh
Maze Ransomware encrypts files and makes them inaccessible while adding a custom extension containing part of the ID of the victim. The ransom note is placed inside a text file and an htm file. There are a few different extensions appended to files which are randomly generated.
Actors are known to exfiltrate the data from the network for further extortion. It spreads mainly using email spam and various exploit kits (Spelevo, Fallout).
The code of Maze ransomware is highly complicated and obfuscated, which helps to evade security solutions using signature-based detections.
Also known as: ChaCha
MALWARE
Malware family identifying win.mayberobot. Origin and technical characteristics tracked via Malpedia.
Also known as: SIMPLEFIX
Maxtrilha
Technical ID: win.maxtrilha
MALWAREfinancialhigh
Banking trojan written in Delphi, targeting customers of European and South American banks.
MALWARE
Malware family identifying win.maui. Origin and technical characteristics tracked via Malpedia.
Maudi
Technical ID: win.maudi
MALWARE
Specialized PoisonIvy Sideloader.
Matsnu
Technical ID: win.matsnu
MALWARE
Malware family identifying win.matsnu. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.matryoshka_rat. Origin and technical characteristics tracked via Malpedia.
Matrix Ransom
Technical ID: win.matrix_ransom
MALWAREfinancialhigh
Matrix is a ransomware that encrypts a victim's files and demands a ransom in cryptocurrency to decrypt them. It is distributed through phishing emails, hacking toolkits, and software downloaders. Matrix is a serious threat and can cause significant damage to a victim's data.
Matrix Banker
Technical ID: win.matrix_banker
MALWARE
Malware family identifying win.matrix_banker. Origin and technical characteristics tracked via Malpedia.
Matiex
Technical ID: win.matiex
MALWARE
Matiex Keylogger is being sold in the underground forums, due to their gained popularity, and can also be used as MaaS (Malware-as-a-service) because of their ease of use, competitive pricing and immediate response from support.
Matanbuchus
Technical ID: win.matanbuchus
MALWARE
According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS). This piece of software is designed to cause chain infections.
Since it is used as a MaaS, both the malware it infiltrates into systems, and the attack reasons can vary - depending on the cyber criminals operating it. Matanbuchus has been observed being used in attacks against US universities and high schools, as well as a Belgian high-tech organization.
MASS Logger
Technical ID: win.masslogger
MALWARE
MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed when identified. This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload.
MaskGramStealer
Technical ID: win.maskgramstealer
MALWARE
Malware family identifying win.maskgramstealer. Origin and technical characteristics tracked via Malpedia.
Masad Stealer
Technical ID: win.masad_stealer
MALWARE
Malware family identifying win.masad_stealer. Origin and technical characteristics tracked via Malpedia.
Mars Stealer
Technical ID: win.mars_stealer
MALWARE
3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto currencies and 2FA plugins.
Mars
Technical ID: win.mars
MALWAREfinancialhigh
Ransomware written in Delphi.
Also known as: MarsDecrypt
MarraCrypt
Technical ID: win.marracrypt
MALWARE
Malware family identifying win.marracrypt. Origin and technical characteristics tracked via Malpedia.
MarkiRAT
Technical ID: win.markirat
MALWARE
Malware family identifying win.markirat. Origin and technical characteristics tracked via Malpedia.
Mariposa
Technical ID: win.mariposa
MALWARE
Malware family identifying win.mariposa. Origin and technical characteristics tracked via Malpedia.
Also known as: Rimecud • Palevo • Autorun
Marap
Technical ID: win.marap
MALWARE
Marap is a downloader, named after its command and control (C&C) phone home parameter "param" spelled backwards. It is written in C and contains a few notable anti-analysis features.
MALWARE
Malware family identifying win.mapiget. Origin and technical characteristics tracked via Malpedia.
Maoloa
Technical ID: win.maoloa
MALWAREfinancialhigh
Ransomware family closely related to GlobeImposter, notable for its use of SHACAL-2 encryption algorithm.
Manjusaka
Technical ID: win.manjusaka
MALWARE
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
MALWARE
Malware family identifying win.manitsme. Origin and technical characteristics tracked via Malpedia.