Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
MeltingClaw
Technical ID: win.meltingclaw
MALWARE
Malware family identifying win.meltingclaw. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-25
View profile →
Melcoz
Technical ID: win.melcoz
MALWARE
Malware family identifying win.melcoz. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
Mekotio
Technical ID: win.mekotio
MALWARE
Malware family identifying win.mekotio. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-13
View profile →
MeguminTrojan
Technical ID: win.megumin
MALWARE
Megumin Trojan, is a malware focused on multiple fields (DDoS, Miner, Loader, Clipper).
Updated: 2022-08-28
View profile →
MegaCreep
Technical ID: win.megacreep
POLONIUM
MALWARE
Malware family identifying win.megacreep. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-10-12
View profile →
MegaCortex
Technical ID: win.megacortex
MALWAREfinancialhigh
Megacortex is a ransomware used in targeted attacks against corporations. Once the ransomware is run it tries to stop security related services and after that it starts its own encryption process adding a .aes128ctr or .megac0rtx extension to the encrypted files. It is used to be carried from downloaders and trojans, it has no own propagation capabilities.
Updated: 2023-01-06
View profile →
Meduza Stealer
Technical ID: win.meduza
MALWARE
Malware family identifying win.meduza. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-24
View profile →
MedusaHTTP
Technical ID: win.medusa_http
MALWARE
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
Updated: 2026-01-12
View profile →
MedusaLocker
Technical ID: win.medusalocker
MALWAREfinancialhigh
A Windows ransomware that will run certain tasks to prepare the target system for the encryption of files. MedusaLocker avoids executable files, probably to avoid rendering the targeted system unusable for paying the ransom. It uses a combination of AES and RSA-2048, and reportedly appends extensions such as .encrypted, .bomber, .boroff, .breakingbad, .locker16, .newlock, .nlocker, and .skynet.
Also known as: AKO Ransomware • AKO Doxware • MedusaReborn
Updated: 2026-01-12
View profile →
Medusa
Technical ID: win.medusa
MALWAREfinancialhigh
According to Unit 42, Medusa surfaced as a ransomware-as-a-service (RaaS) platform in late 2022 and gained notoriety in early 2023, primarily targeting Windows environments. Medusa should not be confused with a similarly named RaaS, MedusaLocker, which has been available since 2019.
Updated: 2026-01-12
View profile →
Medre
Technical ID: win.medre
MALWARE
Malware family identifying win.medre. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
MediaPI
Technical ID: win.mediapi
Charming Kitten
MALWARE
Malware family identifying win.mediapi. Origin and technical characteristics tracked via Malpedia.
Also known as: Eyeglass
Updated: 2024-03-28
View profile →
MECHANICAL
Technical ID: win.mechanical
Kimsuky
MALWARE
Malware family identifying win.mechanical. Origin and technical characteristics tracked via Malpedia.
Also known as: GoldStamp
Updated: 2023-02-09
View profile →
Mebromi
Technical ID: win.mebromi
MALWARE
Malware family identifying win.mebromi. Origin and technical characteristics tracked via Malpedia.
Also known as: MyBios
Updated: 2018-06-28
View profile →
MBR Locker
Technical ID: win.mbrlocker
MALWAREfinancialhigh
Ransomware overwriting the system's MBR, making it impossible to boot into Windows.
Updated: 2021-11-22
View profile →
MBRlock
Technical ID: win.mbrlock
MALWAREfinancialhigh
This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
Also known as: DexLocker
Updated: 2018-03-01
View profile →
Maze
Technical ID: win.maze
FIN6TA2101
MALWAREfinancialhigh
Maze Ransomware encrypts files and makes them inaccessible while adding a custom extension containing part of the ID of the victim. The ransom note is placed inside a text file and an htm file. There are a few different extensions appended to files which are randomly generated. Actors are known to exfiltrate the data from the network for further extortion. It spreads mainly using email spam and various exploit kits (Spelevo, Fallout). The code of Maze ransomware is highly complicated and obfuscated, which helps to evade security solutions using signature-based detections.
Also known as: ChaCha
Updated: 2025-09-09
View profile →
MAYBEROBOT
Technical ID: win.mayberobot
Callisto
MALWARE
Malware family identifying win.mayberobot. Origin and technical characteristics tracked via Malpedia.
Also known as: SIMPLEFIX
Updated: 2025-11-10
View profile →
Maxtrilha
Technical ID: win.maxtrilha
MALWAREfinancialhigh
Banking trojan written in Delphi, targeting customers of European and South American banks.
Updated: 2021-09-14
View profile →
Maui Ransomware
Technical ID: win.maui
Silent Chollima
MALWARE
Malware family identifying win.maui. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-08
View profile →
Maudi
Technical ID: win.maudi
MALWARE
Specialized PoisonIvy Sideloader.
Updated: 2020-01-27
View profile →
Matsnu
Technical ID: win.matsnu
MALWARE
Malware family identifying win.matsnu. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-24
View profile →
Matryoshka RAT
Technical ID: win.matryoshka_rat
Rocket Kitten
MALWARE
Malware family identifying win.matryoshka_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-14
View profile →
Matrix Ransom
Technical ID: win.matrix_ransom
MALWAREfinancialhigh
Matrix is a ransomware that encrypts a victim's files and demands a ransom in cryptocurrency to decrypt them. It is distributed through phishing emails, hacking toolkits, and software downloaders. Matrix is a serious threat and can cause significant damage to a victim's data.
Updated: 2023-07-24
View profile →
Matrix Banker
Technical ID: win.matrix_banker
MALWARE
Malware family identifying win.matrix_banker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-07-11
View profile →
Matiex
Technical ID: win.matiex
MALWARE
Matiex Keylogger is being sold in the underground forums, due to their gained popularity, and can also be used as MaaS (Malware-as-a-service) because of their ease of use, competitive pricing and immediate response from support.
Updated: 2022-07-01
View profile →
Matanbuchus
Technical ID: win.matanbuchus
MALWARE
According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS). This piece of software is designed to cause chain infections. Since it is used as a MaaS, both the malware it infiltrates into systems, and the attack reasons can vary - depending on the cyber criminals operating it. Matanbuchus has been observed being used in attacks against US universities and high schools, as well as a Belgian high-tech organization.
Updated: 2024-11-25
View profile →
MASS Logger
Technical ID: win.masslogger
MALWARE
MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed when identified. This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload.
Updated: 2026-02-03
View profile →
MaskGramStealer
Technical ID: win.maskgramstealer
MALWARE
Malware family identifying win.maskgramstealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-05
View profile →
Masad Stealer
Technical ID: win.masad_stealer
MALWARE
Malware family identifying win.masad_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-03
View profile →
Mars Stealer
Technical ID: win.mars_stealer
MALWARE
3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto currencies and 2FA plugins.
Updated: 2024-11-26
View profile →
Mars
Technical ID: win.mars
MALWAREfinancialhigh
Ransomware written in Delphi.
Also known as: MarsDecrypt
Updated: 2022-09-07
View profile →
MarraCrypt
Technical ID: win.marracrypt
MALWARE
Malware family identifying win.marracrypt. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-26
View profile →
MarkiRAT
Technical ID: win.markirat
MALWARE
Malware family identifying win.markirat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-21
View profile →
Mariposa
Technical ID: win.mariposa
MALWARE
Malware family identifying win.mariposa. Origin and technical characteristics tracked via Malpedia.
Also known as: Rimecud • Palevo • Autorun
Updated: 2019-10-09
View profile →
Marap
Technical ID: win.marap
MALWARE
Marap is a downloader, named after its command and control (C&C) phone home parameter "param" spelled backwards. It is written in C and contains a few notable anti-analysis features.
Updated: 2020-08-28
View profile →
MAPIget
Technical ID: win.mapiget
Comment Crew
MALWARE
Malware family identifying win.mapiget. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
Maoloa
Technical ID: win.maoloa
MALWAREfinancialhigh
Ransomware family closely related to GlobeImposter, notable for its use of SHACAL-2 encryption algorithm.
Updated: 2023-05-30
View profile →
Manjusaka
Technical ID: win.manjusaka
MALWARE
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
Updated: 2022-08-22
View profile →
ManItsMe
Technical ID: win.manitsme
Comment Crew
MALWARE
Malware family identifying win.manitsme. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
← PreviousPage 154 / 269Next →