Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Manifestus
Technical ID: win.manifestus_ransomware
MALWAREfinancialhigh
Malware family identifying win.manifestus_ransomware. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.mangzamel. Origin and technical characteristics tracked via Malpedia.
Also known as: junidor • mengkite • vedratve
MALWARE
Malware family identifying win.mango. Origin and technical characteristics tracked via Malpedia.
ManameCrypt
Technical ID: win.manamecrypt
MALWARE
Malware family identifying win.manamecrypt. Origin and technical characteristics tracked via Malpedia.
Also known as: CryptoHost
Mamba
Technical ID: win.mamba
MALWAREfinancialhigh
According to PCrisk, Mamba is an updated variant of high-risk ransomware called Phobos. After successful infiltration, Mamba encrypts stored files and appends filenames with the ".mamba" extension plus the victim's unique ID and developer's email address.
Also known as: HDDCryptor • DiskCryptor
MalumPOS
Technical ID: win.malumpos
MALWARE
Malware family identifying win.malumpos. Origin and technical characteristics tracked via Malpedia.
Maktub
Technical ID: win.maktub
MALWAREfinancialhigh
According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.
Makop Ransomware
Technical ID: win.makop_ransomware
MALWAREfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
Makop
Technical ID: win.makop
MALWAREfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
MakLoader
Technical ID: win.makloader
MALWARE
Malware family identifying win.makloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.makadocs. Origin and technical characteristics tracked via Malpedia.
MajikPos
Technical ID: win.majik_pos
MALWARE
Malware family identifying win.majik_pos. Origin and technical characteristics tracked via Malpedia.
Mail-O
Technical ID: win.mail_o
MALWARE
Malware family identifying win.mail_o. Origin and technical characteristics tracked via Malpedia.
Mailto
Technical ID: win.mailto
MALWARE
Malware family identifying win.mailto. Origin and technical characteristics tracked via Malpedia.
Also known as: Koko Ransomware • NetWalker
MAILCREEP
Technical ID: win.mailcreep
MALWARE
According to Zscaler, MAILCREEP is a Golang-based backdoor leveraging the Microsoft Graph API for its C2 communications.
Magniber
Technical ID: win.magniber
MALWAREfinancialhigh
According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to conduct malvertising attacks against users in South Korea. However, it has remained active since then, continually updating its tactics by employing new obfuscation techniques and methods of evasion. In April 2022, Magniber gained notoriety for disguising itself as a Windows update file to lure victims into installing it. It then began spreading via JavaScript in September 2022.
MALWARE
According to Talos, MagicRAT is programmed in C++ programming language and uses the Qt Framework by statically linking it to the RAT on 32- and 64-bit versions. The Qt Framework is a programming library for developing graphical user interfaces, of which this RAT has none. Talos thinks that the objective was to increase the complexity of the code, thus making human analysis harder. On the other hand, since there are very few examples (if any) of malware programmed with Qt Framework, this also makes machine learning and heuristic analysis detection less reliable. The RAT uses the Qt classes throughout its entire code. The configuration is dynamically stored in a QSettings class eventually being saved to disk, a typical functionality provided by that class.
MagicRAT provides the operator with a remote shell on the victim's system for arbitrary command execution, along with the ability to rename, move and delete files on the endpoint. The operator can determine the timing for the implant to sleep, change the C2 URLs and delete the implant from the infected system.
Maggie
Technical ID: win.maggie
MALWARE
According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server. The backdoor has capabilities to bruteforce logins to other MSSQL servers, adding a special hardcoded backdoor user in the case of successfully bruteforcing admin logins.
Magala
Technical ID: win.magala
MALWARE
Malware family identifying win.magala. Origin and technical characteristics tracked via Malpedia.
MadMax
Technical ID: win.madmax
MALWARE
Malware family identifying win.madmax. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →Machete
Technical ID: win.machete
MALWARE
According to ESET, Machete’s dropper is a RAR SFX executable. Three py2exe components are dropped: GoogleCrash.exe, Chrome.exe and GoogleUpdate.exe. A single configuration file, jer.dll, is dropped, and it contains base64‑encoded text that corresponds to AES‑encrypted strings.
GoogleCrash.exe is the main component of the malware. It schedules execution of the other two components and creates Windows Task Scheduler tasks to achieve persistence.
Regarding the geolocation of victims, Chrome.exe collects data about nearby Wi-Fi networks and sends it to the Mozilla Location Service API. In short, this application provides geolocation coordinates when it’s given other sources of data such as Bluetooth beacons, cell towers or Wi-Fi access points. Then the malware takes latitude and longitude coordinates to build a Google Maps URL.
The GoogleUpdate.exe component is responsible for communicating with the remote C&C server. The configuration to set the connection is read from the jer.dll file: domain name, username and password. The principal means of communication for Machete is via FTP, although HTTP communication was implemented as a fallback in 2019.
Also known as: El Machete
Macaw
Technical ID: win.macaw
MALWARE
Malware family identifying win.macaw. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.macamax. Origin and technical characteristics tracked via Malpedia.
m0yv
Technical ID: win.m0yv
MALWAREfinancialhigh
Modular x86/x64 file infector created/used by Maze ransomware developer. According to the author, it has been mistakenly tagged by AVs as Expiro.
M00nD3V Logger
Technical ID: win.m00nd3v
MALWAREespionageadvanced
According Zscaler, M00nD3V Logger has the ability to steal confidential information, such as browser passwords, FTP client passwords, email client passwords, DynDNS credentials, JDownloader credentials; capture Windows keystrokes; and gain access to the webcam and hook the clipboard. In all, it has the ability to steal passwords from 42 applications.
Lyposit
Technical ID: win.lyposit
MALWARE
Malware family identifying win.lyposit. Origin and technical characteristics tracked via Malpedia.
Also known as: Lucky Locker • Adneukine • Bomba Locker
Lynx
Technical ID: win.lynx
MALWAREfinancialhigh
According to Nextron, Lynx ransomware is a sophisticated malware threat that has been active since mid-2024. Lynx has claimed over 20 victims across a range of industries. Once it infiltrates a system, it encrypts critical files, appending a ‘.lynx’ extension, and deletes backup files like shadow copies to hinder recovery. Uniquely, it also sends the ransom note to available printers, adding an unexpected element to its attack strategy. This malware shares similarities with previous INC ransomware, indicating that they bought INC ransomware source code.
MALWARE
This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA). This backdoor is running in a loop of three stages:
- Check the connectivity
- Registration of the victim
- Retrieval and execution of commands
This TA is using also variants .NET backdoors utilizing HTTP and DNS.
MALWARE
This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using DNS (.Net) and also one written in Golang.
MALWARE
This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using HTTP (.Net) and also one written in Golang.
Luzo
Technical ID: win.luzo
MALWARE
Malware family identifying win.luzo. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →Luxy
Technical ID: win.luxy
MALWARE
Malware family identifying win.luxy. Origin and technical characteristics tracked via Malpedia.
Lurk
Technical ID: win.lurk
MALWARE
Malware family identifying win.lurk. Origin and technical characteristics tracked via Malpedia.
MALWARE
An uploader that can exfiltrate files to Dropbox.
MALWARE
According to ESET Research, this is a Outlook Add-In that can use email messages for its C&C communication.
MALWARE
Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell.
Also known as: LummaC2 Stealer
MALWARE
Malware family identifying win.luminosity_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: LuminosityLink
Lumar
Technical ID: win.lumar
MALWARE
This family was previously tracked as PovertyStealer until it's actual name was identified via crime forums.
Also known as: PovertyStealer
lukalocker
Technical ID: win.lukalocker
MALWARE
Malware family identifying win.lukalocker. Origin and technical characteristics tracked via Malpedia.
Lucifer
Technical ID: win.lucifer
MALWARE
Malware family identifying win.lucifer. Origin and technical characteristics tracked via Malpedia.