Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Manifestus
Technical ID: win.manifestus_ransomware
MALWAREfinancialhigh
Malware family identifying win.manifestus_ransomware. Origin and technical characteristics tracked via Malpedia.
Mangzamel
Technical ID: win.mangzamel
Red Menshen
MALWARE
Malware family identifying win.mangzamel. Origin and technical characteristics tracked via Malpedia.
Also known as: junidor • mengkite • vedratve
Updated: 2022-08-30
View profile →
Mango
Technical ID: win.mango
OilRig
MALWARE
Malware family identifying win.mango. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-06
View profile →
ManameCrypt
Technical ID: win.manamecrypt
MALWARE
Malware family identifying win.manamecrypt. Origin and technical characteristics tracked via Malpedia.
Also known as: CryptoHost
Updated: 2018-02-05
View profile →
Mamba
Technical ID: win.mamba
MALWAREfinancialhigh
According to PCrisk, Mamba is an updated variant of high-risk ransomware called Phobos. After successful infiltration, Mamba encrypts stored files and appends filenames with the ".mamba" extension plus the victim's unique ID and developer's email address.
Also known as: HDDCryptor • DiskCryptor
Updated: 2023-05-26
View profile →
MalumPOS
Technical ID: win.malumpos
MALWARE
Malware family identifying win.malumpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-23
View profile →
Maktub
Technical ID: win.maktub
MALWAREfinancialhigh
According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.
Updated: 2023-05-26
View profile →
Makop Ransomware
Technical ID: win.makop_ransomware
MALWAREfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
Updated: 2023-03-13
View profile →
Makop
Technical ID: win.makop
MALWAREfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
Updated: 2023-08-14
View profile →
MakLoader
Technical ID: win.makloader
MALWARE
Malware family identifying win.makloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-03
View profile →
Makadocs
Technical ID: win.makadocs
Poseidon Group
MALWARE
Malware family identifying win.makadocs. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-20
View profile →
MajikPos
Technical ID: win.majik_pos
MALWARE
Malware family identifying win.majik_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-11-27
View profile →
Mail-O
Technical ID: win.mail_o
MALWARE
Malware family identifying win.mail_o. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
Mailto
Technical ID: win.mailto
MALWARE
Malware family identifying win.mailto. Origin and technical characteristics tracked via Malpedia.
Also known as: Koko Ransomware • NetWalker
Updated: 2022-04-07
View profile →
MAILCREEP
Technical ID: win.mailcreep
MALWARE
According to Zscaler, MAILCREEP is a Golang-based backdoor leveraging the Microsoft Graph API for its C2 communications.
Updated: 2026-01-29
View profile →
Magniber
Technical ID: win.magniber
MALWAREfinancialhigh
According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to conduct malvertising attacks against users in South Korea. However, it has remained active since then, continually updating its tactics by employing new obfuscation techniques and methods of evasion. In April 2022, Magniber gained notoriety for disguising itself as a Windows update file to lure victims into installing it. It then began spreading via JavaScript in September 2022.
Updated: 2024-01-31
View profile →
MagicRAT
Technical ID: win.magic_rat
Lazarus GroupSilent Chollima
MALWARE
According to Talos, MagicRAT is programmed in C++ programming language and uses the Qt Framework by statically linking it to the RAT on 32- and 64-bit versions. The Qt Framework is a programming library for developing graphical user interfaces, of which this RAT has none. Talos thinks that the objective was to increase the complexity of the code, thus making human analysis harder. On the other hand, since there are very few examples (if any) of malware programmed with Qt Framework, this also makes machine learning and heuristic analysis detection less reliable. The RAT uses the Qt classes throughout its entire code. The configuration is dynamically stored in a QSettings class eventually being saved to disk, a typical functionality provided by that class. MagicRAT provides the operator with a remote shell on the victim's system for arbitrary command execution, along with the ability to rename, move and delete files on the endpoint. The operator can determine the timing for the implant to sleep, change the C2 URLs and delete the implant from the infected system.
Updated: 2023-10-17
View profile →
Maggie
Technical ID: win.maggie
MALWARE
According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server. The backdoor has capabilities to bruteforce logins to other MSSQL servers, adding a special hardcoded backdoor user in the case of successfully bruteforcing admin logins.
Updated: 2022-10-30
View profile →
Magala
Technical ID: win.magala
MALWARE
Malware family identifying win.magala. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-01
View profile →
MadMax
Technical ID: win.madmax
MALWARE
Malware family identifying win.madmax. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →
Machete
Technical ID: win.machete
MALWARE
According to ESET, Machete’s dropper is a RAR SFX executable. Three py2exe components are dropped: GoogleCrash.exe, Chrome.exe and GoogleUpdate.exe. A single configuration file, jer.dll, is dropped, and it contains base64‑encoded text that corresponds to AES‑encrypted strings. GoogleCrash.exe is the main component of the malware. It schedules execution of the other two components and creates Windows Task Scheduler tasks to achieve persistence. Regarding the geolocation of victims, Chrome.exe collects data about nearby Wi-Fi networks and sends it to the Mozilla Location Service API. In short, this application provides geolocation coordinates when it’s given other sources of data such as Bluetooth beacons, cell towers or Wi-Fi access points. Then the malware takes latitude and longitude coordinates to build a Google Maps URL. The GoogleUpdate.exe component is responsible for communicating with the remote C&C server. The configuration to set the connection is read from the jer.dll file: domain name, username and password. The principal means of communication for Machete is via FTP, although HTTP communication was implemented as a fallback in 2019.
Also known as: El Machete
Updated: 2024-11-29
View profile →
Macaw
Technical ID: win.macaw
MALWARE
Malware family identifying win.macaw. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-01
View profile →
MACAMAX
Technical ID: win.macamax
1937CN
MALWARE
Malware family identifying win.macamax. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-27
View profile →
m0yv
Technical ID: win.m0yv
MALWAREfinancialhigh
Modular x86/x64 file infector created/used by Maze ransomware developer. According to the author, it has been mistakenly tagged by AVs as Expiro.
Updated: 2023-04-02
View profile →
M00nD3V Logger
Technical ID: win.m00nd3v
MALWAREespionageadvanced
According Zscaler, M00nD3V Logger has the ability to steal confidential information, such as browser passwords, FTP client passwords, email client passwords, DynDNS credentials, JDownloader credentials; capture Windows keystrokes; and gain access to the webcam and hook the clipboard. In all, it has the ability to steal passwords from 42 applications.
Updated: 2023-05-10
View profile →
Lyposit
Technical ID: win.lyposit
MALWARE
Malware family identifying win.lyposit. Origin and technical characteristics tracked via Malpedia.
Also known as: Lucky Locker • Adneukine • Bomba Locker
Updated: 2025-07-24
View profile →
Lynx
Technical ID: win.lynx
MALWAREfinancialhigh
According to Nextron, Lynx ransomware is a sophisticated malware threat that has been active since mid-2024. Lynx has claimed over 20 victims across a range of industries. Once it infiltrates a system, it encrypts critical files, appending a ‘.lynx’ extension, and deletes backup files like shadow copies to hinder recovery. Uniquely, it also sends the ransom note to available printers, adding an unexpected element to its attack strategy. This malware shares similarities with previous INC ransomware, indicating that they bought INC ransomware source code.
Updated: 2026-02-03
View profile →
Lyceum Golang HTTP Backdoor
Technical ID: win.lyceum_http_backdoor_golang
LYCEUM
MALWARE
This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA). This backdoor is running in a loop of three stages: - Check the connectivity - Registration of the victim - Retrieval and execution of commands This TA is using also variants .NET backdoors utilizing HTTP and DNS.
Updated: 2022-04-05
View profile →
Lyceum .NET TCP Backdoor
Technical ID: win.lyceum_http_backdoor_dotnet
LYCEUM
MALWARE
This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using DNS (.Net) and also one written in Golang.
Updated: 2022-04-05
View profile →
Lyceum .NET DNS Backdoor
Technical ID: win.lyceum_dns_backdoor_dotnet
LYCEUM
MALWARE
This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using HTTP (.Net) and also one written in Golang.
Updated: 2022-06-10
View profile →
Luzo
Technical ID: win.luzo
MALWARE
Malware family identifying win.luzo. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →
Luxy
Technical ID: win.luxy
MALWARE
Malware family identifying win.luxy. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-13
View profile →
Lurk
Technical ID: win.lurk
MALWARE
Malware family identifying win.lurk. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →
LunchMoney
Technical ID: win.lunchmoney
Leviathan
MALWARE
An uploader that can exfiltrate files to Dropbox.
Updated: 2019-03-10
View profile →
LunarMail
Technical ID: win.lunarmail
Turla
MALWARE
According to ESET Research, this is a Outlook Add-In that can use email messages for its C&C communication.
Updated: 2024-05-21
View profile →
Lumma Stealer
Technical ID: win.lumma
Angry Likho
MALWARE
Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell.
Also known as: LummaC2 Stealer
Updated: 2026-02-17
View profile →
Luminosity RAT
Technical ID: win.luminosity_rat
Operation C-Major
MALWARE
Malware family identifying win.luminosity_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: LuminosityLink
Updated: 2020-08-30
View profile →
Lumar
Technical ID: win.lumar
MALWARE
This family was previously tracked as PovertyStealer until it's actual name was identified via crime forums.
Also known as: PovertyStealer
Updated: 2024-10-21
View profile →
lukalocker
Technical ID: win.lukalocker
MALWARE
Malware family identifying win.lukalocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-06
View profile →
Lucifer
Technical ID: win.lucifer
MALWARE
Malware family identifying win.lucifer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-18
View profile →
← PreviousPage 155 / 269Next →