Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,718 entities
APT GROUPfinancialhigh
ESET reports that Vadokrist is a Latin American banking trojan that they have been tracking since 2018 and that is active almost exclusively in Brazil.
APT GROUP
Malware family tracked by Malpedia. ID: win.usbferry
APT GROUP
According to Kaspersky, USBCulprit is a malware that is capable of scanning various paths in victim machines, collecting documents with particular extensions and passing them on to USB drives when they are connected to the system. It can also selectively copy itself to a removable drive in the presence of a particular file, suggesting it can be spread laterally by having designated drives infected and the executable in them opened manually.
APT GROUP
Malware family tracked by Malpedia. ID: win.urlzone
APT GROUP
Malware family tracked by Malpedia. ID: win.urausy
APT GROUP
Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for delivering further malware to the victims, in specific upatre was a prolific delivery mechanism for Gameover P2P in 2013-2014 and then for Dyre in 2015.
APT GROUP
Malware family tracked by Malpedia. ID: win.upas
APT GROUP
Malware family tracked by Malpedia. ID: win.unlock92
This malware uses Azure Functions as its C2.
An infostealer written in Go.
According to Datadog, this malware functions primarily as a credential and infostealer. It enumerates LevelDB files within application data directories for Discord, Chromium-based browsers, cryptocurrency wallets, and Electron applications.
unidentified_121 acts as a downloader and reflective PE loader, employing a dual-mode execution strategy based on its privilege level. When executed without administrative rights, it uniquely attempts to bypass User Account Control (UAC) by first patching its own Process Environment Block (PEB) in memory to masquerade as explorer.exe, and then leveraging a specific COM object ({3E5FC7F9-9A51-4367-9063-A120244FBEC7} with the Elevation:Administrator!new: moniker) to relaunch itself with elevated privileges. This initial stage focuses purely on achieving elevation and does not perform C2 communication or direct payload execution itself in the non-elevated state. Once running with administrative privileges (either initially or after successful elevation), the malware establishes persistence by creating a Scheduled Task named "BlaBlaAgu" using COM, configuring it to run with the highest privileges and repeat every five minutes indefinitely. It actively evades defenses by using PowerShell commands (Add-MpPreference) to add Windows Defender exclusions for its own process and the user's profile directory, reinforcing these exclusions every 60 seconds via a separate thread. Its primary function in this elevated state is to act as a downloader, connecting to its Command and Control (C2) server over TCP port 33334 using a custom protocol encrypted with an RC4-like cipher and the hardcoded key "ALB9SxZBzCqwPFnD"; after a distinct 20-byte client handshake (RC4 Key + integer 444, followed by a 16-byte server response (RC4 Key) for validation), it downloads further encrypted PE payloads and executes them reflectively in its own memory space.
According to Deutsche Telekom CERT, this malware unpacks an obfuscated, multi-stage shellcode payload. After unpacking, a password prompt is displayed to the user. The password is provided to the victim and used to decrypt the final stage payload.
Malware family tracked by Malpedia. ID: win.unidentified_118
Malware family tracked by Malpedia. ID: win.unidentified_117
This malware family delivers its artifacts packed with free and generic packers. It writes files to windows temporary folders, downloads additional malware (generally cryptominers) and deletes itself.
Updated: 2024-08-29
View profile →
According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that will download/decrypt a payload via AES CFB and inject it into a hardcoded process target (e.g. explorer.exe).
According to Trend Micro, this is a small information stealer written in .NET, that pushes its loot to a benign file sharing service and does not have a direct C&C callback.
APT GROUPespionageadvanced
According to Phylum, this is a RAT with these characteristics: * Registers as a scheduled task. * Receives commands from a remote server using web sockets. * Installs Chrome extensions to Secure Preferences. * Configures AnyDesk, hides the screen, and disables shutting down Windows. * Captures keyboard and mouse events. * Collects information about files, browser extensions, and browser history.
APT GROUPespionageadvanced
A Rust-based stealer, observed by Seqrite, along TTPs overlapping with Pakistan-linked APT groups.
According to Deep Instinct, this information stealer is written in Rust and was observed in Operation Rusty Flag.
Malware family tracked by Malpedia. ID: win.unidentified_109
Malware family tracked by Malpedia. ID: win.unidentified_108
APT GROUPespionageadvanced
Small shellcode downloader, likely used by APT29.
This is possibly related to the MATA framework / Dacls.
Malware family tracked by Malpedia. ID: win.unidentified_105
Malware family tracked by Malpedia. ID: win.unidentified_104
APT GROUPfinancialhigh
A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to in coverage on WHITERABBIT ransomware attacks.
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
Updated: 2023-07-24
View profile →
Potential Lazarus sample.
Malware family tracked by Malpedia. ID: win.unidentified_100
APT GROUPespionageadvanced
This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations. It is different from win.boombox, which is another APT29 attributed malware using DropBox (written in .NET).
Malware family tracked by Malpedia. ID: win.unidentified_098
Malware family tracked by Malpedia. ID: win.unidentified_097
Keylogger.
Updated: 2025-10-15
View profile →
Wiper, using EldoS RawDisk for low level access to disks.
Check Point Research observed this malware being used by Sidewinder.
APT GROUPespionageadvanced
According to Antiy CERT, this is a C++ backdoor that was first discovered in an attack by Confucius in September 2020. Its main functions include creating scheduled tasks, retrieving process information, retrieving network adapter information, retrieving disk drive information, uploading files, downloading files, executing files, and providing shell access.
Avast found this unidentified RAT, which abuses a code-signing certificate by the Philippine Navy. It is statically linked against OpenSSL 1.1.1g.
Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
Updated: 2023-07-24
View profile →