Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,744 entities
HZ RAT
Technical ID: win.hzrat
MALWARE
Malware family identifying win.hzrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-11-18
View profile →
HyperSSL
Technical ID: win.hyperssl
EMISSARY PANDA
MALWARE
Sideloader used by EmissaryPanda
Also known as: FOCUSFJORD • Soldier • Sysupdate
Updated: 2025-06-20
View profile →
HYPERSCRAPE
Technical ID: win.hyperscrape
MALWARE
Malware family identifying win.hyperscrape. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-25
View profile →
HyperBro
Technical ID: win.hyperbro
EMISSARY PANDA
MALWARE
HyperBro is a RAT that has been observed to target primarily within the gambling industries, though it has been spotted in other places as well. The malware typically consists of 3 or more components: a) a genuine loader typically with a signed certification b) a malicious DLL loader loaded from the former component via DLL hijacking c) an encrypted and compressed blob that decrypts to a PE-based payload which has its C2 information hardcoded within.
Updated: 2024-10-15
View profile →
HxDef
Technical ID: win.hxdef
MALWARE
Malware family identifying win.hxdef. Origin and technical characteristics tracked via Malpedia.
Also known as: HacDef • HackerDefender • HackDef
Updated: 2020-03-19
View profile →
Hussar
Technical ID: win.hussar
Calypso group
MALWARE
Malware family identifying win.hussar. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-11-12
View profile →
HuskLoader
Technical ID: win.huskloader
MALWARE
Malware family identifying win.huskloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-28
View profile →
Hupigon
Technical ID: win.hupigon
MALWARE
Malware family identifying win.hupigon. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-02
View profile →
Hunters International
Technical ID: win.hunters_international
Storm-0501
MALWAREfinancialhigh
Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet controversial threat actor in the cybercrime ecosystem. While initial analysis revealed a code overlap with the dismantled Hive ransomware, the group claims independence, asserting it purchased Hive’s source code rather than directly rebranding. This operational lineage enables advanced double-extortion campaigns prioritizing data exfiltration over encryption, with confirmed theft of medical records, financial data, and proprietary business information. The group's ransomware is written in Rust, a programming language favored for its resilience to reverse engineering and cross-platform compatibility.
Updated: 2025-05-19
View profile →
Hunter Stealer
Technical ID: win.hunter
MALWARE
Malware family identifying win.hunter. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-12
View profile →
HUI Loader
Technical ID: win.hui_loader
MALWARE
A loader that has been used by multiple threat actor groups since 2015.
Also known as: SIDESTEP
Updated: 2026-01-28
View profile →
http_troy
Technical ID: win.http_troy
MALWARE
Malware family identifying win.http_troy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-19
View profile →
HTTP(S) uploader
Technical ID: win.httpsuploader
Lazarus Group
MALWARE
The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols. It accepts up to 10 command line parameters: a 29-byte decryption key, a C&C for data exfiltration, the name of a local RAR split volume, the name of the multivolume archive on the server side, the size of a RAR split (max 200,000 kB), the starting index of a split, the ending index of a split, and the switch -p with a proxy IP address and port
Updated: 2023-11-27
View profile →
HTTPSnoop
Technical ID: win.httpsnoop
MALWARE
Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the infected endpoint.
Also known as: TOFULOAD
Updated: 2024-10-25
View profile →
httpdropper
Technical ID: win.httpdropper
MALWARE
Malware family identifying win.httpdropper. Origin and technical characteristics tracked via Malpedia.
Also known as: httpdr0pper
Updated: 2018-09-13
View profile →
HttpBrowser
Technical ID: win.httpbrowser
WekbyEMISSARY PANDA
MALWARE
Malware family identifying win.httpbrowser. Origin and technical characteristics tracked via Malpedia.
Also known as: HttpDump
Updated: 2022-07-05
View profile →
HTran
Technical ID: win.htran
GALLIUMUPS
MALWARE
Malware family identifying win.htran. Origin and technical characteristics tracked via Malpedia.
Also known as: HUC Packet Transmit Tool • lcx
Updated: 2025-07-08
View profile →
htpRAT
Technical ID: win.htprat
MALWARE
Malware family identifying win.htprat. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-12-13
View profile →
HtBot
Technical ID: win.htbot
MALWARE
Malware family identifying win.htbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-29
View profile →
Houdini
Technical ID: win.houdini
MALWARE
Houdini is a VBS-based RAT dating back to 2013. Past in the days, it used to be wrapped in an .exe but started being spamvertized or downloaded by other malware directly as .vbs in 2018. In 2019, WSHRAT appeared, a Javascript-based version of Houdini, recoded by the name of Kognito.
Also known as: Hworm • Jenxcus • Kognito • Njw0rm • WSHRAT
Updated: 2023-11-17
View profile →
HOTWAX
Technical ID: win.hotwax
Lazarus Group
MALWARE
HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file. HOTWAX decrypts a payload using the Spritz algorithm with a hard-coded key and then searches the target process and attempts to inject the decrypted payload module from the CHM file into the address space of the target process.
Updated: 2023-08-31
View profile →
HOTCROISSANT
Technical ID: win.hotcroissant
Lazarus Group
MALWARE
Malware family identifying win.hotcroissant. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-17
View profile →
Horus Eyes RAT
Technical ID: win.horus_eyes_rat
MALWAREfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
Updated: 2021-08-06
View profile →
HorusEyes RAT
Technical ID: win.horuseyes
MALWARE
Remote Acess Tool Written in VB.NET.
Updated: 2021-02-06
View profile →
Horus
Technical ID: win.horus
Stealth Falcon
MALWARE
According to Check Point Research, this is a custom-built agent for Mythic, the open-source red teaming C2 framework. Written in C++, the implant shows no significant overlap with known C-based Mythic agents, aside from commonalities in the generic logic related to Mythic C2 communications.
Updated: 2025-06-13
View profile →
Hopscotch
Technical ID: win.hopscotch
MALWARE
Hopscotch is part of the Regin framework.
Updated: 2021-02-06
View profile →
HOPLIGHT
Technical ID: win.hoplight
Lazarus Group
MALWARE
Malware family identifying win.hoplight. Origin and technical characteristics tracked via Malpedia.
Also known as: HANGMAN
Updated: 2020-08-13
View profile →
HookInjEx
Technical ID: win.hookinjex
MALWARE
Malware family identifying win.hookinjex. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-21
View profile →
homefry
Technical ID: win.homefry
Leviathan
MALWARE
a 64-bit Windows password dumper/cracker that has previously been used in conjunction with AIRBREAK and BADFLICK backdoors. Some strings are obfuscated with XOR x56. The malware accepts up to two arguments at the command line: one to display cleartext credentials for each login session, and a second to display cleartext credentials, NTLM hashes, and malware version for each login session.
Updated: 2020-05-23
View profile →
HOLERUN
Technical ID: win.holerun
MALWARE
Malware family identifying win.holerun. Origin and technical characteristics tracked via Malpedia.
Also known as: LAGTOY
Updated: 2025-06-20
View profile →
Holcus Installer (Adware)
Technical ID: win.holcus
MALWARE
Adware, tied to eGobbler and Nephos7 campaigns,
Updated: 2021-02-04
View profile →
Hodur
Technical ID: win.hodur
MUSTANG PANDA
MALWARE
Malware family identifying win.hodur. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-09
View profile →
HLUX
Technical ID: win.hlux
MALWARE
Malware family identifying win.hlux. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-26
View profile →
Hi-Zor RAT
Technical ID: win.hi_zor_rat
MALWARE
Malware family identifying win.hi_zor_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-15
View profile →
Hive
Technical ID: win.hive
MALWAREfinancialhigh
Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe. In 2022 there was a switch from GoLang to Rust.
Updated: 2023-12-27
View profile →
Hisoka
Technical ID: win.hisoka
MALWARE
Malware family identifying win.hisoka. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-09
View profile →
Himera Loader
Technical ID: win.himera_loader
MALWARE
Malware family identifying win.himera_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-18
View profile →
himan
Technical ID: win.himan
MALWARE
Malware family identifying win.himan. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-11
View profile →
HILDACRYPT
Technical ID: win.hildacrypt
MALWAREfinancialhigh
A new ransomware family was discovered in August 2019. Called HILDACRYPT, it is named after the Netflix cartoon “Hilda” because the TV show’s YouTube trailer was included in the ransom note of the original version of the malware.
Updated: 2023-10-10
View profile →
HiKit
Technical ID: win.hikit
Aurora PandaHurricane Panda
MALWARE
Malware family identifying win.hikit. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-17
View profile →
← PreviousPage 162 / 269Next →