Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,744 entities
HijackLoader
Technical ID: win.hijackloader
MALWARE
According to Rapid7, this is a loader first spotted in July 2023. It implements several evasion techniques including Process Doppelgänging, DLL Search Order Hijacking, and Heaven's Gate. It has been observed to store its malicious payload in the IDAT chunk of PNG file format.
Also known as: DOILoader • GHOSTPULSE • IDAT Loader • SHADOWLADDER
Updated: 2025-08-18
View profile →
HIGHNOTE
Technical ID: win.highnote
APT17
MALWARE
Malware family identifying win.highnote. Origin and technical characteristics tracked via Malpedia.
Also known as: ChyNode
Updated: 2019-07-31
View profile →
HIGHNOON.BIN
Technical ID: win.highnoon_bin
APT41
MALWARE
Malware family identifying win.highnoon_bin. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-13
View profile →
HIGHNOON
Technical ID: win.highnoon
APT41Aurora Panda
MALWARE
According to FireEye, HIGHNOON is a backdoor that may consist of multiple components. The components may include a loader, a DLL, and a rootkit. Both the loader and the DLL may be dropped together, but the rootkit may be embedded in the DLL. The HIGHNOON loader may be designed to run as a Windows service.
Updated: 2023-04-28
View profile →
HideDRV
Technical ID: win.hidedrv
MALWARE
Malware family identifying win.hidedrv. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
HiddenTear
Technical ID: win.hiddentear
MALWAREfinancialhigh
HiddenTear is an open source ransomware developed by a Turkish programmer and later released as proof of concept on GitHub. The malware generates a local symmetric key in order to encrypt a configurable folder (/test was the default one) and it sends it to a centralized C&C server. Due to its small payload it was used as real attack vector over email phishing campaigns. Variants are still used in attacks.
Also known as: Cryptear • FuckUnicorn
Updated: 2024-08-19
View profile →
Hidden Bee
Technical ID: win.hiddenbee
MALWARE
Malware family identifying win.hiddenbee. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-01
View profile →
HiAsm
Technical ID: win.hiasm
MALWARE
Malware family identifying win.hiasm. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-11
View profile →
heyoka
Technical ID: win.heyoka
Aoqin Dragon
MALWARE
Malware family identifying win.heyoka. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-01
View profile →
HexaLocker
Technical ID: win.hexalocker
MALWAREfinancialhigh
On August 9th, 2024, the HexaLocker team advertised a new Windows ransomware on its Telegram channel. The message included a demonstration video and text promoting a Golang ransomware that implements a proprietary algorithm.
Updated: 2025-06-30
View profile →
HesperBot
Technical ID: win.hesperbot
MALWARE
Malware family identifying win.hesperbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-07-19
View profile →
HerpesBot
Technical ID: win.herpes
MALWARE
Malware family identifying win.herpes. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →
HermeticWizard
Technical ID: win.hermeticwizard
MALWARE
Malware family identifying win.hermeticwizard. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-20
View profile →
HermeticWiper
Technical ID: win.hermeticwiper
MALWARE
According to SentinelLabs, HermeticWiper is a custom-written application with very few standard functions. It abuses a signed driver called "empntdrv.sys" which is associated with the legitimate Software "EaseUS Partition Master Software" to enumerate the MBR and all partitions of all Physical Drives connected to the victims Windows Device and overwrite the first 512 Bytes of every MBR and Partition it can find, rendering them useless. This malware is associated to the malware attacks against Ukraine during Russians Invasion in February 2022.
Also known as: DriveSlayer • FoxBlade • KillDisk.NCV • NEARMISS
Updated: 2024-04-23
View profile →
Hermes
Technical ID: win.hermes
Lazarus Group
MALWARE
Malware family identifying win.hermes. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-26
View profile →
Heriplor
Technical ID: win.heriplor
Energetic Bear
MALWARE
Malware family identifying win.heriplor. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-26
View profile →
Herbst
Technical ID: win.herbst
MALWARE
Malware family identifying win.herbst. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-29
View profile →
HemiGate
Technical ID: win.hemigate
Earth Estries
MALWARE
Malware family identifying win.hemigate. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-01-27
View profile →
Heloag
Technical ID: win.heloag
MALWARE
Malware family identifying win.heloag. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-25
View profile →
Helminth
Technical ID: win.helminth
APT34
MALWARE
Malware family identifying win.helminth. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-29
View profile →
HelloKitty
Technical ID: win.hellokitty
MALWAREfinancialhigh
Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions.
Also known as: KittyCrypt
Updated: 2023-12-27
View profile →
HelloBot
Technical ID: win.hellobot
Earth Berberoka
MALWARE
Malware family identifying win.hellobot. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-28
View profile →
Helauto
Technical ID: win.helauto
Comment Crew
MALWARE
Malware family identifying win.helauto. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
Headlace
Technical ID: win.headlace
MALWARE
Malware family identifying win.headlace. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-22
View profile →
HeaderTip
Technical ID: win.headertip
MALWARE
The Chinese threat actor "Scarab" is using a custom backdoor dubbed "HeaderTip" according to SentinelLABS. This malware may be the successor of "Scieron".
Updated: 2022-08-05
View profile →
HDRoot
Technical ID: win.hdroot
APT17
MALWARE
Malware family identifying win.hdroot. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-19
View profile →
HDMR
Technical ID: win.hdmr
MALWAREfinancialhigh
HDMR is a ransomware which encrypts user files and adds a .DMR64 extension. It also drops a ransom note named: "!!! READ THIS !!!.hta".
Also known as: GO-SPORT
Updated: 2019-12-18
View profile →
HazyLoad
Technical ID: win.hazy_load
Silent Chollima
MALWARE
Malware family identifying win.hazy_load. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-15
View profile →
Hawking
Technical ID: win.hawking
OilRig
MALWARE
Malware family identifying win.hawking. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-16
View profile →
HawkEye Keylogger
Technical ID: win.hawkeye_keylogger
MALWARE
HawKeye is a keylogger that is distributed since 2013. Discovered by IBM X-Force, it is currently spread over phishing campaigns targeting businesses on a worldwide scale. It is designed to steal credentials from numerous applications but, in the last observed versions, new "loader capabilities" have been spotted. It is sold by its development team on dark web markets and hacking forums.
Also known as: HawkEye • HawkEye Reborn • Predator Pain
Updated: 2025-08-20
View profile →
HAWKBALL
Technical ID: win.hawkball
MALWARE
HAWKBALL is a backdoor that attackers can use to collect information from the victim, as well as to deliver payloads. HAWKBALL is capable of surveying the host, creating a named pipe to execute native Windows commands, terminating processes, creating, deleting and uploading files, searching for files, and enumerating drives.
Updated: 2019-07-10
View profile →
Havoc
Technical ID: win.havoc
MALWARE
First released in October 2022, the Havoc C2 Framework is a flexible post-exploitation framework written in Golang, C++, and Qt, with agents called 'Demons' written in C and ASM, created by @C5pider. Designed to support red team engagements and adversary emulation, it offers a robust set of capabilities tailored for offensive security operations. The framework, which is under active development, utilizes HTTP(s) and SMB as communication protocols for its implants. Havoc can generate implants, known as Demons, in several formats including EXE, DLL, and Shellcode. A notable feature of Havoc is its ability to bypass EDR by employing advanced evasion techniques such as sleep obfuscation, return address stack spoofing, and indirect syscalls. This capability enhances its effectiveness in evading detection and circumventing security measures.
Also known as: Havokiz
Updated: 2026-01-14
View profile →
Havex RAT
Technical ID: win.havex_rat
Energetic Bear
MALWAREespionageadvanced
Havex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control systems (ICS) used across numerous industries and attributed to a hacking group referred to as "Dragonfly" and "Energetic Bear". Havex is estimated to have impacted thousands of infrastructure sites, a majority of which were located in Europe and the United States. Within the energy sector, Havex specifically targeted energy grid operators, major electricity generation firms, petroleum pipeline operators, and industrial equipment providers. Havex also impacted organizations in the aviation, defense, pharmaceutical, and petrochemical industries. Once installed, Havex scanned the infected system to locate any Supervisory Control and Data Acquisition (SCADA) or ICS devices on the network and sent the data back to command and control servers. To do so, the malware leveraged the Open Platform Communications (OPC) standard, which is a universal communication protocol used by ICS components across many industries that facilitates open connectivity and vendor equipment interoperability. Havex used the Distributed Component Object Model (DCOM) to connect to OPC servers inside of an ICS network and collect information such as CLSID, server name, Program ID, OPC version, vendor information, running state, group count, and server bandwidth. Havex was an intelligence-collection tool used for espionage and not for the disruption or destruction of industrial systems. However, the data collected by Havex would have aided efforts to design and develop attacks against specific targets or industries.
Updated: 2022-03-25
View profile →
HavanaCrypt
Technical ID: win.havana_crypt
MALWARE
Malware family identifying win.havana_crypt. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-13
View profile →
Hatef
Technical ID: win.hatef
Handala
MALWARE
According to Intezer, this is a wiper.
Updated: 2024-10-18
View profile →
Haron Ransomware
Technical ID: win.haron
MALWARE
Malware family identifying win.haron. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-09-09
View profile →
Harnig
Technical ID: win.harnig
MALWARE
Malware family identifying win.harnig. Origin and technical characteristics tracked via Malpedia.
Also known as: Piptea
Updated: 2018-01-22
View profile →
HARDRAIN
Technical ID: win.hardrain
Lazarus Group
MALWARE
Malware family identifying win.hardrain. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-11
View profile →
HappyLocker (HiddenTear?)
Technical ID: win.happy_locker
MALWARE
Malware family identifying win.happy_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →
Handala
Technical ID: win.handala
Handala
MALWARE
According to Intezer, this is a second stage loader written in Delphi.
Updated: 2024-10-18
View profile →
← PreviousPage 163 / 269Next →