Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
Hancitor
Technical ID: win.hancitor
MALWARE
Hancitor(aka Chanitor) emerged in 2013 which spread via social engineering techniques mainly through phishing mails embedded with malicious link and weaponized Microsoft office document contains malicious macro in it.
Also known as: Chanitor
Hamweq
Technical ID: win.hamweq
MALWARE
Malware family identifying win.hamweq. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
A stager used by APT29 to deploy CobaltStrike.
Hakuna Matata
Technical ID: win.hakuna_matata
MALWAREfinancialhigh
Ransomware written in C#.
Hakbit
Technical ID: win.hakbit
MALWAREfinancialhigh
Hakbit ransomware is written in .NET. It uploads (some) files to be encrypted to a ftp-server.
The ransom note is embedded - in earlier versions as plain string, then as base64 string. In some versions, these strings are slightly obfuscated.
Contact is via an email address hosted on protonmail. Hakbit (original) had hakbit@, more recent "KiraLock" has kiraransom@ (among others of course).
Also known as: Thanos Ransomware
MALWAREfinancialhigh
According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the ".~HL[5_random_characters] (first 5 characters of encryption password)" extension.
HackSpy
Technical ID: win.hackspy
MALWARE
Py2Exe based tool as found on github.
MALWARE
Malware family identifying win.hacksfase. Origin and technical characteristics tracked via Malpedia.
HackBrowserData
Technical ID: win.hackbrowserdata
MALWARE
Browser information stealer, written in Go.
HabitsRAT
Technical ID: win.habitsrat
MALWARE
Malware family identifying win.habitsrat. Origin and technical characteristics tracked via Malpedia.
H1N1 Loader
Technical ID: win.h1n1
MALWARE
Malware family identifying win.h1n1. Origin and technical characteristics tracked via Malpedia.
Gwisin
Technical ID: win.gwisin
MALWAREfinancialhigh
Ransomware.
GUP Proxy Tool
Technical ID: win.gup_proxy
MALWARE
Malware family identifying win.gup_proxy. Origin and technical characteristics tracked via Malpedia.
GUIDLOADER
Technical ID: win.guidloader
MALWARE
Malware family identifying win.guidloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to haxrob, GTPDOOR is the name of Linux based malware that is intended to be deployed on systems in telco networks adjacent to the GRX (GRPS eXchange Network) with the novel feature of communicating C2 traffic over GTP-C (GPRS Tunnelling Protocol - Control Plane) signalling messages. This allows the C2 traffic to blend in with normal traffic and to reuse already permitted ports that maybe open and exposed to the GRX network.
GSpy
Technical ID: win.gspy
MALWARE
A malware family with a DGA.
gsecdump
Technical ID: win.gsecdump
MALWARE
Malware family identifying win.gsecdump. Origin and technical characteristics tracked via Malpedia.
GRUNT
Technical ID: win.grunt
MALWARE
Malware family identifying win.grunt. Origin and technical characteristics tracked via Malpedia.
Also known as: Covenant
Growtopia
Technical ID: win.growtopia
MALWAREespionageadvanced
According to PCrisk, Growtopia (also known as CyberStealer) is an information stealer written in the C# programming language. It can obtain system information, steal information from various applications, and capture screenshots. Its developer claims that it has created this software for educational purposes only. This stealer uses the name of a legitimate online game.
GroundPeony
Technical ID: win.ground_peony
MALWARE
Malware family identifying win.ground_peony. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.grok. Origin and technical characteristics tracked via Malpedia.
GrimPlant
Technical ID: win.grimplant
MALWARE
This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).
MALWAREfinancialhigh
GRIMAGENT is a backdoor that can execute arbitrary commands, download files, create and delete scheduled tasks, and execute programs via scheduled tasks or via the ShellExecute API. The malware persists via a randomly named scheduled task and a registry Run key. The backdoor communicates to hard-coded C&C servers via HTTP requests with portions of its network communications encrypted using both asymmetric and symmetric cryptography. GRIMAGENT was used during some Ryuk Ransomware intrusions in 2020.
MALWARE
This is a proxy-aware HTTP backdoor that is implemented as a service and uses the compromised system's proxy settings to access the internet. C&C traffic is base64 encoded and the files sent to the server are compressed with aPLib.
Also known as: Hellsing Backdoor
MALWARE
Malware family identifying win.grey_energy. Origin and technical characteristics tracked via Malpedia.
Grenam
Technical ID: win.grenam
MALWARE
A malware that modifies every JPG file found on a computer by adding a string in its bottom corner spelling out 'I am Sorry'.
Grenam is a companion virus, which is a form of file infection. It infects by prepending the letter 'g' in front of host files and placing itself with the original name of the host.
Also known as: Renamer • gnamer
Gremlin
Technical ID: win.gremlin
MALWAREespionageadvanced
This information-stealing malware exfiltrates data from its victims and uploads this information to its web server for publication. It can capture data from browsers, the clipboard and the local disk to steal sensitive data such as credit card details, browser cookies, crypto wallet information, File Transfer Protocol (FTP) and virtual private network (VPN) credentials.
GreetingGhoul
Technical ID: win.greetingghoul
MALWARE
Malware family identifying win.greetingghoul. Origin and technical characteristics tracked via Malpedia.
GreenDispenser
Technical ID: win.green_dispenser
MALWARE
Malware family identifying win.green_dispenser. Origin and technical characteristics tracked via Malpedia.
GreenShaitan
Technical ID: win.greenshaitan
MALWARE
Malware family identifying win.greenshaitan. Origin and technical characteristics tracked via Malpedia.
Also known as: eoehttp
MALWARE
Malware family identifying win.grease. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Mandiant, GRAYRABBIT is a lightweight and simple backdoor that supports simple file operation, system information collection, running modularized plugins, and executing a remote command shell.
Gravity RAT
Technical ID: win.gravity_rat
MALWARE
Malware family identifying win.gravity_rat. Origin and technical characteristics tracked via Malpedia.
Gratem
Technical ID: win.gratem
MALWARE
Malware family identifying win.gratem. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-06
View profile →MALWARE
POS malware targets systems that run physical point-of-sale device and operates by inspecting the process memory for data that matches the structure of credit card data (Track1 and Track2 data), such as the account number, expiration date, and other information stored on a card’s magnetic stripe. After the cards are first scanned, the personal account number (PAN) and accompanying data sit in the point-of-sale system’s memory unencrypted while the system determines where to send it for authorization.
Masked as the LogMein software, the GratefulPOS malware appears to have emerged during the fall 2017 shopping season with low detection ratio according to some of the earliest detections displayed on VirusTotal. The first sample was upload in November 2017. Additionally, this malware appears to be related to the Framework POS malware, which was linked to some of the high-profile merchant breaches in the past.
Also known as: FrameworkPOS • SCRAPMINT • trinity
GraphSteel
Technical ID: win.graphsteel
MALWARE
This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).
Graphon
Technical ID: win.graphon
MALWARE
Malware family identifying win.graphon. Origin and technical characteristics tracked via Malpedia.
MALWARE
Trellix describes Graphite as a malware using the Microsoft Graph API and OneDrive for C&C. It was found being deployed in-memory only and served as a downloader for Empire.
MALWARE
Downloader / information stealer used by UAC-0056, observed since at least October 2022.
MALWAREespionageadvanced
According to Symantec, Graphican is an evolution of the known APT15 backdoor Ketrican, which itself was based on a previous malware - BS2005 - also used by APT15. Graphican has the same basic functionality as Ketrican, with the difference between them being Graphican’s use of the Microsoft Graph API and OneDrive to obtain its command-and-control (C&C) infrastructure.