Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
MALWARE
This loader abuses the benign service Notion for data exchange.
Also known as: SNOWYAMBER
MALWARE
PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected target processes. It uses the Microsoft Graph API and Dropbox API as C&C channel.
Also known as: GraphicalProton • SPICYBEAT
MALWARE
According to Checkpoint Research, GRAPELOADER is a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery. Despite differing roles, it shares similarities in code structure, obfuscation, and string decryption with WINELOADER. GRAPELOADER refines WINELOADER’s anti-analysis techniques while introducing more advanced stealth methods.
GrandSteal
Technical ID: win.grandsteal
MALWARE
Malware family identifying win.grandsteal. Origin and technical characteristics tracked via Malpedia.
Grandoreiro
Technical ID: win.grandoreiro
MALWAREfinancialhigh
According to ESET Research, Grandoreiro is a Latin American banking trojan targeting Brazil, Mexico, Spain and Peru. As such, it shows unusual effort by its authors to evade detection and emulation, and progress towards a modular architecture.
MALWARE
Malware family identifying win.gramdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: Small Sieve
Grager
Technical ID: win.grager
MALWARE
Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of this backdoor revealed that it uses the Graph API to communicate with a command and control (C&C) server hosted on Microsoft OneDrive. The backdoor decrypts a client ID and refresh token for OneDrive from a blob contained within its file body. It supports the following commands:
- Retrieve machine information, including machine name, user, IP address, and machine architecture
- Download or upload a file
- Execute a file
- Gather file system information, including available drives, their sizes, and types of drives
Graftor
Technical ID: win.graftor
MALWARE
Malware family identifying win.graftor. Origin and technical characteristics tracked via Malpedia.
Also known as: MewsSpy
GrabBot
Technical ID: win.grabbot
MALWARE
Malware family identifying win.grabbot. Origin and technical characteristics tracked via Malpedia.
GPCode
Technical ID: win.gpcode
MALWARE
Malware family identifying win.gpcode. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.go_red. Origin and technical characteristics tracked via Malpedia.
Gozi
Technical ID: win.gozi
MALWARE
2000 Ursnif aka Snifula
2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)
-> 2010 Gozi Prinimalka -> Vawtrak/Neverquest
In 2006, Gozi v1.0 ('Gozi CRM' aka 'CRM') aka Papras was first observed.
It was offered as a CaaS, known as 76Service. This first version of Gozi was developed by Nikita Kurmin, and he borrowed code from Ursnif aka Snifula, a spyware developed by Alexey Ivanov around 2000, and some other kits. Gozi v1.0 thus had a formgrabber module and often is classified as Ursnif aka Snifula.
In September 2010, the source code of a particular Gozi CRM dll version was leaked, which led to Vawtrak/Neverquest (in combination with Pony) via Gozi Prinimalka (a slightly modified Gozi v1.0) and Gozi v2.0 (aka 'Gozi ISFB' aka 'ISFB' aka Pandemyia). This version came with a webinject module.
Also known as: CRM • Gozi CRM • Papras • Snifula • Ursnif
GovRAT
Technical ID: win.govrat
MALWARE
Malware family identifying win.govrat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.gotroj. Origin and technical characteristics tracked via Malpedia.
GoToHTTP
Technical ID: win.gotohttp
MALWARE
According to ESET Research, GoToHTTP is a benign tool that allows establishing a remote connection that can be accessed from a browser. It has been observed being abused for malicious purposes by threat actor GhostRedirector.
Gosar
Technical ID: win.gosar
MALWARE
According to Elastic, this is a rewrite of Quasar RAT in Go.
MALWARE
Malware family identifying win.gopuram. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.gopher_rat. Origin and technical characteristics tracked via Malpedia.
Gophe
Technical ID: win.gophe
MALWARE
Malware family identifying win.gophe. Origin and technical characteristics tracked via Malpedia.
GootKit
Technical ID: win.gootkit
MALWAREfinancialhigh
Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts. The loader downloads the payload, stores it in registry and injects it in a copy of the loader process. The loader also contains two encrypted DLLs intended to be injected into each browser process launched in order to place the payload in man in the browser and allow it to apply the webinjects received from the command and control server on HTTPx exchanges. This allows Gootkit to intercept HTTPx requests and responses, steal their content or modify it according to the webinjects.
Also known as: Waldek • Xswkit • talalpek
MALWARE
Malware family identifying win.gooseegg. Origin and technical characteristics tracked via Malpedia.
GooPic Drooper
Technical ID: win.goopic
MALWARE
Malware family identifying win.goopic. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.google_drive_rat. Origin and technical characteristics tracked via Malpedia.
Goodor
Technical ID: win.goodor
MALWARE
Malware family identifying win.goodor. Origin and technical characteristics tracked via Malpedia.
Also known as: Fuerboos
MALWARE
The malware consists of a dropper DLL and an obfuscated, password protected VbaProject.OTM file, which houses macros written for Microsoft Outlook. The malware was originally written by Greg Linares as a backdoor POC called Cordyceps, and presented at Hushcon in 2017.
Also known as: Cordyceps • NOTDOOR
Gomorrah stealer
Technical ID: win.gomorrah_stealer
MALWARE
Gomorrah is a stealer with no or little obfuscation that appeared around March 2020. It is sold for about 150$ lifetime for v4 (originally 400$ for v3) or 100$ per month by its developer called "th3darkly / lucifer" (which is also the developer of CosaNostra botnet). The malware's main functionalities are stealing (passwords, cryptocurrency wallets) and loading of tasks and other payloads.
GoMet
Technical ID: win.gomet
MALWARE
Malware family identifying win.gomet. Origin and technical characteristics tracked via Malpedia.
Golroted
Technical ID: win.golroted
MALWARE
Malware family identifying win.golroted. Origin and technical characteristics tracked via Malpedia.
GoldDragon
Technical ID: win.gold_dragon
MALWARE
GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less, PowerShell-based attack leveraging steganography was executed. The initial attack was observed first in December 2017, when a Korean-language spear phishing campaing targeted organizations linked with Pyeongchang Winter Olympics 2018. GoldDragon was delivered once the attacker had gained an initial foothold in the targeted environment.
The malware was capable of a basic reconnaissance, data exfiltration and downloading of additional components from its C&C server.
Also known as: Lovexxx
MALWARE
Gold Max is a Golang written command and control backdoor used by the NOBELIUM threat actor group. It uses several different techniques to obfuscate its actions and evade detection. The malware writes an encrypted configuration file to disk, where the file name and AES-256 cipher keys are unique per implant and based on environmental variables and information about the network where it is running.
Also known as: SUNSHUTTLE
GoldenSpy
Technical ID: win.goldenspy
MALWARE
According securityweek, GoldenSpy, the malware was observed as part of a campaign that supposedly started in April 2020, but some of the identified samples suggest the threat has been around since at least December 2016.
One of the compromised organizations, a global technology vendor that conducts government business in the US, Australia and UK, and which recently opened offices in China, became infected after installing “Intelligent Tax,” a piece of software from the Golden Tax Department of Aisino Corporation, which a local bank required for paying local taxes.
Although it worked as advertised, the software was found to install a hidden backdoor to provide remote operators with the possibility to execute Windows commands or upload and run files.
GoldenHelper
Technical ID: win.goldenhelper
MALWARE
Malware family identifying win.goldenhelper. Origin and technical characteristics tracked via Malpedia.
GoldenEye
Technical ID: win.goldeneye
MALWARE
Malware family identifying win.goldeneye. Origin and technical characteristics tracked via Malpedia.
Also known as: Petya/Mischa
MALWARE
Malware family identifying win.goldbackdoor. Origin and technical characteristics tracked via Malpedia.
MALWARE
GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets.
It is often used in ClickFix campaigns by North-Korean threat actors.
Also known as: BitStep RAT • WeaselStore
GoGra
Technical ID: win.gogra
MALWARE
According to Symantec, a previously unseen backdoor that was deployed against a media organization in South Asia in November, 2023. GoGra is written in Go and uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services.
Also known as: Onedrivetools
GoGoogle
Technical ID: win.gogoogle
MALWARE
Malware family identifying win.gogoogle. Origin and technical characteristics tracked via Malpedia.
Also known as: BossiTossi
MALWARE
Malware family identifying win.goggles. Origin and technical characteristics tracked via Malpedia.
Gofing
Technical ID: win.gofing
MALWARE
A file infector written in Go, discovered by Karsten Hahn in February 2022. According to Karsten, despite its internal naming, it is not polymorphic and the virus body is not encrypted. Gofing uses the Coldfire Golang malware development library.
Also known as: Velocity Polymorphic Compression Malware
Godzilla Loader
Technical ID: win.godzilla_loader
MALWARE
Malware family identifying win.godzilla_loader. Origin and technical characteristics tracked via Malpedia.