Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
GraphicalNeutrino
Technical ID: win.graphical_neutrino
APT29
MALWARE
This loader abuses the benign service Notion for data exchange.
Also known as: SNOWYAMBER
Updated: 2023-07-28
View profile →
GraphDrop
Technical ID: win.graphdrop
APT29
MALWARE
PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected target processes. It uses the Microsoft Graph API and Dropbox API as C&C channel.
Also known as: GraphicalProton • SPICYBEAT
Updated: 2024-01-24
View profile →
GRAPELOADER
Technical ID: win.grapeloader
APT29
MALWARE
According to Checkpoint Research, GRAPELOADER is a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery. Despite differing roles, it shares similarities in code structure, obfuscation, and string decryption with WINELOADER. GRAPELOADER refines WINELOADER’s anti-analysis techniques while introducing more advanced stealth methods.
Updated: 2025-04-16
View profile →
GrandSteal
Technical ID: win.grandsteal
MALWARE
Malware family identifying win.grandsteal. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-23
View profile →
Grandoreiro
Technical ID: win.grandoreiro
MALWAREfinancialhigh
According to ESET Research, Grandoreiro is a Latin American banking trojan targeting Brazil, Mexico, Spain and Peru. As such, it shows unusual effort by its authors to evade detection and emulation, and progress towards a modular architecture.
Updated: 2024-10-25
View profile →
GRAMDOOR
Technical ID: win.gramdoor
MuddyWater
MALWARE
Malware family identifying win.gramdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: Small Sieve
Updated: 2022-03-14
View profile →
Grager
Technical ID: win.grager
MALWARE
Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of this backdoor revealed that it uses the Graph API to communicate with a command and control (C&C) server hosted on Microsoft OneDrive. The backdoor decrypts a client ID and refresh token for OneDrive from a blob contained within its file body. It supports the following commands: - Retrieve machine information, including machine name, user, IP address, and machine architecture - Download or upload a file - Execute a file - Gather file system information, including available drives, their sizes, and types of drives
Updated: 2024-11-11
View profile →
Graftor
Technical ID: win.graftor
MALWARE
Malware family identifying win.graftor. Origin and technical characteristics tracked via Malpedia.
Also known as: MewsSpy
Updated: 2023-09-28
View profile →
GrabBot
Technical ID: win.grabbot
MALWARE
Malware family identifying win.grabbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-03-28
View profile →
GPCode
Technical ID: win.gpcode
MALWARE
Malware family identifying win.gpcode. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-09
View profile →
GoRed
Technical ID: win.go_red
ExCobalt
MALWARE
Malware family identifying win.go_red. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-13
View profile →
Gozi
Technical ID: win.gozi
MALWARE
2000 Ursnif aka Snifula 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) -> 2010 Gozi Prinimalka -> Vawtrak/Neverquest In 2006, Gozi v1.0 ('Gozi CRM' aka 'CRM') aka Papras was first observed. It was offered as a CaaS, known as 76Service. This first version of Gozi was developed by Nikita Kurmin, and he borrowed code from Ursnif aka Snifula, a spyware developed by Alexey Ivanov around 2000, and some other kits. Gozi v1.0 thus had a formgrabber module and often is classified as Ursnif aka Snifula. In September 2010, the source code of a particular Gozi CRM dll version was leaked, which led to Vawtrak/Neverquest (in combination with Pony) via Gozi Prinimalka (a slightly modified Gozi v1.0) and Gozi v2.0 (aka 'Gozi ISFB' aka 'ISFB' aka Pandemyia). This version came with a webinject module.
Also known as: CRM • Gozi CRM • Papras • Snifula • Ursnif
Updated: 2025-12-19
View profile →
GovRAT
Technical ID: win.govrat
MALWARE
Malware family identifying win.govrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-20
View profile →
GOTROJ
Technical ID: win.gotroj
FIN7
MALWARE
Malware family identifying win.gotroj. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-09-02
View profile →
GoToHTTP
Technical ID: win.gotohttp
MALWARE
According to ESET Research, GoToHTTP is a benign tool that allows establishing a remote connection that can be accessed from a browser. It has been observed being abused for malicious purposes by threat actor GhostRedirector.
Updated: 2025-12-17
View profile →
Gosar
Technical ID: win.gosar
MALWARE
According to Elastic, this is a rewrite of Quasar RAT in Go.
Updated: 2025-01-02
View profile →
Gopuram
Technical ID: win.gopuram
Lazarus Group
MALWARE
Malware family identifying win.gopuram. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-08
View profile →
GopherRAT
Technical ID: win.gopher_rat
Silent Chollima
MALWARE
Malware family identifying win.gopher_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-27
View profile →
Gophe
Technical ID: win.gophe
MALWARE
Malware family identifying win.gophe. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-05
View profile →
GootKit
Technical ID: win.gootkit
MALWAREfinancialhigh
Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts. The loader downloads the payload, stores it in registry and injects it in a copy of the loader process. The loader also contains two encrypted DLLs intended to be injected into each browser process launched in order to place the payload in man in the browser and allow it to apply the webinjects received from the command and control server on HTTPx exchanges. This allows Gootkit to intercept HTTPx requests and responses, steal their content or modify it according to the webinjects.
Also known as: Waldek • Xswkit • talalpek
Updated: 2025-11-13
View profile →
GooseEgg
Technical ID: win.gooseegg
APT28
MALWARE
Malware family identifying win.gooseegg. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-05-21
View profile →
GooPic Drooper
Technical ID: win.goopic
MALWARE
Malware family identifying win.goopic. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-25
View profile →
GoogleDrive RAT
Technical ID: win.google_drive_rat
OilRig
MALWARE
Malware family identifying win.google_drive_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-26
View profile →
Goodor
Technical ID: win.goodor
MALWARE
Malware family identifying win.goodor. Origin and technical characteristics tracked via Malpedia.
Also known as: Fuerboos
Updated: 2020-04-21
View profile →
GONEPOSTAL
Technical ID: win.gonepostal
APT28
MALWARE
The malware consists of a dropper DLL and an obfuscated, password protected VbaProject.OTM file, which houses macros written for Microsoft Outlook. The malware was originally written by Greg Linares as a backdoor POC called Cordyceps, and presented at Hushcon in 2017.
Also known as: Cordyceps • NOTDOOR
Updated: 2025-09-12
View profile →
Gomorrah stealer
Technical ID: win.gomorrah_stealer
MALWARE
Gomorrah is a stealer with no or little obfuscation that appeared around March 2020. It is sold for about 150$ lifetime for v4 (originally 400$ for v3) or 100$ per month by its developer called "th3darkly / lucifer" (which is also the developer of CosaNostra botnet). The malware's main functionalities are stealing (passwords, cryptocurrency wallets) and loading of tasks and other payloads.
Updated: 2022-01-12
View profile →
GoMet
Technical ID: win.gomet
MALWARE
Malware family identifying win.gomet. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-27
View profile →
Golroted
Technical ID: win.golroted
MALWARE
Malware family identifying win.golroted. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-17
View profile →
GoldDragon
Technical ID: win.gold_dragon
MALWARE
GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less, PowerShell-based attack leveraging steganography was executed. The initial attack was observed first in December 2017, when a Korean-language spear phishing campaing targeted organizations linked with Pyeongchang Winter Olympics 2018. GoldDragon was delivered once the attacker had gained an initial foothold in the targeted environment. The malware was capable of a basic reconnaissance, data exfiltration and downloading of additional components from its C&C server.
Also known as: Lovexxx
Updated: 2022-02-10
View profile →
GoldMax
Technical ID: win.goldmax
UNC2452
MALWARE
Gold Max is a Golang written command and control backdoor used by the NOBELIUM threat actor group. It uses several different techniques to obfuscate its actions and evade detection. The malware writes an encrypted configuration file to disk, where the file name and AES-256 cipher keys are unique per implant and based on environmental variables and information about the network where it is running.
Also known as: SUNSHUTTLE
Updated: 2023-12-04
View profile →
GoldenSpy
Technical ID: win.goldenspy
MALWARE
According securityweek, GoldenSpy, the malware was observed as part of a campaign that supposedly started in April 2020, but some of the identified samples suggest the threat has been around since at least December 2016. One of the compromised organizations, a global technology vendor that conducts government business in the US, Australia and UK, and which recently opened offices in China, became infected after installing “Intelligent Tax,” a piece of software from the Golden Tax Department of Aisino Corporation, which a local bank required for paying local taxes. Although it worked as advertised, the software was found to install a hidden backdoor to provide remote operators with the possibility to execute Windows commands or upload and run files.
Updated: 2023-05-21
View profile →
GoldenHelper
Technical ID: win.goldenhelper
MALWARE
Malware family identifying win.goldenhelper. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-17
View profile →
GoldenEye
Technical ID: win.goldeneye
MALWARE
Malware family identifying win.goldeneye. Origin and technical characteristics tracked via Malpedia.
Also known as: Petya/Mischa
Updated: 2017-07-17
View profile →
GOLDBACKDOOR
Technical ID: win.goldbackdoor
APT37
MALWARE
Malware family identifying win.goldbackdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-02
View profile →
GolangGhost
Technical ID: win.golangghost
WageMole
MALWARE
GolanGhost is a RAT written in Go. It uses C2 to receive commands and exfiltrate data such as browser information targeting especially installed cryptocurrency wallets. It is often used in ClickFix campaigns by North-Korean threat actors.
Also known as: BitStep RAT • WeaselStore
Updated: 2026-01-21
View profile →
GoGra
Technical ID: win.gogra
MALWARE
According to Symantec, a previously unseen backdoor that was deployed against a media organization in South Asia in November, 2023. GoGra is written in Go and uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services.
Also known as: Onedrivetools
Updated: 2024-10-25
View profile →
GoGoogle
Technical ID: win.gogoogle
MALWARE
Malware family identifying win.gogoogle. Origin and technical characteristics tracked via Malpedia.
Also known as: BossiTossi
Updated: 2020-07-07
View profile →
Goggles
Technical ID: win.goggles
Comment Crew
MALWARE
Malware family identifying win.goggles. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
Gofing
Technical ID: win.gofing
MALWARE
A file infector written in Go, discovered by Karsten Hahn in February 2022. According to Karsten, despite its internal naming, it is not polymorphic and the virus body is not encrypted. Gofing uses the Coldfire Golang malware development library.
Also known as: Velocity Polymorphic Compression Malware
Updated: 2022-03-18
View profile →
Godzilla Loader
Technical ID: win.godzilla_loader
MALWARE
Malware family identifying win.godzilla_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-15
View profile →
← PreviousPage 165 / 269Next →