Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
MALWAREespionageadvanced
GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities. GodRAT is likely connected with Winnty APT activities.
Old implant codebases, such as Gh0st RAT, which are nearly two decades old, continue to be used today. These are often customized and rebuilt to target a wide range of victims. These old implants are known to have been used by various threat actors for a long time, and the GodRAT discovery demonstrates that legacy codebases like Gh0st RAT can still maintain a long lifespan in the cybersecurity landscape.
goDoH
Technical ID: win.godoh
MALWARE
Proof of concept for data exfiltration via DoH, written in Go.
Godlike12
Technical ID: win.godlike12
MALWARE
Malware family identifying win.godlike12. Origin and technical characteristics tracked via Malpedia.
Also known as: GOSLU
goCryptoLocker
Technical ID: win.gocryptolocker
MALWARE
Malware family identifying win.gocryptolocker. Origin and technical characteristics tracked via Malpedia.
GoBotKR
Technical ID: win.gobotkr
MALWARE
Malware family identifying win.gobotkr. Origin and technical characteristics tracked via Malpedia.
Glupteba
Technical ID: win.glupteba
MALWARE
Glupteba is a trojan horse malware that is one of the top ten malware variants of 2021. After infecting a system, the Glupteba malware can be used to deliver additional malware, steal user authentication information, and enroll the infected system in a cryptomining botnet.
MALWARE
Malware family identifying win.glooxmail. Origin and technical characteristics tracked via Malpedia.
Globe
Technical ID: win.globe_ransom
MALWARE
Malware family identifying win.globe_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →GlobeImposter
Technical ID: win.globeimposter
MALWAREfinancialhigh
GlobeImposter is a ransomware application which is mainly distributed via "blank slate" spam (the spam has no message content and an attached ZIP file), exploits, malicious advertising, fake updates, and repacked installers. GlobeImposter mimics the Globe ransomware family.
This malware may prevent execution of Anti-Virus solutions and other OS related security features and may prevent system restoration.
Also known as: Fake Globe
Global
Technical ID: win.global
MALWAREfinancialhigh
The GLOBAL GROUP is a Ransomware-as-a-Service program which emerged in June 2025. It is suspected to have ties to BlackLock and Mamona, due to code and infrastructure similarities. It's negotiation panel offers AI-driven negotiations to help the operators to engage with the victims.
Also known as: GLOBAL GROUP
GlitchPOS
Technical ID: win.glitch_pos
MALWARE
Malware family identifying win.glitch_pos. Origin and technical characteristics tracked via Malpedia.
GlassRAT
Technical ID: win.glassrat
MALWARE
Malware family identifying win.glassrat. Origin and technical characteristics tracked via Malpedia.
Glasses
Technical ID: win.glasses
MALWARE
Malware family identifying win.glasses. Origin and technical characteristics tracked via Malpedia.
Also known as: Wordpress Bruteforcer
Updated: 2016-12-29
View profile →Ginzo Stealer
Technical ID: win.ginzo
MALWARE
An information stealer written in .NET.
Ginwui
Technical ID: win.ginwui
MALWARE
Malware family identifying win.ginwui. Origin and technical characteristics tracked via Malpedia.
GIMMICK
Technical ID: win.gimmick
MALWARE
Malware family identifying win.gimmick. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data exfiltration.
Giffy
Technical ID: win.giffy
MALWARE
Malware family identifying win.giffy. Origin and technical characteristics tracked via Malpedia.
Gibberish
Technical ID: win.gibberish
MALWAREfinancialhigh
Ransomware.
MALWARE
Malware family identifying win.ghost_secret. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks on Earth.
Below is a list of Gh0st RAT capabilities.
Take full control of the remote screen on the infected bot.
Provide real time as well as offline keystroke logging.
Provide live feed of webcam, microphone of infected host.
Download remote binaries on the infected remote host.
Take control of remote shutdown and reboot of host.
Disable infected computer remote pointer and keyboard input.
Enter into shell of remote infected host with full control.
Provide a list of all the active processes.
Clear all existing SSDT of all existing hooks.
Also known as: Farfli • Gh0st RAT • PCRat
GhostLocker
Technical ID: win.ghost_locker
MALWARE
Malware family identifying win.ghost_locker. Origin and technical characteristics tracked via Malpedia.
GhostAdmin
Technical ID: win.ghost_admin
MALWARE
Malware family identifying win.ghost_admin. Origin and technical characteristics tracked via Malpedia.
Also known as: Ghost iBot
GhostSocks
Technical ID: win.ghostsocks
MALWARE
GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in October 2023. It uses back-connect socket secure internet protocol (SOCKS5) connections and is available for rent for US $100 per month. In February 2024, the author of Lumma Stealer released an update introducing the integration of proxying capabilities. This feature, developed in partnership with GhostSocks, allows the use of infected hosts as SOCKS5 proxies and is available to all subscribers who purchase the "Professional" or higher tier plan. This integration allows Lumma Stealer users to establish a network of residential IP addresses for various purposes, including credential checking, spam distribution, or as general-purpose proxies.
Gh0stnet
Technical ID: win.ghostnet
MALWARE
Malware family identifying win.ghostnet. Origin and technical characteristics tracked via Malpedia.
Also known as: Remosh
MALWARE
Malware family identifying win.ghostengine. Origin and technical characteristics tracked via Malpedia.
GhostEmperor
Technical ID: win.ghostemperor
MALWARE
Malware family identifying win.ghostemperor. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ghole. Origin and technical characteristics tracked via Malpedia.
Also known as: Gholee • CoreImpact (Modified)
GHAMBAR
Technical ID: win.ghambar
MALWAREespionageadvanced
According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP. Its capabilities include filesystem manipulation, file upload and download, shell command execution, keylogging, screen capture, clipboard monitoring, and additional plugin execution.
Gh0stTimes
Technical ID: win.gh0sttimes
MALWARE
Custom RAT developed by the BlackTech actor, based on the Gh0st RAT.
Gh0stBins
Technical ID: win.gh0stbins
MALWARE
Malware family identifying win.gh0stbins. Origin and technical characteristics tracked via Malpedia.
Also known as: Gh0stBins RAT
get_pwd
Technical ID: win.get_pwd
MALWARE
Malware family identifying win.get_pwd. Origin and technical characteristics tracked via Malpedia.
GetMyPass
Technical ID: win.getmypass
MALWARE
Malware family identifying win.getmypass. Origin and technical characteristics tracked via Malpedia.
Also known as: getmypos
MALWARE
Malware family identifying win.getmail. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.get2. Origin and technical characteristics tracked via Malpedia.
Also known as: FRIENDSPEAK • GetandGo
GeminiDuke
Technical ID: win.geminiduke
MALWARE
Malware family identifying win.geminiduke. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key.
GEMCUTTER checks for the presence of the mutex MicrosoftGMMZJ to ensure only one copy of GEMCUTTER is executing. If the mutex doesn't exist, the malware creates it and continues execution; otherwise, the malware signals the MicrosoftGMMExit event.
MALWARE
According to FireEye, GEARSHIFT is a memory-only dropper for two keylogger DLLs. It is designed to replace a legitimate Fax Service DLL.
GearInformer
Technical ID: win.gearinformer
MALWARE
Malware family identifying win.gearinformer. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim information uploaded and payloads delivered.
Also known as: DoomDrive • GoogleDriveSucks