Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
GodRAT
Technical ID: win.godrat
APT41
MALWAREespionageadvanced
GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities. GodRAT is likely connected with Winnty APT activities. Old implant codebases, such as Gh0st RAT, which are nearly two decades old, continue to be used today. These are often customized and rebuilt to target a wide range of victims. These old implants are known to have been used by various threat actors for a long time, and the GodRAT discovery demonstrates that legacy codebases like Gh0st RAT can still maintain a long lifespan in the cybersecurity landscape.
Updated: 2025-11-18
View profile →
goDoH
Technical ID: win.godoh
MALWARE
Proof of concept for data exfiltration via DoH, written in Go.
Updated: 2019-12-08
View profile →
Godlike12
Technical ID: win.godlike12
MALWARE
Malware family identifying win.godlike12. Origin and technical characteristics tracked via Malpedia.
Also known as: GOSLU
Updated: 2020-07-30
View profile →
goCryptoLocker
Technical ID: win.gocryptolocker
MALWARE
Malware family identifying win.gocryptolocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-02
View profile →
GoBotKR
Technical ID: win.gobotkr
MALWARE
Malware family identifying win.gobotkr. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-11
View profile →
Glupteba
Technical ID: win.glupteba
MALWARE
Glupteba is a trojan horse malware that is one of the top ten malware variants of 2021. After infecting a system, the Glupteba malware can be used to deliver additional malware, steal user authentication information, and enroll the infected system in a cryptomining botnet.
Updated: 2024-04-15
View profile →
GlooxMail
Technical ID: win.glooxmail
Comment Crew
MALWARE
Malware family identifying win.glooxmail. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
Globe
Technical ID: win.globe_ransom
MALWARE
Malware family identifying win.globe_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
GlobeImposter
Technical ID: win.globeimposter
MALWAREfinancialhigh
GlobeImposter is a ransomware application which is mainly distributed via "blank slate" spam (the spam has no message content and an attached ZIP file), exploits, malicious advertising, fake updates, and repacked installers. GlobeImposter mimics the Globe ransomware family. This malware may prevent execution of Anti-Virus solutions and other OS related security features and may prevent system restoration.
Also known as: Fake Globe
Updated: 2023-03-20
View profile →
Global
Technical ID: win.global
MALWAREfinancialhigh
The GLOBAL GROUP is a Ransomware-as-a-Service program which emerged in June 2025. It is suspected to have ties to BlackLock and Mamona, due to code and infrastructure similarities. It's negotiation panel offers AI-driven negotiations to help the operators to engage with the victims.
Also known as: GLOBAL GROUP
Updated: 2025-09-23
View profile →
GlitchPOS
Technical ID: win.glitch_pos
MALWARE
Malware family identifying win.glitch_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-13
View profile →
GlassRAT
Technical ID: win.glassrat
MALWARE
Malware family identifying win.glassrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-26
View profile →
Glasses
Technical ID: win.glasses
MALWARE
Malware family identifying win.glasses. Origin and technical characteristics tracked via Malpedia.
Also known as: Wordpress Bruteforcer
Updated: 2016-12-29
View profile →
Ginzo Stealer
Technical ID: win.ginzo
MALWARE
An information stealer written in .NET.
Updated: 2024-05-06
View profile →
Ginwui
Technical ID: win.ginwui
MALWARE
Malware family identifying win.ginwui. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
GIMMICK
Technical ID: win.gimmick
MALWARE
Malware family identifying win.gimmick. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-28
View profile →
GIFTEDCROOK
Technical ID: win.giftedcrook
UAC-0226
MALWARE
According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data exfiltration.
Updated: 2026-01-26
View profile →
Giffy
Technical ID: win.giffy
MALWARE
Malware family identifying win.giffy. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-04
View profile →
Gibberish
Technical ID: win.gibberish
MALWAREfinancialhigh
Ransomware.
Updated: 2020-03-22
View profile →
GhostSecret
Technical ID: win.ghost_secret
Lazarus Group
MALWARE
Malware family identifying win.ghost_secret. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-27
View profile →
Ghost RAT
Technical ID: win.ghost_rat
EMISSARY PANDAHurricane PandaLazarus GroupLeviathan+2 more
MALWARE
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks on Earth. Below is a list of Gh0st RAT capabilities. Take full control of the remote screen on the infected bot. Provide real time as well as offline keystroke logging. Provide live feed of webcam, microphone of infected host. Download remote binaries on the infected remote host. Take control of remote shutdown and reboot of host. Disable infected computer remote pointer and keyboard input. Enter into shell of remote infected host with full control. Provide a list of all the active processes. Clear all existing SSDT of all existing hooks.
Also known as: Farfli • Gh0st RAT • PCRat
Updated: 2026-01-27
View profile →
GhostLocker
Technical ID: win.ghost_locker
MALWARE
Malware family identifying win.ghost_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-25
View profile →
GhostAdmin
Technical ID: win.ghost_admin
MALWARE
Malware family identifying win.ghost_admin. Origin and technical characteristics tracked via Malpedia.
Also known as: Ghost iBot
Updated: 2017-04-05
View profile →
GhostSocks
Technical ID: win.ghostsocks
MALWARE
GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in October 2023. It uses back-connect socket secure internet protocol (SOCKS5) connections and is available for rent for US $100 per month. In February 2024, the author of Lumma Stealer released an update introducing the integration of proxying capabilities. This feature, developed in partnership with GhostSocks, allows the use of infected hosts as SOCKS5 proxies and is available to all subscribers who purchase the "Professional" or higher tier plan. This integration allows Lumma Stealer users to establish a network of residential IP addresses for various purposes, including credential checking, spam distribution, or as general-purpose proxies.
Updated: 2025-10-02
View profile →
Gh0stnet
Technical ID: win.ghostnet
MALWARE
Malware family identifying win.ghostnet. Origin and technical characteristics tracked via Malpedia.
Also known as: Remosh
Updated: 2022-03-07
View profile →
Malware family identifying win.ghostengine. Origin and technical characteristics tracked via Malpedia.
GhostEmperor
Technical ID: win.ghostemperor
MALWARE
Malware family identifying win.ghostemperor. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-21
View profile →
Ghole
Technical ID: win.ghole
Rocket Kitten
MALWARE
Malware family identifying win.ghole. Origin and technical characteristics tracked via Malpedia.
Also known as: Gholee • CoreImpact (Modified)
Updated: 2022-04-29
View profile →
GHAMBAR
Technical ID: win.ghambar
MALWAREespionageadvanced
According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP. Its capabilities include filesystem manipulation, file upload and download, shell command execution, keylogging, screen capture, clipboard monitoring, and additional plugin execution.
Updated: 2023-11-17
View profile →
Gh0stTimes
Technical ID: win.gh0sttimes
MALWARE
Custom RAT developed by the BlackTech actor, based on the Gh0st RAT.
Updated: 2023-06-23
View profile →
Gh0stBins
Technical ID: win.gh0stbins
MALWARE
Malware family identifying win.gh0stbins. Origin and technical characteristics tracked via Malpedia.
Also known as: Gh0stBins RAT
Updated: 2023-08-07
View profile →
get_pwd
Technical ID: win.get_pwd
MALWARE
Malware family identifying win.get_pwd. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-01-23
View profile →
GetMyPass
Technical ID: win.getmypass
MALWARE
Malware family identifying win.getmypass. Origin and technical characteristics tracked via Malpedia.
Also known as: getmypos
Updated: 2022-09-19
View profile →
GetMail
Technical ID: win.getmail
Comment Crew
MALWARE
Malware family identifying win.getmail. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
Get2
Technical ID: win.get2
TA505
MALWARE
Malware family identifying win.get2. Origin and technical characteristics tracked via Malpedia.
Also known as: FRIENDSPEAK • GetandGo
Updated: 2022-02-14
View profile →
GeminiDuke
Technical ID: win.geminiduke
MALWARE
Malware family identifying win.geminiduke. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-05
View profile →
GEMCUTTER
Technical ID: win.gemcutter
APT 30
MALWARE
According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key. GEMCUTTER checks for the presence of the mutex MicrosoftGMMZJ to ensure only one copy of GEMCUTTER is executing. If the mutex doesn't exist, the malware creates it and continues execution; otherwise, the malware signals the MicrosoftGMMExit event.
Updated: 2019-04-17
View profile →
GEARSHIFT
Technical ID: win.gearshift
APT41
MALWARE
According to FireEye, GEARSHIFT is a memory-only dropper for two keylogger DLLs. It is designed to replace a legitimate Fax Service DLL.
Updated: 2019-08-13
View profile →
GearInformer
Technical ID: win.gearinformer
MALWARE
Malware family identifying win.gearinformer. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-21
View profile →
Gdrive
Technical ID: win.gdrive
APT 29APT29
MALWARE
According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim information uploaded and payloads delivered.
Also known as: DoomDrive • GoogleDriveSucks
Updated: 2023-04-22
View profile →
← PreviousPage 166 / 269Next →