Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
gcman
Technical ID: win.gcman
MALWARE
Malware family identifying win.gcman. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-11
View profile →
GCleaner
Technical ID: win.gcleaner
MALWARE
Malware family identifying win.gcleaner. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-02
View profile →
Gazer
Technical ID: win.gazer
Turla
MALWARE
Malware family identifying win.gazer. Origin and technical characteristics tracked via Malpedia.
Also known as: WhiteBear
Updated: 2023-07-28
View profile →
Gazavat
Technical ID: win.gazavat
MALWARE
Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff. Functionality includes: - Loading other executables - Load hash cracking plugin - Load DMSniff plugin - Perform webinjection and webfakes - Form grabbing - Command execution - Download file from infected system - Convert infection into proxy - DDOS - Spreading and EXE infecting
Updated: 2024-03-25
View profile →
Gauss
Technical ID: win.gauss
MALWARE
Malware family identifying win.gauss. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-05
View profile →
Gaudox
Technical ID: win.gaudox
MALWARE
Gaudox is a http loader, written in C/C++. The author claims to have put much effort into making this bot efficient and stable. Its rootkit functionality hides it in Windows Explorer (32bit only).
Updated: 2017-11-21
View profile →
Gasket
Technical ID: win.gasket
MALWAREfinancialhigh
A backdoor used by Mespinoza ransomware gang to maintain access to a compromised network.
Updated: 2021-07-21
View profile →
Gandcrab
Technical ID: win.gandcrab
Pinchy Spider
MALWAREfinancialhigh
GandCrab was a Ransomware-as-a-Service (RaaS) emerged in January 28, 2018, managed by a criminal organization known to be confident and vocal, while running a rapidly evolving ransomware campaign. Through their aggressive, albeit unusual, marketing strategies and constant recruitment of affiliates, they were able to globally distribute a high volume of their malware. In a surprising announcement on May 31, 2019, the GandCrab’s operators posted on a dark web forum, announced the end of a little more than a year of ransomware operations, citing staggering profit figures. However, If there’s one thing that sets these threat actors apart from other groups, it is that they are unpredictable; so there is always the possibility that they might re-surface in one form or another.
Also known as: GrandCrab
Updated: 2024-01-31
View profile →
GAMYBEAR
Technical ID: win.gamybear
MALWARE
GAMYBEAR A software tool developed using the Go programming language. Its main functionality is to receive (“listener”), execute (‘executor’) commands, and send (“sender”) results to the control server in BASE64-encoded form using the HTTP protocol. When launched, it generates a unique identifier (UUID), receives basic information about the computer (“whoami”, “wmic nicconfig where IPEnabled=true get IPAddress”), creates a helper file %APPDATA%\ updater.json, where the URL of the control server is stored in JSON format (key “update_server”), as well as other listed data in BASE64-encoded form (keys: “uuid”, ‘hostname’, “ip”, respectively). During operation, the software regularly sends requests to the control server (URI: “/c2/get_commands/”) and waits for a response in JSON format with the ‘command’ and “arguments” fields. If the “Nop” command is received, a 15-second pause is initiated. After the commands are executed, the result and other data are encoded using BASE64, stored in a JSON structure (keys: “uuid”, “command”, ‘output’) and sent to the control server with a request to the URI “/c2/command_out/”. The consistency of the launch is ensured by another program (script) at the stage of the initial infection of the computer by creating a key in the “Run” branch of the operating system registry.
Updated: 2025-11-21
View profile →
Gamotrol
Technical ID: win.gamotrol
MALWARE
Malware family identifying win.gamotrol. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
GamePlayerFramework
Technical ID: win.game_player_framework
MALWARE
Malware family identifying win.game_player_framework. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-10-25
View profile →
Gameover P2P
Technical ID: win.gameover_p2p
MALWAREfinancialhigh
Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan. According to a report by Symantec, Gameover Zeus has largely been used for banking fraud and distribution of the CryptoLocker ransomware. In early June 2014, the U.S. Department of Justice announced that an international inter-agency collaboration named Operation Tovar had succeeded in temporarily cutting communication between Gameover ZeuS and its command and control servers.
Also known as: GOZ • Gameover ZeuS • Mapp • ZeuS P2P
Updated: 2024-05-14
View profile →
Gameover DGA
Technical ID: win.gameover_dga
MALWARE
Malware family identifying win.gameover_dga. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-18
View profile →
gamapos
Technical ID: win.gamapos
MALWARE
Malware family identifying win.gamapos. Origin and technical characteristics tracked via Malpedia.
Also known as: pios
Updated: 2018-04-25
View profile →
GalaxyLoader
Technical ID: win.galaxyloader
MALWARE
GalaxyLoader is a simple .NET loader. Its name stems from the .pdb and the function naming. It seems to make use of iplogger.com for tracking. It employed WMI to check the system for - IWbemServices::ExecQuery - SELECT * FROM Win32_Processor - IWbemServices::ExecQuery - select * from Win32_VideoController - IWbemServices::ExecQuery - SELECT * FROM AntivirusProduct
Updated: 2018-03-26
View profile →
Gaganode
Technical ID: win.gaganode
MALWARE
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
Updated: 2025-12-08
View profile →
Gacrux
Technical ID: win.gacrux
MALWARE
Malware family identifying win.gacrux. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-29
View profile →
GaboonGrabber
Technical ID: win.gaboongrabber
MALWARE
According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless stages. Additionally, it has the tendency to camouflage itself as a legitimate application, going so far as to mimic legitimate applications in its decompiled code. It also includes a steganographic image used to prepare further payloads. GaboonGrabber's final stage can deploy various types of malware, including Snake Keylogger, AgentTesla, Redline, Lokibot, and more.
Updated: 2024-06-28
View profile →
FuxSocy
Technical ID: win.fuxsocy
MALWARE
FuxSocy has some similarities to win.cerber but is tracked as its own family for now.
Updated: 2019-11-15
View profile →
FuwuqiDrama
Technical ID: win.fuwuqidrama
Lazarus Group
MALWARE
FuwuqiDrama is a server-side RAT. It manages client connections by utilizing I/O completion ports, which are usually used in high-performance server applications as an elegant solution to manage many clients at once. It contains two distinguishing hardcoded lists. First is a list of ~50 video files of South Korean TV series, having their titles translated to Mandarin Chinese, but encoded in the form of Pinyin romanization. That means the sounds are spelled in Latin alphabet without tone marks, for example meiyounihuobuxiaqu.avi represents Can't Live Without You (a K-drama from 2012) or wulalafufu.avi translates to Ohlala Couple (also from 2012). Second is the list of the following corporations: NVIDIA, Amazon, Intel, Skype, 360Safe, Rising, Tencent, Mozilla, Adobe, Yahoo, Google. The same list is contained in some of the WannaCryptor samples. FuwuqiDrama stores its configuration in the INI file data\package_con_x86.cat. It contains the port number and a bot identifier, all within a single section called Fuwuqi – the romanized Chinese word for server.
Updated: 2023-09-11
View profile →
FusionDrive
Technical ID: win.fusiondrive
APT28
MALWARE
Malware family identifying win.fusiondrive. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-25
View profile →
Furtim
Technical ID: win.furtim
MALWARE
Malware family identifying win.furtim. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
FunnyDream
Technical ID: win.funny_dream
MALWARE
Malware family identifying win.funny_dream. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-23
View profile →
FunnySwitch
Technical ID: win.funnyswitch
Earth LuscaWinnti Umbrella
MALWARE
Malware family identifying win.funnyswitch. Origin and technical characteristics tracked via Malpedia.
Also known as: RouterGod
Updated: 2023-08-09
View profile →
FunkSec
Technical ID: win.funksec
MALWAREfinancialhigh
According to Check Point Research, a ransomware written in Rust that was likely developed using the aid of an LLM to produce code snippets.
Updated: 2025-01-14
View profile →
FULLMETAL
Technical ID: win.fullmetal
MALWARE
Malware family identifying win.fullmetal. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-13
View profile →
Fujinama is a custom VB info stealer capable to execute custom commands and custom exfiltrations, keylogging and screenshot. It was involved in the compromise of Leonardo SpA, a major Italian aerospace and defense company.
FudModule
Technical ID: win.fudmodule
Lazarus Group
MALWARE
FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.
Also known as: LIGHTSHOW
Updated: 2025-11-10
View profile →
Fs0ciety
Technical ID: win.fs0ciety
MALWARE
Malware family identifying win.fs0ciety. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-29
View profile →
FROZENHILL
Technical ID: win.frozenhill
MALWARE
FROZENHILL is a launcher written in C++ that is configured to utilize existing files for execution and also infects newly attached storage volumes with additional malware.
Updated: 2025-03-28
View profile →
FrostyGoop
Technical ID: win.frostygoop
MALWARE
Malware family identifying win.frostygoop. Origin and technical characteristics tracked via Malpedia.
Also known as: BUSTLEBERM
Updated: 2025-04-25
View profile →
FriedEx
Technical ID: win.friedex
INDRIK SPIDER
MALWARE
Malware family identifying win.friedex. Origin and technical characteristics tracked via Malpedia.
Also known as: BitPaymer • DoppelPaymer • IEncrypt
Updated: 2023-12-27
View profile →
Freenki Loader
Technical ID: win.freenki
APT37
MALWARE
Malware family identifying win.freenki. Origin and technical characteristics tracked via Malpedia.
Also known as: SHUTTERSPEED
Updated: 2023-08-17
View profile →
FRat
Technical ID: win.frat
MALWARE
A RAT employing Node.js, Sails, and Socket.IO to collect information on a target
Updated: 2020-06-12
View profile →
FPSpy
Technical ID: win.fpspy
MALWARE
Malware family identifying win.fpspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-15
View profile →
FoxSocket
Technical ID: win.foxsocket
MALWARE
Malware family identifying win.foxsocket. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-24
View profile →
FortuneCrypt
Technical ID: win.fortunecrypt
MALWARE
Malware family identifying win.fortunecrypt. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-11
View profile →
FormerFirstRAT
Technical ID: win.former_first_rat
DragonOKSamurai Panda
MALWARE
Malware family identifying win.former_first_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: ffrat
Updated: 2022-08-26
View profile →
Formbook
Technical ID: win.formbook
SWEEDCobalt
MALWARE
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
Also known as: win.xloader
Updated: 2026-01-14
View profile →
ForestTiger
Technical ID: win.forest_tiger
Lazarus Group
MALWARE
Malware family identifying win.forest_tiger. Origin and technical characteristics tracked via Malpedia.
Also known as: ScoringMathTea
Updated: 2025-09-15
View profile →
← PreviousPage 167 / 269Next →