Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
FONIX
Technical ID: win.fonix
MALWARE
Malware family identifying win.fonix. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-04
View profile →
Fog
Technical ID: win.fog
MALWAREfinancialhigh
According to SentinelOne, Fog Ransomware emerged in April of 2024 with operations targeting both Windows and Linux endpoints. Fog is a multi-pronged extortion operation, leveraging a TOR-based DLS to list victims and host data for those that refuse to comply with their ransom demands.
Updated: 2025-06-24
View profile →
Fobber
Technical ID: win.fobber
MALWARE
Malware family identifying win.fobber. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-01
View profile →
FoalShell
Technical ID: win.foalshell
YoroTrooper
MALWARE
According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#. FoalShell allows attackers to execute arbitrary commands in the cmd.exe command line interpreter on a compromised host.
Updated: 2026-01-19
View profile →
FlyStudio
Technical ID: win.flystudio
MALWARE
Malware family identifying win.flystudio. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-19
View profile →
FlyingDutchman
Technical ID: win.flying_dutchman
Calypso group
MALWARE
Malware family identifying win.flying_dutchman. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-11-12
View profile →
Flusihoc
Technical ID: win.flusihoc
MALWARE
Available since 2015, Flusihoc is a versatile C++ malware capable of a variety of DDoS attacks as directed by a Command and Control server. Flusihoc communicates with its C2 via HTTP in plain text.
Updated: 2017-10-09
View profile →
Floxif
Technical ID: win.floxif
MALWARE
Malware family identifying win.floxif. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-06
View profile →
FlowerShop
Technical ID: win.flowershop
MALWARE
Malware family identifying win.flowershop. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-07
View profile →
FlowCloud
Technical ID: win.flowcloud
Stone Panda
MALWARE
Malware family identifying win.flowcloud. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-15
View profile →
FlokiBot
Technical ID: win.floki_bot
MALWARE
Malware family identifying win.floki_bot. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-22
View profile →
FlexiSpy
Technical ID: win.flexispy
MALWARE
Malware family identifying win.flexispy. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-01
View profile →
Flesh Stealer
Technical ID: win.flesh_stealer
MALWARE
According to M4lcode, FleshStealer is a sophisticated, modular, and obfuscated .NET-based information-stealing malware designed for comprehensive data exfiltration from Windows systems. Its architecture is built for scale and stealth, utilizing multithreading to simultaneously run multiple data harvesting routines with minimal system disruption. The malware targets a wide range of applications and services, including browsers, messaging apps, email clients, VPNs, cryptocurrency wallets, FTP clients, game launchers, and local file storage.
Updated: 2025-12-15
View profile →
FlawedGrace
Technical ID: win.flawedgrace
TA505
MALWARE
According to ProofPoint, FlawedGrace is written in C++ and can be categorized as a Remote Access Trojan (RAT). It seems to have been developed in the second half of 2017 mainly. FlawedGrace uses a series of commands: FlawedGrace also uses a series of commands, provided below for reference: * desktop_stat * destroy_os * target_download * target_module_load * target_module_load_external * target_module_unload * target_passwords * target_rdp * target_reboot * target_remove * target_script * target_servers * target_update * target_upload
Also known as: GraceWire
Updated: 2024-08-29
View profile →
FlawedAmmyy
Technical ID: win.flawedammyy
TA505
MALWARE
FlawedAmmyy is a well-known Remote Access Tool (RAT) attributed to criminal gang TA505 and used to get the control of target machines. The name reminds the strong link with the leaked source code of Ammyy Admin from which it took the main structure.
Updated: 2022-02-14
View profile →
FlashDevelop
Technical ID: win.flash_develop
Handala
MALWARE
According to Intezer, this is a shellcode loader.
Updated: 2024-10-18
View profile →
FLASHFLOOD
Technical ID: win.flashflood
APT 30
MALWARE
FLASHFLOOD will scan inserted removable drives for targeted files, and copy those files from the removable drive to the FLASHFLOOD-infected system. FLASHFLOOD may also log or copy additional data from the victim computer, such as system information or contacts.
Updated: 2022-08-25
View profile →
Flame
Technical ID: win.flame
MALWARE
Malware family identifying win.flame. Origin and technical characteristics tracked via Malpedia.
Also known as: sKyWIper
Updated: 2023-10-05
View profile →
Flagpro
Technical ID: win.flagpro
BlackTech
MALWARE
According to PICUS, Flagpro is malware that collects information from the victim and executes commands in the victim’s environment. It targets Japan, Taiwan, and English-speaking countries. When a victim is infected with Flagpro malware, the malware can do the following: Download and execute a tool Execute OS commands and send results Collect and send Windows authentication information
Also known as: BUSYICE
Updated: 2023-05-21
View profile →
FK_Undead
Technical ID: win.fk_undead
MALWARE
This malware family is mainly spread through various private server clients in bundles, and mainly tamper with user system network data packets through technical means such as TDI filtering, DNS hijacking, HTTP(s) injection, and HOSTS redirection, hijacking normal web page access to designated private server websites, and using security software cloud detection and killing data packet shielding, shutdown callback rewriting and other means to achieve counter-detection.
Also known as: Undead
Updated: 2024-10-14
View profile →
FiveHands
Technical ID: win.fivehands
[Unnamed group]
MALWARE
Malware family identifying win.fivehands. Origin and technical characteristics tracked via Malpedia.
Also known as: Thieflock
Updated: 2023-12-28
View profile →
FishMaster
Technical ID: win.fishmaster
Earth Lusca
MALWARE
A custom loader for CobaltStrike.
Also known as: JollyJellyfish
Updated: 2023-04-28
View profile →
FirstRansom
Technical ID: win.first_ransom
MALWARE
Malware family identifying win.first_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
FireMalv
Technical ID: win.firemalv
Rocket Kitten
MALWARE
Malware family identifying win.firemalv. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-17
View profile →
FireCrypt
Technical ID: win.firecrypt
MALWARE
Malware family identifying win.firecrypt. Origin and technical characteristics tracked via Malpedia.
Fire Chili
Technical ID: win.firechili
Shell Crew
MALWARE
The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g. files, processes, registry keys and network connections). According to Fortguard Labs, this malware uses Direct Kernel Object Modification (DKOM), which involves undocumented kernel structures and objects, for its operations, why this malware has to rely on specific OS builds.
Updated: 2022-04-04
View profile →
FireBird RAT
Technical ID: win.firebird_rat
MALWARE
Malware family identifying win.firebird_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
Fireball
Technical ID: win.fireball
MALWARE
Malware family identifying win.fireball. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-07-11
View profile →
FINTEAM
Technical ID: win.finteam
MALWARE
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer. This is achieved by sideloading another DLL among the legit TeamViewer.
Also known as: TeamBot
Updated: 2023-07-24
View profile →
FinFisher RAT
Technical ID: win.finfisher
MALWARE
FinFisher is a commercial software used to steal information and spy on affected victims. It began with few functionalities which included password harvesting and information leakage, but now it is mostly known for its full Remote Access Trojan (RAT) capabilities. It is mostly known for being used in governmental targeted and lawful criminal investigations. It is well known for its anti-detection capabilities and use of VMProtect.
Also known as: FinSpy
Updated: 2023-03-24
View profile →
FindPOS
Technical ID: win.findpos
MALWARE
Malware family identifying win.findpos. Origin and technical characteristics tracked via Malpedia.
Also known as: Poseidon
Updated: 2021-09-19
View profile →
FINALDRAFT
Technical ID: win.finaldraft
MALWARE
Malware family identifying win.finaldraft. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-13
View profile →
Final1stSpy
Technical ID: win.final1stspy
APT37
MALWARE
Malware family identifying win.final1stspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-23
View profile →
Filerase
Technical ID: win.filerase
APT33
MALWARE
Filerase is a .net API-based utility capable of propagating and recursively deleting files.
Updated: 2020-04-21
View profile →
FileIce
Technical ID: win.fileice_ransom
MALWARE
Malware family identifying win.fileice_ransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
Fickle Stealer
Technical ID: win.fickle
MALWARE
Malware family identifying win.fickle. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-25
View profile →
Ficker Stealer
Technical ID: win.fickerstealer
MALWARE
According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information, cryptocurrency wallets and browser information from applications such as WinSCP, Discord, Google Chrome, Electrum, etc. It does all that by implementing a different approach than other stealers (we’ll cover it later). Additionally, FickerStealer can function as a File Grabber and collect additional files from the compromised machine, and it can act as a Downloader to download and execute several second-stage malware.
Updated: 2022-11-09
View profile →
FFDroider
Technical ID: win.ffdroider
MALWARE
According to PCrisk, FFDroider is a malicious program classified as a stealer. It is designed to extract and exfiltrate sensitive data from infected devices. FFDroider targets popular social media and e-commerce platforms in particular.
Updated: 2023-03-27
View profile →
Feodo
Technical ID: win.feodo
MALWAREfinancialhigh
Feodo (also known as Cridex or Bugat) is a Trojan used to commit e-banking fraud and to steal sensitive information from the victims computer, such as credit card details or credentials.
Also known as: Cridex • Bugat
Updated: 2025-07-14
View profile →
Fenix
Technical ID: win.fenix
MALWARE
Malware family identifying win.fenix. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-17
View profile →
← PreviousPage 168 / 269Next →