Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
fengine
Technical ID: win.fengine
MALWARE
Malware family identifying win.fengine. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-22
View profile →
Felixroot
Technical ID: win.felixroot
GreyEnergy
MALWARE
Malware family identifying win.felixroot. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-09
View profile →
Felismus
Technical ID: win.felismus
Sowbug
MALWARE
Malware family identifying win.felismus. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-21
View profile →
FeedLoad
Technical ID: win.feed_load
Lazarus Group
MALWARE
Malware family identifying win.feed_load. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-20
View profile →
FDMTP
Technical ID: win.fdmtp
MUSTANG PANDA
MALWARE
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta. It functions as a simple malware downloader and is based on the TouchSocket framework over the Duplex Message Transport Protocol (DMTP). In one campaign, threat actors embedded FDMTP in the data section of a DLL. This allows it to be launched through DLL side-loading. The embedded network configurations are encoded and encrypted to enhance security and evade detection, utilizing Base64 and DES encryption methods. It has been observed to serve as a secondary control tool, often deployed by the PUBLOAD backdoor.
Updated: 2024-10-25
View profile →
FCT
Technical ID: win.fct
MALWAREfinancialhigh
Ransomware.
Updated: 2020-02-10
View profile →
Fauppod
Technical ID: win.fauppod
MALWARE
Malware family identifying win.fauppod. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-17
View profile →
FatDuke
Technical ID: win.fatduke
APT29
MALWAREespionageadvanced
According to ESET Research, FatDuke is the current flagship backdoor of APT29 and is only deployed on the most interesting machines. It is generally dropped by the MiniDuke backdoor, but ESET also have seen the operators dropping FatDuke using lateral movement tools such as PsExec.The operators regularly repack this malware in order to evade detections. The most recent sample of FatDuke that ESET have seen was compiled on May 24, 2019. They have seen them trying to regain control of a machine multiple times in a few days, each time with a different sample. Their packer, described in a later section, adds a lot of code, leading to large binaries. While the effective code should not be larger than 1MB, ESET have seen one sample weighing in at 13MB, hence our name for this backdoor component: FatDuke.
Updated: 2020-05-23
View profile →
FatalRat
Technical ID: win.fatal_rat
MALWARE
FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels. FatalRAT executes various anti-virtual machine tests to avoid detection before fully infecting systems. Upon successful infiltration, it decrypts configuration strings, disables the CTRL+ALT+DELETE function, and activates a keylogger. The malware can establish persistence via registry modifications or service creation, collect sensitive data, and communicate with its command and control (C&C) server using encrypted methods. FatalRAT also employs techniques like brute-force attacks against weak passwords to propagate within networks.
Also known as: Sainbox RAT
Updated: 2025-09-17
View profile →
FastPOS
Technical ID: win.fast_pos
MALWARE
Malware family identifying win.fast_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-05
View profile →
FastLoader
Technical ID: win.fastloader
MALWARE
FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples. It typically downloads TrickBot. It may create a list of processes and uploads it together with screenshot(s). In more recent versions, it employs simple anti-analysis checks (VM detection) and comes with string obfuscations.
Updated: 2020-01-14
View profile →
Farseer
Technical ID: win.farseer
MALWARE
Malware family identifying win.farseer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-02
View profile →
FantomCrypt
Technical ID: win.fantomcrypt
MALWAREfinancialhigh
According to PCrisk, Fantom is a ransomware-type virus that imitates the Windows update procedure while encrypting files. This is unusual, since most ransomware encrypts files stealthily without showing any activity. During encryption, Fantom appends the names of encrypted files with the ".locked4", ".fantom" or ".locked" extension.
Updated: 2023-05-02
View profile →
Fanny
Technical ID: win.fanny
Equation Group
MALWARE
Malware family identifying win.fanny. Origin and technical characteristics tracked via Malpedia.
Also known as: DEMENTIAWHEEL
Updated: 2022-05-23
View profile →
fancyfilter
Technical ID: win.fancyfilter
Equation Group
MALWARE
FancyFilter is a piece of code that documents code overlap between frameworks used by Regin and Equation Group.
Also known as: 0xFancyFilter
Updated: 2021-02-06
View profile →
FakeWord
Technical ID: win.fakeword
MALWARE
Malware family identifying win.fakeword. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-12
View profile →
FakeTC
Technical ID: win.faketc
MALWARE
Malware family identifying win.faketc. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-08-17
View profile →
FakeRean
Technical ID: win.fakerean
MALWARE
Malware family identifying win.fakerean. Origin and technical characteristics tracked via Malpedia.
Also known as: Braviax
Updated: 2018-07-31
View profile →
FakeCry
Technical ID: win.fakecry
MALWARE
Malware written in .NET that mimics WannaCry.
Updated: 2023-07-24
View profile →
Fabookie
Technical ID: win.fabookie
MALWARE
Fabookie is facebook account info stealer.
Updated: 2024-12-09
View profile →
EYService
Technical ID: win.eyservice
Nazar
MALWAREespionageadvanced
EYService is the main part of the backdoor used by Nazar APT. This a passive backdoor that relies on, now discontinued, Packet Sniffer SDK (PSSDK) from Microolap.
Updated: 2020-05-07
View profile →
Eye Pyramid
Technical ID: win.eye_pyramid
MALWARE
Malware family identifying win.eye_pyramid. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Xtreme RAT
Technical ID: win.extreme_rat
Molerats
MALWAREespionageadvanced
According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information. This RAT has been used in attacks targeting Israeli and Syrian governments last 2012. This malware family of backdoors has the capability to receive commands such as File Management (Download, Upload, and Execute Files), Registry Management (Add, Delete, Query, and Modify Registry), Perform Shell Command, Computer Control (Shutdown, Log on/off), and Screen capture from a remote attacker. In addition, it can also log keystrokes of the infected systems.
Also known as: ExtRat
Updated: 2024-06-05
View profile →
ExplosiveRAT
Technical ID: win.explosive_rat
MALWARE
Malware family identifying win.explosive_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-10-07
View profile →
Expiro
Technical ID: win.expiro
MALWARE
Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features. Also the infection routine was changed in samples fround in 2017 (described by McAfee). Expiro "infiltrates" executables on 32- and 64bit Windows OS versions. It has capabilities to install browser extensions, change security behaviour/settings on the infected system, and steal information (e.g. account credentials). There is a newly described EPO file infector source code called m0yv in 2022, which is wrongly identified as expiro by some AVs.
Also known as: Xpiro
Updated: 2023-08-31
View profile →
Exorcist
Technical ID: win.exorcist
MALWAREfinancialhigh
According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a ransom string of characters. For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.
Updated: 2023-05-21
View profile →
ExMatter
Technical ID: win.exmatter
MALWAREfinancialhigh
Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
Updated: 2024-06-12
View profile →
Exile RAT
Technical ID: win.exilerat
TA413
MALWAREespionageadvanced
ExileRAT is a simple RAT platform capable of getting information on the system (computer name, username, listing drives, network adapter, process name), getting/pushing files and executing/terminating processes.
Updated: 2020-09-16
View profile →
MS Exchange Tool
Technical ID: win.exchange_tool
Mirage
MALWARE
Malware family identifying win.exchange_tool. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-29
View profile →
Excalibur
Technical ID: win.excalibur
MALWARE
Malware family identifying win.excalibur. Origin and technical characteristics tracked via Malpedia.
Also known as: Sabresac • Saber
Updated: 2018-04-26
View profile →
ExByte
Technical ID: win.exbyte
MALWAREfinancialhigh
ExByte is a custom data exfiltration tool and infostealer observed being used during BlackByte ransomware attacks.
Updated: 2023-08-25
View profile →
Exaramel
Technical ID: win.exaramel
TeleBots
MALWARE
Malware family identifying win.exaramel. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-25
View profile →
Evrial
Technical ID: win.evrial
MALWARE
Malware family identifying win.evrial. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-01
View profile →
EvilPony
Technical ID: win.evilpony
MALWARE
Privately modded version of the Pony stealer.
Also known as: CREstealer
Updated: 2017-10-20
View profile →
EvilPlayout
Technical ID: win.evilplayout
MALWARE
A wiper used against in an attack against Iran’s state broadcaster. Using campaign name coined by Check Point in lack of a better name for the wiper component.
Updated: 2022-03-02
View profile →
EVILNUM
Technical ID: win.evilnum
MALWARE
Malware family identifying win.evilnum. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-20
View profile →
EvilGrab
Technical ID: win.evilgrab
Stone Panda
MALWARE
Malware family identifying win.evilgrab. Origin and technical characteristics tracked via Malpedia.
Also known as: Vidgrab
Updated: 2020-05-18
View profile →
EvilExtractor
Technical ID: win.evilextractor
MALWARE
Malware family identifying win.evilextractor. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-03-07
View profile →
EvilConwi
Technical ID: win.evilconwi
MALWARE
EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise. This software is a remote access software. Threat actors modify the configuration extensively so that any signs of an active remote connection are removed. EvilConwi often pretends to perform a Windows update by using fake Windows update images embedded in the config. The purpose is to keep the system running while the threat actor connect remotely. Other EvilConwi signs are fake application icons. E.g., it may pretend to be an installer for Zoom and use its icons and application titles in the ConnectWise config.
Updated: 2025-06-30
View profile →
Evilbunny
Technical ID: win.evilbunny
SNOWGLOBE
MALWARE
Malware family identifying win.evilbunny. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-09
View profile →
← PreviousPage 169 / 269Next →