Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUPespionageadvanced
Downloader used in suspected APT attack against Vietnam.
APT GROUPfinancialhigh
Ransomware written in Nim.
APT GROUP
Symantec describes this family as an unidentified tool set used to target a range of organizations in South East Asia. The campaign was first noticed in September 2020.
APT GROUP
A RAT written in .NET, potentially used by Transparent Tribe.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_083
APT GROUP
This Trojan is a full-featured RAT capable of executing common tasks such as command execution and downloading/uploading files. This is implemented through a couple dozen C++ classes such as CMFile, CMFile, CMProcess, TFileDownload, TDrive, TProcessInfo, TSock, etc. The first stage custom installer utilizes the same classes. The Trojan uses HTTP Server API to filter HTTPS packets at port 443 and parse commands.
It is also used by attackers to gather a target’s data, make lateral movements and create SOCKS tunnels to their C2 using the Earthworm tunneler.Given that the Trojan is an HTTPS server itself, the SOCKS tunnel is used for targets without an external IP, so the C2 is able to send commands.
Suspected Zebrocy loader written in Nim.
Malware family tracked by Malpedia. ID: win.unidentified_077
Malware family tracked by Malpedia. ID: win.unidentified_076
APT GROUP
Unpacked http_dll.dat from the blog post.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_074
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_073
APT GROUP
MSI-based loader that has been observed as a stager for win.metamorfo.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_071
APT GROUP
Unidentified downloader, possibly related to KONNI.
APT GROUP
Zeus derivate, no known public references.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_068
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_067
APT GROUP
This .net executable can receive commands from c2 sever, upload and download files according to the returned content, perform an uninstall, or modify the registry to achieve persistence across reboots. At the end, it downloads a Python-based RAT, called PeppyRAT.
APT GROUP
Was previously wrongly tagged as PoweliksDropper, now looking for additional context.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_058
APT GROUP
Unnamed portscanner as used in the Australian Parliament Hack (Feb 2019).
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_053
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_052
APT GROUPespionageadvanced
RAT written in Delphi used by Patchwork APT.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_045
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_044
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_042
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_041
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_039
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_038
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_037
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_031
APT GROUPfinancialhigh
Unnamed ransomware that camouflages as a program performing system cleanup called "System Analyzer Pro".
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_029
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_028
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_025_clickfraud
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_024_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_023
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_022_ransom