Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
EtumBot
Technical ID: win.etumbot
IXESHE
MALWARE
Malware family identifying win.etumbot. Origin and technical characteristics tracked via Malpedia.
Also known as: HighTide
Updated: 2020-05-23
View profile →
Eternity Worm
Technical ID: win.eternity_worm
MALWARE
This malware is part of the Eternity Malware "Framework".
Updated: 2022-07-28
View profile →
Eternity Stealer
Technical ID: win.eternity_stealer
MALWARE
This Stealer is part of the eternity malware project.
Updated: 2024-11-26
View profile →
Eternity Ransomware
Technical ID: win.eternity_ransomware
MALWAREfinancialhigh
Eternity Framework Ransomware Payload
Updated: 2022-07-28
View profile →
Eternity Clipper
Technical ID: win.eternity_clipper
MALWARE
This malware is part of the Eternity Malware "Framework".
Updated: 2023-03-23
View profile →
EternalPetya
Technical ID: win.eternal_petya
TeleBotsSandworm
MALWAREfinancialhigh
According to proofpoint, Bad Rabbit is a strain of ransomware that first appeared in 2017 and is a suspected variant of Petya. Like other strains of ransomware, Bad Rabbit virus infections lock up victims’ computers, servers, or files preventing them from regaining access until a ransom—usually in Bitcoin—is paid.
Also known as: ExPetr • Pnyetya • Petna • NotPetya • Nyetya
Updated: 2024-04-23
View profile →
EternalRocks
Technical ID: win.eternalrocks
MALWARE
Malware family identifying win.eternalrocks. Origin and technical characteristics tracked via Malpedia.
Also known as: MicroBotMassiveNet
Updated: 2023-11-14
View profile →
ESPecter
Technical ID: win.especter
MALWARE
Malware family identifying win.especter. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-11-19
View profile →
Eris
Technical ID: win.eris
MALWAREfinancialhigh
Ransomware.
Updated: 2019-10-10
View profile →
Erica Ransomware
Technical ID: win.erica_ransomware
MALWAREfinancialhigh
Malware family identifying win.erica_ransomware. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-01
View profile →
Eredel
Technical ID: win.eredel
MALWARE
Eredel Stealer is a low price malware that allows for extracting passwords, cookies, screen desktop from browsers and programs. According to nulled[.]to: Supported browsers Chromium Based: Chromium, Google Chrome, Kometa, Amigo, Torch, Orbitum, Opera, Opera Neon, Comodo Dragon, Nichrome (Rambler), Yandex Browser, Maxthon5, Sputnik, Epic Privacy Browser, Vivaldi, CocCoc and other Chromium Based browsers. - Stealing FileZilla - Stealing an account from Telegram - Stealing AutoFill - Theft of wallets: Bitcoin | Dash | Monero | Electrum | Ethereum | Litecoin - Stealing files from the desktop. Supports any formats, configurable via telegram-bot
Updated: 2018-09-21
View profile →
Erebus
Technical ID: win.erebus
MALWARE
Malware family identifying win.erebus. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Erbium Stealer
Technical ID: win.erbium_stealer
MALWARE
Erbium is an information stealer advertised and sold as a Malware-as-a-Service on cybercrime forums and Telegram since at least July 2022. Its capabilities are those of a classic information stealer, with a focus on cryptocurrency wallets, and file grabber capabilities.
Updated: 2022-12-05
View profile →
Equationgroup (Sorting)
Technical ID: win.equationgroup
MALWARE
Rough collection EQGRP samples, to be sorted
Updated: 2024-12-02
View profile →
EquationDrug
Technical ID: win.equationdrug
Equation Group
MALWARE
Malware family identifying win.equationdrug. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-23
View profile →
Epsilon Stealer
Technical ID: win.epsilon_stealer
MALWARE
Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon". This malware is distributed as a game, mainly on discord, but steals user credentials, crypto wallets, and stored cookies. It evades static detection by being packed with NSIS, which then launches a malicious Electron package.
Updated: 2024-12-09
View profile →
Epsilon Red
Technical ID: win.epsilon_red
MALWAREfinancialhigh
According to PCrisk, Epsilon is a ransomware-type program. This malware is designed to encrypt the data of infected systems in order to demand payment for decryption.
Also known as: BlackCocaine
Updated: 2025-07-28
View profile →
EnvyScout
Technical ID: win.envyscout
MALWARE
Malware family identifying win.envyscout. Origin and technical characteristics tracked via Malpedia.
Also known as: ROOTSAW
Updated: 2024-02-02
View profile →
Enviserv
Technical ID: win.enviserv
MALWARE
According to Microsoft, Enviserv is a malicious program that is unable to spread of its own accord. It may perform a number of actions of an attacker's choice on an affected computer.
Updated: 2024-09-04
View profile →
EntryShell
Technical ID: win.entryshell
MALWARE
Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old KeyBoy samples. The embedded malware config was encrypted with a unique algorithm.
Updated: 2025-10-29
View profile →
Entropy
Technical ID: win.entropy
MALWAREfinancialhigh
Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomware uses a custom packer to pack itself which has been seen in some early dridex samples.
Updated: 2023-03-23
View profile →
Enigma Loader
Technical ID: win.enigma_loader
MALWARE
According to Trend Micro, this is a downloader, dedicated to stage execution of a second stage malware called Enigma Stealer.
Updated: 2023-02-13
View profile →
Enfal
Technical ID: win.enfal
MALWARE
Malware family identifying win.enfal. Origin and technical characteristics tracked via Malpedia.
Also known as: Lurid
Updated: 2022-08-30
View profile →
Emudbot
Technical ID: win.emudbot
MALWARE
Supposedly a worm that was active around 2012-2013.
Updated: 2020-08-13
View profile →
Empire Downloader
Technical ID: win.empire_downloader
MALWARE
Malware family identifying win.empire_downloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-31
View profile →
Emotet
Technical ID: win.emotet
GOLD CABINMUMMY SPIDERMealybug
MALWAREfinancialhigh
While Emotet historically was a banking malware organized in a botnet, nowadays Emotet is mostly seen as infrastructure as a service for content delivery. For example, since mid 2018 it is used by Trickbot for installs, which may also lead to ransomware attacks using Ryuk, a combination observed several times against high-profile targets. It is always stealing information from victims but what the criminal gang behind it did, was to open up another business channel by selling their infrastructure delivering additional malicious software. From malware analysts it has been classified into epochs depending on command and control, payloads, and delivery solutions which change over time. Emotet had been taken down by authorities in January 2021, though it appears to have sprung back to life in November 2021.
Also known as: Geodo • Heodo
Updated: 2025-06-18
View profile →
Emmenhtal
Technical ID: win.emmenhtal
MALWARE
Emmenhtal is a malicious loader likely distributed since early 2024, and publicly detailed by Orange Cyberdefense CERT in August 2024. Emmenhtal is an obfuscated multistage payload that spawns an execution of the LOLBIN mshta.exe to read a first HTA stage that embeds a malicious JavaScript code. Once interpreted and executed, the JavaScript decodes and runs a PowerShell script. The latter decrypts an obfuscated PowerShell loader which finally downloads and runs final-stage stealers and commodity RATs. As of March 2025, Orange Cyberdefense CERT has identified three versions of the loader, all actively distributed.
Also known as: IDATDropper • PEAKLIGHT
Updated: 2025-05-12
View profile →
Emissary
Technical ID: win.emissary
MALWARE
Malware family identifying win.emissary. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-04
View profile →
Emdivi
Technical ID: win.emdivi
Stone Panda
MALWARE
Malware family identifying win.emdivi. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-02
View profile →
emansrepo
Technical ID: win.emansrepo
MALWARE
Infostealer
Updated: 2024-11-04
View profile →
ELMER
Technical ID: win.elmer
DantiAPT 16
MALWARE
ELMER is a non-persistent proxy-aware HTTP backdoor written in Delphi, and is capable of performing file uploads and downloads, file execution, and process and directory listings. To retrieve commands, ELMER sends HTTP GET requests to a hard-coded CnC server, and parses the HTTP response packets received from the CnC server for an integer string corresponding to the command that needs to be executed.
Also known as: Elmost
Updated: 2022-07-05
View profile →
El Machete APT Backdoor Dropper
Technical ID: win.elmachete_dropper_2022
El Machete
MALWARE
This dropper masquerades itself as Adobe software, titled as Adobe.msi. It is used to executes the python written Backdoor used by this threat actor.
Updated: 2022-04-05
View profile →
ElizaRAT
Technical ID: win.eliza_rat
Operation C-Major
MALWARE
Malware family identifying win.eliza_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-19
View profile →
Elise
Technical ID: win.elise
Lotus Blossom
MALWARE
Malware family identifying win.elise. Origin and technical characteristics tracked via Malpedia.
Also known as: EVILNEST
Updated: 2021-05-25
View profile →
Elirks
Technical ID: win.elirks
MALWARE
Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. Mostly attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. Multiple Elirks variants using Japanese blog services for the last couple of years.
Updated: 2023-08-29
View profile →
ElectricPowder
Technical ID: win.electric_powder
MALWARE
Malware family identifying win.electric_powder. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-02-14
View profile →
ELECTRICFISH
Technical ID: win.electricfish
Lazarus Group
MALWARE
The application is a command-line utility and its primary purpose is to tunnel traffic between two IP addresses. The application accepts command-line arguments allowing it to be configured with a destination IP address and port, a source IP address and port, a proxy IP address and port, and a user name and password, which can be utilized to authenticate with a proxy server. It will attempt to establish TCP sessions with the source IP address and the destination IP address. If a connection is made to both the source and destination IPs, this malicious utility will implement a custom protocol, which will allow traffic to rapidly and efficiently be tunneled between two machines. If necessary, the malware can authenticate with a proxy to be able to reach the destination IP address. A configured proxy server is not required for this utility.
Updated: 2023-02-21
View profile →
Ekipa RAT
Technical ID: win.ekipa
MALWARE
Malware family identifying win.ekipa. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-05
View profile →
EHDevel
Technical ID: win.ehdevel
MALWARE
Malware family identifying win.ehdevel. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-08-19
View profile →
Egregor
Technical ID: win.egregor
MALWAREfinancialhigh
According to Heimdal, Egregor ransomware infection happens via a loader, then, in the victim’s firewall, it enables the Remote Desktop Protocol. After this part, the malware is free to move inside the victim’s network, identifying and disabling all the antivirus software it can find. The next step is the encryption of the data and the insertion of a ransom note named “RECOVER-FILES.txt” in all the compromised folders.
Updated: 2024-02-16
View profile →
← PreviousPage 170 / 269Next →