Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_020_cia_vault7
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_013_korean_malware
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_006
unidentified 003
Technical ID: unidentified_003
APT GROUP
Malware family tracked by Malpedia. ID: py.unidentified_003
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_001
APT GROUP
Malware family tracked by Malpedia. ID: win.underminer_ek
APT GROUPfinancialhigh
Umbral is a data-stealing Trojan that targets Windows systems. It spreads through phishing emails and malicious attachments. Once installed, Umbral can steal a variety of data, including usernames, passwords, online banking credentials, and confidential files. It can also change computer settings and execute harmful commands. Umbral is a serious security threat and should be removed immediately if found.
APT GROUP
Malware family tracked by Malpedia. ID: win.uiwix
APT GROUP
Malware family tracked by Malpedia. ID: win.udpos
APT GROUP
A toolkit maintained by hfiref0x which incorporates numerous UAC bypass techniques for Windows 7 - Windows 10. Typically, components of this tool are stripped out and reused by malicious actors.
APT GROUP
Malware family tracked by Malpedia. ID: win.t_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.t_cmd
APT GROUP
Malware family tracked by Malpedia. ID: win.tyupkin
APT GROUP
According to PCrisk, Typhon is a stealer-type malware written in the C# programming language. Newer versions of this program are called Typhon Reborn (TyphonReborn). Malware within this classification is designed to extract data from infected systems. The older variants of Typhon have a broader range of functionalities, while Typhon Reborn versions are streamlined stealers.
APT GROUP
Malware family tracked by Malpedia. ID: win.typehash
APT GROUP
TYPEFRAME is a RAT.
It supports ~25 commands that include operations on the victim’s filesystem, manipulation with its configuration, modification of the system's firewall, the download and execution of additional tools from the attacker’s C&C and the uninstall via a self-delete batch. The commands are indexed by 16-bit integers, starting with the value 0x8000.
The RAT uses RC4 for decryption of its binary configuration. It has a statically linked OpenSSL 0.9.8k library used for SSL communication.
APT GROUP
Malware family tracked by Malpedia. ID: win.twodash
APT GROUP
Malware family tracked by Malpedia. ID: win.turnedup
APT GROUP
Malware family tracked by Malpedia. ID: win.turla_silentmoon
APT GROUP
Malware family tracked by Malpedia. ID: win.turla_rpc
APT GROUP
Malware family tracked by Malpedia. ID: win.turkojan
APT GROUP
According to Mitre, Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.
APT GROUPespionageadvanced
According to its Github repo, Tuoni is a sophisticated, cross-platform red teaming framework designed to enhance cybersecurity education and training through large-scale cyber defense exercises. Developed using Java for robustness, Docker for versatility, and featuring an intuitive web browser interface, it supports and streamlines cyber exercises. With its modular, extendable plugin system, Tuoni offers Red Teamers the flexibility to tailor its capabilities for specific educational and exercise needs. Its user-friendly interface facilitates easy operation and efficient reporting, essential in training environments. Tuoni embodies a commitment to power, adaptability, and collaboration, aimed at empowering Red Teamers with a tool that meets the dynamic demands of modern cyber defense education.
APT GROUP
Malware family tracked by Malpedia. ID: win.tunnelspecter
APT GROUP
Malware family tracked by Malpedia. ID: win.tunnelfish
APT GROUPespionageadvanced
TsunamiKit is a multi-stage malware toolkit written in Python and .NET.
The execution chain consists of several modules—including TsunamiLoader, TsunamiInjector, TsunamiInstaller, TsunamiPayload and the core TsunamiClient. The name is derived from the developer's recurring use of "Tsunami" in its components, e.g. "C# Tsunami Dist Version 3.0.0" or "Tsunami Stable\Tsunami Payload".
The primary purpose of the core module depends on the variant. It either carries out information theft by exfiltrating browser data, or monetize its presence by dropping cryptocurrency miners like XMRig and NBMiner. It also fingerprints the compromised system and uses the Tor network for command-and-control (C&C) communication.
While it was delivered by the InvisibleFerret malware in November 2024, older samples dating back to November 2021 suggest TsunamiKit is a pre-existing dark web project adapted by the APT actors.
APT GROUP
Malware family tracked by Malpedia. ID: win.tsifiri
APT GROUPespionageadvanced
TrustConnect RAT is a malware-as-a-service remote access trojan disguised as a legitimate remote monitoring tool. It gives attackers full control of infected systems through a web dashboard, allowing them to manage compromised devices, run commands, transfer files, collect system data, initiate remote desktop sessions, and record screens via standard SSL/TLS-protected web APIs.
DocConnect RAT is an upgraded and reengineered version of TrustConnect RAT. It fixes earlier security and detection weaknesses (such as poor credential storage, weak persistence, and detectable command-and-control mechanisms) while adding new capabilities, including an interactive multi-session terminal, stronger process protection against termination, a fake Windows Update overlay for deception, and a PDF-based lure and delivery system.
APT GROUP
Malware family tracked by Malpedia. ID: win.trump_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.troystealer
APT GROUP
Malware family tracked by Malpedia. ID: win.troublegrabber
APT GROUPespionageadvanced
Tropidoor is an advanced HTTP/S Remote Access Trojan (RAT) written as a C project, which exhibits significant code overlap with the PostNapTea RAT. In November 2024, it was deployed in campaigns targeting developers via fake recruiters as part of a social engineering campaign distributing trojanized open-source projects on platforms like Bitbucket. It is a final-stage payload in a multi-stage execution chain, which also deployed an obfuscated BeaverTail malware.
The RAT uses RSA and AES for encryption and decryption of network traffic. Communication with the C2 uses specific HTTP POST parameters, including tropi2p, gumi, s_width, and letter, with the first parameter loosely inspiring its code name. It stores its configuration in a binary format and resolves required Windows APIs during runtime via the Fowler–Noll–Vo (FNV) hash function. Many of its characteristic strings are XOR encrypted.
A key technical feature is its custom implementation of various Windows administrative and reconnaissance commands. By implementing this functionality internally, the RAT avoids executing the legitimate Windows binaries, making its command execution activities harder to detect by behavioral monitoring tools. Custom implemented commands include functionality equivalent to standard utilities like:
arp
dir
ipconfig
kill
net
netsh
netstat
nslookup
ping
reg
rm
sc
schtasks
systeminfo
tracert
wmic logicaldisk
wmic process
APT GROUP
Malware family tracked by Malpedia. ID: win.troll_stealer
APT GROUPfinancialhigh
According to Malwarebyte, Ransomware is a type of malware that prevents users from accessing their system or personal files and demands ransom payment in order to regain access. Ransom.Troldesh is spread by malspam, typically in the form of attached .zip files. This ransomware sometimes uses a CMS on a compromised site to host downloads.
APT GROUP
Trochilus is a C++ written RAT, which is available on GitHub.
GitHub Repo:
- https://github.com/m0n0ph1/malware-1/tree/master/Trochilus
- https://github.com/5loyd/trochilus
APT GROUP
Malware attacking commonly used in Industrial Control Systems (ICS) Triconex Safety Instrumented System (SIS) controllers.
APT GROUPfinancial
According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.
Affiliates: Wazawaka
Infra: 🔗 6n5tfadusp4sarzuxntz…🔗 trigonax2zb3fw34rbaa…🔗 trigonax2zb3fw34rbaa…+7 more
RSLUpdated: 2026-08-04
View profile →APT GROUPfinancialhigh
A financial Trojan believed to be a derivative of Dyre: the bot uses very similar code, web injects, and operational tactics. Has multiple modules including VNC and Socks5 Proxy. Uses SSL for C2 communication.
- Q4 2016 - Detected in wild
Oct 2016 - 1st Report
2017 - Trickbot primarily uses Necurs as vehicle for installs.
Jan 2018 - Use XMRIG (Monero) miner
Feb 2018 - Theft Bitcoin
Mar 2018 - Unfinished ransomware module
Q3/4 2018 - Trickbot starts being spread through Emotet.
Infection Vector
1. Phish > Link MS Office > Macro Enabled > Downloader > Trickbot
2. Phish > Attached MS Office > Macro Enabled > Downloader > Trickbot
3. Phish > Attached MS Office > Macro enabled > Trickbot installed
APT GROUP
Malware family tracked by Malpedia. ID: win.treasurehunter