Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari. Originated in Russia, it was available in dark forums for $500+ claiming to be the "The Next Zeus Malware". It performed many functionalities typical from bankers trojan such as keyloggers, auto-fill credit card modules, email backups, config files (encrypted), http access, Pop3 grabbers and FTP grabbers. SpyEye allowed hackers to steal money from online bank accounts and initiate transactions even while valid users are logged into their bank account.
APT GROUP
Malware family tracked by Malpedia. ID: win.spyder_patchwork
APT GROUP
Malware family tracked by Malpedia. ID: win.spyder
APT GROUP
Malware family tracked by Malpedia. ID: win.spybot
APT GROUP
Malware family tracked by Malpedia. ID: win.spora_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.splitloader
APT GROUP
According to Unit 42, Splinter is a post-exploitation red team tool, written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: win.spider_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.spicyhotpot
APT GROUP
Malware family tracked by Malpedia. ID: win.spica
APT GROUP
According to Trend Micro, this is a tool designed to disable security products, adopting two approaches to achieve this purpose. One approach terminates the security product process by using a vulnerable driver, zamguard64.sys, published by Zemana (vulnerability designated as CVE-2018-5713). Meanwhile, another approach disables process launching by using a new technique that they named stack rumbling.
APT GROUP
Malware family tracked by Malpedia. ID: win.spedear
APT GROUP
Mixed RAT and Botnet malware sold in underground forums. In march 2021 it was advertised with the Spectre 2.0, it reached version 3 in June 2021 and then quickly version 4. This crimeware tool was being abused in malicious campaigns targeting European users in September 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.spectralviper
APT GROUP
Malware family tracked by Malpedia. ID: win.spearal
APT GROUPfinancialhigh
Spartacus is ransomware written in .NET and emerged in the first half of 2018.
APT GROUP
Malware family tracked by Malpedia. ID: win.sparrow_door
APT GROUP
SparkRAT is a cross-platform, open-source Remote Administration Tool (RAT) written in Go and released on GitHub in 2022. Compatible with Windows, macOS, and Linux systems, it offers extensive remote access capabilities, including file and process management, file transfer, remote desktop monitoring, system information collection, and command execution via terminal access.
APT GROUP
Malware family tracked by Malpedia. ID: win.sparksrv
APT GROUP
Malware family tracked by Malpedia. ID: win.sparkle
APT GROUP
Malware family tracked by Malpedia. ID: win.spark
APT GROUP
SPACESHIP searches for files with a specified set of file extensions and copies them to
a removable drive. FireEye believes that SHIPSHAPE is used to copy SPACESHIP to a removable drive,
which could be used to infect another victim computer, including an air-gapped computer. SPACESHIP is
then used to steal documents from the air-gapped system, copying them to a removable drive inserted
into the SPACESHIP-infected system
APT GROUP
According to ESET, Spacecolon is a collection of malware written in Delphi, consisting of ScRansom, ScHackTool, ScInstaller, ScService, and ScPatcher.
APT GROUP
Malware family tracked by Malpedia. ID: win.soundbite
APT GROUP
According to Cisco Talos, this is a customized shellcode loader that has been observed to stage Mimikatz and CobaltStrike.
APT GROUP
SoulSearcher is a second-stage loader responsible for executing the Soul backdoor main module and parsing its configuration. SoulSearcher has multiple variants based on where the configuration and payload are located and on the type of configuration.
APT GROUP
Malware family tracked by Malpedia. ID: win.soul
APT GROUP
Malware family tracked by Malpedia. ID: win.sorgu
APT GROUP
Malware family tracked by Malpedia. ID: win.sorefang
APT GROUP
Malware family tracked by Malpedia. ID: win.soraya
APT GROUP
Malware family tracked by Malpedia. ID: win.sorano
APT GROUP
Malware family tracked by Malpedia. ID: win.somnia
APT GROUP
Malware family tracked by Malpedia. ID: win.sombrat
APT GROUPespionageadvanced
Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities, mainly delivered through search engine optimization (SEO) manipulation to convince users to download malicious documents.
Some of SolarMarker’s capabilities include the exfiltration of auto-fill data, saved passwords and saved credit card information from victims’ web browsers. Besides capabilities typical for infostealers, SolarMarker has additional capabilities such as file transfer and execution of commands received from a C2 server.
The malware invests significant effort into defense evasion, which consists of techniques like signed files, huge files, impersonation of legitimate software installations and obfuscated PowerShell scripts.
APT GROUP
Malware family tracked by Malpedia. ID: win.solarbot
APT GROUP
Malware family tracked by Malpedia. ID: win.solar
APT GROUP
This is a RAT that is usually loaded with one or more shellcode and/or reflective DLL injection techniques. The RAT uses RC4 or a hardcoded RSA key for traffic encryption/decryption. Its communication can either happen via a raw TCP socket or a HTTP POST request. Depending on the version, the RAT may remotely execute DLLs or shellcode.
APT GROUP
Malware family tracked by Malpedia. ID: win.socksbot
APT GROUP
Sockbot is a customized and in Go written fork of the Ligolo reverse tunneling open-source
tool. Several modification were performed by the threat actors who rewrote that code, e.g. execution checks, hardcoded values.
Ligolo: https://github.com/sysdream/ligolo
APT GROUP
Socelars is an infostealer with main focus on:
* Facebook Stealer (ads/manager)
* Cookie Stealer | AdsCreditCard {Amazon}