Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Attor
Technical ID: win.attor
MALWAREespionageadvanced
Attor is a cyberespionage platform used in targeted attacks against diplomatic missions and governmental institutions since at least 2013. Its most interesting features are a complex modular architecture, elaborate network communications, and a unique plugin to fingerprint GSM/GPRS devices. Attor’s core lies in its dispatcher, which serves as a management unit for additional plugins which provide all of malware’s key capabilities. This allows the attackers to customize the platform on a per-victim basis. Plugins themselves are heavily synchronized. Network communication is based on Tor, aiming for anonymity and untraceability. The most notable plugin can detect connected GSM/GPRS modems or mobile devices. Attor speaks to them directly using the AT command set, in order to collect sensitive information such as the IMEI, IMSI or MSISDN numbers, possibly identifying both the device and its subscriber. Other plugins provide persistence, an exfiltration channel, C&C communication and several further spying capabilities. The plugin responsible for capturing victim's screen targets social networks and blogging platforms, email services, office software, archiving utilities, file sharing and messaging services.
Updated: 2022-12-12
View profile →
ATOMSILO
Technical ID: win.atomsilo
MALWARE
According to PCrisk, AtomSilo is a type of malware that blocks access to files by encrypting them and renames every encrypted file by appending the ".ATOMSILO" to its filename. It renames "1.jpg" to "1.jpg.ATOMSILO", "2.jpg" to "2.jpg.ATOMSILO", and so on. As its ransom note, AtomSilo creates the "README-FILE-#COMPUTER-NAME#-#CREATION-TIME#.hta" file.
Updated: 2023-05-15
View profile →
ATMSpitter
Technical ID: win.atmspitter
Cobalt
MALWARE
The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either CSCWCNG.dll or MFSXFS.dll. Both libraries are legitimate Windows drivers used to interact with the components of different ATM models.
Updated: 2020-05-23
View profile →
Atmosphere
Technical ID: win.atmosphere
Silence group
MALWARE
Malware family identifying win.atmosphere. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-05-10
View profile →
ATMitch
Technical ID: win.atmitch
MALWARE
Malware family identifying win.atmitch. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-26
View profile →
ATMii
Technical ID: win.atmii
MALWARE
Malware family identifying win.atmii. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-17
View profile →
AtlasAgent
Technical ID: win.atlas_agent
MALWARE
Malware family identifying win.atlas_agent. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-16
View profile →
Atlantida
Technical ID: win.atlantida
MALWARE
Malware family identifying win.atlantida. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-23
View profile →
ATI-Agent
Technical ID: win.ati_agent
APT 29
MALWARE
Malware family identifying win.ati_agent. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-03-14
View profile →
AthenaGo RAT
Technical ID: win.athenago
MALWARE
Malware family identifying win.athenago. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-13
View profile →
Athena
Technical ID: win.athena
MALWARE
Part of the Mythic framework, payload in C# (.NET 6), support HTTP, Websockets, Slack, SMB for C2.
Updated: 2023-10-12
View profile →
Atharvan
Technical ID: win.atharvan
Silent Chollima
MALWARE
Malware family identifying win.atharvan. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-15
View profile →
AsyncRAT
Technical ID: win.asyncrat
MALWARE
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victim’s computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques.
Updated: 2026-02-03
View profile →
AstraLocker
Technical ID: win.astralocker
MALWARE
Malware family identifying win.astralocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-05
View profile →
Astasia
Technical ID: win.astasia
MALWAREfinancialhigh
Astasia is a banking trojan that spreads through phishing emails that contain an executable attachment. Once the attachment is executed, Astasia downloads and installs a trojan that runs in the background. The trojan can steal personal information, such as passwords and credit card numbers, from victims.
Updated: 2023-10-17
View profile →
Astaroth
Technical ID: win.astaroth
MALWAREfinancialhigh
First spotted in the wild in 2017, Astaroth is a highly prevalent, information-stealing Latin American banking trojan. It is written in Delphi and has some innovative execution and attack techniques. Originally, this malware variant targeted Brazilian users, but Astaroth now targets users both in North America and Europe.
Also known as: Guildma
Updated: 2026-02-17
View profile →
AstarionRAT
Technical ID: win.astarion_rat
MALWARE
According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution, with RSA-encrypted C2 communication disguised as application telemetry.
Also known as: MIMICRAT
Asruex
Technical ID: win.asruex
DarkHotel
MALWARE
Malware family identifying win.asruex. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-16
View profile →
Asprox
Technical ID: win.asprox
MALWARE
Malware family identifying win.asprox. Origin and technical characteristics tracked via Malpedia.
Also known as: Aseljo • BadSrc
Updated: 2018-11-28
View profile →
ASPC
Technical ID: win.aspc
MALWARE
Malware family identifying win.aspc. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-19
View profile →
Ashen
Technical ID: win.ashen
WIRTE
MALWARE
According to Unit 42, Ashen / AshTag is a modular .NET toolset currently in active development, with extensive features, including file exfiltration, content download and in-memory execution of additional modules.
Also known as: AshTag
AscentLoader
Technical ID: win.ascentloader
MALWARE
Malware family identifying win.ascentloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-05
View profile →
Asbit
Technical ID: win.asbit
MALWARE
Malware family identifying win.asbit. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-01
View profile →
Artra Downloader
Technical ID: win.artra
MALWARE
Malware family identifying win.artra. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-26
View profile →
ARTFULPIE
Technical ID: win.artfulpie
Lazarus Group
MALWARE
Malware family identifying win.artfulpie. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-27
View profile →
ARS VBS Loader
Technical ID: win.ars_loader
MALWARE
ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via different available commands, acting as a remote access trojan (RAT). Its code is based on ASPC, another Visual Basic Script malware, which at the same time seems to be based on SafeLoader.
Updated: 2018-10-25
View profile →
ArrowRAT
Technical ID: win.arrowrat
MALWARE
It is available as a service, purchasable by anyone to use in their own campaigns. It’s features are generally fairly typical of a RAT, with its most notable aspect being the hVNC module which basically gives an attacker full remote access with minimal need for technical knowledge to use it.
Updated: 2022-09-29
View profile →
Arkei Stealer
Technical ID: win.arkei_stealer
MALWARE
Arkei is a stealer that appeared around May 2018. It collects data about browsers (saved passwords and autofill forms), cryptocurrency wallets, and steal files matching an attacker-defined pattern. It then exfiltrates everything in a zip file uploaded to the attacker's panel. Later, it was forked and used as a base to create Vidar stealer.
Also known as: ArkeiStealer
Updated: 2024-01-30
View profile →
Arik Keylogger
Technical ID: win.arik_keylogger
MALWARE
Malware family identifying win.arik_keylogger. Origin and technical characteristics tracked via Malpedia.
Also known as: Aaron Keylogger
Updated: 2018-02-07
View profile →
AridHelper
Technical ID: win.aridhelper
AridViper
MALWARE
Helper malware associated with AridGopher, which will provide an alternative persistence mechanism in case "360 total security" is found on a target system.
Updated: 2022-03-25
View profile →
Arid Gopher
Technical ID: win.aridgopher
AridViper
MALWARE
This malware is a Go written variant of Micropsia and according to DeepInstinct it is still in development.
Updated: 2023-04-25
View profile →
Aria-body
Technical ID: win.ariabody
Naikon
MALWARE
Malware family identifying win.ariabody. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-06-04
View profile →
ArguePatch
Technical ID: win.arguepatch
APT28Sandworm
MALWARE
During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by ESET researchers. ArguePatch is a modified version of Hex-Ray's Remote Debugger Server (win32_remote.exe). ArguePatch expects a decryption key and the file of the CaddyWiper shellcode as command line parameters.
Updated: 2022-09-26
View profile →
AresLoader
Technical ID: win.aresloader
MALWARE
AresLoader is a new malware "downloader" that has been advertised on some Russian language Dark Web forums “RAMP and "XSS" by a threat actor called "DarkBLUP". Researchers assess this loader is likely a legitimate penetration testing tool that is now being abused by threat actors. This is because of a similar project, dubbed “Project Ares,” was previously uploaded to GitHub as a proof-of-concept (PoC) by the well-regarded user and red teamer “CerberSec.” The loader mimics legitimate software to trick victims into executing malware with administrator rights on their machines. Additional features of the loader include: 1. Written in C/C++ 2. Supports 64-bit payloads 3. Makes it look like malware spawned by another process 4. Prevents non-Microsoft signed binaries from being injected into malware 5. Hides suspicious imported Windows APIs 6. Leverages anti-analysis techniques to avoid reverse engineering Furthermore, It was observed that SystemBC, Amadey, and several Raccoon Stealers were directly installing AresLoader. To date, the AresLoader downloader has been seen delivering payloads like SystemBC, Lumma Stealer, StealC, Aurora Stealer, and Laplas Clipper.
Updated: 2023-04-22
View profile →
Ares
Technical ID: win.ares
MALWAREfinancialhigh
A banking trojan, derived from the source code of win.kronos. In August 2022 it started to incorporate DGA code from win.qakbot.
Updated: 2023-05-26
View profile →
Arefty
Technical ID: win.arefty
MALWARE
Malware family identifying win.arefty. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-25
View profile →
ArdaMax
Technical ID: win.ardamax
MALWAREespionageadvanced
According to f-secure, Ardamax is a commercial keylogger program that can be installed onto the system from the product's website.& When run, the program can capture a range of user activities, such as keystrokes typed, instant messenger chat logs, web browser activity and even screenshots of the active desktop. This program can be configured to a complete stealth mode, with password protection, to avoid user detection. The information gathered is stored in an encrypted log file, which is only viewable using the built-in Log Viewer. The log file can be sent to an external party through e-mail, via a local area network (LAN) or by upload to an FTP server (in either HTML or encrypted format).
Updated: 2025-01-07
View profile →
Archer RAT
Technical ID: win.archer_rat
MALWARE
Malware family identifying win.archer_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: RustyWater
Updated: 2026-01-12
View profile →
ArcaneStealer
Technical ID: win.arcane_stealer
MALWARE
Malware family identifying win.arcane_stealer. Origin and technical characteristics tracked via Malpedia.
Appleseed
Technical ID: win.appleseed
Kimsuky
MALWARE
Malware family identifying win.appleseed. Origin and technical characteristics tracked via Malpedia.
Also known as: JamBog
Updated: 2025-06-11
View profile →
← PreviousPage 185 / 269Next →