Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
W4SP Stealer
Technical ID: py.w4sp_stealer
APT GROUP
A basic info stealer w/ some capability to inject code into legit applications.
Updated: 2024-09-27
View profile →
VileRAT
Technical ID: py.vilerat
APT GROUP
Malware family identifying py.vilerat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-02
View profile →
Venus Stealer
Technical ID: py.venus_stealer
APT GROUP
Venus Stealer is a python based Infostealer observed early 2023.
Updated: 2023-02-21
View profile →
Venomous
Technical ID: py.venomous
APT GROUPfinancialhigh
Ransomware written in Python and delivered as compiled executable created using PyInstaller.
Updated: 2021-08-06
View profile →
UPSTYLE
Technical ID: py.upstyle
APT GROUP
Malware family identifying py.upstyle. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-15
View profile →
unidentified_003
Technical ID: py.unidentified_003
APT GROUP
Malware family identifying py.unidentified_003. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-11
View profile →
unidentified_002
Technical ID: py.unidentified_002
APT GROUP
Malware family identifying py.unidentified_002. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-11
View profile →
Stormous
Technical ID: py.stormous
APT GROUP
Malware family identifying py.stormous. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-05-14
View profile →
Stitch
Technical ID: py.stitch
APT GROUP
Malware family identifying py.stitch. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-07
View profile →
stealler
Technical ID: py.stealler
APT GROUP
Malware family identifying py.stealler. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-04
View profile →
SpaceCow
Technical ID: py.spacecow
APT GROUP
Malware family identifying py.spacecow. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
Serpent
Technical ID: py.serpent
APT GROUP
According to Proofpoint, this is a backdoor written in Python, used in attacks against French entities in the construction, real estate, and government industries.
Updated: 2023-11-30
View profile →
Saphyra
Technical ID: py.saphyra
APT GROUP
Malware family identifying py.saphyra. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
RN Stealer
Technical ID: py.rn_stealer
TraderTraitor
APT GROUP
Malware family identifying py.rn_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-29
View profile →
Responder
Technical ID: py.responder
APT GROUP
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Also known as: SpiderLabs Responder
Updated: 2021-06-16
View profile →
RedTiger Stealer
Technical ID: py.redtiger
APT GROUP
Malware family identifying py.redtiger. Origin and technical characteristics tracked via Malpedia.
Also known as: RedTiger Ste4ler • redtiger • redtiger-tools
Updated: 2025-03-21
View profile →
QUIETBOARD
Technical ID: py.quietboard
APT GROUP
Malware family identifying py.quietboard. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-31
View profile →
PyVil
Technical ID: py.pyvil
APT GROUP
PyVil RAT
Updated: 2021-02-18
View profile →
PY#RATION
Technical ID: py.pyration
APT GROUP
According to Securonix, this malware exhibits remote access trojan (RAT) behavior, allowing for control of and persistence on the affected host. As with other RATs, PY#RATION possesses a whole host of features and capabilities, including data exfiltration and keylogging. What makes this malware particularly unique is its utilization of websockets for both command and control (C2) communication and exfiltration as well as how it evades detection from antivirus and network security measures.
Updated: 2024-11-06
View profile →
Pyramid
Technical ID: py.pyramid
APT GROUP
According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed binary (e.g. python.exe) by importing their dependencies in memory. It was created to demonstrate a bypass strategy against EDRs based on some blind-spots assumptions.
Updated: 2025-12-22
View profile →
PylangGhost
Technical ID: py.pylangghost
WageMole
APT GROUP
Python-version of GolangGhost RAT
Updated: 2026-01-21
View profile →
pyback
Technical ID: py.pyback
APT GROUP
Malware family identifying py.pyback. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-04
View profile →
PyArk
Technical ID: py.pyark
El Machete
APT GROUP
Malware family identifying py.pyark. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-02
View profile →
PyAesLoader
Technical ID: py.pyaesloader
APT GROUP
Malware family identifying py.pyaesloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-23
View profile →
PXA Stealer
Technical ID: py.pxa_stealer
APT GROUPfinancialhigh
PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a Vietnamese-speaking threat actor (2024). The stealer targets sensitive data such as credentials for online accounts, VPN and FTP clients, financial information, browser cookies, and gaming-related data. Notably, PXA Stealer is capable of decrypting browser master passwords to exfiltrate stored credentials. The campaign leverages heavily obfuscated batch scripts for delivery and execution. The actor behind this operation is linked to the Telegram channel “Mua Bán Scan MINI,” known to host credential trade and cybercrime activity. While there are connections to the CoralRaider adversary, attribution to this group remains unconfirmed. In q2 2025 PXA stealer was observed to target Italy.
Also known as: PXAStealer • PXA
Updated: 2025-11-17
View profile →
pupy
Technical ID: py.pupy
APT GROUP
Malware family identifying py.pupy. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-11
View profile →
poweRAT
Technical ID: py.powerat
APT GROUP
Malware family identifying py.powerat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-21
View profile →
Poet RAT
Technical ID: py.poet_rat
APT GROUP
Cisco Talos has discovered a Python-based RAT they call Poet RAT. It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.
Updated: 2023-03-20
View profile →
PLUGGYAPE
Technical ID: py.pluggyape
Void Blizzard
APT GROUP
According to CERT-UA, this malware establishes a connection to the management server using web sockets and/or MQTT, data is transmitted in JSON format. Based on basic information about the computer (MAC address, BIOS serial number, disk and processor ID), it generates a unique device identifier using the SHA-256 algorithm (the first 16 bytes are used). It ensures the execution of the program code received from the server. Persistence is achieved by creating an entry in the Run branch of the operating system registry.
Updated: 2026-01-14
View profile →
PIRAT
Technical ID: py.pirat
APT GROUP
Malware family identifying py.pirat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-09
View profile →
NightshadeC2
Technical ID: py.nightshade_c2
APT GROUPespionageadvanced
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies from victim systems for both Gecko and Chromium based browsers.
Updated: 2025-09-09
View profile →
NetWorm
Technical ID: py.networm
APT GROUP
Malware family identifying py.networm. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
N3Cr0m0rPh
Technical ID: py.n3cr0m0rph
APT GROUP
An IRC bot written in (obfuscated) Python code. Distributed in attack campaign FreakOut, written by author Freak/Fl0urite and development potentially dating back as far as 2015.
Also known as: FreakOut • Necro
Updated: 2024-01-12
View profile →
MASEPIE
Technical ID: py.masepie
APT28
APT GROUP
Malware family identifying py.masepie. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-22
View profile →
Luna Grabber
Technical ID: py.lunagrabber
APT GROUP
Malware family identifying py.lunagrabber. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-22
View profile →
Loki RAT
Technical ID: py.lokirat
El Machete
APT GROUPespionageadvanced
This RAT written in Python is an open-source fork of the Ares RAT. This malware integrates additional modules, like recording, lockscreen, and locate options. It was used in a customized form version by El Machete APT in an ongoing champaign since 2020. The original code can be found at: https://github.com/TheGeekHT/Loki.Rat/
Updated: 2025-03-05
View profile →
Lofy
Technical ID: py.lofy
APT GROUP
Malware family identifying py.lofy. Origin and technical characteristics tracked via Malpedia.
Also known as: LofyLife
Updated: 2022-08-28
View profile →
LaZagne
Technical ID: py.lazagne
APT GROUP
The author described LaZagne as an open source project used to retrieve lots of passwords stored on a local computer. It has been developed for the purpose of finding these passwords for the most commonly-used software. It is written in Python and provided as compiled standalone binaries for Linux, Mac, and Windows.
Updated: 2025-06-24
View profile →
LAMEHUG
Technical ID: py.lamehug
APT28
APT GROUP
According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.
Updated: 2025-09-09
View profile →
KeyPlexer
Technical ID: py.keyplexer
APT GROUP
Malware family identifying py.keyplexer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
← PreviousPage 189 / 269Next →