Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUP
tRat is a modular RAT written in Delphi and has appeared in campaigns in September and October of 2018.
APT GROUP
Malware family tracked by Malpedia. ID: win.transferloader
APT GROUP
According to Trend Micro, this is a backdoor abusing the Dropbox API, used by threat actor Earth Yako.
APT GROUPfinancialhigh
ToxicEye is a ransomware that spreads through phishing emails. The malware encrypts system files with AES-256 and demands a ransom in Bitcoin.
APT GROUP
According to Google Threat Intelligence Group, this malware uses Google Calendar events for command and control (C2).
APT GROUP
Malware family tracked by Malpedia. ID: win.touchshift
APT GROUP
Malware family tracked by Malpedia. ID: win.touchmove
APT GROUP
Downloader, delivered via a lure with fake exploits published on Github.
APT GROUP
Malware family tracked by Malpedia. ID: win.torrentlocker
APT GROUP
Torisma is a complex HTTP(S) downloader, that can serve as an orchestrator handling the execution of additional payloads from the C&C server.
It uses VEST-32 for encryption and decryption of network traffic between the client and the server.
Typically, it uses these parameter names for its HTTP POST requests: ACTION, CODE, CACHE, REQUEST, RES. It sends the victim's MAC address in the initial request.
The response of the server informing the client about a successful authentication is "Your request has been accepted. ClientID: {f9102bc8a7d81ef01ba}". The client then requests additional data from the server, that decrypts to shellcode and its data parameters, and is executed. The client also creates a named pipe, \\.\pipe\fb4d1181bb09b484d058768598b, that allows inter-process communication with the executed shellcode.
Torisma was usually downloaded by NedDnLoader, and deployed in the Operation DreamJob campaigns starting around Q4 2019.
APT GROUP
Malware family tracked by Malpedia. ID: win.topinambour
APT GROUP
Malware family tracked by Malpedia. ID: win.tonnerre
APT GROUP
Malware family tracked by Malpedia. ID: win.toneshell
APT GROUP
According to Symantec, Grager was deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of the backdoor revealed that it used the Graph API to communicate with a C&C server hosted on Microsoft OneDrive. Grager was downloaded from a typosquatted URL mimicking the open-source file archiver 7-Zip.
APT GROUP
TONEDEAF is a backdoor that communicates with Command and Control servers using HTTP or DNS. Supported commands include system information collection, file upload, file download, and arbitrary shell command execution. When executed, this variant of TONEDEAF wrote encrypted data to two temporary files – temp.txt and temp2.txt – within the same directory of its execution.
APT GROUP
Malware family tracked by Malpedia. ID: win.tomiris
APT GROUP
Malware family tracked by Malpedia. ID: win.tollbooth
APT GROUP
Malware family tracked by Malpedia. ID: win.tokyox
APT GROUP
According to PCrisk, Tofsee (also known as Gheg) is a malicious Trojan-type program that is capable of performing DDoS attacks, mining cryptocurrency, sending emails, stealing various account credentials, updating itself, and more.
Cyber criminals mainly use this program as an email-oriented tool (they target users' email accounts), however, having Tofsee installed can also lead to many other problems.
APT GROUP
Malware family tracked by Malpedia. ID: win.tmanger
APT GROUP
The stealer is written in Go and capable of stealing a variety of information from infected Windows machines, including credential data from browsers and crypto wallets, FTP client details, screenshots, system information, and grabbed files.
APT GROUP
Malware family tracked by Malpedia. ID: win.tiop
APT GROUP
Talos describes this as a malware family with very scoped functionality and thus a small code footprint, likely used as a second chance backdoor.
APT GROUP
Malware family tracked by Malpedia. ID: win.tinyzbot
APT GROUP
Malware family tracked by Malpedia. ID: win.tinytyphon
APT GROUP
Cisco Talos states that TinyTurla-NG is a small “last chance” backdoor that is left behind to be used when all other unauthorized access/backdoor mechanisms have failed or been detected on the infected systems. TinyTurla-NG was seen as early as December 2023 targeting a Polish non-governmental organization (NGO) working on improving Polish democracy and supporting Ukraine during the Russian invasion.
APT GROUPfinancialhigh
TinyNuke (aka Nuclear Bot) is a fully-fledged banking trojan including HiddenDesktop/VNC server and a reverse socks4 server. It was for sale on underground marketplaces for $2500 in 2016. The program's author claimed the malware was written from scratch, but that it functioned similarly to the ZeuS banking trojan in that it could steal passwords and inject arbitrary content when victims visited banking Web sites. However, he then proceeded to destroy his own reputation on hacker forums by promoting his development too aggressively. As a displacement activity, he published his source code on Github. XBot is an off-spring of TinyNuke, but very similar to its ancestor.
APT GROUP
Malware family tracked by Malpedia. ID: win.tinyloader
APT GROUP
TinyFluff is a dropper developed by the OldGremlin group. In one of their March '22 campaigns, TinyFluff included a JavaScript RAT with a time-independent DGA.
APT GROUPfinancialhigh
F-Secure notes that TinyBanker or short Tinba is usually distributed through malvertising (advertising content that leads the user to sites hosting malicious threats), exploit kits and spam email campaigns. According to news reports, Tinba has been found targeting bank customers in the United States and Europe.
If Tinba successfully infects a device, it can steal banking and personal information through webinjects. To do this, the malware monitors the user's browser activity and if specific banking portals are visited, Tinba injects code to present the victim with fake web forms designed to mimic the legitimate web site. The malware then tricks them into entering their personal information, log-in credentials, etc in the legitimate-looking page.
Tinba may also display socially-engineered messages to lure or pressure the user into entering their information on the fake page; for example, a message may be shown which attempts to convince the victim that funds were accidentally deposited to his account and must be refunded immediately.
APT GROUP
Malware family tracked by Malpedia. ID: win.timbre_stealer
APT GROUP
Standalone implant. Potentially tied to a framework called PATROLWAGON.
APT GROUPfinancialhigh
This is third stage backdoor mentioned in the Kaspersky blog, "Andariel evolves to target South Korea with ransomware". The third stage payload was created via the second stage payload, is interactively executed in the operation and exists in both x64 and x86 versions. Most of them use Internet Explorer or Google Chrome icons and corresponding file names to disguise themselves as legitimate internet browsers. The malware decrypts the embedded payload at runtime. It uses an embedded 16-byte XOR key to decrypt the base64 encoded payload. The decrypted payload is another portable executable file that runs in memory. Before getting decrypted with a hardcoded XOR key, the backdoor also checks for sandbox environment.
The backdoor has some code overlap with a know malware family PEBBLEDASH, attributed to Lazarus/LABYRINTH CHOLLIMA.
APT GROUP
TigerLite is a TCP downloader.
It creates mutexes like "qtrgads32" or "Microsoft32".
It uses RC4 with the key "MicrosoftCorporationValidation@#$%^&*()!US" for decryption of its character strings, and a custom algorithm for encryption and decryption of network traffic.
It supports from 5 up to 8 commands with the following identifiers: 1111, 1234, 2099/3333, 4444, 8877, 8888, 9876, 9999. The commands mostly perform various types of execution - either of code received from the server, or native Windows commands, with their output collected and sent back to the server.
TigerLite is an intermediate step of a multi-stage attack, in which Tiger RAT is usually the next step. This malware was observed in attacks against South Korean entities in H1 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.tidepool
APT GROUP
Malware family tracked by Malpedia. ID: win.thunker
APT GROUPfinancial
thunder x — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.thumbthief
APT GROUP
Malware family tracked by Malpedia. ID: win.threebyte