Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.sobig
APT GROUP
According to ESET, this RAT was derived from (the open-source) Quasar RAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.snslocker
APT GROUP
Information stealer, written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: win.snojan
APT GROUP
SnipVex is a virus that infects files with .exe extension via prepending itself to the host. It is written in .NET. It has a clipbanker as payload.
APT GROUP
Malware family tracked by Malpedia. ID: win.snifula
APT GROUP
Malware family tracked by Malpedia. ID: win.sneepy
APT GROUP
A downloader trojan with some infostealer capabilities focused on the browser. Previously observed as part of RigEK campaigns.
APT GROUP
Malware observed in the SnatchCrypto campaign, attributed by Kaspersky Labs to BlueNoroff with high confidence.
APT GROUP
Malware family tracked by Malpedia. ID: win.snappybee
APT GROUP
According to X-Force, SnakeDisk is a USB worm, dropping further payloads
APT GROUP
Malware family tracked by Malpedia. ID: win.sn0wslogger
APT GROUP
Malware family tracked by Malpedia. ID: win.smominru
APT GROUP
The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.
APT GROUP
According to Mandiant, SMOKEDHAM is dropped through a powershell script that contains the (C#) source code for this backdoor, which is stored in an encrypted variable. The dropper dynamically defines a cmdlet and .NET class for the backdoor, meaning the compiled code is only found in memory.
APT GROUPfinancialhigh
According to PCrisk, Smaug ransomware is available for download on the dark web: it is for sale as Ransomware as a Service (RaaS). Therefore, cyber criminals who purchase it can perform ransomware attacks without having to develop malware of this type. Smaug is designed to encrypt files, rename them and create a ransom message.
APT GROUP
Malware family tracked by Malpedia. ID: win.smartloader
APT GROUP
Malware family tracked by Malpedia. ID: win.smarteyes
APT GROUP
Malware family tracked by Malpedia. ID: win.smanager
APT GROUP
Malware family tracked by Malpedia. ID: win.smackdown
APT GROUP
Malware family tracked by Malpedia. ID: win.smac
APT GROUP
Malware family tracked by Malpedia. ID: win.slub
APT GROUP
According to ESET, SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components, programmed in C++, Python, and Go.
APT GROUP
According to MITRE, SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.
APT GROUP
According to HarfangLab, SloppyMIO is written in C#. It retrieves its configuration steganographically from images whose URLs are obtained via a Dead Drop Resolver (DDR) backed by GitHub. From these images, it extracts a XOR key, Telegram bot token and chat ID, and module URLs from an LSB-hidden payload. The malware can fetch and cache multiple modules from remote storage, run arbitrary commands, collect and exfiltrate files and deploy further malware with persistence via scheduled tasks. SloppyMIO beacons status messages, polls for commands and sends exfiltrated files over to a specified operator leveraging the Telegram Bot API for command-and-control.
APT GROUP
Malware family tracked by Malpedia. ID: win.slnrat
APT GROUP
According to VK9 Seecurity, Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants (slivers) that can run on virtually every architecture out there, and securely manage these connections through a central server. Sliver supports multiple callback protocols including DNS, TCP, and HTTP(S) to make egress simple, even when those pesky blue teams block your domains. You can even have multiple operators (players) simultaneously commanding your sliver army.
APT GROUP
According to Proofpoint, SlipScreen is a first stage loader and has variants written in Rust and in C++. Its crypter is updated for each campaign, making static detection difficult.
APT GROUP
According to CERT-UA, this is a malware developed using the C++ programming language. The main functional purpose is the production of screenshots.
APT GROUP
Malware family tracked by Malpedia. ID: win.slickshoes
APT GROUP
Malware family tracked by Malpedia. ID: win.slave
APT GROUP
Malware family tracked by Malpedia. ID: win.skyplex
APT GROUP
Malware family tracked by Malpedia. ID: win.skynet
APT GROUP
Skuld, also known as TMPN Stealer, is an information-stealing malware written in Golang (Go) that emerged in May 2023.
APT GROUP
Malware family tracked by Malpedia. ID: win.skipper
APT GROUP
Malware family tracked by Malpedia. ID: win.skinnyboy
APT GROUP
Malware family tracked by Malpedia. ID: win.skimer
APT GROUP
Malware family tracked by Malpedia. ID: win.sisfader