Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
InvisibleFerret
Technical ID: py.invisibleferret
WageMole
APT GROUP
Malware family identifying py.invisibleferret. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-21
View profile →
Guard
Technical ID: py.guard
APT GROUP
According to Kaspersky Labs, Guard is a malware developed by threat actor WildPressure. It is written in Python and packaged using PyInstaller, both for Windows and macOS operating systems. Its intrinsics resemble parts of how win.milum operates.
Updated: 2021-12-17
View profile →
Evil Ant
Technical ID: py.evil_ant
APT GROUPfinancialhigh
Ransomware written in Python.
Updated: 2024-03-25
View profile →
Empyrean
Technical ID: py.empyrean
APT GROUP
Discord Stealer written in Python with Javascript-based inject files.
Updated: 2023-04-25
View profile →
DropboxC2C
Technical ID: py.dropboxc2c
APT GROUP
Malware family identifying py.dropboxc2c. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-06
View profile →
Creal Stealer
Technical ID: py.creal_stealer
APT GROUP
Creal is an open-source grabber/credential stealer that was originally made by a GitHub user named Ayhuuu, who even advertised a "premium" version on his now-deleted Telegram channel @Crealstealer. To the day of release, it was already not FUD, but its open-source nature made it attractive for threat actors to modify the base malware and even obfuscate it for less detection ratios. The base project came with a compiler, and the general source code the compiler used was PyInstaller for compilation into native formats like exe. For C2, Discord webhooks were utilized, which in later versions got protected with a service called https://stealer.to to make deletion not possible. It Compromised following Data on Execution: * Discord Information * Browser Data * Crypto Related Data * Steam * Riot Games * Telegram * System Information * Tokens/Secrets
Updated: 2025-02-10
View profile →
CHERRYSPY
Technical ID: py.cherryspy
UAC-0063
APT GROUP
According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.
Updated: 2025-05-26
View profile →
BrickerBot
Technical ID: py.brickerbot
APT GROUP
Malware family identifying py.brickerbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-12
View profile →
Braodo
Technical ID: py.braodo
APT GROUP
According to K7 Security Labs, Braodo Stealer is written in Python and collects all cookies and saved credentials from the browsers and all services and process information of that particular system as a zip file, which is then exfiltrated to a Telegram Channel.
Updated: 2025-01-23
View profile →
BlankGrabber
Technical ID: py.blankgrabber
APT GROUP
Stealer written in Python 3, typically distributed bundled via PyInstaller.
Updated: 2025-08-15
View profile →
Ares
Technical ID: py.ares
APT GROUP
Ares is a Python RAT.
Updated: 2023-12-27
View profile →
Archivist
Technical ID: py.archivist
APT GROUP
Malware family identifying py.archivist. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
Anubis Backdoor
Technical ID: py.anubisbackdoor
FIN7
APT GROUP
According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
Updated: 2025-03-26
View profile →
AndroxGh0st
Technical ID: py.androxgh0st
Xcatze
APT GROUP
According to Laceworks, this is a SMTP cracker, which is primarily intended to scan for and parse Laravel application secrets from exposed .env files. Note: Laravel is an open source PHP framework and the Laravel .env file is often targeted for its various configuration data including AWS, SendGrid and Twilio. AndroxGh0st has multiple features to enable SMTP abuse including scanning, exploitation of exposed creds and APIs, and even deployment of webshells. For AWS specifically, the malware scans for and parses AWS keys but also has the ability to generate keys for brute force attacks. However, the brute force capability is likely a novelty and is a statistically unlikely attack vector.
Also known as: AndroxGhost • Androx
Updated: 2025-05-21
View profile →
Amnesia RAT
Technical ID: py.amnesia_rat
APT GROUPfinancialhigh
According to Fortinet, Amnesia RAT is written in Python and designed for broad, multi-category data theft combined with real-time surveillance and system control. Its capabilities include: Browser credentials and session data, Telegram Desktop session hijacking, Seed phrase discovery and clipboard monitoring, Discord and Steam data theft, Cryptocurrency wallets and financial assets, System and hardware intelligence, Screen, audio, and activity surveillance, Process and system control, Persistence, multiple exfiltration channels.
Updated: 2026-01-27
View profile →
Akira Stealer
Technical ID: py.akira_stealer
APT GROUP
Malware family identifying py.akira_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-28
View profile →
WRECKSTEEL
Technical ID: ps1.wrecksteel
APT GROUP
According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.
Updated: 2026-01-26
View profile →
WMImplant
Technical ID: ps1.wmimplant
APT GROUP
Malware family identifying ps1.wmimplant. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-06
View profile →
WannaRen Downloader
Technical ID: ps1.wannaren_loader
APT GROUP
Malware family identifying ps1.wannaren_loader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-05
View profile →
WannaMine
Technical ID: ps1.wannamine
APT GROUP
Malware family identifying ps1.wannamine. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-11-25
View profile →
ViperSoftX
Technical ID: ps1.vipersoftx
APT GROUP
Malware family identifying ps1.vipersoftx. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-15
View profile →
Unidentified PS 005 (Telegram Bot)
Technical ID: ps1.unidentified_005
YoroTrooper
APT GROUP
Malware family identifying ps1.unidentified_005. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-13
View profile →
Unidentified PS 004 (RAT)
Technical ID: ps1.unidentified_004
Kimsuky
APT GROUP
Malware family identifying ps1.unidentified_004. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-18
View profile →
Unidentified PS 003 (RAT)
Technical ID: ps1.unidentified_003
APT GROUP
This malware is a RAT written in PowerShell. It has the following capabilities: Downloading and Uploading files, loading and execution of a PowerShell script, execution of a specific command. It was observed by Malwarebytes LABS Threat Intelligence Team in a newly discovered campaign: this campaigns tries to lure Germans with a promise of updates on the current threat situation in Ukraine according to Malwarebyte LABS.
Updated: 2022-05-17
View profile →
Unidentified PS 002 (RAT)
Technical ID: ps1.unidentified_002
APT GROUP
A Powershell-based RAT capable of pulling further payloads, delivered through Russia-themed phishing mails.
Updated: 2022-03-31
View profile →
Unidentified PS 001
Technical ID: ps1.unidentified_001
APT-C-12
APT GROUPespionageadvanced
Recon and exfiltration script, dropped from a LNK file. Attributed to APT-C-12.
Updated: 2020-02-13
View profile →
ThunderShell
Technical ID: ps1.thundershell
APT GROUP
Malware family identifying ps1.thundershell. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-16
View profile →
Tater PrivEsc
Technical ID: ps1.tater
APT GROUP
Malware family identifying ps1.tater. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-04
View profile →
Swrort Stager
Technical ID: ps1.swrort
APT GROUP
Malware family identifying ps1.swrort. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-12-19
View profile →
SUBTLE-PAWS
Technical ID: ps1.subtle_paws
APT GROUP
Malware family identifying ps1.subtle_paws. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-05
View profile →
STEELHOOK
Technical ID: ps1.steelhook
APT28
APT GROUP
Malware family identifying ps1.steelhook. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-22
View profile →
Snugy
Technical ID: ps1.snugy
APT GROUP
Malware family identifying ps1.snugy. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-25
View profile →
sLoad
Technical ID: ps1.sload
APT GROUP
sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries.
Also known as: Starslord
Updated: 2025-04-01
View profile →
skyrat
Technical ID: ps1.skyrat
APT GROUP
Malware family identifying ps1.skyrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-17
View profile →
SilentPrism
Technical ID: ps1.silent_prism
Larva-208
APT GROUP
According to Trend Micro, SilentPrism is a backdoor malware designed to achieve persistence, dynamically execute shell commands, and maintain unauthorized remote control of compromised systems. It implements persistence mechanisms differently based on user privileges: for non-administrative users, it leverages the Windows registry to create auto-run entries using mshta.exe combined with VBScript to download and execute remote payloads; for administrative users, it deploys scheduled tasks with similar execution methods. SilentPrism retrieves additional payloads and instructions from a C&C server, ensuring modular functionality. The malware communicates with its C&C server using encrypted channels, employing AES encryption and Base64 encoding to obfuscate data. Commands received are decrypted and executed in various ways, including direct PowerShell script execution, dynamic script block creation, or job-based execution. Each task is tracked using unique identifiers, allowing the malware to monitor execution states and return results to the server. SilentPrism incorporates anti-analysis techniques such as virtual machine detection and randomized sleep intervals (ranging from 300 to 700 milliseconds) between operations, making its behavior less predictable. Additionally, it continuously polls the C&C server for commands, enabling operators to dynamically control infected systems.
Updated: 2025-08-25
View profile →
Schtasks
Technical ID: ps1.schtasks
APT GROUP
Malware family identifying ps1.schtasks. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-19
View profile →
Royal Ransom
Technical ID: ps1.royal_ransom
APT GROUPfinancialhigh
Toolkit downloader used by Royal Ransomware group, involving GnuPG for decryption.
Updated: 2025-01-15
View profile →
RogueRobin
Technical ID: ps1.roguerobin
DarkHydrus
APT GROUP
Malware family identifying ps1.roguerobin. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-13
View profile →
RMOT
Technical ID: ps1.rmot
DarkHotel
APT GROUP
According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS. It is able to establish a foothold and exfiltrate data. Targets identified include hotels in Macao.
Updated: 2022-03-18
View profile →
RandomQuery
Technical ID: ps1.randomquery
Kimsuky
APT GROUP
A set of powershell scripts, using services like Google Docs and Dropbox as C2.
Updated: 2025-09-16
View profile →
← PreviousPage 190 / 269Next →