Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
QUADAGENT
Technical ID: ps1.quadagent
APT34
APT GROUP
Malware family identifying ps1.quadagent. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-29
View profile →
PteroGraphin
Technical ID: ps1.ptero_graphin
Gamaredon Group
APT GROUP
Malware family identifying ps1.ptero_graphin. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-26
View profile →
PresFox
Technical ID: ps1.presfox
APT GROUPfinancialhigh
The family is adding a fake root certificate authority, sets a proxy.pac-url for local browsers and redirects infected users to fake banking applications (currently targeting Poland). Based on information shared, it seems the PowerShell script is dropped by an exploit kit.
Updated: 2019-02-05
View profile →
POWRUNER
Technical ID: ps1.powruner
APT34
APT GROUP
Malware family identifying ps1.powruner. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-29
View profile →
PowGoop
Technical ID: ps1.powgoop
MuddyWater
APT GROUP
DLL loader that decrypts and runs a powershell-based downloader.
Updated: 2022-05-25
View profile →
PowerRAT
Technical ID: ps1.power_rat
APT GROUP
Malware family identifying ps1.power_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-23
View profile →
PowerMagic
Technical ID: ps1.power_magic
APT GROUP
Malware family identifying ps1.power_magic. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
PowerZure
Technical ID: ps1.powerzure
APT GROUP
PowerZure is a PowerShell project created to assess and exploit resources within Microsoft’s cloud platform, Azure. PowerZure was created out of the need for a framework that can both perform reconnaissance and exploitation of Azure, AzureAD, and the associated resources.
Updated: 2020-08-18
View profile →
PowerWare
Technical ID: ps1.powerware
APT GROUP
Malware family identifying ps1.powerware. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →
POWERTRASH
Technical ID: ps1.powertrash
FIN7
APT GROUP
This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload. According to Mandiant's blog article: "POWERTRASH is a uniquely obfuscated iteration of a shellcode invoker included in the PowerSploit framework available on GitHub."
Updated: 2025-06-17
View profile →
POWERTON
Technical ID: ps1.powerton
APT33
APT GROUP
Malware family identifying ps1.powerton. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
POWERSTATS
Technical ID: ps1.powerstats
MuddyWater
APT GROUP
POWERSTATS is a backdoor written in powershell. It has the ability to disable Microsoft Office Protected View, fingerprint the victim and receive commands.
Also known as: Valyria
Updated: 2023-09-12
View profile →
POWERSTAR
Technical ID: ps1.powerstar
APT GROUP
Malware family identifying ps1.powerstar. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-28
View profile →
PowerSpritz
Technical ID: ps1.powerspritz
Lazarus Group
APT GROUP
Malware family identifying ps1.powerspritz. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-01-23
View profile →
POWERSOURCE
Technical ID: ps1.powersource
Anunak
APT GROUP
POWERSOURCE is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage. The backdoor uses DNS TXT requests for command and control and is installed in the registry or Alternate Data Streams.
Updated: 2023-07-28
View profile →
PowerShower
Technical ID: ps1.powershower
Inception Framework
APT GROUP
Malware family identifying ps1.powershower. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-26
View profile →
PowerShortShell
Technical ID: ps1.powershortshell
APT GROUP
Malware family identifying ps1.powershortshell. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-11-29
View profile →
powershell_web_backdoor
Technical ID: ps1.powershell_web_backdoor
APT GROUP
Malware family identifying ps1.powershell_web_backdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-04
View profile →
POWERPLANT
Technical ID: ps1.powerplant
FIN7
APT GROUP
This powershell code is a PowerShell written backdoor used by FIN7. Regarding to Mandiant that is was revealed to be a "vast backdoor framework with a breadth of capabilities, depending on which modules are delivered from the C2 server."
Updated: 2022-04-07
View profile →
POWERPIPE
Technical ID: ps1.powerpipe
Anunak
APT GROUP
Malware family identifying ps1.powerpipe. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-25
View profile →
PowerPepper
Technical ID: ps1.powerpepper
Evilnum
APT GROUP
Malware family identifying ps1.powerpepper. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-08
View profile →
PowerNet
Technical ID: ps1.powernet
FIN7
APT GROUP
According to Insikt Group, PowerNet is a custom Powershell loader that decompresses and executes NetSupport RAT.
Updated: 2025-07-07
View profile →
PowerHarbor
Technical ID: ps1.powerharbor
APT GROUP
PowerHarbor is a modular PowerShell-based malware that consists of various modules. The primary module maintains constant communication with the C2 server, executing and deleting additional modules received from it. Currently, the communication with the C2 server is encrypted using RSA encryption and hardcoded key data. Moreover, the main module incorporates virtual machine (VM) detection capabilities. The StealData module employs the Invoke-Stealer function as its core, enabling the theft of system information, browser-stored credentials, cryptocurrency wallet details, and credentials for various applications like Telegram, FileZilla, and WinSCP.
Updated: 2023-07-19
View profile →
PowerBrace
Technical ID: ps1.powerbrace
Lazarus Group
APT GROUP
Malware family identifying ps1.powerbrace. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-31
View profile →
POSHSPY
Technical ID: ps1.poshspy
APT 29
APT GROUP
Malware family identifying ps1.poshspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-05-30
View profile →
PhonyC2
Technical ID: ps1.phonyc2
MuddyWater
APT GROUP
Malware family identifying ps1.phonyc2. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-08
View profile →
OilRig
Technical ID: ps1.oilrig
OilRigAPT39Chafer
APT GROUP
Malware family identifying ps1.oilrig. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-23
View profile →
Octopus
Technical ID: ps1.octopus
APT GROUP
The author describes Octopus as an "open source, pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S." It is different from the malware win.octopus written in Delphi and attributed to DustSquad by Kaspersky Labs.
Updated: 2022-05-17
View profile →
NosyDownloader
Technical ID: ps1.nosy_downloader
APT GROUP
According to ESET Research, this malware is used by LongNosedGoblin and executes a chain of obfuscated commands passed to a spawned PowerShell process as one long command line argument, meaning that the script is not stored on disk. Every subsequent stage is encoded with base64, where the last one is additionally deflated with gzip. The second stage bypasses AMSI. In this case, NosyDownloader uses Matt Graeber’s reflection method and disabling script logging techniques made available on GitHub to bypass AMSI.
Updated: 2026-01-19
View profile →
LightBot
Technical ID: ps1.lightbot
APT GROUPfinancialhigh
According to Bleeping Computer and Vitali Kremez, LightBot is a compact reconnaissance tool suspected to be used to identify high-value targets for potential follow-up ransomware attacks.
Updated: 2020-11-23
View profile →
LazyWiper
Technical ID: ps1.lazywiper
APT GROUP
Malware family identifying ps1.lazywiper. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-30
View profile →
Lazyscripter
Technical ID: ps1.lazyscripter
APT GROUP
Malware family identifying ps1.lazyscripter. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-11
View profile →
Kalambur
Technical ID: ps1.kalambur
Sandworm
APT GROUP
According to EclecticIQ, Kalambur is designed to gather local system information, then download a repackaged TOR binary inside a ZIP file and retrieve additional tools from what is likely an attacker-controlled TOR onion site.
Updated: 2025-02-17
View profile →
JasperLoader
Technical ID: ps1.jasperloader
APT GROUP
Malware family identifying ps1.jasperloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-27
View profile →
HTTP-Shell
Technical ID: ps1.http_shell
APT GROUP
The author describes this open source shell as follows. HTTP-Shell is Multiplatform Reverse Shell. This tool helps you to obtain a shell-like interface on a reverse connection over HTTP. Unlike other reverse shells, the main goal of the tool is to use it in conjunction with Microsoft Dev Tunnels, in order to get a connection as close as possible to a legitimate one. This shell is not fully interactive, but displays any errors on screen (both Windows and Linux), is capable of uploading and downloading files, has command history, terminal cleanup (even with CTRL+L), automatic reconnection, movement between directories and supports sudo (or sudo su) on Linux-based OS.
Updated: 2024-02-22
View profile →
GhostWeaver
Technical ID: ps1.ghostweaver
APT GROUPfinancialhigh
According to TRAC Labs, the GhostWeaver backdoor not only maintains continuous, authenticated communication with its command-and-control server but also includes functionalities to generate DGA domains (using a fixed-seed algorithm based on the week number and year), deliver additional payloads via remote commands and bypass certificate validation by leveraging a RemoteCertificateValidationCallback that always returns true. Multiple delivered plugins are designed to target sensitive information - including credentials from popular browsers (Brave, Chrome, Firefox, Edge), Outlook data, and cryptocurrency wallets. The Formgrabber plugin includes web injection methods by dynamically manipulating HTML content, modifying JA3 fingerprints via cipher suite reordering, and employing a man-in-the-middle proxy setup to intercept the traffic. GhostWeaver’s and plugins’ delivery on systems that are not part of an Active Directory domain suggests that attackers are extending their reach beyond typical corporate targets, aligning with a financially motivated agenda that exploits environments with weaker security controls.
Updated: 2025-05-01
View profile →
GhostMiner
Technical ID: ps1.ghostminer
APT GROUP
Malware family identifying ps1.ghostminer. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-09-30
View profile →
FTCODE
Technical ID: ps1.ftcode
APT GROUPfinancialhigh
The malware ftcode is a ransomware which encrypts files and changes their extension into .FTCODE. It later asks for a ransom in order to release the decryption key, mandatory to recover your files. It is infamous for attacking Italy pretending to be a notorious telecom provider asking for due payments.
Updated: 2025-06-05
View profile →
FRat Loader
Technical ID: ps1.frat_loader
APT GROUP
Loader used to deliver FRat (see family windows.frat)
Updated: 2020-06-12
View profile →
FlowerPower
Technical ID: ps1.flowerpower
Kimsuky
APT GROUP
Malware family identifying ps1.flowerpower. Origin and technical characteristics tracked via Malpedia.
Also known as: BoBoStealer
Updated: 2025-06-11
View profile →
← PreviousPage 191 / 269Next →