Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
EugenLoader
Technical ID: ps1.eugenloader
APOTHECARY SPIDERStorm-1113
APT GROUP
A loader written in Powershell, usually delivered packaged in MSI/MSIX files.
Also known as: FakeBat • NUMOZYLOD • PaykLoader
Updated: 2025-06-17
View profile →
DarkWisp
Technical ID: ps1.dark_wisp
Larva-208
APT GROUP
According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and intelligence gathering. It enables attackers to exfiltrate sensitive data while maintaining persistent control over the compromised system. The malware collects extensive information about the compromised system to create a detailed profile. It determines whether the user has administrative privileges, checks for membership in a corporate domain, and identifies the presence of cryptocurrency wallets or VPN software by scanning specified directories and applications. It also gathers data about the system's operating environment, including public IP address, geographic location, installed antivirus products, firewall status, and system uptime. This information is compiled into a structured format and transmitted to the C&C server.
Updated: 2025-04-11
View profile →
COOKBOX
Technical ID: ps1.cookbox
UAC-0149
APT GROUP
According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets. For each affected computer, a unique identifier is calculated using cryptographic transformations (SHA256/MD5 hash functions) based on a combination of computer name and disk serial number, which is transmitted in the “X-Cookie” header of HTTP requests when interacting with the management server. The persistence of the backdoor is ensured by the corresponding key in the Run branch of the operating system (OS) registry, which is created at the stage of the initial infection by a third-party PowerShell script (including the COOKBOX deployer). As a rule, obfuscation elements are used in the program code: chr-character encoding, character replacement (replace()), base64 conversion, GZIP compression.
Updated: 2025-05-02
View profile →
CASHY200
Technical ID: ps1.cashy200
APT GROUP
Malware family identifying ps1.cashy200. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-25
View profile →
BONDUPDATER
Technical ID: ps1.bondupdater
OilRigAPT34
APT GROUP
Malware family identifying ps1.bondupdater. Origin and technical characteristics tracked via Malpedia.
Also known as: Poison Frog • Glimpse
Updated: 2024-10-14
View profile →
BlackSun
Technical ID: ps1.blacksun
APT GROUPfinancialhigh
Ransomware.
Updated: 2022-02-02
View profile →
Silence DDoS
Technical ID: pl.silence_ddos
APT GROUP
Malware family identifying pl.silence_ddos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-06
View profile →
WSO
Technical ID: php.wso
Energetic Bear
APT GROUP
Malware family identifying php.wso. Origin and technical characteristics tracked via Malpedia.
Also known as: Webshell by Orb
Updated: 2024-10-21
View profile →
A PHP webshell that allows file system management, data exfiltration and command execution.
RedHat Hacker WebShell
Technical ID: php.redhat_hacker
Lazarus Group
APT GROUP
Malware family identifying php.redhat_hacker. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-16
View profile →
PS1Bot
Technical ID: php.ps1bot
APT GROUPespionageadvanced
According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality, including the ability to deliver follow-on modules including an information stealer, keylogger, screen capture collector and more. It also establishes persistence to continue operations following system reboots. The design of this malware framework appears to attempt to minimize artifacts left on infected systems by facilitating the delivery and execution of modules in-memory, without requiring them to be written to disk. Due to similarities in the design and implementation with the malware family AHK Bot, we are referring to this PowerShell-based malware as “PS1Bot.”
Updated: 2025-08-18
View profile →
Prometheus Backdoor
Technical ID: php.prometheus_backdoor
APT GROUP
Backdoor written in php
Updated: 2022-05-25
View profile →
PAS
Technical ID: php.pas
APT GROUP
Malware family identifying php.pas. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-29
View profile →
Parrot TDS WebShell
Technical ID: php.parrot_tds_shell
APT GROUP
In combination with Parrot TDS the usage of a classical web shell was observed by DECODED Avast.io.
Updated: 2025-08-15
View profile →
p0wnyshell
Technical ID: php.p0wnyshell
APT GROUP
Malware family identifying php.p0wnyshell. Origin and technical characteristics tracked via Malpedia.
Also known as: Pownyshell • Ponyshell
Updated: 2023-07-11
View profile →
Glutton
Technical ID: php.glutton
APT GROUP
According to Xlab, Glutton is a modular PHP fileless attack framework, capable of data exfiltration and running backdoors.
Updated: 2024-12-20
View profile →
Ensikology
Technical ID: php.ensikology
APT GROUP
Malware family identifying php.ensikology. Origin and technical characteristics tracked via Malpedia.
Also known as: Ensiko
Updated: 2020-07-30
View profile →
DollyWay
Technical ID: php.dollyway
APT GROUP
PHP/JavaScript malware for WordPress that injects multi-stage scripts, turning compromised sites into distributed TDS/C2 nodes. Delivers signed payloads, maintains persistence via helper files, and redirects traffic to monetized scam networks.
Updated: 2025-08-18
View profile →
DEWMODE
Technical ID: php.dewmode
APT GROUP
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.
Updated: 2022-04-15
View profile →
c99shell
Technical ID: php.c99
APT GROUP
C99shell is a PHP backdoor that provides a lot of functionality, for example: * run shell commands; * download/upload files from and to the server (FTP functionality); * full access to all files on the hard disk; * self-delete functionality.
Also known as: c99
Updated: 2020-01-13
View profile →
Behinder
Technical ID: php.behinder
APT GROUP
A webshell for multiple web languages (asp/aspx, jsp/jspx, php), openly distributed through Github.
Updated: 2025-02-28
View profile →
ASPXSpy
Technical ID: php.aspxspy
APT39APT41HAFNIUM
APT GROUP
ASPXSpy is an open-source web shell written in C# that allows a threat actor to accomplish various post-exploitation tasks, including file access and command execution.
Updated: 2025-07-22
View profile →
ANTAK
Technical ID: php.antak
APT39Anunak
APT GROUP
Antak is a webshell written in ASP.Net which utilizes PowerShell.
Updated: 2020-06-25
View profile →
Ani-Shell
Technical ID: php.anishell
APT GROUP
Ani-Shell is a simple PHP shell with some unique features like Mass Mailer, a simple Web-Server Fuzzer, Dosser, Back Connect, Bind Shell, Back Connect, Auto Rooter etc.
Also known as: anishell
Updated: 2019-10-24
View profile →
ZuRu
Technical ID: osx.zuru
APT GROUP
A malware that was observed being embedded alongside legitimate applications (such as iTerm2) offered for download on suspicious websites pushed in search engines. It uses a Python script to perform reconnaissance on the compromised system an pulls additional payload(s).
Updated: 2021-10-19
View profile →
Yort
Technical ID: osx.yort
Lazarus Group
APT GROUP
Malware family identifying osx.yort. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-20
View profile →
XSLCmd
Technical ID: osx.xslcmd
APT GROUP
Malware family identifying osx.xslcmd. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-18
View profile →
Xloader
Technical ID: osx.xloader
APT GROUP
Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well. Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent. Not to be confused with apk.xloader or ios.xloader.
Also known as: Formbook
Updated: 2025-06-25
View profile →
XCSSET
Technical ID: osx.xcsset
APT GROUP
Malware family identifying osx.xcsset. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-11
View profile →
X-Agent
Technical ID: osx.xagent
APT28
APT GROUP
Malware family identifying osx.xagent. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
Wirenet
Technical ID: osx.wirenet
APT GROUP
Malware family identifying osx.wirenet. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-23
View profile →
WireLurker
Technical ID: osx.wirelurker
APT GROUP
Malware family identifying osx.wirelurker. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-17
View profile →
Winnti
Technical ID: osx.winnti
APT17
APT GROUP
Malware family identifying osx.winnti. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-17
View profile →
WindTail
Technical ID: osx.windtail
WindShift
APT GROUP
Malware family identifying osx.windtail. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-08
View profile →
WAVESHAPER
Technical ID: osx.waveshaper
UNC1069
APT GROUP
According to Mandiant, WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS. The backdoor supports downloading and executing arbitrary payloads retrieved from its command-and-control (C2 or C&C) server, which is provided via the command-line parameters. To communicate with the adversary infrastructure, WAVESHAPER leverages the curl library for either HTTP or HTTPS, depending on the command-line argument provided. WAVESHAPER also runs as a daemon by forking itself into a child process that runs in the background detached from the parent session and collects system information, which is sent to the C&C server in a HTTP POST request.
WatchCat
Technical ID: osx.watchcat
Lazarus Group
APT GROUP
Malware family identifying osx.watchcat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-11
View profile →
Vigram
Technical ID: osx.vigram
APT GROUP
Malware family identifying osx.vigram. Origin and technical characteristics tracked via Malpedia.
Also known as: WizardUpdate
Updated: 2022-03-25
View profile →
Uroburos
Technical ID: osx.uroburos
Turla
APT GROUP
Malware family identifying osx.uroburos. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-12
View profile →
UpdateAgent
Technical ID: osx.update_agent
APT GROUP
Malware family identifying osx.update_agent. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-06-04
View profile →
Unidentified macOS 001 (UnionCryptoTrader)
Technical ID: osx.unidentified_001
Lazarus Group
APT GROUP
Malware family identifying osx.unidentified_001. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-21
View profile →
← PreviousPage 192 / 269Next →