Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Tsunami
Technical ID: osx.tsunami
APT GROUP
Malware family identifying osx.tsunami. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-04-04
View profile →
systemd
Technical ID: osx.systemd
APT GROUP
General purpose backdoor
Also known as: Demsty • ReverseWindow
Updated: 2022-06-04
View profile →
SysJoker
Technical ID: osx.sysjoker
APT GROUP
Malware family identifying osx.sysjoker. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-04-04
View profile →
SUGARLOADER
Technical ID: osx.sugarloader
Lazarus Group
APT GROUP
Malware family identifying osx.sugarloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-01-14
View profile →
SpectralBlur
Technical ID: osx.spectral_blur
Lazarus Group
APT GROUP
Malware family identifying osx.spectral_blur. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-18
View profile →
SimpleTea
Technical ID: osx.simpletea
Lazarus Group
APT GROUP
SimpleTea is a RAT for macOS that is based on the same object-oriented project as SimpleTea for Linux (SimplexTea). It also shares similarities with POOLRAT (also known as SIMPLESEA), like the supported commands or a single-byte XOR encryption of its configuration. However, the indices of commands are different. SimpleTea for macOS was uploaded to VirusTotal from Hong Kong and China in September 2023.
Updated: 2025-01-14
View profile →
Silver Sparrow
Technical ID: osx.silver_sparrow
APT GROUP
According to Red Canary, Silver Sparrow is an activity cluster that includes a binary compiled to run on Apple’s new M1 chips but has been distributed without payload so far.
Updated: 2022-03-23
View profile →
Shlayer
Technical ID: osx.shlayer
APT GROUP
According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote fake search engines. It is typically disguised as a Adobe Flash Player installer and various software cracking tools. In most cases, users encounter this virus when visiting dubious Torrent websites that are full of intrusive advertisements and deceptive downloads.
Updated: 2023-05-16
View profile →
RustBucket
Technical ID: osx.rustbucket
Lazarus Group
APT GROUP
Malware family identifying osx.rustbucket. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-01-14
View profile →
Dok
Technical ID: osx.retefe
APT GROUPfinancialhigh
Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an app bundle within a DMG disk image, posing as a document. The primary purpose of the dropper is to install a Tor client as well as a malicious CA certificate and proxy pac URL, in order to redirect traffic to targeted sites through their Tor node, effectively carrying out a MITM attack against selected web traffic. It also installs a custom hosts file to prevent access to Apple and VirusTotal. The macOS version shares its MO, many TTPs and infrastructure with the Windows counterpart.
Also known as: Retefe
Updated: 2019-05-02
View profile →
Pwnet
Technical ID: osx.pwnet
APT GROUP
Cryptocurrency miner that was distributed masquerading as a Counter-Strike: Global Offensive hack.
Updated: 2018-01-28
View profile →
Pureland
Technical ID: osx.pureland
APT GROUP
According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.
Updated: 2025-11-19
View profile →
Proton RAT
Technical ID: osx.proton_rat
APT GROUPespionageadvanced
Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems. It is known for providing attackers with complete remote control over the infected system, allowing the execution of commands, keystroke capturing, access to the camera and microphone, and the ability to steal credentials stored in browsers and other password managers. This malware typically spreads through malicious or modified applications, which, when downloaded and installed by unsuspecting users, trigger its payload. Proton RAT is notorious for its sophistication and evasion capabilities, including techniques to bypass detection by installed security solutions.
Also known as: Calisto
Updated: 2024-07-01
View profile →
Poseidon Stealer
Technical ID: osx.poseidonstealer
APT GROUP
macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which when executed spawns osascript executing an AppleScript with the actual infostealer payload. The AppleScript payload will steal files by packing them in a ZIP archive and uploading them to a hardcoded C2 via HTTP.
Also known as: Rodrigo Stealer
Updated: 2025-11-19
View profile →
Poseidon
Technical ID: osx.poseidon
APT GROUP
Part of Mythic C2, written in Golang.
Updated: 2023-10-12
View profile →
POOLRAT
Technical ID: osx.poolrat
Lazarus Group
APT GROUP
Malware family identifying osx.poolrat. Origin and technical characteristics tracked via Malpedia.
Also known as: SIMPLESEA • SIMPLETEA
Updated: 2025-12-30
View profile →
Pirrit
Technical ID: osx.pirrit
APT GROUP
Malware family identifying osx.pirrit. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-13
View profile →
PintSized
Technical ID: osx.pintsized
APT GROUP
Backdoor as a fork of OpenSSH_6.0 with no logging, and “-P” and “-z” hidden command arguments. “PuffySSH_5.8p1” string.
Updated: 2019-04-03
View profile →
Pearl Stealer
Technical ID: osx.pearl_stealer
APT GROUP
Malware family identifying osx.pearl_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-24
View profile →
Patcher
Technical ID: osx.patcher
APT GROUPfinancialhigh
This crypto-ransomware for macOS was caught spreading via BitTorrent distribution sites in February 2017, masquerading as 'Patcher', an application used for pirating popular software like Adobe Premiere Pro or Microsoft Office for Mac. The downloaded torrent contained an application bundle in the form of a single zip file. After launching the fake application, the main window of the fake cracking tool was displayed. The file encryption process was launched after the misguided victim clicked 'Start'. Once executed, the ransomware generated a random 25-character string and set it as the key for RC4 encryption of all of the user's files. It then demanded ransom in Bitcoin, as instructed in the 'README!' .txt file copied all over the user's directories. Despite the instructions being quite thorough, Patcher lacked the functionality to communicate with any C&C server, and therefore made it impossible for its operators to decrypt affected files. The randomly generated encryption key was also too long to be guessed via a brute-force attack, leaving the encrypted data unrecoverable in a reasonable amount of time.
Also known as: FileCoder • Findzip
Updated: 2019-04-03
View profile →
OSAMiner
Technical ID: osx.osaminer
APT GROUP
Malware family identifying osx.osaminer. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-18
View profile →
oRAT
Technical ID: osx.orat
APT GROUP
SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.
Updated: 2022-07-25
View profile →
Olyx
Technical ID: osx.olyx
APT GROUP
Malware family identifying osx.olyx. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
Odyssey Stealer
Technical ID: osx.odyssey_stealer
APT GROUP
Malware family identifying osx.odyssey_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-19
View profile →
OceanLotus
Technical ID: osx.oceanlotus
APT32
APT GROUP
According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies. The OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).
Updated: 2025-07-28
View profile →
NetWire
Technical ID: osx.netwire
APT GROUP
Malware family identifying osx.netwire. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-24
View profile →
Mughthesec
Technical ID: osx.mughthesec
APT GROUP
Malware family identifying osx.mughthesec. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-10
View profile →
Mokes
Technical ID: osx.mokes
APT GROUP
Malware family identifying osx.mokes. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-20
View profile →
Manuscrypt
Technical ID: osx.manuscrypt
Lazarus Group
APT GROUP
Malware family identifying osx.manuscrypt. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-29
View profile →
MaMi
Technical ID: osx.mami
APT GROUP
Malware family identifying osx.mami. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-14
View profile →
MacVX
Technical ID: osx.macvx
APT GROUP
Malware family identifying osx.macvx. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
MacSpy
Technical ID: osx.macspy
APT GROUP
Malware family identifying osx.macspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-06-13
View profile →
MacRansom
Technical ID: osx.macransom
APT GROUP
Malware family identifying osx.macransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-06-13
View profile →
MacInstaller
Technical ID: osx.macinstaller
APT GROUP
Malware family identifying osx.macinstaller. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
MacDownloader
Technical ID: osx.macdownloader
APT GROUP
Malware family identifying osx.macdownloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
LockBit
Technical ID: osx.lockbit
APT GROUP
Malware family identifying osx.lockbit. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-19
View profile →
LIGHTSPY
Technical ID: osx.lightspy
APT GROUP
According to Volexity, LIGHTSPY is a multi-platform malware family with documented variants for Android, iOS, and macOS.
Updated: 2024-11-25
View profile →
Leverage
Technical ID: osx.leverage
APT GROUP
Malware family identifying osx.leverage. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-31
View profile →
Laoshu
Technical ID: osx.laoshu
APT GROUP
Malware family identifying osx.laoshu. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-28
View profile →
Lambert
Technical ID: osx.lambert
Longhorn
APT GROUP
Malware family identifying osx.lambert. Origin and technical characteristics tracked via Malpedia.
Also known as: GreenLambert
Updated: 2021-10-24
View profile →
← PreviousPage 193 / 269Next →