Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Crisis
Technical ID: osx.crisis
APT GROUP
Malware family identifying osx.crisis. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
CreativeUpdater
Technical ID: osx.creative_updater
APT GROUP
Malware family identifying osx.creative_updater. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-07
View profile →
CpuMeaner
Technical ID: osx.cpumeaner
APT GROUP
Malware family identifying osx.cpumeaner. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-12-15
View profile →
Convuster
Technical ID: osx.convuster
APT GROUP
Malware family identifying osx.convuster. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-16
View profile →
Coldroot RAT
Technical ID: osx.coldroot_rat
APT GROUP
Malware family identifying osx.coldroot_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-11
View profile →
CoinThief
Technical ID: osx.cointhief
APT GROUP
CoinThief was a malware package designed to steal Bitcoins from the victim, consisting of a binary patcher, browser extensions, and a backdoor component. It was spreading in early 2014 from several different sources: - on Github (where the trojanized compiled binary didn’t match the displayed source code), o - on popular and trusted download sites line CNET's Download.com or MacUpdate.com, and - as cracked applications via torrents camouflaged as Bitcoin Ticker TTM, BitVanity, StealthBit, Litecoin Ticker, BBEdit, Pixelmator, Angry Birds and Delicious Library. The patcher‘s role was to locate and modify legitimate versions of the Bitcoin-Qt wallet application. The analyzed malware samples targeted versions of Bitcoin-Qt 0.8.1, 0.8.0 and 0.8.5. The earlier patch modified Bitcoin-Qt adding malicious code that would send nearly all the victim’s Bitcoins to one of the hard-coded addresses belonging to the attacker. The browser extensions targeted Chrome and Firefox and are disguised as a “Pop-up blocker”. The extensions monitored visited websites, download malicious JavaScripts and injected them into various Bitcoin-related websites (mostly Bitcoin exchanges and online wallet sites). The injected JS scripts were able to modify transactions to redirect Bitcoin transfers to an attacker’s address or simply harvest login credentials to the targeted online service. The backdoor enabled the attacker to take full control over the victim’s computer: - collect information about the infected computer - execute arbitrary shell scripts on the target computer - upload an arbitrary file from the victim’s hard drive to a remote server - update itself to a newer version
Updated: 2019-09-12
View profile →
CloudMensis
Technical ID: osx.cloud_mensis
APT GROUP
Malware family identifying osx.cloud_mensis. Origin and technical characteristics tracked via Malpedia.
Also known as: BadRAT
Updated: 2025-11-19
View profile →
Choziosi
Technical ID: osx.choziosi
APT GROUP
A loader delivering malicious Chrome and Safari extensions.
Also known as: ChromeLoader • Chropex
Updated: 2023-11-23
View profile →
CDDS
Technical ID: osx.cdds
APT GROUP
Google TAG has observed this malware being delivered via watering hole attacks using 0-day exploits, targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political group.
Also known as: Macma
Updated: 2024-08-29
View profile →
Casso
Technical ID: osx.casso
Lazarus Group
APT GROUP
Malware family identifying osx.casso. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-30
View profile →
Careto
Technical ID: osx.careto
APT GROUP
Malware family identifying osx.careto. Origin and technical characteristics tracked via Malpedia.
Also known as: Mask • Appetite
Updated: 2025-05-26
View profile →
Bundlore
Technical ID: osx.bundlore
APT GROUP
Malware family identifying osx.bundlore. Origin and technical characteristics tracked via Malpedia.
Also known as: SurfBuyer
Updated: 2021-06-23
View profile →
Bella
Technical ID: osx.bella
APT GROUP
Malware family identifying osx.bella. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-03-23
View profile →
BeaverTail
Technical ID: osx.beavertail
APT GROUP
Malware family identifying osx.beavertail. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-22
View profile →
BANSHEE
Technical ID: osx.banshee
APT GROUP
Malware family identifying osx.banshee. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-26
View profile →
AppleJeus
Technical ID: osx.applejeus
Lazarus Group
APT GROUP
According to PcRisk AppleJeus is the name of backdoor malware that was distributed by the Lazarus group. They spread this malicious software through a fake app disguised as a cryptocurrency trading application called Celas Trade Pro.
Updated: 2024-11-29
View profile →
AMOS
Technical ID: osx.amos
APT GROUP
Malware family identifying osx.amos. Origin and technical characteristics tracked via Malpedia.
Also known as: Atomic macOS Stealer
Updated: 2025-12-11
View profile →
3CX Backdoor
Technical ID: osx.3cx_backdoor
Lazarus Group
APT GROUP
Malware family identifying osx.3cx_backdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-06
View profile →
Icesword
Technical ID: jsp.icesword
Gelsemium
APT GROUP
webshell
Updated: 2024-11-26
View profile →
Godzilla Webshell
Technical ID: jsp.godzilla_webshell
APT GROUP
Malware family identifying jsp.godzilla_webshell. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-13
View profile →
witchcoven
Technical ID: js.witchcoven
APT GROUP
Malware family identifying js.witchcoven. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
WEEVILPROXY
Technical ID: js.weevilproxy
APT GROUP
WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS. The developer has put in concerted effort to develop the malware’s breadth of capabilities, including novel techniques not observed in any prior malware campaigns - to our knowledge. These new TTPs include methods to modify Windows Setup and Windows Recovery to enable long-term persistence, as well as methods to patch browser extensions ‘on the fly’.
Also known as: JSCEAL
Updated: 2025-08-15
View profile →
APT GROUP
The threat actor of this family compromised Chrome extension developer accounts and attached malicious code to the extensions. Web Developer 0.4.9, Chrometana 1.1.3, Infinity New Tab 3.12.3, CopyFish 2.8.5, Web Paint 1.2.1, and Social Fixer 20.1.1 were affected by this. TouchVPN and BetterVPN were assumed to be targets as well. This lead to the execution of another Javascript that substitutes ad banners for their own, effectively hijacking ad traffic. It is also reported that fake pop-up alerts were used to lure victims to download possibly other malware.
Valak
Technical ID: js.valak
APT GROUP
According to PCrisk, Valak is malicious software that downloads JScript files and executes them. What happens next depends on the actions performed by the executed JScript files. It is very likely that cyber criminals behind Valak attempt to use this malware to cause chain infections (i.e., using Valak to distribute other malware). Research shows that Valak is distributed through spam campaigns, however, in some cases, it infiltrates systems when they are already infected with malicious program such as Ursnif (also known as Gozi).
Also known as: Valek
Updated: 2023-07-28
View profile →
Unidentified JS 002
Technical ID: js.unidentified_js_002
APT GROUP
Malware family identifying js.unidentified_js_002. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-21
View profile →
Unidentified JS 006 (Winter Wyvern)
Technical ID: js.unidentified_006
Winter Vivern
APT GROUP
A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.
Updated: 2024-02-20
View profile →
Unidentified JS 005 (Stealer)
Technical ID: js.unidentified_005
APT GROUP
Malware family identifying js.unidentified_005. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-20
View profile →
Unidentified JS 004
Technical ID: js.unidentified_004
APT GROUP
A simple loader written in JavaScript found by Marco Ramilli.
Updated: 2020-12-01
View profile →
Unidentified JS 003 (Emotet Downloader)
Technical ID: js.unidentified_003
MUMMY SPIDER
APT GROUP
According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages. The first stage is an office file that contains a macro. This macro then loads the second stage, which is either a PowerShell script or a piece of JavaScript, which is this family entry.
Updated: 2020-04-14
View profile →
Unidentified JS 001 (APT32 Profiler)
Technical ID: js.unidentified_001
APT32
APT GROUP
Malware family identifying js.unidentified_001. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
Maintools.js
Technical ID: js.turla_maintools
Turla
APT GROUP
Expects a parameter to run: needs to be started as 'maintools.js EzZETcSXyKAdF_e5I2i1'.
Updated: 2017-11-17
View profile →
HTML5 Encoding
Technical ID: js.turla_ff_ext
Turla
APT GROUP
Malware family identifying js.turla_ff_ext. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-20
View profile →
Tsundere
Technical ID: js.tsundere
MuddyWater
APT GROUP
Malware family identifying js.tsundere. Origin and technical characteristics tracked via Malpedia.
Also known as: DinDoor
Swid
Technical ID: js.swid
APT GROUP
Malware family identifying js.swid. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-08-24
View profile →
StarFish
Technical ID: js.starfish
APT GROUP
According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.
Updated: 2025-07-25
View profile →
Starfighter
Technical ID: js.starfighter
APT GROUP
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on local powershell availability.
Updated: 2020-04-07
View profile →
SQLRat
Technical ID: js.sqlrat
Anunak
APT GROUP
SQLRat campaigns typically involve a lure document that includes an image overlayed by a VB Form trigger. Once a user has double-clicked the embedded image, the form executes a VB setup script. The script writes files to the path %appdata%\Roaming\Microsoft\Templates\, then creates two task entries triggered to run daily. The scripts are responsible for deobfuscating and executing the main JavaScript file mspromo.dot. The file uses a character insertion obfuscation technique, making it appear to contain Chinese characters. After deobfuscating the file, the main JavaScript is easily recognizable. It contains a number of functions designed to drop files and execute scripts on a host system. The SQLRat script is designed to make a direct SQL connection to a Microsoft database controlled by the attackers and execute the contents of various tables.
Updated: 2022-05-05
View profile →
SpyPress
Technical ID: js.spypress
APT28
APT GROUP
According to ESET, SpyPress is a set of Javascript payloads targeting different webmail frameworks (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA). The observed payloads have common characteristics. All are similarly obfuscated, with variable and function names replaced with random-looking strings. Furthermore, strings used by the code, such as webmail and C&C server URLs, are also obfuscated and contained in an encrypted list. Each of those strings is only decrypted when it is used. Note that the variable and function names are randomized for each sample, so the final SpyPress payloads will have different hashes. Another common characteristic is that there are no persistence or update mechanisms. The payload is fully contained in the email and only executed when the email message is viewed from a vulnerable webmail instance. Finally, all payloads communicate with their hardcoded C&C servers via HTTP POST requests. There is a small number of C&C servers that are shared by all payloads (there is no separation by victim or payload type).
Updated: 2025-05-20
View profile →
Smokest Stealer
Technical ID: js.smokest
APT GROUP
Malware family identifying js.smokest. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-19
View profile →
SmartApeSG
Technical ID: js.smartapesg
APT GROUP
According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.
Also known as: HANEYMANEY • ZPHP
Updated: 2026-01-21
View profile →
← PreviousPage 195 / 269Next →