Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
APT GROUP
Malware family identifying jar.adzok. Origin and technical characteristics tracked via Malpedia.
AdWind
Technical ID: jar.adwind
APT GROUP
Part of Malware-as-service platform
Used as a generic name for Java-based RAT
Functionality
- collect general system and user information
- terminate process
-log keystroke
-take screenshot and access webcam
- steal cache password from local or web forms
- download and execute Malware
- modify registry
- download components
- Denial of Service attacks
- Acquire VPN certificates
Initial infection vector
1. Email to JAR files attached
2. Malspam URL to downlaod the malware
Persistence
- Runkey - HKCU\Software\Microsoft\Windows\current version\run
Hiding
Uses attrib.exe
Notes on Adwind
The malware is not known to be proxy aware
Also known as: AlienSpy • JSocket • Frutas • UNRECOM • JBifrost
APT GROUP
Malware family identifying ios.xagent. Origin and technical characteristics tracked via Malpedia.
WireLurker
Technical ID: ios.wirelurker
APT GROUP
The iOS malware that is installed over USB by osx.wirelurker
APT GROUP
According to Google, this reconnaissance payload uses a profiling framework drawing canvas to identify the target’s exact iPhone model, a technique used by many other actors. The iPhone model is sent back to the C2 along with screen size, whether or not a touch screen is present, and a unique identifier per initial GET request (e.g., 1lwuzddaxoom5ylli37v90kj).
The server replies with either an AES encrypted next stage or 0, indicating that no payload is available for this device. The payload makes another request to the exploit server with gcr=1 as a parameter to get the AES decryption key from the C2.
TriangleDB
Technical ID: ios.triangledb
APT GROUP
Malware family identifying ios.triangledb. Origin and technical characteristics tracked via Malpedia.
Predator
Technical ID: ios.predator
APT GROUP
Commercial spyware by Intellexa.
Also known as: PREYHUNTER
Postlo
Technical ID: ios.postlo
APT GROUP
Malware family identifying ios.postlo. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying ios.poisoncarp. Origin and technical characteristics tracked via Malpedia.
Also known as: INSOMNIA
APT GROUP
Malware family identifying ios.phenakite. Origin and technical characteristics tracked via Malpedia.
Also known as: Dakkatoni
lightSpy
Technical ID: ios.lightspy
APT GROUP
Malware family identifying ios.lightspy. Origin and technical characteristics tracked via Malpedia.
GuiInject
Technical ID: ios.guiinject
APT GROUP
Malware family identifying ios.guiinject. Origin and technical characteristics tracked via Malpedia.
DualToy
Technical ID: ios.dualtoy
APT GROUP
Malware family identifying ios.dualtoy. Origin and technical characteristics tracked via Malpedia.
Coruna
Technical ID: ios.coruna
APT GROUP
According to Google, this is a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023). The exploit kit, named "Coruna" by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.
APT GROUP
According to Google, this is a cookie stealer
AutoCAD Downloader
Technical ID: fas.acad
APT GROUP
Small downloader composed as a Fast-AutoLoad LISP (FAS) module for AutoCAD.
Also known as: Acad.Bursted • Duxfas
ZuoRAT
Technical ID: elf.zuo_rat
MALWAREespionageadvanced
According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets being transmitted over the infected device and perform person-in-the-middle attacks (DNS and HTTPS hijacking based on predefined rules).
Zollard
Technical ID: elf.zollard
MALWARE
Malware family identifying elf.zollard. Origin and technical characteristics tracked via Malpedia.
Also known as: darlloz
ZHtrap
Technical ID: elf.zhtrap
MALWARE
Malware family identifying elf.zhtrap. Origin and technical characteristics tracked via Malpedia.
ZeroBot
Technical ID: elf.zerobot
MALWARE
ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities. It is offered as malware as a service (MaaS) and infrastructure overlaps with DDoS-for-hire services seized by the FBI in December 2022.
Also known as: ZeroStresser
Zergeca
Technical ID: elf.zergeca
MALWARE
Zergeca is a DDoS-botnet and backdoor written in Golang. It uses modified UPX for packing, with the magic number 0x30219101 instead of "UPX!". It is being distributed via weak telnet passwords and known vulnerabilities.
XMRIG
Technical ID: elf.xmrig
MALWARE
Malware family identifying elf.xmrig. Origin and technical characteristics tracked via Malpedia.
xdr33
Technical ID: elf.xdr33
MALWARE
According to 360 netlab, this backdoor was derived from the leaked CIA Hive project. It propagates via a vulnerability in F5 and communicates using SSL with a forged Kaspersky certificate.
MALWARE
Malware family identifying elf.xbash. Origin and technical characteristics tracked via Malpedia.
Xaynnalc
Technical ID: elf.xaynnalc
MALWARE
Malware family identifying elf.xaynnalc. Origin and technical characteristics tracked via Malpedia.
Xanthe
Technical ID: elf.xanthe
MALWARE
Malware family identifying elf.xanthe. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.xagent. Origin and technical characteristics tracked via Malpedia.
Also known as: splm • chopstick • fysbis
MALWARE
Malware family identifying elf.wolfsbane. Origin and technical characteristics tracked via Malpedia.
Wirenet
Technical ID: elf.wirenet
MALWARE
Malware family identifying elf.wirenet. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.winnti. Origin and technical characteristics tracked via Malpedia.
WhiteRabbit
Technical ID: elf.whiterabbit
MALWARE
Malware family identifying elf.whiterabbit. Origin and technical characteristics tracked via Malpedia.
WHIRLPOOL
Technical ID: elf.whirlpool
MALWARE
Malware family identifying elf.whirlpool. Origin and technical characteristics tracked via Malpedia.
elf.wellmess
APT 29
MALWARE
Malware family identifying elf.wellmess. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.wellmail. Origin and technical characteristics tracked via Malpedia.
WatchBog
Technical ID: elf.watchbog
MALWARE
According to Intezer, this is a spreader module used by WatchBog. It is a dynamically linked ELF executable, compiled with Cython. C&C adresses are fetched from Pastebin. C&C communication references unique identification keys per victim. It contains a BlueKeep scanner, reporting positively scanned hosts to the C&C server (RC4 encrypted within SSL/TLS). It contains 5 exploits targeting Jira, Exim, Solr, Jenkins and Nexus Repository Manager 3.
WalkLoader
Technical ID: elf.walkloader
MALWARE
Malware family identifying elf.walkloader. Origin and technical characteristics tracked via Malpedia.
VPNFilter
Technical ID: elf.vpnfilter
MALWARE
Malware family identifying elf.vpnfilter. Origin and technical characteristics tracked via Malpedia.
VoidLink
Technical ID: elf.voidlink
MALWARE
VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong operational security through runtime encryption, environment awareness (cloud provider and container detection), and the use of user-mode and kernel-level rootkit techniques to evade detection.
VoidLink is not a repurposed legacy tool but a purpose-built framework optimized for cloud infrastructure, indicating a shift in advanced threat development toward Linux-based cloud workloads. Although no confirmed large-scale infections have been observed, its maturity and design suggest potential use by sophisticated threat actors for long-term, stealthy access to cloud environments.
vGet
Technical ID: elf.vget
MALWARE
According to Synacktiv, vGet is an in-memory stager for vShell, written in Rust.