Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Vermilion Strike
Technical ID: elf.vermilion_strike
MALWARE
Malware family identifying elf.vermilion_strike. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.vault8_hive. Origin and technical characteristics tracked via Malpedia.
Unidentified ELF 006 (Tox Backdoor)
Technical ID: elf.unidentified_006
MALWARE
Enables remote execution of scripts on a host, communicates via Tox.
MALWARE
Malware family identifying elf.unidentified_005. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi surveillance cameras.
Unidentified Linux 001
Technical ID: elf.unidentified_001
MALWARE
According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA: CVE-2019-10149. This attack leverages a week-old vulnerability to gain remote command execution on the target machine, search the Internet for other machines to infect, and initiates a crypto miner.
Umbreon
Technical ID: elf.umbreon
MALWARE
Malware family identifying elf.umbreon. Origin and technical characteristics tracked via Malpedia.
Also known as: Espeon
Turla RAT
Technical ID: elf.turla_rat
MALWARE
Malware family identifying elf.turla_rat. Origin and technical characteristics tracked via Malpedia.
Tsunami
Technical ID: elf.tsunami
MALWARE
Malware family identifying elf.tsunami. Origin and technical characteristics tracked via Malpedia.
Also known as: Muhstik • Radiation • Amnesia
tsh
Technical ID: elf.tsh
MALWARE
Malware family identifying elf.tsh. Origin and technical characteristics tracked via Malpedia.
Also known as: TINYSHELL
MALWARE
Malware family identifying elf.tscookie. Origin and technical characteristics tracked via Malpedia.
Trump Bot
Technical ID: elf.trump_bot
MALWARE
Malware family identifying elf.trump_bot. Origin and technical characteristics tracked via Malpedia.
TripleCross
Technical ID: elf.triplecross
MALWARE
According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.
Torii
Technical ID: elf.torii
MALWARE
Malware family identifying elf.torii. Origin and technical characteristics tracked via Malpedia.
TNTbotinger
Technical ID: elf.tntbotinger
MALWARE
Malware family identifying elf.tntbotinger. Origin and technical characteristics tracked via Malpedia.
TheMoon
Technical ID: elf.themoon
MALWARE
Malware family identifying elf.themoon. Origin and technical characteristics tracked via Malpedia.
TeamTNT
Technical ID: elf.teamtnt
MALWARE
Since Fall 2019, Team TNT is a well known threat actor which targets *nix based systems and misconfigured Docker container environments. It has constantly evolved its capabilities for its cloud-based cryptojacking operations. They have shifted their focus on compromising Kubernetes Clusters.
SystemBC
Technical ID: elf.systembc
MALWARE
Malware family identifying elf.systembc. Origin and technical characteristics tracked via Malpedia.
SysJoker
Technical ID: elf.sysjoker
MALWARE
Malware family identifying elf.sysjoker. Origin and technical characteristics tracked via Malpedia.
Symbiote
Technical ID: elf.symbiote
MALWAREespionageadvanced
A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit. It uses three methods for hiding its network activity, by hooking and hijacking 1) fopen/fopen64, 2) eBPF, 3) a set of libpcap functions.
MALWARE
Malware family identifying elf.sword2033. Origin and technical characteristics tracked via Malpedia.
Suterusu
Technical ID: elf.suterusu
MALWARE
Malware family identifying elf.suterusu. Origin and technical characteristics tracked via Malpedia.
Also known as: HCRootkit
sustes miner
Technical ID: elf.sustes
MALWARE
Sustes Malware doesn’t infect victims by itself (it’s not a worm) but it is spread over exploitation and brute-force activities with special focus on IoT and Linux servers. The initial infection stage comes from a custom wget directly on the victim machine followed by a simple /bin/bash mr.sh. The script is a simple bash script which drops and executes additional software.
Sunless
Technical ID: elf.sunless
MALWARE
Malware family identifying elf.sunless. Origin and technical characteristics tracked via Malpedia.
STEELCORGI
Technical ID: elf.steelcorgi
MALWARE
According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key material from environment variables.
Stantinko
Technical ID: elf.stantinko
MALWARE
Malware family identifying elf.stantinko. Origin and technical characteristics tracked via Malpedia.
SSHDoor
Technical ID: elf.sshdoor
MALWARE
Malware family identifying elf.sshdoor. Origin and technical characteristics tracked via Malpedia.
Sshdinjector
Technical ID: elf.sshdinjector
MALWARE
Malware family identifying elf.sshdinjector. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.spry_socks. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.speculoos. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.spectral_blur. Origin and technical characteristics tracked via Malpedia.
Specter
Technical ID: elf.specter
MALWARE
Malware family identifying elf.specter. Origin and technical characteristics tracked via Malpedia.
SpeakUp
Technical ID: elf.speakup
MALWARE
Malware family identifying elf.speakup. Origin and technical characteristics tracked via Malpedia.
SPAWNSNARE
Technical ID: elf.spawnsnare
MALWARE
According to Mandiant, this is a utility that is written in C and targets Linux. It can be used to extract the uncompressed linux kernel image (vmlinux) into a file and encrypt it using AES without the need for any command line tools.
Spamtorte
Technical ID: elf.spamtorte
MALWARE
Malware family identifying elf.spamtorte. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
This is an implant used by APT31 on home routers to utilize them as ORBs.
MALWARE
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
MALWARE
According to PwC, SnappyTCP is a simple reverse shell for Linux/Unix systems, with variants for plaintext and TLS communication. SeaTurtle has used SnappyTCP at least between 2021 and 2023.
SLAPSTICK
Technical ID: elf.slapstick
MALWARE
According to FireEye, SLAPSTICK is a Solaris PAM backdoor that grants a user access to the system with a secret, hard-coded password.