Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Vermilion Strike
Technical ID: elf.vermilion_strike
MALWARE
Malware family identifying elf.vermilion_strike. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
Hive (Vault 8)
Technical ID: elf.vault8_hive
Longhorn
MALWARE
Malware family identifying elf.vault8_hive. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-02
View profile →
Unidentified ELF 006 (Tox Backdoor)
Technical ID: elf.unidentified_006
MALWARE
Enables remote execution of scripts on a host, communicates via Tox.
Updated: 2022-08-26
View profile →
Unidentified 005 (Sidecopy)
Technical ID: elf.unidentified_005
SideCopy
MALWARE
Malware family identifying elf.unidentified_005. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-22
View profile →
Unidentified ELF 004
Technical ID: elf.unidentified_004
APT31
MALWAREespionageadvanced
Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi surveillance cameras.
Updated: 2021-11-12
View profile →
Unidentified Linux 001
Technical ID: elf.unidentified_001
MALWARE
According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA: CVE-2019-10149. This attack leverages a week-old vulnerability to gain remote command execution on the target machine, search the Internet for other machines to infect, and initiates a crypto miner.
Updated: 2021-06-29
View profile →
Umbreon
Technical ID: elf.umbreon
MALWARE
Malware family identifying elf.umbreon. Origin and technical characteristics tracked via Malpedia.
Also known as: Espeon
Updated: 2018-06-28
View profile →
Turla RAT
Technical ID: elf.turla_rat
MALWARE
Malware family identifying elf.turla_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-28
View profile →
Tsunami
Technical ID: elf.tsunami
MALWARE
Malware family identifying elf.tsunami. Origin and technical characteristics tracked via Malpedia.
Also known as: Muhstik • Radiation • Amnesia
Updated: 2024-10-21
View profile →
tsh
Technical ID: elf.tsh
MALWARE
Malware family identifying elf.tsh. Origin and technical characteristics tracked via Malpedia.
Also known as: TINYSHELL
Updated: 2025-03-14
View profile →
TSCookie
Technical ID: elf.tscookie
BlackTech
MALWARE
Malware family identifying elf.tscookie. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-30
View profile →
Trump Bot
Technical ID: elf.trump_bot
MALWARE
Malware family identifying elf.trump_bot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-10-25
View profile →
TripleCross
Technical ID: elf.triplecross
MALWARE
According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.
Updated: 2024-03-19
View profile →
Torii
Technical ID: elf.torii
MALWARE
Malware family identifying elf.torii. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-27
View profile →
TNTbotinger
Technical ID: elf.tntbotinger
MALWARE
Malware family identifying elf.tntbotinger. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-12
View profile →
TheMoon
Technical ID: elf.themoon
MALWARE
Malware family identifying elf.themoon. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-21
View profile →
TeamTNT
Technical ID: elf.teamtnt
MALWARE
Since Fall 2019, Team TNT is a well known threat actor which targets *nix based systems and misconfigured Docker container environments. It has constantly evolved its capabilities for its cloud-based cryptojacking operations. They have shifted their focus on compromising Kubernetes Clusters.
Updated: 2025-03-21
View profile →
SystemBC
Technical ID: elf.systembc
MALWARE
Malware family identifying elf.systembc. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-23
View profile →
Sysrv-hello
Technical ID: elf.sysrvhello
MALWARE
Cryptojacking botnet
Also known as: Sysrv
Updated: 2024-10-17
View profile →
SysJoker
Technical ID: elf.sysjoker
MALWARE
Malware family identifying elf.sysjoker. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-04-04
View profile →
Symbiote
Technical ID: elf.symbiote
MALWAREespionageadvanced
A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit. It uses three methods for hiding its network activity, by hooking and hijacking 1) fopen/fopen64, 2) eBPF, 3) a set of libpcap functions.
Updated: 2023-07-16
View profile →
Sword2033
Technical ID: elf.sword2033
GALLIUM
MALWARE
Malware family identifying elf.sword2033. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-08
View profile →
Suterusu
Technical ID: elf.suterusu
MALWARE
Malware family identifying elf.suterusu. Origin and technical characteristics tracked via Malpedia.
Also known as: HCRootkit
Updated: 2024-03-12
View profile →
sustes miner
Technical ID: elf.sustes
MALWARE
Sustes Malware doesn’t infect victims by itself (it’s not a worm) but it is spread over exploitation and brute-force activities with special focus on IoT and Linux servers. The initial infection stage comes from a custom wget directly on the victim machine followed by a simple /bin/bash mr.sh. The script is a simple bash script which drops and executes additional software.
Updated: 2019-10-30
View profile →
Sunless
Technical ID: elf.sunless
MALWARE
Malware family identifying elf.sunless. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-01-23
View profile →
STEELCORGI
Technical ID: elf.steelcorgi
MALWARE
According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key material from environment variables.
Updated: 2022-03-17
View profile →
Stantinko
Technical ID: elf.stantinko
MALWARE
Malware family identifying elf.stantinko. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-26
View profile →
SSHDoor
Technical ID: elf.sshdoor
MALWARE
Malware family identifying elf.sshdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-20
View profile →
Sshdinjector
Technical ID: elf.sshdinjector
MALWARE
Malware family identifying elf.sshdinjector. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-10
View profile →
SprySOCKS
Technical ID: elf.spry_socks
Earth Lusca
MALWARE
Malware family identifying elf.spry_socks. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-18
View profile →
Speculoos
Technical ID: elf.speculoos
APT17
MALWARE
Malware family identifying elf.speculoos. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
SpectralBlur
Technical ID: elf.spectral_blur
Lazarus Group
MALWARE
Malware family identifying elf.spectral_blur. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-18
View profile →
Specter
Technical ID: elf.specter
MALWARE
Malware family identifying elf.specter. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-15
View profile →
SpeakUp
Technical ID: elf.speakup
MALWARE
Malware family identifying elf.speakup. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-02-07
View profile →
SPAWNSNARE
Technical ID: elf.spawnsnare
MALWARE
According to Mandiant, this is a utility that is written in C and targets Linux. It can be used to extract the uncompressed linux kernel image (vmlinux) into a file and encrypt it using AES without the need for any command line tools.
Updated: 2025-04-11
View profile →
Spamtorte
Technical ID: elf.spamtorte
MALWARE
Malware family identifying elf.spamtorte. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-20
View profile →
SoWaT
Technical ID: elf.sowat
APT31
MALWAREespionageadvanced
This is an implant used by APT31 on home routers to utilize them as ORBs.
Updated: 2023-09-08
View profile →
SNOWLIGHT
Technical ID: elf.snowlight
UNC5174
MALWARE
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
Updated: 2026-01-19
View profile →
SnappyTCP
Technical ID: elf.snappy_tcp
Sea Turtle
MALWARE
According to PwC, SnappyTCP is a simple reverse shell for Linux/Unix systems, with variants for plaintext and TLS communication. SeaTurtle has used SnappyTCP at least between 2021 and 2023.
Updated: 2024-02-15
View profile →
SLAPSTICK
Technical ID: elf.slapstick
MALWARE
According to FireEye, SLAPSTICK is a Solaris PAM backdoor that grants a user access to the system with a secret, hard-coded password.
Updated: 2022-03-17
View profile →
← PreviousPage 199 / 269Next →