Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,713 entities
APT GROUPfinancialhigh
According to PCrisk, PLAY is the name of a ransomware-type program. Malware categorized as such operates by encrypting data and demanding ransoms for the decryption. After we executed a sample of this ransomware on our test machine, it encrypted files and appended their filenames with a ".PLAY" extension. For example, a file titled "1.jpg" appeared as "1.jpg.PLAY", "2.png" as "2.png.PLAY", etc. Once the encryption process was completed, PLAY created a text file named "ReadMe.txt" on the desktop.
APT GROUP
Malware family tracked by Malpedia. ID: win.payloadbin
APT GROUPfinancialhigh
According to EG-FinCIRT, Payload is a cross-platform ransomware family with native compiled binaries for Windows and Linux/ESXi, exposing rich command-line options that let operators tune targeting, performance, and anti-forensic behavior. The Windows variant aggressively prepares the system by deleting recovery points, stopping key services and processes, wiping or bypassing logging mechanisms, and optionally hiding and self-deleting its executable while running encryption in the background. Its core uses an offline hybrid cryptosystem combining Curve25519 key exchange with optimized ChaCha20 (using CPU feature detection and multithreading, plus partial encryption for large files) and appends an obfuscated metadata footer needed for decryption. The Linux/ESXi variant is a small stripped ELF binary that parses virtual machine inventory data to locate and encrypt VM disk files, focusing on efficient disruption of virtualized workloads with fewer ancillary features than the Windows version.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.nightsky
APT GROUP
Malware family tracked by Malpedia. ID: win.mortalkombat
APT GROUPfinancialhigh
Ransomware. Identical samples (apart from note) operated by Morpheus and HellCat ransomware groups.
APT GROUPfinancialhigh
A new ransomware gang hitting companies in worldwide firstly spotted by Zscaler.
APT GROUPfinancialhigh
Ransomware, potential rebranding of win.sfile.
APT GROUP
Malware family tracked by Malpedia. ID: win.metaencryptor
APT GROUPfinancialhigh
According to PCrisk, MEOW is ransomware based on other ransomware called CONTI. MEOW encrypts files and appends the ".MEOW" extension to their filenames. It also drops the "readme.txt" file (a ransom note). An example of how MEOW ransomware modifies filenames: it renames "1.jpg" to "1.jpg.MEOW", "2.png" to "2.png.MEOW", and so forth.
APT GROUP
Malware family tracked by Malpedia. ID: win.mailto
APT GROUPfinancialhigh
According to Nextron, Lynx ransomware is a sophisticated malware threat that has been active since mid-2024. Lynx has claimed over 20 victims across a range of industries. Once it infiltrates a system, it encrypts critical files, appending a ‘.lynx’ extension, and deletes backup files like shadow copies to hinder recovery. Uniquely, it also sends the ransom note to available printers, adding an unexpected element to its attack strategy. This malware shares similarities with previous INC ransomware, indicating that they bought INC ransomware source code.
APT GROUPfinancialhigh
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
APT GROUPfinancialhigh
LokiLocker is a .Net ransomware, which was seen first in August 2021. This malware is protected with NETGuard (modified ConfuserEX) using the additional KoiVM virtualization plugin. The victims were observed ti be scattered around the world, with main concentation in Estern Europe and Asia (BlackBerry).
APT GROUPfinancialhigh
A ransomware that was active in 2018.
APT GROUPfinancialhigh
According to Symantec, this is a ransomware written in Golang and obfuscated with Gobfuscate. The source code for Knight (originally known as Cyclops) was offered for sale on underground forums in February 2024 after Knight’s developers decided to shut down their operation.
APT GROUPfinancialhigh
Trend Micro describes this as a Ransomware with possible ties to BlackMatter.
APT GROUPfinancialhigh
Ransomware.
T1123T1566T1125
JobCrypter
Technical ID: win.JobCrypter
MALWARE
Malware family tracked by Malpedia. ID: win.jobcrypter
APT GROUPfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
APT GROUP
Malware family tracked by Malpedia. ID: win.hermes
APT GROUP
Malware family tracked by Malpedia. ID: win.globe_ransom
Updated: 2017-02-15
View profile →
APT GROUPfinancialhigh
The GLOBAL GROUP is a Ransomware-as-a-Service program which emerged in June 2025. It is suspected to have ties to BlackLock and Mamona, due to code and infrastructure similarities. It's negotiation panel offers AI-driven negotiations to help the operators to engage with the victims.
APT GROUP
Malware family tracked by Malpedia. ID: win.gcman
APT GROUPfinancialhigh
According to SentinelOne, Fog Ransomware emerged in April of 2024 with operations targeting both Windows and Linux endpoints. Fog is a multi-pronged extortion operation, leveraging a TOR-based DLS to list victims and host data for those that refuse to comply with their ransom demands.
APT GROUP
Malware family tracked by Malpedia. ID: win.donex
APT GROUPfinancialhigh
DEVMAN is a ransomware which shares a large part of its codebase with DragonForce ransomware. It is highly probable that the group used a DragonForce ransomware build and simply changed the extension added to the encrypted files (from .dragonforce_encrypted to .devman). In one of the first observed samples, the ransom note still claimed to be part of the DragonForce Ransomware Cartel. The ransomware implements common features such as the deletion of ShadowCopies, and avoid encrypting files with some extensions present in a hard-coded list. The ransomware implements multiple encryption modes: - Full encryption - Header-only encryption - Custom encryption These modes allow the operator to choose between a quick or a strong encryption depending on the scenario. The ransomware also tries to connect to SMB folders. DEVMAN ransomware creates a temporary session under the following registry key: `HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000`. The use of the Restart Manager to bypass file locks and ensure encrypted access to active user session files. This capability seems to be a legacy of Conti ransomware, which inspired DragonForce and DEVMAN. As part of this legacy, the ransomware use a hard-coded mutex to prevent multiple instances from running in parallel.
APT GROUP
Malware family tracked by Malpedia. ID: win.darkbit
APT GROUP
According to HarfangLabs, Cyclops is a malware platform written in Go which dates back to December 2023, and that they believe has been deployed against targets in the Middle-East in 2024. Cyclops allows operators to execute arbitrary commands on the target’s file system, as well as pivot inside the infected network. Notably, Cyclops is controlled through a HTTP REST API which is exposed to operators within an SSH tunnel.
APT GROUP
Malware family tracked by Malpedia. ID: win.ctb_locker
APT GROUPfinancialhigh
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256 bit key and IV. * The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
APT GROUP
Malware family tracked by Malpedia. ID: win.crosslock
APT GROUP
Malware family tracked by Malpedia. ID: win.crazyhunter
APT GROUP
Malware family tracked by Malpedia. ID: win.cicada3301
APT GROUP
Malware family tracked by Malpedia. ID: win.catb
APT GROUP
Malware family tracked by Malpedia. ID: win.cactus
APT GROUP
Malware family tracked by Malpedia. ID: win.buhtrap
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.blacksnake