Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,718 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.thinmon
Malware family tracked by Malpedia. ID: win.theme_forest_rat
Malware family tracked by Malpedia. ID: win.thanatos_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.thanatos
APT GROUPfinancialhigh
TFlower is a new ransomware targeting mostly corporate networks discovered in August, 2019. It is reportedly installed on networks by attackers after they gain access via RDP. TFlower displays a console showing activity being performed by the ransomware when it encrypts a machine, further indicating that this ransomware is triggered by the attacker post compromise, similar to Samsam/Samas in terms of TTP. Once encryption is started, the ransomware will conduct a status report to an apparently hard-coded C2. Shadow copies are deleted and the Windows 10 repair environment is disabled by this ransomware. This malware also will terminate any running Outlook.exe process so that the mail files can be encrypted. This ransomware does not add an extention to encrypted files, but prepends the marker "*tflower" and what may be the encrypted encryption key for the file to each affected file. Once encryption is completed, another status report is sent to the C2 server.
APT GROUP
According to Cisco Talos, this is loader is written in Rust and was observed to stage Cobalt Strike Beacons and VShell.
APT GROUPfinancialhigh
According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers. Amongst other types of target files, it tries to infect typical gaming files: game saves, user profiles, recoded replays etc. That said, TeslaCrypt does not encrypt files that are larger than 268 MB. Recently,
APT GROUP
TerraTV is a custom DLL designed to hijack legit TeamViewer applications. It was discovered and documented by QuoINT. It has been attributed to Golden Chickens malware as a service group.
APT GROUP
According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email clients, web browsers, and file transfer utilities. Attributed to Golden Chickens.
APT GROUP
According to QuoINT TerraRecon is a reconnaissance tool, looking for a specific piece of hardware and software targeting retail and payment services sectors. Attributed to Golden Chickens.
APT GROUP
Malware family tracked by Malpedia. ID: win.terra_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.terrapreter
APT GROUPfinancialhigh
TerraLogger is a standalone keylogger malware developed by Golden Chickens, a financially motivated threat actor. It uses a common low-level keyboard hook to record keystrokes and writes the logs to local files. The malware is typically delivered as an OCX file and employs initial execution checks before proceeding. Upon execution, it opens a file handle to log keystrokes and implements its keylogger using a SetWindowsHookExA hook. Keystrokes are written to the open log file, with special characters handled accordingly. Five distinct TerraLogger samples were identified, reflecting minor updates and active development.
APT GROUPfinancial
Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including Starbucks.
Infra: 🔗 termiteuslbumdge2zmf📁 pqw3hepvky2pgyyv6dup📁 4xklh64cl2lymm6n5xyw+2 more
RLUpdated: 2026-08-04
View profile →
Malware family tracked by Malpedia. ID: win.terminator_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.tendyron_dropper
APT GROUP
According to Cyble, this is a stealer targeting several crypto currency wallets along browser data.
APT GROUP
Malware family tracked by Malpedia. ID: win.templedoor
APT GROUP
Malware family tracked by Malpedia. ID: win.tempedreve
Updated: 2016-04-20
View profile →
APT GROUPfinancialhigh
According to PCrisk, Tellyouthepass is one of many ransomware-type programs used to block access to files by encryption and keep them in this state unless a ransom is paid. The program renames all encrypted files by adding the ".locked" extension and creates a ransom message in a text file called "README.html". For example, "1.jpg" is renamed by Tellyouthepass to "1.jpg.locked". According to cyber criminals, this ransomware encrypts data using RSA-1024 and AES-256 cryptography algorithms.
APT GROUP
Malware family tracked by Malpedia. ID: win.telepowerbot
APT GROUP
Cisco Talos reports that this is a data exfiltration tool used by TA505.
APT GROUP
Malware family tracked by Malpedia. ID: win.telemiris
Malware family tracked by Malpedia. ID: win.telegram_grabber
APT GROUP
Malware family tracked by Malpedia. ID: win.teledoor
APT GROUP
Malware family tracked by Malpedia. ID: win.telebot
APT GROUP
According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
APT GROUP
According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
APT GROUP
Malware family tracked by Malpedia. ID: win.tefosteal
APT GROUP
TEARDROP is a memory only dropper that runs as a service, spawns a thread and reads from the file “gracious_truth.jpg”, which likely has a fake JPG header. Next it checks that HKU\SOFTWARE\Microsoft\CTF exists, decodes an embedded payload using a custom rolling XOR algorithm and manually loads into memory an embedded payload using a custom PE-like file format. TEARDROP does not have code overlap with any previously seen malware. FireEye believe that this was used to execute a customized Cobalt Strike BEACON.
APT GROUP
Malware family tracked by Malpedia. ID: win.teamspy
APT GROUP
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer. This is achieved by sideloading another DLL among the legit TeamViewer.
Updated: 2023-07-24
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.tdtess
APT GROUP
F-Secure described tDiscoverer (also known as HammerDuke) as interesting because it is written in .NET, and even more so because of its occasional use of Twitter as a C&C communication channel. Some HammerDuke variants only contain a hardcoded C&C server address from which they will retrieve commands, but other HammerDuke variants will first use a custom algorithm to generate a Twitter account name based on the current date. If the account exists, HammerDuke will then search for tweets from that account with links to image files that contain embedded commands for the toolset to execute.
APT GROUP
Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
According to Zscaler, Taurus is a stealer that surfaced in June 2020. It is being developed by the author(s) that previously created Predator the Thief. The name overlaps partly with the StealerOne / Terra* family (also aliased Taurus Loader) but appears to be a completely disjunct project.
APT GROUP
Malware family tracked by Malpedia. ID: win.tarsip
APT GROUPfinancial
targetcompany — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.tapaoux
Updated: 2018-05-03
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.tandfuy
Updated: 2018-07-24
View profile →