Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.sinowal
Malware family tracked by Malpedia. ID: win.simplefilemover
APT GROUP
Malware family tracked by Malpedia. ID: win.simda
APT GROUP
Malware family tracked by Malpedia. ID: win.siluhdur
Updated: 2018-07-24
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.silon
APT GROUP
Malware family tracked by Malpedia. ID: win.silent_sweeper
According to Mandiant, SILENTUPLOADER is an uploader written in MSIL that is dropped by DOSTEALER and is designed to work specifically in tandem with it. It checks for files in a specified folder every 30 seconds and uploads them to a remote server.
APT GROUP
Malware family tracked by Malpedia. ID: win.silentgh0st
APT GROUP
Malware family tracked by Malpedia. ID: win.sihost
APT GROUP
Malware family tracked by Malpedia. ID: win.sigloader
APT GROUP
Malware family tracked by Malpedia. ID: win.siggen6
Updated: 2016-12-28
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.siesta_graph
Malware family tracked by Malpedia. ID: win.sierras
APT GROUPfinancialhigh
Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
APT GROUPfinancialhigh
Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sidewalk
APT GROUP
Malware family tracked by Malpedia. ID: win.sidetwist
APT GROUP
Malware family tracked by Malpedia. ID: win.shylock
APT GROUP
Malware family tracked by Malpedia. ID: win.shurl0ckr
APT GROUP
Malware family tracked by Malpedia. ID: win.shurk
APT GROUP
Malware family tracked by Malpedia. ID: win.shrinklocker
APT GROUPespionageadvanced
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.
APT GROUPespionageadvanced
SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.
APT GROUP
Malware family tracked by Malpedia. ID: win.shimrat
APT GROUPfinancialhigh
Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.
APT GROUP
According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine. It uses the Dropbox API for C2 and data exfiltration.
APT GROUPfinancialhigh
PCRIsk states that ShellLocker is a ransomware-type virus developed using .NET framework. It was first discovered by Jakub Kroustek and is virtually identical to another ransomware virus called Exotic. Following infiltration, this virus encrypts stored data (video, audio, etc.) and renames encrypted files using the "[random_characters].L0cked" pattern (e.g., "sample.jpg" might be renamed to "gd&=AA0fgoi.L0cked"). Following successful encryption, ShellLocker opens a pop-up window containing ransom-demand message.
Malware family tracked by Malpedia. ID: win.shellclient
APT GROUP
According to Zscaler, SHEETCREEP is a lightweight backdoor written in C# that uses Google Sheets for C2 communication.
APT GROUPfinancialhigh
Kaspersky Labs observed Andariel to drop this ransomware in one case within a series of attacks carried out against targets in South Korea in April 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.sharp_rhino
APT GROUP
SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at runtime. SharPyShell supports only C# web applications that runs on .NET Framework >= 2.0 VB is not supported atm.
APT GROUP
According to its Github repository, SharpWMI is a C# implementation of various WMI functionality.
APT GROUP
Malware family tracked by Malpedia. ID: win.sharpstats
APT GROUP
The SharpStage backdoor is a .NET malware with backdoor capabilities. Its name is a derivative of the main activity class called “Stage_One”. SharpStage can take screenshots, run arbitrary commands and downloads additional payloads. It exfiltrates data from the infected machine to a dropbox account by implementing a dropbox client in its code. SharpStage was seen used by the Molerats group in targeted attacks in the middle east.
APT GROUP
This tool is made to simplify penetration testing of networks and to create a Swiss-army knife that is made for running on Windows which is often a requirement during insider threat simulation engagements.
APT GROUP
Malware family tracked by Malpedia. ID: win.sharpknot
APT GROUP
According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
APT GROUP
.NET reimplementation of Cobalt Strike beacon/stager
APT GROUP
Malware family tracked by Malpedia. ID: win.shareip