Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Singularity
Technical ID: elf.singularity
MALWARE
According to its author, this is a stealthy Linux Kernel Rootkit for modern kernels (6x).
Updated: 2026-01-21
View profile →
Sindoor
Technical ID: elf.sindoor
Operation C-Major
MALWARE
Malware family identifying elf.sindoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-01
View profile →
SimpleTea
Technical ID: elf.simpletea
Lazarus Group
MALWARE
SimpleTea for Linux is an HTTP(S) RAT. It was discovered in Q1 2023 as an instance of the Lazarus group's Operation DreamJob campaign for Linux. It was a payload downloaded in an execution chain which started with an HSBC-themed job offer lure. It shared the same C&C server as payloads from the 3CX incident around the same time. It’s an object-oriented project, which does not run on Linux distributions without a graphical user interface, and decrypts its configuration from /home/%user%/.config/apdl.cf using 0x7E as the XOR key. It uses AES-GCM for encryption and decryption of its network traffic. It supports basic commands that include operations on the victim’s filesystem, manipulation with its configuration, file exfiltration (via ZIP archives), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 16-bit integers, starting with the value 0x27C3. SimpleTea for Linux seems like an updated version of BadCall for Linux, rewritten from C to C++, as there are similarities in class names and function names between the two.
Also known as: PondRAT • SimplexTea
Updated: 2025-09-15
View profile →
Silex
Technical ID: elf.silex
MALWARE
Malware family identifying elf.silex. Origin and technical characteristics tracked via Malpedia.
Also known as: silexbot
Updated: 2019-11-22
View profile →
SilentRaid
Technical ID: elf.silent_raid
MALWARE
According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.
Also known as: MystRodX
Updated: 2026-01-09
View profile →
SideWalk
Technical ID: elf.sidewalk
MALWARE
Malware family identifying elf.sidewalk. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-02
View profile →
ShortLeash
Technical ID: elf.shortleash
MALWAREespionageadvanced
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.
Updated: 2025-06-24
View profile →
Shishiga
Technical ID: elf.shishiga
MALWARE
Malware family identifying elf.shishiga. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-01
View profile →
ShellBind
Technical ID: elf.shellbind
MALWARE
Malware family identifying elf.shellbind. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-31
View profile →
ShadowV2
Technical ID: elf.shadowv2
MALWARE
According to Fortinet, this is a Mirai fork propagating through multiple vulnerabilities. ShadowV2 had previously been observed targeting AWS EC2 instances in campaigns disclosed in September 2025.
Updated: 2025-11-28
View profile →
SEXi
Technical ID: elf.sexi
SEXi
MALWAREfinancialhigh
Ransomware, likely based on the leaked Babuk source code.
Also known as: Limpopo • Formosa • Socotra
Updated: 2024-12-11
View profile →
sedexp
Technical ID: elf.sedexp
MALWARE
Malware family identifying elf.sedexp. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-08-29
View profile →
SECONDDATE
Technical ID: elf.seconddate
MALWARE
Malware family identifying elf.seconddate. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-19
View profile →
SEASPY
Technical ID: elf.seaspy
MALWAREespionageadvanced
According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service. The malware is designed to listen to commands received from the Threat Actor’s Command-and-Control through TCP packets. When executed, the malware uses libpcap sniffer to monitor traffic for a magic packet on TCP port 25 (SMTP) and TCP port 587. It checks the network packet captured for a hard-coded string. When the right sequence of packet is captured, it establishes a TCP reverse shell to the C2 server for further exploitation. This allows the TA to execute arbitrary commands on the compromised system. The malware is based on an open-source backdoor program named "cd00r".
Updated: 2025-01-27
View profile →
SBIDIOT
Technical ID: elf.sbidiot
MALWARE
Malware family identifying elf.sbidiot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-03-07
View profile →
Satori
Technical ID: elf.satori
MALWARE
Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab. It uses exploit to exhibit worm-like behaviour to spread over ports 37215 and 52869 (CVE-2014-8361).
Updated: 2021-03-22
View profile →
SALTWATER
Technical ID: elf.saltwater
MALWARE
According to Mandiant, SALTWATER is a module for the Barracuda SMTP daemon (bsmtpd) that has backdoor functionality. SALTWATER can upload or download arbitrary files, execute commands, and has proxy and tunneling capabilities. The backdoor is implemented using hooks on the send, recv, close syscalls via the 3rd party kubo/funchook hooking library, and amounts to five components, most of which are referred to as "Channels" within the binary. In addition to providing backdoor and proxying capabilities, these components exhibit classic backdoor functionality.
Updated: 2025-01-27
View profile →
RushDrop
Technical ID: elf.rush_drop
MALWARE
According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid
Also known as: ChronosRAT
Updated: 2026-01-09
View profile →
RudeDevil
Technical ID: elf.rude_devil
MALWARE
Malware family identifying elf.rude_devil. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
Rshell
Technical ID: elf.rshell
Earth Berberoka
MALWARE
Malware family identifying elf.rshell. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-18
View profile →
Royal Ransom
Technical ID: elf.royal_ransom
MALWAREfinancialhigh
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.
Also known as: Royal_unix • Royal
Updated: 2025-07-28
View profile →
RotaJakiro
Technical ID: elf.rotajakiro
APT32
MALWARE
RotaJakiro is a stealthy Linux backdoor which remained undetected between 2018 and 2021. The malware uses rotating encryption to encrypt the resource information within the sample, and C2 communication, using a combination of AES, XOR, ROTATE encryption and ZLIB compression.
Updated: 2021-05-08
View profile →
Roboto
Technical ID: elf.roboto
MALWARE
P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows attackers to run malicious code with root privileges and take over older Webmin versions. Based on the Netlabs360 analysis, the botnet serves mainly 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs and four DDoS attack methods: ICMP Flood, HTTP Flood, TCP Flood, and UDP Flood.
Updated: 2019-12-09
View profile →
Rhysida
Technical ID: elf.rhysida
Vanilla Tempest
MALWARE
Malware family identifying elf.rhysida. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-20
View profile →
RHOMBUS
Technical ID: elf.rhombus
MALWARE
Malware family identifying elf.rhombus. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-25
View profile →
Rex
Technical ID: elf.rex
MALWARE
Malware family identifying elf.rex. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
REvil
Technical ID: elf.revil
MALWARE
ELF version of win.revil targeting VMware ESXi hypervisors.
Also known as: REvix
Updated: 2022-10-10
View profile →
reptile
Technical ID: elf.reptile
MALWARE
Malware family identifying elf.reptile. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-12
View profile →
Rekoobe
Technical ID: elf.rekoobe
MALWARE
A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers. The Trojan’s configuration data is stored in a file encrypted with XOR algorithm. Some versions have there configuration stored within the .data section using RC4 to encrypt the details. Configuration options include C2 IP and Port, as well as defence evasion details for changing the process name.
Updated: 2024-12-02
View profile →
RedAlert Ransomware
Technical ID: elf.red_alert
MALWAREfinancialhigh
Ransomware that targets Linux VMware ESXi servers. Encryption procedure uses the NTRUEncrypt public-key encryption algorithm.
Also known as: N13V
Updated: 2022-10-10
View profile →
RedXOR
Technical ID: elf.redxor
MALWARE
RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR. Believed to be developed by Chinese nation-state actors, this malware shows similarities to other malware associated with the Winnti umbrella threat group. RedXOR uses various techniques such as open-source LKM rootkits, Python pty shell, and network data encoding with XOR. It also employs persistence methods and communication with a Command and Control server over HTTP. The malware can execute various commands including system information collection, updates, shell commands, and network tunneling.
Updated: 2024-05-15
View profile →
RedTail
Technical ID: elf.redtail
MALWARE
RedTail is a cryptomining malware, which is based on the open-source XMRIG mining software. It is being spread via known vulnerabilities such as: - CVE-2024-3400 - CVE-2023-46805 - CVE-2024-21887 - CVE-2023-1389 - CVE-2022-22954 - CVE-2018-20062
Updated: 2025-02-28
View profile →
rbs_srv
Technical ID: elf.rbs_srv
MALWARE
Malware family identifying elf.rbs_srv. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-12
View profile →
rat_hodin
Technical ID: elf.rat_hodin
MALWARE
Malware family identifying elf.rat_hodin. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-12
View profile →
RaspberryPiBotnet
Technical ID: elf.raspberrypibotnet
MALWARE
Malware family identifying elf.raspberrypibotnet. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-17
View profile →
RapperBot
Technical ID: elf.rapper_bot
MALWARE
A Mirai derivate bruteforcing SSH servers.
Updated: 2025-09-09
View profile →
RansomExx2
Technical ID: elf.ransomexx2
MALWARE
According to IBM Security X-Force, this is a new but functionally very similar version of RansomExx, fully rewritten in Rust and internally referred to as RansomExx2.
Updated: 2024-01-08
View profile →
RansomEXX
Technical ID: elf.ransomexx
GOLD DUPONT
MALWARE
According to SentineOne, RansomEXX (aka Defray, Defray777), a multi-pronged extortion threat, has been observed in the wild since late 2020. RansomEXX is associated with attacks against the Texas Department of Transportation, Groupe Atlantic, and several other large enterprises. There are Windows and Linux variants of this malware family, and they are known for their limited and exclusive targeting.
Also known as: Defray777
Updated: 2024-01-08
View profile →
Rakos
Technical ID: elf.rakos
MALWARE
Malware family identifying elf.rakos. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-09-01
View profile →
RagnarLocker
Technical ID: elf.ragnarlocker
MALWARE
Malware family identifying elf.ragnarlocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-18
View profile →
← PreviousPage 200 / 269Next →