Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
r2r2
Technical ID: elf.r2r2
MALWARE
Malware family identifying elf.r2r2. Origin and technical characteristics tracked via Malpedia.
QUIETEXIT
Technical ID: elf.quietexit
MALWARE
Mandiant observed this backdoor being observed by UNC3524. It is based on the open-source Dropbear SSH source code.
QSnatch
Technical ID: elf.qsnatch
MALWARE
The malware infects QNAP NAS devices, is persisting via various mechanisms and resists cleaning by preventing firmware updates and interfering with QNAP MalwareRemover. The malware steals passwords and hashes
QNAPCrypt
Technical ID: elf.qnapcrypt
MALWAREfinancialhigh
The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences:
1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint.
2. Every victim is provided with a different, unique Bitcoin wallet—this could help the attackers avoid being traced.
3. Once a victim is compromised, the malware requests a wallet address and a public RSA key from the command and control server (C&C) before file encryption.
Also known as: eCh0raix
Qilin
Technical ID: elf.qilin
MALWAREfinancialhigh
Qilin ransomware, initially observed in July 2022 under the name “Agenda,” operates on a Ransomware-as-a-Service (RaaS) model. This model allows core developers to provide their malicious software and infrastructure to affiliates in exchange for a percentage of the profits generated from attacks. The name “Qilin” references a Chinese mythological creature symbolizing power and prosperity, a fitting metaphor for the group’s perceived influence and financial objectives. Despite the Chinese name, the group is linked to Russian-speaking cybercriminals, often recruiting affiliates on Russian-language forums and notably excluding Commonwealth of Independent States (CIS) countries from its targets.
PWNLNX
Technical ID: elf.pwnlnx
MALWARE
Malware family identifying elf.pwnlnx. Origin and technical characteristics tracked via Malpedia.
pupy
Technical ID: elf.pupy
MALWARE
Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python. Pupy can be loaded from various loaders, including PE EXE, reflective DLL, Linux ELF, pure python, powershell and APK. Most of the loaders bundle an embedded python runtime, python library modules in source/compiled/native forms as well as a flexible configuration. They bootstrap a python runtime environment mostly in-memory for the later stages of pupy to run in. Pupy can communicate using various transports, migrate into processes, load remote python code, python packages and python C-extensions from memory.
PUMAKIT
Technical ID: elf.pumakit
MALWARE
According to Elastic, PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with command-and-control servers.
The rootkit component, referenced by the malware authors as “PUMA", employs an internal Linux function tracer (ftrace) to hook 18 different syscalls and several kernel functions, enabling it to manipulate core system behaviors. Unique methods are used to interact with PUMA, including using the rmdir() syscall for privilege escalation and specialized commands for extracting configuration and runtime information.
Key functionalities of the kernel module include privilege escalation, hiding files and directories, concealing itself from system tools, anti-debugging measures, and establishing communication with command-and-control (C2) servers.
There is also an accompanying userland SO rootkit internally referred to as Kitsune.
Also known as: PUMA • Kitsune
PumaBot
Technical ID: elf.pumabot
MALWARE
Malware family identifying elf.pumabot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Unit 42 describes this as a malware used by Rocke Group that deploys an XMRig miner.
Prometei
Technical ID: elf.prometei
MALWARE
Malware family identifying elf.prometei. Origin and technical characteristics tracked via Malpedia.
PrivetSanya
Technical ID: elf.privet_sanya
MALWARE
Black Lotus Labs identified malware for the Windows Subsystem for Linux (WSL). Mostly written in Python but compiled as Linux ELF files.
PRISM
Technical ID: elf.prism
MALWARE
Malware family identifying elf.prism. Origin and technical characteristics tracked via Malpedia.
Also known as: waterdrop
Poseidon
Technical ID: elf.poseidon
MALWARE
Part of Mythic C2, written in Golang.
PolarEdge
Technical ID: elf.polaredge
MALWARE
According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family, but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB) to facilitate offensive cyber operations.
MALWARE
Malware family identifying elf.plead. Origin and technical characteristics tracked via Malpedia.
Plague
Technical ID: elf.plague
MALWARE
According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access.
PITSOCK
Technical ID: elf.pitsock
MALWARE
According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.
PITHOOK
Technical ID: elf.pithook
MALWARE
According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.
PITFUEL
Technical ID: elf.pitfuel
MALWARE
According to Mandiant, this is a SparkGateway plugin that loads LITTLELAMB.WOOLTEA through JNI.
Pink
Technical ID: elf.pink
MALWARE
A botnet with P2P and centralized C&C capabilities.
MALWARE
Malware family identifying elf.pingpull. Origin and technical characteristics tracked via Malpedia.
PigmyGoat
Technical ID: elf.pigmy_goat
MALWARE
Malware family identifying elf.pigmy_goat. Origin and technical characteristics tracked via Malpedia.
PG_MEM
Technical ID: elf.pg_mem
MALWARE
Malware family identifying elf.pg_mem. Origin and technical characteristics tracked via Malpedia.
Persirai
Technical ID: elf.persirai
MALWARE
Malware family identifying elf.persirai. Origin and technical characteristics tracked via Malpedia.
PerlBot
Technical ID: elf.perlbot
MALWARE
Malware family identifying elf.perlbot. Origin and technical characteristics tracked via Malpedia.
Also known as: ShellBot • DDoS Perl IrcBot
perfctl
Technical ID: elf.perfctl
MALWARE
Malware family identifying elf.perfctl. Origin and technical characteristics tracked via Malpedia.
Also known as: perfcc
MALWARE
Malware family identifying elf.penquin_turla. Origin and technical characteristics tracked via Malpedia.
pbot
Technical ID: elf.pbot
MALWARE
P2P botnet derived from the Mirai source code.
P2Pinfect
Technical ID: elf.p2pinfect
MALWARE
P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown. Written in Rust, it is compatible with Windows and Linux, including a MIPS variant for Linux based routers and IoT devices. It is capable of brute forcing SSH logins and exploiting Redis servers in order to propagate itself both to random IPs on the internet and to hosts it can find references to in files present on the infected system.
p0sT5n1F3r
Technical ID: elf.p0st5n1f3r
MALWARE
According to Yarix digital security, this is a malware that allows to sniff on HTTPS traffic, implemented as Apache module.
Owari
Technical ID: elf.owari
MALWARE
Mirai variant by actor "Anarchy" that used CVE-2017-17215 in July 2018 to compromise 18,000+ devices.
OrBit
Technical ID: elf.orbit
MALWARE
According to stormshield, Orbit is a two-stage malware that appeared in July 2022, discovered by Intezer lab. Acting as a stealer and backdoor on 64-bit Linux systems, it consists of an executable acting as a dropper and a dynamic library.
NOTROBIN
Technical ID: elf.notrobin
MALWARE
FireEye states that NOTROBIN is a utility written in Go 1.10 and compiled to a 64-bit ELF binary for BSD systems. It periodically scans for and deletes files matching filename patterns and content characteristics. The purpose seems to be to block exploitation attempts against the CVE-2019-19781 vulnerability; however, FireEye believes that NOTROBIN provides backdoor access to the compromised system.
Also known as: remove_bds
MALWAREespionageadvanced
According to Black Lotus Labs, Nosedive is a custom variation of the Mirai implant that is supported on all major SOHO and IoT architectures (e.g. MIPS, ARM, SuperH, PowerPC, etc.). Nosedive implants are typically deployed from Tier 2 payload servers in the Raptor Train infrastructure through a unique URL encoding scheme and domain injection method. Nosedive droppers use this method to request payloads for specific C2s by encoding the requested C2 domain and joining it with a unique "key" that identifies the bot and the target architecture of the compromised device (e.g. MIPS, ARM, etc.), which is then injected into the Nosedive implant payload that is deployed to the Tier 1 node. Once deployed, Nosedive runs in-memory only and allows the operators to execute commands, upload and download files, and run DDoS attacks on compromised devices.
The malware and its associated droppers are memory-resident only and deleted from disk. This, in addition to anti-forensics techniques employed on these devices including the obfuscation of running process names, compromising devices through a multi-stage infection chain, and killing remote management processes, makes detection and forensics much more difficult.
Nood RAT
Technical ID: elf.noodrat
MALWARE
Malware family identifying elf.noodrat. Origin and technical characteristics tracked via Malpedia.
NoaBot
Technical ID: elf.noabot
MALWARE
Malware family identifying elf.noabot. Origin and technical characteristics tracked via Malpedia.
NiuB
Technical ID: elf.niub
MALWARE
Golang-based RAT that offers execution of shell commands and download+run capability.
Nimbo-C2
Technical ID: elf.nimbo_c2
MALWARE
According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework. The agent currently supports Windows x64 and Linux. It's written in Nim, with some usage of .NET (by dynamically loading the CLR to the process).
MALWARE
Malware family identifying elf.ngioweb. Origin and technical characteristics tracked via Malpedia.