Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Nextcry
Technical ID: elf.nextcry
MALWAREfinancialhigh
Ransomware used against Linux servers.
Mumblehard
Technical ID: elf.mumblehard
MALWARE
Malware family identifying elf.mumblehard. Origin and technical characteristics tracked via Malpedia.
MrBlack
Technical ID: elf.mrblack
MALWARE
MrBlack, first identified in May 2014 by Russian security firm Dr. Web, is a botnet that targets Linux OS and is designed to conduct distributed denial-of-service (DDoS) attacks. In May 2015, Incapsula clients suffered a large-scale DDoS attack which the company attributed to network traffic generated by tens of thousands of small office/home office (SOHO) routers infected with MrBlack. This massive botnet spans over 109 countries, especially in Thailand and Brazil.
MrBlack scans for and infects routers that have not had their default login credentials changed and that allow remote access to HTTP and SSH via port 80 and port 22, respectively. One of the most impacted router brands is Ubiquiti, a U.S.-based firm that provides bulk network hub solutions for internet service providers to lease to their customers. Once a vulnerable router is compromised and MrBlack is injected into the system, a remote server is contacted and system information from the device is transmitted. This allows the host server to receive commands in order to perform different types of DDoS attacks, download and execute files, and terminate processes.
Also known as: AESDDoS • Dofloo
Mozi
Technical ID: elf.mozi
MALWARE
Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.
Moose
Technical ID: elf.moose
MALWARE
Malware family identifying elf.moose. Origin and technical characteristics tracked via Malpedia.
MooBot
Technical ID: elf.moobot
MALWARE
Malware family identifying elf.moobot. Origin and technical characteristics tracked via Malpedia.
Monti
Technical ID: elf.monti
MALWAREfinancialhigh
A ransomware, derived from the leaked Conti source code.
Momentum
Technical ID: elf.momentum
MALWARE
Malware family identifying elf.momentum. Origin and technical characteristics tracked via Malpedia.
Mokes
Technical ID: elf.mokes
MALWARE
Malware family identifying elf.mokes. Origin and technical characteristics tracked via Malpedia.
Mirai
Technical ID: elf.mirai
MALWARE
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.
Also known as: Katana
MINOCAT
Technical ID: elf.minocat
MALWARE
According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast Reverse Proxy (FRP) client that handles the actual tunneling.
MiKey
Technical ID: elf.mikey
MALWARE
Malware family identifying elf.mikey. Origin and technical characteristics tracked via Malpedia.
Midrashim
Technical ID: elf.midrashim
MALWARE
A x64 ELF file infector with non-destructive payload.
MALWARE
MESSAGETAP is a 64-bit ELF data miner initially loaded by an installation script. It is designed to monitor and save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft.
Melofee
Technical ID: elf.melofee
MALWARE
Malware family identifying elf.melofee. Origin and technical characteristics tracked via Malpedia.
Also known as: Mélofée
Matryosh
Technical ID: elf.matryosh
MALWARE
Malware family identifying elf.matryosh. Origin and technical characteristics tracked via Malpedia.
MALWARE
Masuta is a variant of Mirai that targets IoT devices, primarily routers, using dictionary attacks to target weak credentials. PureMasuta is a variant of Masuta that targets the EDB 38722 D-Link HNAP Bug.
Also known as: PureMasuta
MALWARE
Malware family identifying elf.masol. Origin and technical characteristics tracked via Malpedia.
Manjusaka
Technical ID: elf.manjusaka
MALWARE
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
LZRD
Technical ID: elf.lzrd
MALWARE
According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
Luna
Technical ID: elf.luna
MALWAREfinancialhigh
ESXi encrypting ransomware written in Rust.
MALWARE
Malware family identifying elf.lootwodniw. Origin and technical characteristics tracked via Malpedia.
Log Collector
Technical ID: elf.log_collector
MALWARE
Malware family identifying elf.log_collector. Origin and technical characteristics tracked via Malpedia.
Loerbas
Technical ID: elf.loerbas
MALWARE
Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
LockBit
Technical ID: elf.lockbit
MALWARE
Malware family identifying elf.lockbit. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates. It was observed in both DLL and executable versions, both of them 32-bit PEs. The main purpose of LittleDaemon is to communicate with the hijacking node to obtain the downloader that we call DaemonicLogistics. LittleDaemon does not establish persistence.
LiquorBot
Technical ID: elf.liquorbot
MALWARE
BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has recently incorporated Monero cryptocurrency mining features. Interestingly, LiquorBot is written in Go (also known as Golang), which offers some programming advantages over traditional C-style code, such as memory safety, garbage collection, structural typing, and even CSP-style concurrency.
Linodas
Technical ID: elf.linodas
MALWARE
Malware family identifying elf.linodas. Origin and technical characteristics tracked via Malpedia.
Also known as: XDealer • DinodasRAT
LinkPro
Technical ID: elf.linkpro
MALWARE
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
lilyofthevalley
Technical ID: elf.lilyofthevalley
MALWARE
Malware family identifying elf.lilyofthevalley. Origin and technical characteristics tracked via Malpedia.
LiLock
Technical ID: elf.lilock
MALWARE
Malware family identifying elf.lilock. Origin and technical characteristics tracked via Malpedia.
Also known as: Lilu • Lilocked
Lightning Framework
Technical ID: elf.lightning
MALWARE
Malware family identifying elf.lightning. Origin and technical characteristics tracked via Malpedia.
LeetHozer
Technical ID: elf.leethozer
MALWARE
Malware family identifying elf.leethozer. Origin and technical characteristics tracked via Malpedia.
Lady
Technical ID: elf.lady
MALWARE
Malware family identifying elf.lady. Origin and technical characteristics tracked via Malpedia.
Kuiper
Technical ID: elf.kuiper
MALWARE
Malware family identifying elf.kuiper. Origin and technical characteristics tracked via Malpedia.
Kubo Injector
Technical ID: elf.kubo_injector
MALWARE
According to the author if this open source project, this is a library for injecting a shared library into a Linux, Windows and MacOS process.
MALWARE
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning.
KrustyLoader
Technical ID: elf.krustyloader
MALWARE
ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.
Krasue RAT
Technical ID: elf.krasue_rat
MALWARE
Malware family identifying elf.krasue_rat. Origin and technical characteristics tracked via Malpedia.
Kobalos
Technical ID: elf.kobalos
MALWARE
Malware family identifying elf.kobalos. Origin and technical characteristics tracked via Malpedia.