Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Nextcry
Technical ID: elf.nextcry
MALWAREfinancialhigh
Ransomware used against Linux servers.
Updated: 2019-11-17
View profile →
Mumblehard
Technical ID: elf.mumblehard
MALWARE
Malware family identifying elf.mumblehard. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-11
View profile →
MrBlack
Technical ID: elf.mrblack
MALWARE
MrBlack, first identified in May 2014 by Russian security firm Dr. Web, is a botnet that targets Linux OS and is designed to conduct distributed denial-of-service (DDoS) attacks. In May 2015, Incapsula clients suffered a large-scale DDoS attack which the company attributed to network traffic generated by tens of thousands of small office/home office (SOHO) routers infected with MrBlack. This massive botnet spans over 109 countries, especially in Thailand and Brazil. MrBlack scans for and infects routers that have not had their default login credentials changed and that allow remote access to HTTP and SSH via port 80 and port 22, respectively. One of the most impacted router brands is Ubiquiti, a U.S.-based firm that provides bulk network hub solutions for internet service providers to lease to their customers. Once a vulnerable router is compromised and MrBlack is injected into the system, a remote server is contacted and system information from the device is transmitted. This allows the host server to receive commands in order to perform different types of DDoS attacks, download and execute files, and terminate processes.
Also known as: AESDDoS • Dofloo
Updated: 2023-08-31
View profile →
Mozi
Technical ID: elf.mozi
MALWARE
Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.
Updated: 2024-11-12
View profile →
Moose
Technical ID: elf.moose
MALWARE
Malware family identifying elf.moose. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-03-10
View profile →
MooBot
Technical ID: elf.moobot
MALWARE
Malware family identifying elf.moobot. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-17
View profile →
Monti
Technical ID: elf.monti
MALWAREfinancialhigh
A ransomware, derived from the leaked Conti source code.
Updated: 2023-12-27
View profile →
Momentum
Technical ID: elf.momentum
MALWARE
Malware family identifying elf.momentum. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-29
View profile →
Mokes
Technical ID: elf.mokes
MALWARE
Malware family identifying elf.mokes. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-10-25
View profile →
Mirai
Technical ID: elf.mirai
MALWARE
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.
Also known as: Katana
Updated: 2026-01-14
View profile →
MINOCAT
Technical ID: elf.minocat
MALWARE
According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast Reverse Proxy (FRP) client that handles the actual tunneling.
Updated: 2026-01-19
View profile →
MiKey
Technical ID: elf.mikey
MALWARE
Malware family identifying elf.mikey. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-19
View profile →
Midrashim
Technical ID: elf.midrashim
MALWARE
A x64 ELF file infector with non-destructive payload.
Updated: 2021-01-21
View profile →
MESSAGETAP
Technical ID: elf.messagetap
APT41
MALWARE
MESSAGETAP is a 64-bit ELF data miner initially loaded by an installation script. It is designed to monitor and save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft.
Updated: 2022-08-30
View profile →
Melofee
Technical ID: elf.melofee
MALWARE
Malware family identifying elf.melofee. Origin and technical characteristics tracked via Malpedia.
Also known as: Mélofée
Updated: 2024-11-25
View profile →
Matryosh
Technical ID: elf.matryosh
MALWARE
Malware family identifying elf.matryosh. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-04
View profile →
Masuta
Technical ID: elf.masuta
Nexus Zeta
MALWARE
Masuta is a variant of Mirai that targets IoT devices, primarily routers, using dictionary attacks to target weak credentials. PureMasuta is a variant of Masuta that targets the EDB 38722 D-Link HNAP Bug.
Also known as: PureMasuta
Updated: 2025-06-11
View profile →
MASOL
Technical ID: elf.masol
Earth Estries
MALWARE
Malware family identifying elf.masol. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-28
View profile →
Manjusaka
Technical ID: elf.manjusaka
MALWARE
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
Updated: 2022-08-22
View profile →
LZRD
Technical ID: elf.lzrd
MALWARE
According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
Updated: 2025-05-20
View profile →
Luna
Technical ID: elf.luna
MALWAREfinancialhigh
ESXi encrypting ransomware written in Rust.
Updated: 2023-01-13
View profile →
Lootwodniw
Technical ID: elf.lootwodniw
Hellsing
MALWARE
Malware family identifying elf.lootwodniw. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-03
View profile →
Log Collector
Technical ID: elf.log_collector
MALWARE
Malware family identifying elf.log_collector. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-12-18
View profile →
Loerbas
Technical ID: elf.loerbas
MALWARE
Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
Updated: 2020-05-18
View profile →
LockBit
Technical ID: elf.lockbit
MALWARE
Malware family identifying elf.lockbit. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-02-03
View profile →
LittleDaemon
Technical ID: elf.little_daemon
PlushDaemon
MALWARE
According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates. It was observed in both DLL and executable versions, both of them 32-bit PEs. The main purpose of LittleDaemon is to communicate with the hijacking node to obtain the downloader that we call DaemonicLogistics. LittleDaemon does not establish persistence.
Updated: 2025-11-21
View profile →
LiquorBot
Technical ID: elf.liquorbot
MALWARE
BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has recently incorporated Monero cryptocurrency mining features. Interestingly, LiquorBot is written in Go (also known as Golang), which offers some programming advantages over traditional C-style code, such as memory safety, garbage collection, structural typing, and even CSP-style concurrency.
Updated: 2020-01-13
View profile →
Linodas
Technical ID: elf.linodas
MALWARE
Malware family identifying elf.linodas. Origin and technical characteristics tracked via Malpedia.
Also known as: XDealer • DinodasRAT
Updated: 2024-04-11
View profile →
LinkPro
Technical ID: elf.linkpro
MALWARE
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
Updated: 2025-11-03
View profile →
lilyofthevalley
Technical ID: elf.lilyofthevalley
MALWARE
Malware family identifying elf.lilyofthevalley. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-12
View profile →
LiLock
Technical ID: elf.lilock
MALWARE
Malware family identifying elf.lilock. Origin and technical characteristics tracked via Malpedia.
Also known as: Lilu • Lilocked
Updated: 2019-09-10
View profile →
Lightning Framework
Technical ID: elf.lightning
MALWARE
Malware family identifying elf.lightning. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-25
View profile →
LeetHozer
Technical ID: elf.leethozer
MALWARE
Malware family identifying elf.leethozer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-20
View profile →
Lady
Technical ID: elf.lady
MALWARE
Malware family identifying elf.lady. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-06
View profile →
Kuiper
Technical ID: elf.kuiper
MALWARE
Malware family identifying elf.kuiper. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-17
View profile →
Kubo Injector
Technical ID: elf.kubo_injector
MALWARE
According to the author if this open source project, this is a library for injecting a shared library into a Linux, Windows and MacOS process.
Updated: 2025-10-28
View profile →
KTLVdoor
Technical ID: elf.ktlv_door
Earth Lusca
MALWARE
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning.
Updated: 2024-09-13
View profile →
KrustyLoader
Technical ID: elf.krustyloader
MALWARE
ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.
Updated: 2025-12-08
View profile →
Krasue RAT
Technical ID: elf.krasue_rat
MALWARE
Malware family identifying elf.krasue_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-12
View profile →
Kobalos
Technical ID: elf.kobalos
MALWARE
Malware family identifying elf.kobalos. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-16
View profile →
← PreviousPage 202 / 269Next →