Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
KIVARS
Technical ID: elf.kivars
MALWARE
Malware family identifying elf.kivars. Origin and technical characteristics tracked via Malpedia.
kitty-socks5
Technical ID: elf.kitty_soks5
MALWARE
Malware family identifying elf.kitty_soks5. Origin and technical characteristics tracked via Malpedia.
Kinsing
Technical ID: elf.kinsing
MALWARE
Malware family identifying elf.kinsing. Origin and technical characteristics tracked via Malpedia.
Also known as: h2miner
kfos
Technical ID: elf.kfos
MALWARE
Malware family identifying elf.kfos. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.keyplug. Origin and technical characteristics tracked via Malpedia.
Also known as: ELFSHELF
MALWARE
Malware family identifying elf.kerberods. Origin and technical characteristics tracked via Malpedia.
Kaiten
Technical ID: elf.kaiten
MALWARE
According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities. The trojan does not create any copies of itself. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Also known as: STD
Kaiji
Technical ID: elf.kaiji
MALWARE
Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.
KadNap
Technical ID: elf.kadnap
MALWARE
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.
Kaden
Technical ID: elf.kaden
MALWARE
Kaden is a DDoS botnet that is heavily based on Bashlite/Gafgyt. Next to DDoS capabilities it contains wiper functionality, which currently can not be triggerred (yet).
J-Magic
Technical ID: elf.j_magic
MALWARE
According to Lumen, J-Magic is a variant of cd00r and passively scans for five different predefined parameters before activating. If any of these parameters or “magic packets” are received, the agent sends back a secondary challenge. Once that challenge is complete, J-magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or deploy malicious software.
JenX
Technical ID: elf.jenx
MALWARE
Malware family identifying elf.jenx. Origin and technical characteristics tracked via Malpedia.
IZ1H9
Technical ID: elf.iz1h9
MALWARE
ccording to Fortinet, this is a Mirai-based DDoS botnet.
IPStorm
Technical ID: elf.ipstorm
MALWARE
Malware family identifying elf.ipstorm. Origin and technical characteristics tracked via Malpedia.
Also known as: InterPlanetary Storm
IoT Reaper
Technical ID: elf.iot_reaper
MALWARE
Malware family identifying elf.iot_reaper. Origin and technical characteristics tracked via Malpedia.
Also known as: IoTroop • Reaper • iotreaper
elf.iocontrol
Cyber Av3ngers
MALWARE
IOControl is a Linux backdoor which targets ARM-based IoT and OT systems, which a particular focus on Fuel and Industrial Control Systems.
Also known as: OrpraCab • QueueCat
Interlock
Technical ID: elf.interlock
MALWAREfinancialhigh
According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024 conducting Big Game Hunting and double extortion campaigns.
MALWARE
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports Quic.
Variants in C# and GO.
MALWARE
Malware family identifying elf.inc. Origin and technical characteristics tracked via Malpedia.
Icnanker
Technical ID: elf.icnanker
MALWARE
Malware family identifying elf.icnanker. Origin and technical characteristics tracked via Malpedia.
iceFire
Technical ID: elf.icefire
MALWARE
Malware family identifying elf.icefire. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.hyperssl. Origin and technical characteristics tracked via Malpedia.
Also known as: SysUpdate
Hubnr
Technical ID: elf.hubnr
MALWARE
Malware family identifying elf.hubnr. Origin and technical characteristics tracked via Malpedia.
Horse Shell
Technical ID: elf.horseshell
MALWAREespionageadvanced
Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a custom MIPS32 ELF implant. HorseShell, the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities:
* Remote shell: Execution of arbitrary shell commands on the infected router
* File transfer: Upload and download files to and from the infected router.
* SOCKS tunneling: Relay communication between different clients.
Hive
Technical ID: elf.hive
MALWARE
Malware family identifying elf.hive. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.hipid. Origin and technical characteristics tracked via Malpedia.
HinataBot
Technical ID: elf.hinata_bot
MALWARE
HinataBot is a Go-based DDoS-focused botnet. It was observed in the first quarter of 2023 targeting HTTP and SSH endpoints leveraging old vulnerabilities and weak credentials. Amongst those infection vectors are exploitation of the miniigd SOAP service on Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215), and exposed Hadoop YARN servers.
Hide and Seek
Technical ID: elf.hideandseek
MALWARE
Malware family identifying elf.hideandseek. Origin and technical characteristics tracked via Malpedia.
Also known as: HNS
HiddenWasp
Technical ID: elf.hiddenwasp
MALWARE
HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.
HiatusRAT
Technical ID: elf.hiatus_rat
MALWARE
Lumen discovered this malware used in campaign targeting business-grade routers using a RAT they call HiatusRAT and a variant of tcpdump for traffic interception.
HelloKitty
Technical ID: elf.hellokitty
MALWAREfinancialhigh
Linux version of the HelloKitty ransomware.
HelloBot
Technical ID: elf.hellobot
MALWARE
Malware family identifying elf.hellobot. Origin and technical characteristics tracked via Malpedia.
HellDown
Technical ID: elf.helldown
MALWAREfinancialhigh
Ransomware.
HeadCrab
Technical ID: elf.headcrab
MALWARE
Malware family identifying elf.headcrab. Origin and technical characteristics tracked via Malpedia.
Hand of Thief
Technical ID: elf.hand_of_thief
MALWARE
Malware family identifying elf.hand_of_thief. Origin and technical characteristics tracked via Malpedia.
Also known as: Hanthie
HandyMannyPot
Technical ID: elf.handymannypot
MALWARE
Malware family identifying elf.handymannypot. Origin and technical characteristics tracked via Malpedia.
Hakai
Technical ID: elf.hakai
MALWARE
Malware family identifying elf.hakai. Origin and technical characteristics tracked via Malpedia.
Hajime
Technical ID: elf.hajime
MALWARE
Malware family identifying elf.hajime. Origin and technical characteristics tracked via Malpedia.
Haiduc
Technical ID: elf.haiduc
MALWARE
Malware family identifying elf.haiduc. Origin and technical characteristics tracked via Malpedia.
Hadooken
Technical ID: elf.hadooken
MALWARE
Malware family identifying elf.hadooken. Origin and technical characteristics tracked via Malpedia.