Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
KIVARS
Technical ID: elf.kivars
MALWARE
Malware family identifying elf.kivars. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-06
View profile →
kitty-socks5
Technical ID: elf.kitty_soks5
MALWARE
Malware family identifying elf.kitty_soks5. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-10
View profile →
Kinsing
Technical ID: elf.kinsing
MALWARE
Malware family identifying elf.kinsing. Origin and technical characteristics tracked via Malpedia.
Also known as: h2miner
Updated: 2024-10-21
View profile →
kfos
Technical ID: elf.kfos
MALWARE
Malware family identifying elf.kfos. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-06
View profile →
KEYPLUG
Technical ID: elf.keyplug
APT41
MALWARE
Malware family identifying elf.keyplug. Origin and technical characteristics tracked via Malpedia.
Also known as: ELFSHELF
Updated: 2026-01-28
View profile →
kerberods
Technical ID: elf.kerberods
Rocke
MALWARE
Malware family identifying elf.kerberods. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-18
View profile →
Kaiten
Technical ID: elf.kaiten
MALWARE
According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities. The trojan does not create any copies of itself. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Also known as: STD
Updated: 2023-03-27
View profile →
Kaiji
Technical ID: elf.kaiji
MALWARE
Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.
Updated: 2024-10-18
View profile →
KadNap
Technical ID: elf.kadnap
MALWARE
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.
Kaden
Technical ID: elf.kaden
MALWARE
Kaden is a DDoS botnet that is heavily based on Bashlite/Gafgyt. Next to DDoS capabilities it contains wiper functionality, which currently can not be triggerred (yet).
Updated: 2024-08-01
View profile →
J-Magic
Technical ID: elf.j_magic
MALWARE
According to Lumen, J-Magic is a variant of cd00r and passively scans for five different predefined parameters before activating. If any of these parameters or “magic packets” are received, the agent sends back a secondary challenge. Once that challenge is complete, J-magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or deploy malicious software.
Updated: 2025-01-24
View profile →
JenX
Technical ID: elf.jenx
MALWARE
Malware family identifying elf.jenx. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-02
View profile →
IZ1H9
Technical ID: elf.iz1h9
MALWARE
ccording to Fortinet, this is a Mirai-based DDoS botnet.
Updated: 2023-10-11
View profile →
IPStorm
Technical ID: elf.ipstorm
MALWARE
Malware family identifying elf.ipstorm. Origin and technical characteristics tracked via Malpedia.
Also known as: InterPlanetary Storm
Updated: 2023-11-22
View profile →
IoT Reaper
Technical ID: elf.iot_reaper
MALWARE
Malware family identifying elf.iot_reaper. Origin and technical characteristics tracked via Malpedia.
Also known as: IoTroop • Reaper • iotreaper
Updated: 2020-04-13
View profile →
elf.iocontrol
Cyber Av3ngers
MALWARE
IOControl is a Linux backdoor which targets ARM-based IoT and OT systems, which a particular focus on Fuel and Industrial Control Systems.
Also known as: OrpraCab • QueueCat
Interlock
Technical ID: elf.interlock
MALWAREfinancialhigh
According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024 conducting Big Game Hunting and double extortion campaigns.
Updated: 2025-04-17
View profile →
InsidiousGh0st
Technical ID: elf.insidiousgh0st
Unfading Sea Haze
MALWARE
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports Quic. Variants in C# and GO.
INC
Technical ID: elf.inc
Storm-0494Vanilla Tempest
MALWARE
Malware family identifying elf.inc. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-19
View profile →
Icnanker
Technical ID: elf.icnanker
MALWARE
Malware family identifying elf.icnanker. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-01
View profile →
iceFire
Technical ID: elf.icefire
MALWARE
Malware family identifying elf.icefire. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-11
View profile →
HyperSSL
Technical ID: elf.hyperssl
APT27
MALWARE
Malware family identifying elf.hyperssl. Origin and technical characteristics tracked via Malpedia.
Also known as: SysUpdate
Updated: 2025-06-20
View profile →
Hubnr
Technical ID: elf.hubnr
MALWARE
Malware family identifying elf.hubnr. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-14
View profile →
Horse Shell
Technical ID: elf.horseshell
MALWAREespionageadvanced
Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a custom MIPS32 ELF implant. HorseShell, the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities: * Remote shell: Execution of arbitrary shell commands on the infected router * File transfer: Upload and download files to and from the infected router. * SOCKS tunneling: Relay communication between different clients.
Updated: 2023-06-02
View profile →
Hive
Technical ID: elf.hive
MALWARE
Malware family identifying elf.hive. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-21
View profile →
Hipid
Technical ID: elf.hipid
BlackTech
MALWARE
Malware family identifying elf.hipid. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-19
View profile →
HinataBot
Technical ID: elf.hinata_bot
MALWARE
HinataBot is a Go-based DDoS-focused botnet. It was observed in the first quarter of 2023 targeting HTTP and SSH endpoints leveraging old vulnerabilities and weak credentials. Amongst those infection vectors are exploitation of the miniigd SOAP service on Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215), and exposed Hadoop YARN servers.
Updated: 2023-05-09
View profile →
Hide and Seek
Technical ID: elf.hideandseek
MALWARE
Malware family identifying elf.hideandseek. Origin and technical characteristics tracked via Malpedia.
Also known as: HNS
Updated: 2023-08-28
View profile →
HiddenWasp
Technical ID: elf.hiddenwasp
MALWARE
HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.
Updated: 2025-02-28
View profile →
HiatusRAT
Technical ID: elf.hiatus_rat
MALWARE
Lumen discovered this malware used in campaign targeting business-grade routers using a RAT they call HiatusRAT and a variant of tcpdump for traffic interception.
Updated: 2023-08-21
View profile →
HelloKitty
Technical ID: elf.hellokitty
MALWAREfinancialhigh
Linux version of the HelloKitty ransomware.
Updated: 2023-02-03
View profile →
HelloBot
Technical ID: elf.hellobot
MALWARE
Malware family identifying elf.hellobot. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-18
View profile →
HellDown
Technical ID: elf.helldown
MALWAREfinancialhigh
Ransomware.
Updated: 2025-01-24
View profile →
HeadCrab
Technical ID: elf.headcrab
MALWARE
Malware family identifying elf.headcrab. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-13
View profile →
Hand of Thief
Technical ID: elf.hand_of_thief
MALWARE
Malware family identifying elf.hand_of_thief. Origin and technical characteristics tracked via Malpedia.
Also known as: Hanthie
Updated: 2020-03-02
View profile →
HandyMannyPot
Technical ID: elf.handymannypot
MALWARE
Malware family identifying elf.handymannypot. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-04
View profile →
Hakai
Technical ID: elf.hakai
MALWARE
Malware family identifying elf.hakai. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-05
View profile →
Hajime
Technical ID: elf.hajime
MALWARE
Malware family identifying elf.hajime. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-23
View profile →
Haiduc
Technical ID: elf.haiduc
MALWARE
Malware family identifying elf.haiduc. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-11-08
View profile →
Hadooken
Technical ID: elf.hadooken
MALWARE
Malware family identifying elf.hadooken. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-21
View profile →
← PreviousPage 203 / 269Next →