Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
HabitsRAT
Technical ID: elf.habitsrat
MALWARE
Malware family identifying elf.habitsrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-09-10
View profile →
Gwisin
Technical ID: elf.gwisin
MALWARE
Malware family identifying elf.gwisin. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-27
View profile →
GRIMBOLT
Technical ID: elf.grimbolt
MALWARE
According to Mandiant, GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX. It provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload. It's unclear if the threat actor's replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response.
GreedyAntd
Technical ID: elf.greedyantd
Pacha Group
MALWARE
Malware family identifying elf.greedyantd. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-05-18
View profile →
GoTitan
Technical ID: elf.gotitan
MALWARE
GoTitan is a DDoS bot under development, which support ten different methods of launching distributed denial-of-service (DDoS) attacks: UDP, UDP HEX, TCP, TLS, RAW, HTTP GET, HTTP POST, HTTP HEAD, and HTTP PUT.
Updated: 2023-12-11
View profile →
GOSH
Technical ID: elf.gosh
MALWARE
Malware family identifying elf.gosh. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-18
View profile →
Gorilla
Technical ID: elf.gorilla
MALWARE
A DDoS botnet, based on Mirai.
Updated: 2024-11-25
View profile →
GOREVERSE
Technical ID: elf.goreverse
UNC5174
MALWARE
GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).
Updated: 2025-07-07
View profile →
GOREshell
Technical ID: elf.goreshell
MALWARE
Malware family identifying elf.goreshell. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-02
View profile →
Gomir
Technical ID: elf.gomir
Kimsuky
MALWARE
Malware family identifying elf.gomir. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-05-21
View profile →
gokcpdoor
Technical ID: elf.gokcpdoor
MALWAREespionageadvanced
According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in Japan. This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
Updated: 2024-12-13
View profile →
Godlua
Technical ID: elf.godlua
MALWARE
Malware family identifying elf.godlua. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-02
View profile →
GobRAT
Technical ID: elf.gobrat
MALWARE
Malware family identifying elf.gobrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-30
View profile →
Glupteba Proxy
Technical ID: elf.glupteba_proxy
MALWARE
ARM32 SOCKS proxy, written in Go, used in the Glupteba campaign.
Updated: 2022-03-28
View profile →
Gitpaste-12
Technical ID: elf.gitpaste12
MALWARE
Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT devices. It uses GitHub and Pastebin as dead drop C2 locations.
Updated: 2023-05-21
View profile →
GhostPenguin
Technical ID: elf.ghostpenguin
MALWARE
Malware family identifying elf.ghostpenguin. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-12-11
View profile →
Gaganode
Technical ID: elf.gaganode
MALWARE
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
Updated: 2025-12-08
View profile →
FritzFrog
Technical ID: elf.fritzfrog
MALWARE
Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. It is a worm which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk.
Updated: 2024-03-25
View profile →
FontOnLake
Technical ID: elf.fontonlake
MALWARE
This family utilizes custom modules allowing for remote access, credential harvesting (e.g. by modifying sshd) and proxy usage. It comes with a rootkit as well.
Updated: 2021-10-11
View profile →
Fodcha
Technical ID: elf.fodcha
MALWARE
Malware used to run a DDoS botnet.
Updated: 2022-11-01
View profile →
floodor
Technical ID: elf.floodor
MALWARE
Malware family identifying elf.floodor. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-12
View profile →
Flodrix
Technical ID: elf.flodrix
MALWARE
Malware family identifying elf.flodrix. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-23
View profile →
FireWood
Technical ID: elf.firewood
Gelsemium
MALWARE
Malware family identifying elf.firewood. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-09
View profile →
FinFisher
Technical ID: elf.finfisher
MALWARE
Malware family identifying elf.finfisher. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-08
View profile →
FINALDRAFT
Technical ID: elf.finaldraft
MALWARE
Malware family identifying elf.finaldraft. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-25
View profile →
FBot
Technical ID: elf.fbot
MALWARE
Malware family identifying elf.fbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-04
View profile →
Facefish
Technical ID: elf.facefish
MALWARE
Malware family identifying elf.facefish. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-07
View profile →
ext4
Technical ID: elf.ext4
MALWARE
Malware family identifying elf.ext4. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-15
View profile →
Exaramel
Technical ID: elf.exaramel
TeleBots
MALWARE
Malware family identifying elf.exaramel. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-25
View profile →
EwDoor
Technical ID: elf.ewdoor
MALWARE
Malware family identifying elf.ewdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-07
View profile →
EvilGnome
Technical ID: elf.evilgnome
Gamaredon Group
MALWARE
According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension. Legitimate extensions help to extend Linux functionality, but instead of a healthy boost in system functionality, EvilGnome begins spying on users with an array of functionalities uncommon for most Linux malware types.
Updated: 2025-02-28
View profile →
Evilginx
Technical ID: elf.evilginx
MALWARE
According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication.
Updated: 2024-03-18
View profile →
ESXiArgs
Technical ID: elf.esxi_args
MALWAREfinancialhigh
Ransomware used to target ESXi servers.
Updated: 2023-02-13
View profile →
Erebus
Technical ID: elf.erebus
MALWARE
Malware family identifying elf.erebus. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-10
View profile →
EnemyBot
Technical ID: elf.enemybot
MALWARE
According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks. This threat, which seems to be disseminated by the Keksec group, expanded its features by adding recent vulnerabilities discovered in 2022. It was designed to attack web servers, Android devices and content management systems (CMS) servers.
Updated: 2024-11-06
View profile →
Elevator
Technical ID: elf.elevator
MALWARE
Malware family identifying elf.elevator. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-12
View profile →
EdgeStepper
Technical ID: elf.edgestepper
PlushDaemon
MALWARE
According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network to a malicious DNS node. This allows the attackers to redirect the traffic from software updates to a hijacking node that serves instructions to the legitimate software to download a malicious update.
Updated: 2025-11-21
View profile →
Echobot
Technical ID: elf.echobot
MALWARE
The latest in this long line of Mirai scourges is a new variant named Echobot. Coming to life in mid-May, the malware was first described by Palo Alto Networks in a report published at the start of June, and then again in a report by security researchers from Akamai, in mid-June. When it was first spotted by Palo Alto Networks researchers in early June, Echobot was using exploits for 18 vulnerabilities. In the Akamai report, a week later, Echobot was at 26. https://www.zdnet.com/article/new-echobot-malware-is-a-smorgasbord-of-vulnerabilities
Updated: 2023-08-28
View profile →
Ebury
Technical ID: elf.ebury
MALWARE
This payload has been used to compromise kernel.org back in August of 2011 and has hit cPanel Support which in turn, has infected quite a few cPanel servers. It is a credential stealing payload which steals SSH keys, passwords, and potentially other credentials. This family is part of a wider range of tools which are described in detail in the operation windigo whitepaper by ESET.
Updated: 2025-01-23
View profile →
DriveSwitch
Technical ID: elf.drive_switch
MALWARE
According to Cisco Talos, DriveSwitch is a launcher for SilentRaid.
Updated: 2026-01-09
View profile →
← PreviousPage 204 / 269Next →