Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
HabitsRAT
Technical ID: elf.habitsrat
MALWARE
Malware family identifying elf.habitsrat. Origin and technical characteristics tracked via Malpedia.
Gwisin
Technical ID: elf.gwisin
MALWARE
Malware family identifying elf.gwisin. Origin and technical characteristics tracked via Malpedia.
GRIMBOLT
Technical ID: elf.grimbolt
MALWARE
According to Mandiant, GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX. It provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload. It's unclear if the threat actor's replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response.
MALWARE
Malware family identifying elf.greedyantd. Origin and technical characteristics tracked via Malpedia.
GoTitan
Technical ID: elf.gotitan
MALWARE
GoTitan is a DDoS bot under development, which support ten different methods of launching distributed denial-of-service (DDoS) attacks: UDP, UDP HEX, TCP, TLS, RAW, HTTP GET, HTTP POST, HTTP HEAD, and HTTP PUT.
GOSH
Technical ID: elf.gosh
MALWARE
Malware family identifying elf.gosh. Origin and technical characteristics tracked via Malpedia.
Gorilla
Technical ID: elf.gorilla
MALWARE
A DDoS botnet, based on Mirai.
MALWARE
GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).
GOREshell
Technical ID: elf.goreshell
MALWARE
Malware family identifying elf.goreshell. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.gomir. Origin and technical characteristics tracked via Malpedia.
gokcpdoor
Technical ID: elf.gokcpdoor
MALWAREespionageadvanced
According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in Japan. This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
Godlua
Technical ID: elf.godlua
MALWARE
Malware family identifying elf.godlua. Origin and technical characteristics tracked via Malpedia.
GobRAT
Technical ID: elf.gobrat
MALWARE
Malware family identifying elf.gobrat. Origin and technical characteristics tracked via Malpedia.
Glupteba Proxy
Technical ID: elf.glupteba_proxy
MALWARE
ARM32 SOCKS proxy, written in Go, used in the Glupteba campaign.
Gitpaste-12
Technical ID: elf.gitpaste12
MALWARE
Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT devices. It uses GitHub and Pastebin as dead drop C2 locations.
GhostPenguin
Technical ID: elf.ghostpenguin
MALWARE
Malware family identifying elf.ghostpenguin. Origin and technical characteristics tracked via Malpedia.
Gaganode
Technical ID: elf.gaganode
MALWARE
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
FritzFrog
Technical ID: elf.fritzfrog
MALWARE
Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. It is a worm which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk.
FontOnLake
Technical ID: elf.fontonlake
MALWARE
This family utilizes custom modules allowing for remote access, credential harvesting (e.g. by modifying sshd) and proxy usage.
It comes with a rootkit as well.
Fodcha
Technical ID: elf.fodcha
MALWARE
Malware used to run a DDoS botnet.
floodor
Technical ID: elf.floodor
MALWARE
Malware family identifying elf.floodor. Origin and technical characteristics tracked via Malpedia.
Flodrix
Technical ID: elf.flodrix
MALWARE
Malware family identifying elf.flodrix. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.firewood. Origin and technical characteristics tracked via Malpedia.
FinFisher
Technical ID: elf.finfisher
MALWARE
Malware family identifying elf.finfisher. Origin and technical characteristics tracked via Malpedia.
FINALDRAFT
Technical ID: elf.finaldraft
MALWARE
Malware family identifying elf.finaldraft. Origin and technical characteristics tracked via Malpedia.
FBot
Technical ID: elf.fbot
MALWARE
Malware family identifying elf.fbot. Origin and technical characteristics tracked via Malpedia.
Facefish
Technical ID: elf.facefish
MALWARE
Malware family identifying elf.facefish. Origin and technical characteristics tracked via Malpedia.
ext4
Technical ID: elf.ext4
MALWARE
Malware family identifying elf.ext4. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying elf.exaramel. Origin and technical characteristics tracked via Malpedia.
EwDoor
Technical ID: elf.ewdoor
MALWARE
Malware family identifying elf.ewdoor. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension. Legitimate extensions help to extend Linux functionality, but instead of a healthy boost in system functionality, EvilGnome begins spying on users with an array of functionalities uncommon for most Linux malware types.
Evilginx
Technical ID: elf.evilginx
MALWARE
According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication.
ESXiArgs
Technical ID: elf.esxi_args
MALWAREfinancialhigh
Ransomware used to target ESXi servers.
Erebus
Technical ID: elf.erebus
MALWARE
Malware family identifying elf.erebus. Origin and technical characteristics tracked via Malpedia.
EnemyBot
Technical ID: elf.enemybot
MALWARE
According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks. This threat, which seems to be disseminated by the Keksec group, expanded its features by adding recent vulnerabilities discovered in 2022. It was designed to attack web servers, Android devices and content management systems (CMS) servers.
Elevator
Technical ID: elf.elevator
MALWARE
Malware family identifying elf.elevator. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network to a malicious DNS node. This allows the attackers to redirect the traffic from software updates to a hijacking node that serves instructions to the legitimate software to download a malicious update.
Echobot
Technical ID: elf.echobot
MALWARE
The latest in this long line of Mirai scourges is a new variant named Echobot. Coming to life in mid-May, the malware was first described by Palo Alto Networks in a report published at the start of June, and then again in a report by security researchers from Akamai, in mid-June.
When it was first spotted by Palo Alto Networks researchers in early June, Echobot was using exploits for 18 vulnerabilities. In the Akamai report, a week later, Echobot was at 26.
https://www.zdnet.com/article/new-echobot-malware-is-a-smorgasbord-of-vulnerabilities
Ebury
Technical ID: elf.ebury
MALWARE
This payload has been used to compromise kernel.org back in August of 2011 and has hit cPanel Support which in turn, has infected quite a few cPanel servers. It is a credential stealing payload which steals SSH keys, passwords, and potentially other credentials.
This family is part of a wider range of tools which are described in detail in the operation windigo whitepaper by ESET.
DriveSwitch
Technical ID: elf.drive_switch
MALWARE
According to Cisco Talos, DriveSwitch is a launcher for SilentRaid.