Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
DreamBus
Technical ID: elf.dreambus
MALWARE
Malware family identifying elf.dreambus. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-21
View profile →
DoubleFantasy
Technical ID: elf.doublefantasy
Equation Group
MALWARE
Malware family identifying elf.doublefantasy. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-05
View profile →
Doki
Technical ID: elf.doki
MALWARE
Malware family identifying elf.doki. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-29
View profile →
Dofloo
Technical ID: elf.dofloo
MALWARE
Dofloo (aka AESDDoS) is a popular malware used to create large scale botnets that can launch DDoS attacks and load cryptocurrency miners to the infected machines.
Also known as: AESDDoS
Updated: 2026-01-27
View profile →
DISGOMOJI
Technical ID: elf.disgomoji
MALWARE
Malware family identifying elf.disgomoji. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-21
View profile →
Derusbi
Technical ID: elf.derusbi
MALWARE
Malware family identifying elf.derusbi. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-30
View profile →
Denonia
Technical ID: elf.denonia
MALWARE
Cado discovered this malware, written in Go and targeting AWS Lambda environments.
Updated: 2022-08-08
View profile →
Decoy Dog RAT
Technical ID: elf.decoy_dog
MALWARE
Malware family identifying elf.decoy_dog. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-15
View profile →
DEADBOLT
Technical ID: elf.deadbolt
MALWAREfinancialhigh
DEADBOLT is a linux ransomware written in Go, targeting QNAP NAS devices worldwide. The files are encrypted with AES128 encryption and will have the .deadbolt extension appended to file names.
Updated: 2023-05-11
View profile →
ddoor
Technical ID: elf.ddoor
MALWARE
Malware family identifying elf.ddoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
DDG
Technical ID: elf.ddg
MALWARE
First activity observed in October 2017. DDG is a botnet with P2P capability that is targeting crypto currency mining (Monero).
Updated: 2023-05-15
View profile →
DarkRadiation
Technical ID: elf.dark_radiation
MALWARE
Malware family identifying elf.dark_radiation. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-23
View profile →
DarkSide
Technical ID: elf.darkside
MALWARE
Malware family identifying elf.darkside. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-19
View profile →
Dark Nexus
Technical ID: elf.darknexus
MALWARE
Malware family identifying elf.darknexus. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-05
View profile →
DarkCracks
Technical ID: elf.darkcracks
MALWARE
A sophisticated payload delivery and upgrade framework, discovered in 2024. DarkCracks exploits compromised GLPI and WordPress sites to function as Downloaders and C2 servers.
Updated: 2024-09-23
View profile →
Dark
Technical ID: elf.dark
MALWARE
Mirai variant exploiting CVE-2021-20090 and CVE2021-35395 for spreading.
Also known as: Dark.IoT
Updated: 2022-06-15
View profile →
Dacls
Technical ID: elf.dacls
MALWARE
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control infected computers remotely. Research shows that this malware is tied to Lazarus Group (a group of cyber criminals) and targets Linux and the Windows Operating System. Typically, cyber criminals use RATs to steal sensitive, confidential information, infect systems with other malware, and so on. In any case, no RAT is harmless and should be uninstalled immediately.
Updated: 2023-07-24
View profile →
CyclopsBlink
Technical ID: elf.cyclops_blink
MALWARE
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink deployment also appears indiscriminate and widespread. The actor has so far primarily deployed Cyclops Blink to WatchGuard and ASUS devices, but it is likely that Sandworm would be capable of compiling the malware for other architectures and firmware.
Updated: 2022-12-12
View profile →
CronRAT
Technical ID: elf.cronrat
MALWARE
A malware written in Bash that hides in the Linux calendar system on February 31st. Observed in relation to Magecart attacks.
Updated: 2021-11-29
View profile →
Cr1ptT0r
Technical ID: elf.cr1ptt0r
MALWARE
Malware family identifying elf.cr1ptt0r. Origin and technical characteristics tracked via Malpedia.
Also known as: CriptTor
Updated: 2019-03-20
View profile →
Cpuminer
Technical ID: elf.cpuminer
MALWARE
This was observed to be pushed by IoT malware, abusing devices for LiteCoin and BitCoin mining.
Updated: 2021-06-16
View profile →
corona
Technical ID: elf.corona
MALWARE
Malware family identifying elf.corona. Origin and technical characteristics tracked via Malpedia.
Conti
Technical ID: elf.conti
MALWAREfinancialhigh
Ransomware
Also known as: Conti Locker
Updated: 2025-06-04
View profile →
ConnectBack
Technical ID: elf.connectback
MALWARE
ConnectBack malware is a type of malicious software designed to establish unauthorized connections from an infected system to a remote server. Once a victim's device is compromised, ConnectBack creates a covert channel for communication, allowing the attacker to remotely control and gather sensitive information from the compromised system.
Also known as: Getshell
Updated: 2023-06-19
View profile →
CMS8000 Backdoor
Technical ID: elf.cms8000_backdoor
MALWARE
According to CISA, this is an implant found in firmware for the Contec CMS8000, a patient monitor used by the Healthcare and Public Health sector. An embedded backdoor function with a hard-coded IP address and functionality that enables patient data spillage was identified.
Updated: 2025-02-11
View profile →
Cloud Snooper
Technical ID: elf.cloud_snooper
MALWARE
Malware family identifying elf.cloud_snooper. Origin and technical characteristics tracked via Malpedia.
Also known as: Snoopy
Updated: 2022-01-28
View profile →
Clop
Technical ID: elf.clop
MALWAREfinancialhigh
ELF version of clop ransomware.
Also known as: Cl0p
Updated: 2026-01-12
View profile →
Chisel
Technical ID: elf.chisel
MALWAREfinancialhigh
Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP. It is available across platforms and written in Go. While benign in itself, Chisel has been utilized by multiple threat actors. It was for example observed by SentinelOne during a PYSA ransomware campaign to achieve persistence and used as backdoor. Github: https://github.com/jpillora/chisel
Updated: 2022-04-25
View profile →
Chapro
Technical ID: elf.chapro
MALWARE
Malware family identifying elf.chapro. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
Chaos
Technical ID: elf.chaos
MALWARE
Multi-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji.
Updated: 2022-12-14
View profile →
Chalubo
Technical ID: elf.chalubo
MALWARE
Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua. Variants exist for multiple architectures and it incorporates code from XorDDoS and Mirai.
Also known as: ChaChaDDoS
Updated: 2024-09-13
View profile →
Cetus
Technical ID: elf.cetus
MALWARE
Malware family identifying elf.cetus. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-31
View profile →
Cephei
Technical ID: elf.cephei
MALWARE
Malware family identifying elf.cephei. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-11
View profile →
CDRThief
Technical ID: elf.cdrthief
MALWARE
Malware family identifying elf.cdrthief. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-15
View profile →
CDorked
Technical ID: elf.cdorked
MALWARE
This is in the same family as eBury, Calfbot, and is also likely related to DarkLeech
Also known as: CDorked.A
Updated: 2018-07-23
View profile →
cd00r
Technical ID: elf.cd00r
MALWARE
A backdoor for UNIX operating systems that implements knocking as authentication method.
Updated: 2025-01-24
View profile →
Capoae
Technical ID: elf.capoae
MALWARE
XMRig-based mining malware written in Go.
Updated: 2021-09-19
View profile →
Caligula
Technical ID: elf.caligula
MALWARE
According to Avast Decoded, Caligula is an IRC multiplatform bot that allows to perform DDoS attacks. It is written in Go and distributed in ELF files targeting Intel 32/64bit code, as well as ARM 32bit and PowerPC 64bit. It is based on the Hellabot open source project.
Updated: 2022-07-15
View profile →
Caja
Technical ID: elf.caja
APT32
MALWARE
Linux malware cross-compiled for x86, MIPS, ARM. XOR encoded strings, 13 commands supported for its C&C, including downloading, file modification and execution and ability to run shell commands.
Updated: 2022-11-15
View profile →
Bvp47
Technical ID: elf.bvp47
Equation Group
MALWARE
Pangu Lab discovered this backdoor during a forensic investigation in 2013. They refer to related incidents as "Operation Telescreen".
Updated: 2022-09-19
View profile →
← PreviousPage 205 / 269Next →