Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
ACBackdoor
Technical ID: elf.acbackdoor
MALWARE
A Linux backdoor that was apparently ported to Windows. This entry represents the Linux version. This version appears to have been written first and the Windows version was ported later, without full functionality. The Linux version offers persistence as well as some process manipulation techniques, though both versions apparently offer the ability to access the command line and execute programs as well as self-update.
Abyss Locker
Technical ID: elf.abyss
MALWAREfinancialhigh
Family based on HelloKitty Ransomware. Encryption algorithm changed from AES to ChaCha. Sample seems to be unpacked.
Also known as: elf.hellokitty
Abcbot
Technical ID: elf.abcbot
MALWARE
Abcbot is a modular Go-based botnet and malware that propagates via exploits and brute force attempts. The botnet was observed launching DDoS attacks, perform internet scans, and serve web pages. It is probably linked to Xanthe-based clipjacking campaign.
APT GROUP
Malware family identifying asp.unidentified_001. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-04-18
View profile →APT GROUP
According to Unit42, TwoFace is a two-staged (loader+payload) webshell, written in C# and meant to run on webservers with ASP.NET. The author of the initial loader webshell included legitimate and expected content that will be displayed if a visitor accesses the shell in a browser, likely to remain undetected. The code in the loader webshell includes obfuscated variable names and the embedded payload is encoded and encrypted. To interact with the loader webshell, the threat actor uses HTTP POST requests to the compromised server.
The secondary webshell, which we call the payload, is embedded within the loader in encrypted form and contains additional functionality that we will discuss in further detail. When the threat actor wants to interact with the remote server, they provide data that the loader will use to modify a decryption key embedded within the loader that will be in turn used to decrypt the embedded TwoFace payload. Commands supported by the payload are execution of programs, up-, download and deletion of files and capability to manipulate MAC timestamps.
Also known as: Minion • HighShell • HyperShell • SEASHARPEE
APT GROUP
According to Microsoft, this is a web shell, written in ASPX supporting C#, carrying sufficient yet rudimentary functionality to support the following secondary activities: uploading and downloading files, running shell commands, opening a port (default port is set to TCP 250).
Ztorg
Technical ID: apk.ztorg
APT GROUP
Malware family identifying apk.ztorg. Origin and technical characteristics tracked via Malpedia.
Also known as: Qysly
ZooPark
Technical ID: apk.zoopark
APT GROUP
Malware family identifying apk.zoopark. Origin and technical characteristics tracked via Malpedia.
Zen
Technical ID: apk.zen
APT GROUP
Malware family identifying apk.zen. Origin and technical characteristics tracked via Malpedia.
Zanubis
Technical ID: apk.zanubis
APT GROUP
According to cyware, Zanubis malware pretends to be a malicious PDF application. The threat actor uses it as a key to decrypt responses received from the C2 server.
YellYouth
Technical ID: apk.yellyouth
APT GROUP
Malware family identifying apk.yellyouth. Origin and technical characteristics tracked via Malpedia.
XRat
Technical ID: apk.xrat
APT GROUP
Malware family identifying apk.xrat. Origin and technical characteristics tracked via Malpedia.
XploitSPY
Technical ID: apk.xploitspy
APT GROUP
Malware family identifying apk.xploitspy. Origin and technical characteristics tracked via Malpedia.
xHelper
Technical ID: apk.xhelper
APT GROUP
Xhelper is a very persistent malware that can reinstall itself after factory reset, Xhelper downloads malicious apps and displays annoying ads.
Xenomorph
Technical ID: apk.xenomorph
APT GROUPfinancialhigh
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.
Xbot
Technical ID: apk.xbot
APT GROUP
Malware family identifying apk.xbot. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying apk.wyrmspy. Origin and technical characteristics tracked via Malpedia.
Also known as: AndroidControl
Wroba
Technical ID: apk.wroba
APT GROUPfinancialhigh
According to Avira, this is a banking trojan targeting Japan.
WolfRAT
Technical ID: apk.wolf_rat
APT GROUP
Malware family identifying apk.wolf_rat. Origin and technical characteristics tracked via Malpedia.
WireX
Technical ID: apk.wirex
APT GROUP
Malware family identifying apk.wirex. Origin and technical characteristics tracked via Malpedia.
Vultur
Technical ID: apk.vultur
APT GROUP
Malware family identifying apk.vultur. Origin and technical characteristics tracked via Malpedia.
Also known as: Vulture
vo1d
Technical ID: apk.vo1d
APT GROUP
According to Xlab, this malware is used to compromise Android TVs and set-top boxes, and its corresponding botnet had more than 1 million nodes observed via sinkholing (Jan 2025).
Viper RAT
Technical ID: apk.viper_rat
APT GROUP
Malware family identifying apk.viper_rat. Origin and technical characteristics tracked via Malpedia.
VINETHORN
Technical ID: apk.vinethorn
APT GROUP
According to Mandiant, VINETHORN is an Android malware family capable of a wide range of backdoor functionality. It can steal system information, read SMS inboxes, send SMS messages, access contact lists and call histories, record audio and video, and track device location via GPS.
vamp
Technical ID: apk.vamp
APT GROUP
Related to the micropsia windows malware and also sometimes named micropsia.
Also known as: android.micropsia
VajraSpy
Technical ID: apk.vajraspy
APT GROUP
Malware family identifying apk.vajraspy. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to Google, a Chrome reconnaissance payload
Unidentified APK 008
Technical ID: apk.unidentified_008
APT GROUPfinancialhigh
Android malware distributed through fake shopping websites targeting Malaysian users, targeting banking information.
Unidentified 007 (ARMAAN RAT)
Technical ID: apk.unidentified_007
APT GROUP
According to Cyble, this is an Android application that pretends to be the legitimate application for the Army Mobile Aadhaar App Network (ARMAAN), intended to be used by Indian army personnel. The application was customized to include RAT functionality.
Unidentified APK 006
Technical ID: apk.unidentified_006
APT GROUPfinancialhigh
Information stealer posing as a fake banking app, targeting Korean users.
APT GROUP
Malware family identifying apk.unidentified_005. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-24
View profile →APT GROUP
According to Check Point Research, this is a RAT that is disguised as a set of dating apps like "GrixyApp", "ZatuApp", "Catch&See", including dedicated websites to conceal their malicious purpose.
Unidentified APK 002
Technical ID: apk.unidentified_002
APT GROUP
Malware family identifying apk.unidentified_002. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-31
View profile →Unidentified APK 001
Technical ID: apk.unidentified_001
APT GROUP
Malware family identifying apk.unidentified_001. Origin and technical characteristics tracked via Malpedia.
UltimaSMS
Technical ID: apk.ultima_sms
APT GROUP
Malware family identifying apk.ultima_sms. Origin and technical characteristics tracked via Malpedia.
TsarBot
Technical ID: apk.tsarbot
APT GROUPespionageadvanced
According to Cyble, this is a banking trojan that targets over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce apps. The malware spreads via phishing sites masquerading as legitimate financial platforms and is installed through a dropper disguised as Google Play Services. It uses overlay attacks to steal banking credentials, credit card details, and login credentials by displaying fake login pages over legitimate apps. TsarBot can record and remotely control the screen, executing fraud by simulating user actions such as swiping, tapping, and entering credentials while hiding malicious activities using a black overlay screen. It captures device lock credentials using a fake lock screen to gain full control. TsarBot communicates with its C&C server using WebSocket across multiple ports to receive commands, send stolen data, and dynamically execute on-device fraud.
Triout
Technical ID: apk.triout
APT GROUP
Bitdefender described Triout as a Android spyware, which appears to act as a framework for building extensive surveillance capabilities into seemingly benign applications. Found bundled with a repackaged app, the spyware’s surveillance capabilities involve hiding its presence on the device, recording phone calls, logging incoming text messages, recoding videos, taking pictures and collecting GPS coordinates, then broadcasting all of that to an attacker-controlled C&C (command and control) server.
Updated: 2018-10-23
View profile →TrickMo
Technical ID: apk.trickmo
APT GROUPfinancialhigh
TrickMo is an advanced banking trojan for Android. Starting out as a companion malware to TrickBot in 2020, it first became a standalone banking trojan by addition of overlay attacks in 2021 and was later (2024) upgraded with remote control capabilities for on-device fraud. The continued development and progressively improved obfuscation suggests an active Threat Actor.