Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Triada
Technical ID: apk.triada
APT GROUP
Triada is a remote access trojan (RAT) malware that is used to compromise Android devices in order to steal confidential and sensitive information such as credit card numbers, passwords, bank account information, etc. It also provides a backdoor for attackers to include the device as part of a botnet and perform other malicious activities.
ToxicPanda
Technical ID: apk.toxic_panda
APT GROUPfinancialhigh
ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.
APT GROUP
Malware family identifying apk.titan. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying apk.tinyz. Origin and technical characteristics tracked via Malpedia.
Also known as: Catelites Android Bot • MarsElite Android Bot
TianySpy
Technical ID: apk.tianyspy
APT GROUP
According to Trend Micro, this malware appears to have been designed to steal credentials associated with membership websites of major Japanese telecommunication services.
ThiefBot
Technical ID: apk.thiefbot
APT GROUP
Malware family identifying apk.thiefbot. Origin and technical characteristics tracked via Malpedia.
TgToxic
Technical ID: apk.tgtoxic
APT GROUPfinancialhigh
According to Trend Micro, TgToxic has been used in an ongoing campaign that has been targeting Android users in Southeast Asia since July 2022. Goal of the campaign is to steal victims’ assets from finance and banking applications (such as cryptocurrency wallets, credentials for official bank apps on mobile, and money in deposit), via a banking trojan they named TgToxic (based on its special encrypted filename) embedded in multiple fake apps. While previously targeting users in Taiwan, Trend Micro observed the fraudulent activities and phishing lures targeting users from Thailand and Indonesia as of this writing. Users are advised to be wary of opening embedded links from unknown email and message senders, and to avoid downloading apps from third party platforms.
TemptingCedar Spyware
Technical ID: apk.tempting_cedar
APT GROUP
Tempting cedar spyware is an Android spyware campaign, active since at least 2015, that used social engineering via fake, attractive Facebook profiles to trick victims into downloading malware. The spyware was designed to steal a wide range of sensitive personal data.
TeleRAT
Technical ID: apk.telerat
APT GROUP
Malware family identifying apk.telerat. Origin and technical characteristics tracked via Malpedia.
TangleBot
Technical ID: apk.tangle_bot
APT GROUP
Malware family identifying apk.tangle_bot. Origin and technical characteristics tracked via Malpedia.
TalentRAT
Technical ID: apk.talent_rat
APT GROUP
Malware family identifying apk.talent_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: Assassin RAT
Switcher
Technical ID: apk.switcher
APT GROUP
Malware family identifying apk.switcher. Origin and technical characteristics tracked via Malpedia.
Svpeng
Technical ID: apk.svpeng
APT GROUPfinancialhigh
Svpeng is a malicious banking trojan targeting Android devices, and it poses a significant threat to both mobile users and the developers of mobile banking apps. Svpeng has been active since around 2013. It primarily targets Android users, and its main objective is to steal sensitive financial information, particularly login credentials and personal data related to banking and financial apps. Svpeng typically spreads through malicious apps, phishing campaigns, or drive-by downloads.
Sturnus
Technical ID: apk.sturnus
APT GROUPespionageadvanced
According to ThreatFabric, Sturnus is a privately operated Android banking trojan. This malware supports a broad range of fraud-related capabilities, including full device takeover. A key differentiator is its ability to bypass encrypted messaging. By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal.
The trojan can harvest banking credentials through convincing fake login screens that replicate legitimate banking apps. In addition, it provides attackers with extensive remote control, enabling them to observe all user activity, inject text without physical interaction, and even black out the device screen while executing fraudulent transactions in the background—without the victim’s knowledge.
APT GROUP
Malware family identifying apk.stealthmango. Origin and technical characteristics tracked via Malpedia.
StealthAgent
Technical ID: apk.stealthagent
APT GROUP
Malware family identifying apk.stealthagent. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.
Also known as: CypherRat
SpyMax
Technical ID: apk.spymax
APT GROUP
SpyMax is a popular Android surveillance tool. Its predecessor, SpyNote, was one of the most widely used spyware frameworks.
SpyFRPTunnel
Technical ID: apk.spyfrptunnel
APT GROUP
A sophisticated mobile surveillance implant operating as a Remote Control System (RCS). This malware family is characterized by a unique, multi-sided communication architecture that abandons traditional HTTP polling. Instead, it hybridizes Firebase Cloud Messaging (FCM) for asynchronous command signaling with Fast Reverse Proxy (FRP) to establish persistent, NAT-bypassing network tunnels, effectively turning the infected mobile device into a server accessible by the attacker.
Also known as: fvncBot
APT GROUP
Malware family identifying apk.spyc23. Origin and technical characteristics tracked via Malpedia.
SpyBanker
Technical ID: apk.spybanker
APT GROUP
Malware family identifying apk.spybanker. Origin and technical characteristics tracked via Malpedia.
S.O.V.A.
Technical ID: apk.sova
APT GROUP
Malware family identifying apk.sova. Origin and technical characteristics tracked via Malpedia.
SoumniBot
Technical ID: apk.soumnibot
APT GROUP
Malware family identifying apk.soumnibot. Origin and technical characteristics tracked via Malpedia.
SMSspy
Technical ID: apk.smsspy
APT GROUP
Malware family identifying apk.smsspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-09
View profile →SmsAgent
Technical ID: apk.smsagent
APT GROUP
SMSAgent appears as a game application, but silently performs malicious routines in the background. It attempts to download other potentially malicious files from a remote server and sends out SMS or MMS messages that places expensive charges on the user's bill.
Slocker
Technical ID: apk.slocker
APT GROUP
Slocker also known as jisut and pigetrl, is a screen locker that is distributed through telegram groups.
Also known as: Jisut • Simple Locker
Slempo
Technical ID: apk.slempo
APT GROUP
Malware family identifying apk.slempo. Origin and technical characteristics tracked via Malpedia.
Also known as: SlemBunk
Skygofree
Technical ID: apk.skygofree
APT GROUP
Malware family identifying apk.skygofree. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying apk.silkbean. Origin and technical characteristics tracked via Malpedia.
APT GROUP
SideWinder involved a fake VPN app for Android devices published on Google Play Store along with a custom tool that filters victims for better targeting.
Shopper
Technical ID: apk.shopper
APT GROUP
Shopper/LeifAccess is a malicious Android app that uses Android's AccessibilityService to secretly control the device. It installs apps, leaves fake reviews, opens ads, and even registers users on various platforms. Disguised as a system app, it collects personal and device information and sends it to remote servers. The malware was most active in late 2019, especially in Russia, Brazil, and India.
Also known as: LeifAccess
SharkBot
Technical ID: apk.sharkbot
APT GROUPfinancialhigh
SharkBot is a piece of malicious software targeting Android Operating Systems (OSes). It is designed to obtain and misuse financial data by redirecting and stealthily initiating money transfers. SharkBot is particularly active in Europe (United Kingdom, Italy, etc.), but its activity has also been detected in the United States.
Sauron Locker
Technical ID: apk.sauron_locker
APT GROUPfinancialhigh
An Android ransomware that locks the device, changes the wallpaper, and demands money in exchange for unlocking the phone.
Salvador Stealer
Technical ID: apk.salvador
APT GROUPfinancialhigh
According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number, Aadhaar number, PAN card details, Date of birth, and Net banking user ID and password. It uses Telegram as C2.
Rootnik
Technical ID: apk.rootnik
APT GROUP
Malware family identifying apk.rootnik. Origin and technical characteristics tracked via Malpedia.
Rogue
Technical ID: apk.rogue
APT GROUP
Malware family identifying apk.rogue. Origin and technical characteristics tracked via Malpedia.
Roaming Mantis
Technical ID: apk.roaming_mantis
APT GROUP
Malware family identifying apk.roaming_mantis. Origin and technical characteristics tracked via Malpedia.
Riltok
Technical ID: apk.riltok
APT GROUP
Malware family identifying apk.riltok. Origin and technical characteristics tracked via Malpedia.
Revive
Technical ID: apk.revive
APT GROUPfinancialhigh
According to PCrisk, Revive is the name of a banking Trojan targeting Android users (customers of a specific Spanish bank). It steals sensitive information. Cybercriminals use Revive to take ownership of online accounts using stolen login credentials. This malware abuses Accessibility Services to perform malicious activities.
Retefe
Technical ID: apk.retefe
APT GROUP
The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor. Further is a bank logo added to the specific Android app to trick users into thinking this is a legitimate app. Moreover, if the victim is not a real victim, the link to download the APK is not the malicious APK, but the real 'Signal Private Messenger' tool, hence the victim's phone doesn't get infected.