Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
ResidentBat
Technical ID: apk.residentbat
APT GROUP
Malware family identifying apk.residentbat. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-27
View profile →
RemRAT
Technical ID: apk.remrat
APT GROUP
Malware family identifying apk.remrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-25
View profile →
Remo
Technical ID: apk.remo
APT GROUP
Malware family identifying apk.remo. Origin and technical characteristics tracked via Malpedia.
Also known as: PlayPraetor
Updated: 2025-07-28
View profile →
RedAlert2
Technical ID: apk.redalert2
APT GROUPfinancialhigh
RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps. The malware works by overlaying a login screen with a fake display that sends the credentials to a C2 server. The malware also has the ability to block incoming calls from banks, to prevent the victim of being notified. As a distribution vector RedAlert 2 uses third-party app stores and imitates real Android apps like Viber, Whatsapp or fake Adobe Flash Player updates.
Updated: 2019-02-15
View profile →
Raxir
Technical ID: apk.raxir
APT GROUP
Malware family identifying apk.raxir. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
RatOn
Technical ID: apk.rat_on
APT GROUP
According to ThreatFabric, this RAT can perform NFC relay attacks and has Automated Transfer ystem (ATS) capabilities
Updated: 2025-09-09
View profile →
RatMilad
Technical ID: apk.ratmilad
APT GROUP
RatMilad, a newly discovered Android spyware, has been stealing data from mobile devices in the Middle East. The malware is spread through links on social media and pretends to be applications for services like VPN and phone number spoofing. Unwary users download these trojan applications and grant access to malware.
Updated: 2022-11-09
View profile →
Rana
Technical ID: apk.rana
APT39
APT GROUP
Malware family identifying apk.rana. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-08
View profile →
RambleOn
Technical ID: apk.rambleon
APT GROUP
Malware family identifying apk.rambleon. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-27
View profile →
Rafel RAT
Technical ID: apk.rafelrat
APT GROUP
Malware family identifying apk.rafelrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-06-05
View profile →
Princess
Technical ID: apk.princess
APT GROUP
Malware family identifying apk.princess. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-24
View profile →
Premier RAT
Technical ID: apk.premier_rat
APT GROUP
Malware family identifying apk.premier_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-01-23
View profile →
Fake Pornhub
Technical ID: apk.pornhub
APT GROUP
Malware family identifying apk.pornhub. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
X-Agent
Technical ID: apk.popr-d30
APT28
APT GROUP
Malware family identifying apk.popr-d30. Origin and technical characteristics tracked via Malpedia.
Also known as: Popr-d30
Updated: 2017-01-09
View profile →
Podec
Technical ID: apk.podec
APT GROUP
Malware family identifying apk.podec. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-11-07
View profile →
PlainGnome
Technical ID: apk.plain_gnome
Gamaredon Group
APT GROUP
According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s installed. The code of PlainGnome’s second stage payload evolved significantly from January 2024 through at least October. In particular, PlainGnome’s developers shifted to using Jetpack WorkManager classes to handle data exfiltration, which eases development and maintenance of related code. In addition, WorkManager allows for specifying execution conditions. For example, PlainGnome only exfiltrates data from victim devices when the device enters an idle state. This mechanism is probably intended to reduce the chance of a victim noticing the presence of PlainGnome on their device. As opposed to the minimalist first (installer) stage, the second stage carries out all surveillance functionality and relies on 38 permissions.
Updated: 2024-12-13
View profile →
PjobRAT
Technical ID: apk.pjobrat
APT GROUP
Malware family identifying apk.pjobrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-20
View profile →
PixStealer
Technical ID: apk.pixstealer
APT GROUP
Malware family identifying apk.pixstealer. Origin and technical characteristics tracked via Malpedia.
Also known as: BrazKing
Updated: 2021-11-18
View profile →
PixPirate
Technical ID: apk.pixpirate
APT GROUPfinancialhigh
According to PCrisk, The PixPirate is a dangerous Android banking Trojan that has the capability to carry out ATS (Automatic Transfer System) attacks. This allows threat actors to automatically transfer funds through the Pix Instant Payment platform, which numerous Brazilian banks use. In addition to launching ATS attacks, PixPirate can intercept and delete SMS messages, prevent the uninstallation process, and carry out malvertising attacks.
Updated: 2024-12-16
View profile →
PINEFLOWER
Technical ID: apk.pineflower
APT GROUP
According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing system inform information, logging and recording phone calls, initiating audio recordings, reading SMS inboxes and sending SMS messages. The malware also has features to facilitate device location tracking, deleting, downloading, and uploading files, reading connectivity state, speed, and activity, and toggling Bluetooth, Wi-Fi, and mobile data settings.
Updated: 2023-11-17
View profile →
PhoneSpy
Technical ID: apk.phonespy
APT GROUP
According to Zimperium, PhoneSpy is a spyware aimed at South Korean residents with Android devices.
Updated: 2021-11-17
View profile →
Phoenix
Technical ID: apk.phoenix
APT GROUP
Malware family identifying apk.phoenix. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-29
View profile →
PhantomLance
Technical ID: apk.phantomlance
APT32
APT GROUP
Malware family identifying apk.phantomlance. Origin and technical characteristics tracked via Malpedia.
Also known as: PWNDROID1
Updated: 2022-08-28
View profile →
pcTattletale
Technical ID: apk.pctattletale
APT GROUP
According to TechCrunch, this is a remote surveillance app that allows ordinary consumers to buy software capable of tracking people and their data without their knowledge. Once physically planted on a person’s phone or computer (usually with knowledge of the victim’s passcode or login), the app would continuously upload a copy of the victim’s information, including messages, photos, and location data, to pcTattletale’s servers and make the data accessible to whoever planted the spyware.
Updated: 2026-01-08
View profile →
PackChat
Technical ID: apk.packchat
APT GROUP
Malware family identifying apk.packchat. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-18
View profile →
Oscorp
Technical ID: apk.oscorp
APT GROUP
Malware family identifying apk.oscorp. Origin and technical characteristics tracked via Malpedia.
Also known as: UBEL
Updated: 2021-07-27
View profile →
OmniRAT
Technical ID: apk.omnirat
APT GROUP
Malware family identifying apk.omnirat. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-27
View profile →
Nexus
Technical ID: apk.nexus
APT GROUP
Malware family identifying apk.nexus. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-12
View profile →
MysteryBot
Technical ID: apk.mysterybot
APT GROUPfinancialhigh
MysteryBot is an Android banking Trojan with overlay capabilities with support for Android 7/8 but also provides other features such as key logging and ransomware functionality.
Updated: 2018-06-19
View profile →
Mudwater
Technical ID: apk.mudwater
MuddyWater
APT GROUP
Malware family identifying apk.mudwater. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-23
View profile →
MOrder RAT
Technical ID: apk.morder_rat
APT GROUP
Malware family identifying apk.morder_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-12
View profile →
MoqHao
Technical ID: apk.moqhao
Yanbian Gang
APT GROUPfinancialhigh
MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based mobile threat that is associated with a financially motivated Chinese group called Roaming Mantis. The malware claims to be the default SMS application and has dropper and banker capabilities.
Also known as: Shaoye • Wroba • XLoader
Updated: 2025-02-25
View profile →
Monokle
Technical ID: apk.monokle
APT GROUP
Monokle is a sophisticated mobile surveillanceware that possesses remote access trojan (RAT) functionality, advanced data exfiltration techniques as well as the ability to install an attacker-specified certificate to the trusted certificates on an infected device that would allow for man-in-the-middle (MITM) attacks. According to Lookout researchers, It is believed to be developed by Special Technology Center (STC), which is a Russian defense contractor sanctioned by the U.S. Government in connection to alleged interference in the 2016 US presidential elections.
Updated: 2025-02-03
View profile →
MobileOrder
Technical ID: apk.mobile_order
Scarlet Mimic
APT GROUP
Check Point has identified samples of this spyware being distributed since 2015. No samples were found on Google Play, meaning they were likely through other channels like social engineering.
Updated: 2022-09-26
View profile →
Meterpreter
Technical ID: apk.meterpreter
APT GROUP
Malware family identifying apk.meterpreter. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-24
View profile →
Medusa
Technical ID: apk.medusa
APT GROUPfinancialhigh
According to ThreatFabric, this is an Android banking trojan under active development as of July 2020. It is using TCP for C&C communication and targets Turkish banks.
Also known as: Gorgona
Updated: 2024-06-28
View profile →
MazarBot
Technical ID: apk.mazarbot
APT GROUP
Malware family identifying apk.mazarbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-19
View profile →
MasterFred
Technical ID: apk.masterfred
APT GROUP
According to heimdal, MasterFred malware, this is designed as an Android trojan that makes use of false login overlays to target not only Netflix, Instagram, and Twitter users, but also bank customers. The hackers’ goal is to steal credit card information.
Also known as: Brox
Updated: 2023-05-15
View profile →
Marcher
Technical ID: apk.marcher
APT GROUP
Malware family identifying apk.marcher. Origin and technical characteristics tracked via Malpedia.
Also known as: ExoBot
Updated: 2025-02-19
View profile →
Mandrake
Technical ID: apk.mandrake
APT GROUP
Malware family identifying apk.mandrake. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-14
View profile →
← PreviousPage 209 / 269Next →