Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.tampered_chef
APT GROUP
Malware family tracked by Malpedia. ID: win.taleret
APT GROUP
Malware family tracked by Malpedia. ID: win.taintedscribe
APT GROUP
[Taidoor](https://attack.mitre.org/groups/G0015) has been deprecated, as the only technique it was linked to was deprecated in ATT&CK v7.
Updated: 2026-08-04
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.tabmsgsql
APT GROUP
Malware family tracked by Malpedia. ID: win.t34loader
APT GROUP
Malware family tracked by Malpedia. ID: win.szribi
APT GROUP
Malware family tracked by Malpedia. ID: elf.systembc
APT GROUP
Malware family tracked by Malpedia. ID: win.sysscan
APT GROUP
Sysraw stealer got its name because at some point, it was started as "ZSysRaw\sysraw.exe". PDB strings suggest the name "Clipsa" though. First stage connects to /WPCoreLog/, the second one to /WPSecurity/. Its behavior suggest that it is an info stealer. It creates a rather large amount of files in a subdirectory (e.g. data) named "1?[-+].dat" and POSTs them.
APT GROUP
Malware family tracked by Malpedia. ID: win.syskit
APT GROUP
Malware family tracked by Malpedia. ID: elf.sysjoker
APT GROUP
Malware family tracked by Malpedia. ID: win.sysget
APT GROUP
SYSCON is a Remote Access Trojan used in a targeted champing against US government agencies. It has been recently observed in conjunction with CARROTBAT and CARROTBALL downloaders and it uses the File Transfer Protocol as Command and Control channel. Use of the family is attributed by Unit 42 to the Konni Group.
APT GROUP
Malware family tracked by Malpedia. ID: win.sys10
APT GROUP
Malware family tracked by Malpedia. ID: win.synth_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.synflooder
APT GROUP
According to Cyfirma, Sync-Scheduler is a dedicated document stealer that targets Word documents, Excel Spreadsheets, PowerPoint presentations, PDFs and ZIP compress files. The malware is written in C++ and equipped with anti-analysis and defense evasion techniques. It uses obfuscation in its code and terminates itself if it detects an analysis environment.
APT GROUP
Malware family tracked by Malpedia. ID: win.synccrypt
APT GROUPfinancial
SynAck is a sophisticated ransomware operation first spotted in 2017, known for using hybrid ECIES encryption and the Doppelganging process injection technique to evade detection; in August 2021 the group rebranded as El_Cometa, transitioning to a full RaaS model and releasing master decryption keys for prior victims.
Infra: 🔗 xqkz2rmrqkeqf6sjbrb4…
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.sykipot
APT GROUP
Malware family tracked by Malpedia. ID: win.sword
APT GROUP
According to ESET, this is a wiper written in Go, that was deployed against an Ukrainian organization on January 25th 2023 through Group Policy, which suggests that the attackers had taken control of the victim’s Active Directory environment.
APT GROUP
Malware family tracked by Malpedia. ID: win.swen
APT GROUP
Malware family tracked by Malpedia. ID: win.sweetspecter
APT GROUP
Malware family tracked by Malpedia. ID: win.swaet_rat
APT GROUP
According to Broadcom, SVCStealer is an information stealer written in C++, targeting devices running an windows operating system. It collects sensitive information from the infected device such as system information, credentials, cryptocurrency wallets, data stored in browsers, screenshots, data from messaging applications such as Telegram or VPN apps. The collected information is compressed into a .zip archive and extracted to botnet C2 servers.
APT GROUP
According to PCrisk, SVCReady collects information about the infected system such as username, computer name, time zone, computer manufacturer, BIOS, and firmware. Also, it gathers lists of running processes and installed software. SVCReady sends collected data to the C2 server. Additionally, SVCReady attempts to maintain its foothold on the system by creating a scheduled task.
APT GROUPfinancialhigh
According to PCrisk, Surtr is ransomware. Malware of this type encrypts files (and renames them) and generates a ransom note. Surtr appends the decryptmydata@mailfence.com email address and the ".SURT" extension to filenames.
APT GROUP
Malware family tracked by Malpedia. ID: win.suppobox
APT GROUP
Supper is a 64-bit Windows backdoor and tunnelling utility first observed in the wild in July 2024. This malware operates as both a Remote Access Trojan (RAT) and a SOCKS5 proxy, offering threat actors persistent access to infected systems and the ability to route arbitrary traffic through victim environments.
Once executed, it establishes a TCP connection to its primary C2 endpoint, i.e. hardcoded in the file, over port 443. A fallback mechanism allows the malware to retrieve alternate C2 IP addresses from an encoded file, %temp%/s01bafg, ensuring resilience in case the primary server is unavailable. The malware supports up to 16,384 concurrent sessions over a single TCP connection, each uniquely identified via a 16-bit session ID.
Communication begins with an unencrypted 300-byte handshake payload that includes a static bot identifier (0x00691155), system metadata (hostname, domain, OS version, integrity level), and a fixed flag. Following this, all network traffic is wrapped in a 12-byte obfuscated header and an encrypted payload (8 bytes) which consists of two encrypted IP addresses. The header is transformed using two hardcoded XOR keys: 0x4d4d4d4d4d4d4d4d and 0x4d4d4d4d. Payload encryption is performed with a non-standard, stateful XOR cipher, where each byte of the message is encrypted based on a calculated offset and a cycling key (xored with 0x4d4d4d4d) derived from the header.
It supports a range of C2 commands, including remote shell execution, session teardown, SOCKS5 proxy operations, self-deletion, and dynamic updating of fallback IPs. When executing commands, Supper spawns a hidden cmd.exe instance and forwards command outputs back to the C2 server after encryption. As a proxy, it accepts operator-specified connection requests, establishes TCP sessions to external targets, and forwards data between the target and the attacker, all managed under the session multiplexing framework.
If instructed or if a C2 session fails, the malware can delete itself using cmd.exe or schtasks.exe, often masquerading the operation under the guise of a scheduled task named "GoogleUpdateTask". The file used to store fallback C2 IPs (%temp%/s01bafg) is updated by the malware using its encryption routine.
APT GROUPespionageadvanced
According to CISA, SUPERNOVA is a malicious webshell backdoor that allows a remote operator to dynamically inject C# source code into a web portal to subsequently inject code. APT actors use SUPERNOVA to perform reconnaissance, conduct domain mapping, and steal sensitive information and credentials.
APT GROUP
Malware family tracked by Malpedia. ID: win.superbear
APT GROUPespionageadvanced
According to Proofpoint, this is a Lua-based malware likely used by a nation-state sponsored attacker used to target European government personnel involved in managing the logistics of refugees fleeing Ukraine.
APT GROUP
Malware family tracked by Malpedia. ID: win.sunorcal
APT GROUPfinancial
SunCrypt is a RaaS operation first observed in October 2019, notable for pioneering triple extortion (encryption, data publication threats, and DDoS attacks on non-paying victims), operating a closed small affiliate program and partnering with TrickBot for initial access.
Infra: 🔗 x2miyuiwpib2imjr5yky…🔗 nbzzb6sa6xuura2z.oni…
RLUpdated: N/A
View profile →APT GROUP
FireEye describes SUNBURST as a trojanized SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. After an initial dormant period of up to two weeks, it uses a DGA to generate specific subdomains for a set C&C domain. The backdoor retrieves and executes commands, that include the ability to transfer files, execute files, profile the system, reboot the machine, and disable system services. The C2 traffic to the malicious domains is designed to mimic normal SolarWinds API communications: Orion Improvement Program (OIP) protocol. The backdoor uses multiple obfuscated blocklists to identify forensic and anti-virus tools running as processes, services, and drivers. Multiple trojanzied updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website.
APT GROUP
According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.
APT GROUP
According to Mandiant, SUGARUSH is a backdoor written to establish a connection with an embedded C2 and to execute CMD commands.