Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.shapeshift
APT GROUP
Malware family tracked by Malpedia. ID: win.shakti
APT GROUP
Malware family tracked by Malpedia. ID: win.shady_hammock
APT GROUP
Malware family tracked by Malpedia. ID: win.shadow_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.shadowpad
APT GROUP
Malware family tracked by Malpedia. ID: win.shadowhammer
APT GROUPfinancialhigh
Ransomware
A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the network behind.
APT GROUP
ServHelper is written in Delphi and according to ProofPoint best classified as a backdoor. ProofPoint noticed two distinct variant - "tunnel" and "downloader" (citation): "The 'tunnel' variant has more features and focuses on setting up reverse SSH tunnels to allow the threat actor to access the infected host via Remote Desktop Protocol (RDP). Once ServHelper establishes remote desktop access, the malware contains functionality for the threat actor to 'hijack' legitimate user accounts or their web browser profiles and use them as they see fit. The 'downloader' variant is stripped of the tunneling and hijacking functionality and is used as a basic downloader."
Malware family tracked by Malpedia. ID: win.serpent
APT GROUP
This malware is protected using VMProtect and related to the loading of KEYPLUG.
APT GROUP
Malware family tracked by Malpedia. ID: win.sepulcher
APT GROUP
Malware family tracked by Malpedia. ID: win.sendsafe
Malware family tracked by Malpedia. ID: win.selfmake
APT GROUP
Malware family tracked by Malpedia. ID: win.seinup
APT GROUP
simple tool to facilitate download and persistence of a next-stage tool; collects system information and metadata probably in an attempt to tell sandbox-environments apart from real targets on the server-side; uses domains of search engines like Google to check for Internet connectivity; XOR-based string obfuscation with a 16-byte key
APT GROUP
Malware family tracked by Malpedia. ID: win.sedreco
APT GROUP
Malware family tracked by Malpedia. ID: win.sedll
APT GROUP
SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.
APT GROUPfinancialhigh
SecondHandTea is a full-featured Remote Access Trojan (RAT), closely related to BackbitingTea, the flagship backdoor used in the DangerousPassword campaigns (also known as SnatchCrypto). Both malware families appear to share a common codebase and are compiled within the same build environment. While they share most core functionality and supported commands, SecondHandTea differs from BackbitingTea variants in several technical aspects: - Configuration file paths - Network libraries: OpenSSL 1.1.0f vs. wolfSSL or Winsock TCP/IP - Encryption algorithms: AES-256 vs. RC4 - Compression methods: LZ4 vs. ZIP These differences suggest active development and customization efforts tailored to specific operational needs. The malware's name was inferred from its internal filename: SecondT_x64.exe. Between H2 2022 and Q1 2023, SecondHandTea was observed in targeted attacks against entities involved in cryptotrading and blockchain technology, indicating a continued focus on financially motivated cyber operations.
APT GROUP
Malware family tracked by Malpedia. ID: win.seasalt
APT GROUP
Backdoor written in Python 2, deployed with PyInstaller.
APT GROUP
Malware family tracked by Malpedia. ID: win.sdbbot
APT GROUP
ScrubCrypt is the rebranded "Jlaive" crypter, with a unique capability of .BAT packing
APT GROUP
Malware family tracked by Malpedia. ID: win.screenlocker
APT GROUPespionageadvanced
SentinelOne describes this malware as capable of doing screen capture and keylogging. It is uses by a threat cluster they named WIP19, targeting telecommunications and IT service providers in the Middle East and Asia.
APT GROUP
Malware family tracked by Malpedia. ID: win.scranos
APT GROUP
Malware family tracked by Malpedia. ID: win.scoutc2
APT GROUP
A downloader that uses Windows messages to control its execution flow.
APT GROUP
Malware family tracked by Malpedia. ID: win.scote
According to ESET Research, ScoringMathTea is a RAT that offers the attackers full control over the compromised machine. Its first appearance dates to late 2022, when its dropper was uploaded to VirusTotal. Soon after, it was seen in the wild, and since then in multiple attacks attributed to Lazarus’ Operation DreamJob campaigns, which makes it the attacker’s payload of choice for already three years. It uses compromised servers for C&C communication, with the server part usually stored under the WordPress folder containing design templates or plugins.
APT GROUP
The Chinese threat actor has used a custom backdoor dubbed "Scieron" over years in several campaigns according to SentinelLABS.
APT GROUP
Schneiken is a VBS 'Double-dropper'. It comes with two RATs embedded in the code (Dunihi and Ratty). Entire code is Base64 encoded.
APT GROUP
Scavenger is a stealthy, two-stage malware family first observed in July 2025 following a targeted supply chain attack on the NPM ecosystem. The infection began with a phishing campaign that leveraged a typo-squatted domain (npnjs.com) to impersonate the legitimate NPM login page. The adversaries abused NPM's web-based login flow—akin to device code phishing—to trick a package maintainer into generating an automation access token, which does not expire and can bypass 2FA under certain configurations. With the stolen credentials, the attackers injected malicious payloads into several trusted NPM packages, including eslint-config-prettier, by modifying their install scripts to execute a DLL loader. This first-stage loader, compiled in Visual Studio, performs anti-VM checks, dynamic API resolution using CRC32 hashing, indirect syscalls to bypass EDR, and string decryption routines. If the environment passes these checks, it executes a second-stage infostealer that targets browser data—particularly from Chromium—such as extension state, cached content, and visited URLs. The malware communicates with its command and control infrastructure using libcurl and XXTEA-encrypted payloads over HTTP(S), implementing challenge-response integrity checks during session initialization. Development artifacts like a leftover PDB path and operational overlaps have linked Scavenger to other campaigns, including one involving an infected BeamNG game binary, further suggesting a broader and evolving threat infrastructure.
APT GROUP
Based on the leaked Conti source code.
Malware family tracked by Malpedia. ID: win.scarab_ransom
APT GROUPfinancialhigh
Ransomware with ransomnote in Russian and encryption extension .scarab.
APT GROUP
Malware family tracked by Malpedia. ID: win.scanpos
APT GROUP
Malware family tracked by Malpedia. ID: win.scano
APT GROUP
According to CISA, this is a command-line port scanning utility from Foundstone. It is used to scan for open UDP and TCP ports, grab banners from open ports, resolve IP addresses to host names, and bind to specified ports and IP addresses.