Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
LunaSpy
Technical ID: apk.luna_spy
APT GROUP
Malware family identifying apk.luna_spy. Origin and technical characteristics tracked via Malpedia.
Also known as: Backdoor.916
Updated: 2025-08-26
View profile →
LuckyCat
Technical ID: apk.luckycat
TA413
APT GROUP
Malware family identifying apk.luckycat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-16
View profile →
LokiBot
Technical ID: apk.lokibot
APT GROUPfinancialhigh
Android banker Trojan with the standard banking capabilities such as overlays, SMS stealing. It also features ransomware functionality. Note, the network traffic is obfuscated the same way as in Android Bankbot.
Updated: 2024-04-23
View profile →
Loki
Technical ID: apk.loki
APT GROUP
Malware family identifying apk.loki. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-29
View profile →
LittleLooter
Technical ID: apk.little_looter
Charming Kitten
APT GROUP
Malware family identifying apk.little_looter. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-09-02
View profile →
LANDFALL
Technical ID: apk.landfall
APT GROUP
Malware family identifying apk.landfall. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-09
View profile →
KSREMOTE
Technical ID: apk.ksremote
APT GROUP
Malware family identifying apk.ksremote. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-27
View profile →
KoSpy
Technical ID: apk.kospy
APT37
APT GROUP
According to Lookout, this spyware was first observed in March 2022 and remains active with new samples still publicly hosted. It uses a two-stage C2 infrastructure that retrieves initial configurations from a Firebase cloud database. KoSpy can collect extensive data, such as SMS messages, call logs, location, files, audio, and screenshots via dynamically loaded plugins. The spyware has Korean language support with samples distributed across Google Play and third-party app stores such as Apkpure.
Updated: 2025-03-13
View profile →
Konni
Technical ID: apk.konni
APT GROUP
Malware family identifying apk.konni. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-09
View profile →
Koler
Technical ID: apk.koler
APT GROUP
Malware family identifying apk.koler. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-21
View profile →
KnSpy
Technical ID: apk.knspy
APT-C-35
APT GROUP
Malware family identifying apk.knspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-24
View profile →
Kimwolf
Technical ID: apk.kimwolf
APT GROUP
KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as participating in distributed denial-of-service (DDoS). KIMWOLF primarily infects unofficial Android-TV set-top boxes and digital photo frames. The malware has frequently been noted to achieve infection spread via abusing Android Debug Bridge (ADB) and residential proxies. There are multiple reports suggesting a connection to the Aisuru botnet, with Kimwolf acting as the Android variant.
Updated: 2026-02-17
View profile →
KevDroid
Technical ID: apk.kevdroid
APT37
APT GROUP
Malware family identifying apk.kevdroid. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-03
View profile →
Joker
Technical ID: apk.joker
APT GROUP
Joker is one of the most well-known malware families on Android devices. It manages to take advantage of Google’s official app store with the help of its trail signatures which includes updating the virus’s code, execution process, and payload-retrieval techniques. This malware is capable of stealing users’ personal information including contact details, device data, WAP services, and SMS messages.
Also known as: Bread
Updated: 2026-01-14
View profile →
JadeRAT
Technical ID: apk.jaderat
APT GROUP
Malware family identifying apk.jaderat. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-17
View profile →
IRRat
Technical ID: apk.irrat
APT GROUP
Malware family identifying apk.irrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-22
View profile →
IRATA
Technical ID: apk.irata
APT GROUP
According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application. IRATA can collect sensitive information from your mobile phone including bank details. Since it infects your mobile, it can also gather your SMS messages which then can be used to obtain 2FA tokens.
Updated: 2023-05-16
View profile →
IPStorm
Technical ID: apk.ipstorm
APT GROUP
Android variant of IPStorm (InterPlanetary Storm).
Also known as: InterPlanetary Storm
Updated: 2025-06-20
View profile →
Hydra
Technical ID: apk.hydra
APT GROUPfinancialhigh
Avira states that Hydra is an Android BankBot variant, a type of malware designed to steal banking credentials. The way it does this is by requesting the user enables dangerous permissions such as accessibility and every time the banking app is opened, the malware is hijacking the user by overwriting the legit banking application login page with a malicious one. The goal is the same, to trick the user to enter his login credentials so that it will go straight to the malware authors.
Updated: 2025-06-20
View profile →
Hook
Technical ID: apk.hook
APT GROUP
According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. It provides WebSocket communication and has RAT capabilities.
Updated: 2025-11-25
View profile →
HilalRAT
Technical ID: apk.hilalrat
APT GROUP
RAT, which can be used to extract sensitive information, e.g. contact lists, txt messages, location information.
Updated: 2022-04-25
View profile →
HiddenAd
Technical ID: apk.hiddenad
APT GROUP
HiddenAd is a malware that shows ads as overlays on the phone.
Updated: 2023-11-14
View profile →
HeroRAT
Technical ID: apk.hero_rat
APT GROUP
Malware family identifying apk.hero_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-25
View profile →
Hermit
Technical ID: apk.hermit
APT GROUP
Lookout states that Hermit is an advanced spyware designed to target iOS and Android mobile devices. It is designed to collect extensive amounts of sensitive data on its victims such as their location, contacts, private messages, photos, call logs, phone conversations, ambient audio recordings, and more.
Updated: 2023-05-16
View profile →
HenBox
Technical ID: apk.henbox
HenBox
APT GROUP
Malware family identifying apk.henbox. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-02
View profile →
HawkShaw
Technical ID: apk.hawkshaw
APT GROUP
Malware family identifying apk.hawkshaw. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-12
View profile →
HARDRAIN
Technical ID: apk.hardrain
Lazarus Group
APT GROUP
Malware family identifying apk.hardrain. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-09-09
View profile →
Gustuff
Technical ID: apk.gustuff
APT GROUPfinancialhigh
Group-IB describes Gustuff as a mobile Android Trojan, which includes potential targets of customers in leading international banks, users of cryptocurrency services, popular ecommerce websites and marketplaces. Gustuff has previously never been reported. Gustuff is a new generation of malware complete with fully automated features designed to steal both fiat and crypto currency from user accounts en masse. The Trojan uses the Accessibility Service, intended to assist people with disabilities. The analysis of Gustuff sample revealed that the Trojan is equipped with web fakes designed to potentially target users of Android apps of top international banks including Bank of America, Bank of Scotland, J.P.Morgan, Wells Fargo, Capital One, TD Bank, PNC Bank, and crypto services such as Bitcoin Wallet, BitPay, Cryptopay, Coinbase etc. Group-IB specialists discovered that Gustuff could potentially target users of more than 100 banking apps, including 27 in the US, 16 in Poland, 10 in Australia, 9 in Germany, and 8 in India and users of 32 cryptocurrency apps.
Updated: 2021-05-04
View profile →
Guerrilla
Technical ID: apk.guerrilla
APT GROUP
Malware family identifying apk.guerrilla. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-03-02
View profile →
GriftHorse
Technical ID: apk.grifthorse
APT GROUP
Malware family identifying apk.grifthorse. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-24
View profile →
Gravity RAT
Technical ID: apk.gravity_rat
APT GROUP
Malware family identifying apk.gravity_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-26
View profile →
GPlayed
Technical ID: apk.gplayed
APT GROUPespionageadvanced
Cisco Talos identifies GPlayed as a malware written in .NET using the Xamarin environment for mobile applications. It is considered powerful because of its capability to adapt after its deployment. In order to achieve this adaptability, the operator has the capability to remotely load plugins, inject scripts and even compile new .NET code that can be executed.
Updated: 2018-11-16
View profile →
goontact
Technical ID: apk.goontact
APT GROUP
Malware family identifying apk.goontact. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-09-19
View profile →
GoldDigger
Technical ID: apk.gold_digger
APT GROUP
Malware family identifying apk.gold_digger. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-09
View profile →
GoldenRAT
Technical ID: apk.goldenrat
APT-C-27
APT GROUP
Malware family identifying apk.goldenrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-21
View profile →
GoldenEagle
Technical ID: apk.goldeneagle
HenBox
APT GROUP
Malware family identifying apk.goldeneagle. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
Godfather
Technical ID: apk.godfather
APT GROUPfinancialhigh
According to PCrisk, Godfather is the name of an Android malware targeting online banking pages and cryptocurrency exchanges in 16 countries. It opens fake login windows over legitimate applications. Threat actors use Godfather to steal account credentials. Additionally, Godfather can steal SMSs, device information, and other data.
Updated: 2025-08-29
View profile →
GoatRAT
Technical ID: apk.goat_rat
APT GROUP
Malware family identifying apk.goat_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-01
View profile →
GnatSpy
Technical ID: apk.gnatspy
AridViper
APT GROUP
Malware family identifying apk.gnatspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-26
View profile →
GlanceLove
Technical ID: apk.glancelove
AridViper
APT GROUP
Malware family identifying apk.glancelove. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-06
View profile →
← PreviousPage 210 / 269Next →