Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
Ginp
Technical ID: apk.ginp
APT GROUPfinancialhigh
Ginp is a mobile banking software targeting Android devices that was discovered by Kaspersky. The malware is able to steal both user credentials and credit cards numbers by implementing overlay attacks. For this, overlay targets are for example the default SMS application. What makes Ginp a remarkable family is how its operators managed to have it remain undetected over time even and it receiving version upgrades over many years. According to ThreatFabric, Ginp has the following features:
Overlaying: Dynamic (local overlays obtained from the C2)
SMS harvesting: SMS listing
SMS harvesting: SMS forwarding
Contact list collection
Application listing
Overlaying: Targets list update
SMS: Sending
Calls: Call forwarding
C2 Resilience: Auxiliary C2 list
Self-protection: Hiding the App icon
Self-protection: Preventing removal
Self-protection: Emulation-detection.
Gigabud
Technical ID: apk.gigabud
APT GROUPfinancialhigh
Gigabud is the name of an Android Remote Access Trojan (RAT) Android that can record the victim's screen and steal banking credentials by abusing the Accessibility Service. Gigabud masquerades as banking, shopping, and other applications. Threat actors have been observed using deceptive websites to distribute Gigabud RAT.
GhostChat
Technical ID: apk.ghost_chat
APT GROUP
According to ESET Research, GhostChat is a malicious Android app (package name com.datingbatch.chatapp) disguised to appear a legitimate chat platform called Dating Apps without payment; this legitimate app is available on Google Play and is unrelated to GhostChat other than through the latter using its icon. Ghostchat’s source and mode of distribution remain unknown.
GhostCtrl
Technical ID: apk.ghostctrl
APT GROUP
Malware family identifying apk.ghostctrl. Origin and technical characteristics tracked via Malpedia.
Ghimob
Technical ID: apk.ghimob
APT GROUP
Malware family identifying apk.ghimob. Origin and technical characteristics tracked via Malpedia.
Geost
Technical ID: apk.geost
APT GROUP
Malware family identifying apk.geost. Origin and technical characteristics tracked via Malpedia.
Gaganode
Technical ID: apk.gaganode
APT GROUP
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
APT GROUP
According to Check Point, they uncovered an operation dubbed "Domestic Kitten", which uses malicious Android applications to steal sensitive personal information from its victims: screenshots, messages, call logs, surrounding voice recordings, and more. This operation managed to remain under the radar for a long time, as the associated files were not attributed to a known malware family and were only detected by a handful of security vendors.
APT GROUP
Malware family identifying apk.funkybot. Origin and technical characteristics tracked via Malpedia.
FlyTrap
Technical ID: apk.flytrap
APT GROUP
Zimperium notes that this malware has hit more than 10,000 victims in 140+ countries using social media hijacking, 3rd party app stores and sideloading.
FluHorse
Technical ID: apk.fluhorse
APT GROUP
According to Check Point, this malware features several malicious Android applications that mimic legitimate applications, most of which have more than 1,000,000 installs. These malicious apps steal the victims’ credentials and Two-Factor Authentication (2FA) codes. FluHorse targets different sectors of Eastern Asian markets and is distributed via emails. In some cases, the emails used in the first stage of the attacks belong to high-profile entities. The malware can remain undetected for months making it a persistent, dangerous, and hard-to-spot threat.
FluBot
Technical ID: apk.flubot
APT GROUPfinancialhigh
PRODAFT describes FluBot as a banking malware which originally targeted Spain. Since the first quarter of 2021 it has been targeting many other European countries as well as Japan. It uses a DGA for it's C&C and relies on both DNS and DNS-over-HTTPS for name resolution. Despite arrests of multiple people suspected of involvement with this malware in March of 2021, the campaign has only intensified since.
Also known as: Cabassous • FakeChat
FlexNet
Technical ID: apk.flexnet
APT GROUP
Malware family identifying apk.flexnet. Origin and technical characteristics tracked via Malpedia.
Also known as: gugi
FlexiSpy
Technical ID: apk.flexispy
APT GROUP
Malware family identifying apk.flexispy. Origin and technical characteristics tracked via Malpedia.
FinFisher
Technical ID: apk.finfisher
APT GROUP
Malware family identifying apk.finfisher. Origin and technical characteristics tracked via Malpedia.
FileCoder
Technical ID: apk.filecoder
APT GROUPfinancialhigh
According to heimdal, A new strain of ransomware emerged on Android mobile devices. It targets those who are running the operating system Android 5.1 and higher. This Android ransomware strain has been dubbed by security researchers FileCoder (Android/Filecoder.c) and it spreads via text messages containing a malicious link.
APT GROUP
Malware family identifying apk.fastspy. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying apk.fastfire. Origin and technical characteristics tracked via Malpedia.
FakeGram
Technical ID: apk.faketgram
APT GROUP
Malware family identifying apk.faketgram. Origin and technical characteristics tracked via Malpedia.
Also known as: FakeTGram
FakeSpy
Technical ID: apk.fakespy
APT GROUP
Malware family identifying apk.fakespy. Origin and technical characteristics tracked via Malpedia.
FakeDefend
Technical ID: apk.fakedefend
APT GROUP
Malware family identifying apk.fakedefend. Origin and technical characteristics tracked via Malpedia.
Fakecalls
Technical ID: apk.fakecalls
APT GROUPfinancialhigh
According to Kaspersky, Fakecalls is a Trojan that masquerades as a banking app and imitates phone conversations with bank employees.
FakeAdBlocker
Technical ID: apk.fakeadblocker
APT GROUP
Malware family identifying apk.fakeadblocker. Origin and technical characteristics tracked via Malpedia.
FaceStealer
Technical ID: apk.facestealer
APT GROUP
Facebook Credential Stealer.
Exodus
Technical ID: apk.exodus
APT GROUP
Malware family identifying apk.exodus. Origin and technical characteristics tracked via Malpedia.
ExoBot
Technical ID: apk.exobot
APT GROUP
Malware family identifying apk.exobot. Origin and technical characteristics tracked via Malpedia.
Eventbot
Technical ID: apk.eventbot
APT GROUPfinancialhigh
According to ThreatFabric, the app overlays 15 financial targets from UK, Italy, and Spain, sniffs 234 apps from banks located in Europe as well as crypto wallets.
ErrorFather
Technical ID: apk.errorfather
APT GROUPfinancialhigh
ErrorFather is an Android banking trojan with a multi-stage dropper. The final payload is derived from the Cerberus source code leak.
ERMAC
Technical ID: apk.ermac
APT GROUPfinancialhigh
According to Intel471, ERMAC, an Android banking trojan enables bad actors to determine when certain apps are launched and then overwrites the screen display to steal the user's credentials
Elibomi
Technical ID: apk.elibomi
APT GROUP
Malware family identifying apk.elibomi. Origin and technical characteristics tracked via Malpedia.
Also known as: Drinik
EagleMsgSpy
Technical ID: apk.eagle_msg_spy
APT GROUPespionageadvanced
According to Lookout, EagleMsgSpy is a lawful intercept surveillance tool developed by a Chinese software development company with use by public security bureaus in mainland China. Early samples indicate the surveillance tool has been operational since at least 2017, with development continued into late 2024. EagleMsgSpy collects extensive data from the user: third-party chat messages, screen recording and screenshot capture, audio recordings, call logs, device contacts, SMS messages, location data, network activity.
Through infrastructure overlap and artifacts from open command and control directories, Lookout attributes EagleMsgSpy to Wuhan Chinasoft Token Information Technology Co., Ltd. with high confidence.
Dvmap
Technical ID: apk.dvmap
APT GROUP
Malware family identifying apk.dvmap. Origin and technical characteristics tracked via Malpedia.
DualToy
Technical ID: apk.dualtoy
APT GROUP
Malware family identifying apk.dualtoy. Origin and technical characteristics tracked via Malpedia.
DroidWatcher
Technical ID: apk.droidwatcher
APT GROUP
Malware family identifying apk.droidwatcher. Origin and technical characteristics tracked via Malpedia.
DroidLock
Technical ID: apk.droidlock
APT GROUPespionageadvanced
According to Zimperium, DroidLock has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials, leading to a total takeover of the compromised device.
It employs deceptive system update screens to trick victims and can stream and remotely control devices via VNC. The malware also exploits device administrator privileges to lock or erase data, capture the victim's image with the front camera, and silence the device. Overall, it utilizes 15 distinct commands to interact with its C2 panel.
DroidJack
Technical ID: apk.droidjack
APT GROUP
Malware family identifying apk.droidjack. Origin and technical characteristics tracked via Malpedia.
DroidBot
Technical ID: apk.droidbot
APT GROUP
According to Cleafy, DroidBot is a modern RAT that combines hidden VNC and overlay attack techniques with spyware-like capabilities, such as keylogging and user interface monitoring. Moreover, it leverages dual-channel communication, transmitting outbound data through MQTT and receiving inbound commands via HTTPS, providing enhanced operation flexibility and resilience.
APT GROUP
Android variant of ios.LightSpy.
Also known as: LightSpy
APT GROUP
Android malware that impersonates genuine applications such as Signal, Telegram, WhatsApp, YouTube, and other chat applications and distributes through phishing sites.
DoubleLocker
Technical ID: apk.doublelocker
APT GROUP
Malware family identifying apk.doublelocker. Origin and technical characteristics tracked via Malpedia.