Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,747 entities
APT GROUP
Malware family identifying apk.doubleagent. Origin and technical characteristics tracked via Malpedia.
dmsSpy
Technical ID: apk.dmsspy
APT GROUP
Malware family identifying apk.dmsspy. Origin and technical characteristics tracked via Malpedia.
Dendroid
Technical ID: apk.dendroid
APT GROUP
Malware family identifying apk.dendroid. Origin and technical characteristics tracked via Malpedia.
DEFENSOR ID
Technical ID: apk.defensor_id
APT GROUP
Malware family identifying apk.defensor_id. Origin and technical characteristics tracked via Malpedia.
Also known as: Defensor Digital
APT GROUPespionageadvanced
According to Lookout, DCHSpy is an Android surveillanceware tool leveraged by Iranian cyber espionage group MuddyWater. DCHSpy collects WhatsApp data, accounts, contacts, SMS, files, location, and call logs, and can record audio and take photos.
DawDropper
Technical ID: apk.dawdropper
APT GROUP
Malware family identifying apk.dawdropper. Origin and technical characteristics tracked via Malpedia.
Dark Shades
Technical ID: apk.darkshades
APT GROUP
Malware family identifying apk.darkshades. Origin and technical characteristics tracked via Malpedia.
Also known as: Rogue
DAAM
Technical ID: apk.daam
APT GROUP
According to PCrisk, DAAM is an Android malware utilized to gain unauthorized access to targeted devices since 2021. With the DAAM Android botnet, threat actors can bind harmful code with a genuine application using its APK binding service.
Lookout refers to this malware as BouldSpy and assesses with medium confidence that this Android surveillance tool is used by the Law Enforcement Command of the Islamic Republic of Iran (FARAJA).
Also known as: BouldSpy
APT GROUP
Malware family identifying apk.cyber_azov. Origin and technical characteristics tracked via Malpedia.
CryCryptor
Technical ID: apk.crycryptor
APT GROUP
According to NHS Digital, CryCryptor is distributed via websites that spoof health organisations. At the time of publication these websites have affected the Canadian health service. CryCryptor cannot be obtained from the Google Play store, so devices restricted to only running apps from the store are not affected.
When CryCryptor is run it encrypts common file types and saves a ransom note to every directory where files have been encrypted. Encrypted files have the extension '.enc' appended to the filenames. Additional files are saved containing the salt values used in each encryption and an initialisation vector. These files have the extensions '.enc.salt' and '.enc.iv' respectively.
When files have been encrypted, a notification is displayed directing users to open the ransom note.
Also known as: CryCrypter • CryDroid
Crocodilus
Technical ID: apk.crocodilus
APT GROUP
According to ThreatFabric, this malware offers remote control, black screen overlays, and advanced data harvesting via accessibility logging.
CraxsRAT
Technical ID: apk.craxs_rat
APT GROUP
Malware family identifying apk.craxs_rat. Origin and technical characteristics tracked via Malpedia.
Cpuminer
Technical ID: apk.cpuminer
APT GROUP
Malware family identifying apk.cpuminer. Origin and technical characteristics tracked via Malpedia.
Coronavirus Android Worm
Technical ID: apk.corona_worm
APT GROUP
Poses as an app that can offer a "corona safety mask" but phone's address book and sends sms to contacts, spreading its own download link.
Copybara
Technical ID: apk.copybara
APT GROUP
Malware family identifying apk.copybara. Origin and technical characteristics tracked via Malpedia.
Coper
Technical ID: apk.coper
APT GROUPfinancialhigh
Coper is an Android banking trojan and RAT descended from ExobotCompact, itself a rewrite of Exobot. It uses a modular architecture, a multi-stage infection chain and (in some variants) a DGA. First observed in Colombia, it has since spread to Europe.
Also known as: ExobotCompact • Octo
Connic
Technical ID: apk.connic
APT GROUP
Malware family identifying apk.connic. Origin and technical characteristics tracked via Malpedia.
Also known as: SpyBanker
CometBot
Technical ID: apk.comet_bot
APT GROUP
Malware family identifying apk.comet_bot. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying apk.cloudatlas. Origin and technical characteristics tracked via Malpedia.
Clipper
Technical ID: apk.clipper
APT GROUP
Malware family identifying apk.clipper. Origin and technical characteristics tracked via Malpedia.
Clientor
Technical ID: apk.clientor
APT GROUP
Malware family identifying apk.clientor. Origin and technical characteristics tracked via Malpedia.
Chrysaor
Technical ID: apk.chrysaor
APT GROUP
Malware family identifying apk.chrysaor. Origin and technical characteristics tracked via Malpedia.
Also known as: Pegasus • JigglyPuff
APT GROUP
Malware family identifying apk.chinotto. Origin and technical characteristics tracked via Malpedia.
Charger
Technical ID: apk.charger
APT GROUP
Malware family identifying apk.charger. Origin and technical characteristics tracked via Malpedia.
Chamois
Technical ID: apk.chamois
APT GROUP
Malware family identifying apk.chamois. Origin and technical characteristics tracked via Malpedia.
Chameleon
Technical ID: apk.chameleon
APT GROUP
The malware chamaleon is an Android trojan that pretends to be legitimate entities to steal data from users in Australia and Poland. It exploits the Accessibility Service to monitor and modify the device screen.
Cerberus
Technical ID: apk.cerberus
APT GROUPfinancialhigh
According to PCrisk, Cerberus is an Android banking Trojan which can be rented on hacker forums. It was been created in 2019 and is used to steal sensitive, confidential information. Cerberus can also be used to send commands to users' devices and perform dangerous actions.
Catelites
Technical ID: apk.catelites
APT GROUPfinancialhigh
Catelites Bot (identified by Avast and SfyLabs in December 2017) is an Android trojan, with ties to CronBot. Once the malicious app is installed, attackers use social engineering tricks and window overlays to get credit card details from the victim.
The distribution vector seems to be fake apps from third-party app stores (not Google Play) or via malvertisement. After installation and activation, the app creates fake Gmail, Google Play and Chrome icons. Furthermore, the malware sends a fake system notification, telling the victim that they need to re-authenticate with Google Services and ask for their credit card details to be entered.
Currently the malware has overlays for over 2,200 apps of banks and financial institutions.
APT GROUP
Malware family identifying apk.carbonsteal. Origin and technical characteristics tracked via Malpedia.
APT GROUPespionageadvanced
According to PCrisk, CapraRAT is the name of an Android remote access trojan (RAT), possibly a modified version of another (open-source) RAT called AndroRAT. It is known that CapraRAT is used by an advanced persistent threat group (ATP) called APT36 (also known as Earth Karkaddan). CapraRAT allows attackers to perform certain actions on the infected Android device.
BusyGasper
Technical ID: apk.busygasper
APT GROUP
Malware family identifying apk.busygasper. Origin and technical characteristics tracked via Malpedia.
BTMOB RAT
Technical ID: apk.btmob
APT GROUP
According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration. It spreads via phishing sites impersonating streaming services like iNat TV and fake mining platforms. The malware abuses Android’s Accessibility Service to unlock devices, log keystrokes, and automate credential theft through injections. It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.
Brunhilda
Technical ID: apk.brunhilda
APT GROUP
PRODAFT describes Brunhilda as a "Dropper as a Service" for Google Play, delivering e.g. Alien.
BRATA
Technical ID: apk.brata
APT GROUP
According to Cleafy, the victim's Android device is factory reset after the attackers siphon money from the victim's bank account. This distracts users from the crime, while removing traces or footprints that might be of interest to forensic analysts.
Also known as: AmexTroll • Copybara
BrasDex
Technical ID: apk.brasdex
APT GROUPfinancialhigh
According to PCrisk, BraDex is a banking malware targeting Android operating systems. This malicious program aims to gain access to victims' bank accounts and make fraudulent transactions.
At the time of writing, BrasDex targets Brazilian banking applications exclusively. In previous BrasDex campaigns, it infiltrated devices under the guise of Android system related apps. Lately, this malware has been installed by a fake Brazilian Banco Santander banking application.
APT GROUP
According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical code, names, and log messages in multiple classes related to the handling of databases containing collected exfil data such as call logs, location tracking, SMS messages, notifications, and browser bookmarks. Class names for many entry points (receivers, activities, and services) were either the same or very similar to DroidWatcher samples.
BlankBot
Technical ID: apk.blankbot
APT GROUP
Malware family identifying apk.blankbot. Origin and technical characteristics tracked via Malpedia.
BingoMod
Technical ID: apk.bingomod
APT GROUP
Malware family identifying apk.bingomod. Origin and technical characteristics tracked via Malpedia.
BianLian
Technical ID: apk.bianlian
APT GROUP
Malware family identifying apk.bianlian. Origin and technical characteristics tracked via Malpedia.
Also known as: Hydra
Basbanke
Technical ID: apk.basbanke
APT GROUP
Malware family identifying apk.basbanke. Origin and technical characteristics tracked via Malpedia.