Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,747 entities
Bahamut
Technical ID: apk.bahamut
BahamutDropping Elephant
APT GROUP
According to PCrisk, Bahamut is the name of Android malware with spyware functionality. Threat actors use Bahamut to steal sensitive information. The newest malware version targets various messaging apps and personally identifiable information.
Updated: 2024-02-08
View profile →
BadPatch
Technical ID: apk.badpatch
Molerats
APT GROUP
Malware family identifying apk.badpatch. Origin and technical characteristics tracked via Malpedia.
Also known as: WelcomeChat
Updated: 2020-07-15
View profile →
BADCALL
Technical ID: apk.badcall
Lazarus Group
APT GROUP
remote access tool (RAT) payload on Android devices
Updated: 2023-05-15
View profile →
BADBOX
Technical ID: apk.badbox
APT GROUP
According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android electronics with preinstalled malware.
Updated: 2026-01-27
View profile →
badbazaar
Technical ID: apk.badbazaar
APT15
APT GROUP
BadBazaar is a type of malware primarily functioning as a spyware. Designed to compromise Android and iOS devices, it is often distributed through malicious apps downloaded from unofficial app stores, third-party websites, Telegram channels, and social engineering. Once installed, BadBazaar seeks to surveil the victim by intercepting SMS messages, performing screen recordings, and logging keystrokes on the device. Additionally, it can execute remote commands and download and install other malicious applications, further compromising the security of the affected device.
Updated: 2025-04-09
View profile →
AxBanker
Technical ID: apk.axbanker
APT GROUPfinancialhigh
According to EnigmaSoft, AxBanker is a banking Trojan targeting Android devices specifically. The threatening tool has been deployed as part of large attack campaigns against users in India. The threat actors use smishing (SMS phishing) techniques to smuggle the malware threat onto the victims' devices. The fake applications carrying AxBanker are designed to visually impersonate the official applications of popular Indian banking organizations. The weaponized applications use fake promises or rewards and discounts as additional lures.
Updated: 2023-11-14
View profile →
ATANK
Technical ID: apk.atank
APT GROUPfinancialhigh
According to Lukas Stefanko, this is an open-source crypto-ransomware found on Github in 2018. IT can en/decrypt files (AES, key: 32 random chars, sent to C&C), uses email as contact point but will remove all files after 24 hours or after a reboot.
Updated: 2020-08-12
View profile →
Ashas
Technical ID: apk.ashas
APT GROUP
Malware family identifying apk.ashas. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-28
View profile →
Asacub
Technical ID: apk.asacub
APT GROUP
Malware family identifying apk.asacub. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-26
View profile →
AnubisSpy
Technical ID: apk.anubisspy
Sphinx (APT-C-15)
APT GROUP
Malware family identifying apk.anubisspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-12-22
View profile →
Anubis
Technical ID: apk.anubis
APT GROUPespionageadvanced
BleepingComputer found that Anubis will display fake phishing login forms when users open up apps for targeted platforms to steal credentials. This overlay screen will be shown over the real app's login screen to make victims think it's a legitimate login form when in reality, inputted credentials are sent to the attackers. In the new version spotted by Lookout, Anubis now targets 394 apps and has the following capabilities: Recording screen activity and sound from the microphone Implementing a SOCKS5 proxy for covert communication and package delivery Capturing screenshots Sending mass SMS messages from the device to specified recipients Retrieving contacts stored on the device Sending, reading, deleting, and blocking notifications for SMS messages received by the device Scanning the device for files of interest to exfiltrate Locking the device screen and displaying a persistent ransom note Submitting USSD code requests to query bank balances Capturing GPS data and pedometer statistics Implementing a keylogger to steal credentials Monitoring active apps to mimic and perform overlay attacks Stopping malicious functionality and removing the malware from the device
Also known as: BankBot • android.bankbot • android.bankspy
Updated: 2025-06-20
View profile →
Antidot
Technical ID: apk.antidot
APT GROUP
The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese, Romanian, and English, indicating potential targets in these regions. Antidot uses overlay attacks and keylogging techniques to efficiently collect sensitive information such as login credentials.
Updated: 2025-06-20
View profile →
ANDROSNATCH
Technical ID: apk.androsnatch
APT29
APT GROUP
According to Google, a Chrome cookie stealer.
Updated: 2024-09-13
View profile →
AndroRAT
Technical ID: apk.androrat
APT GROUP
Androrat is a remote administration tool developed in Java Android for the client side and in Java/Swing for the Server. The name Androrat is a mix of Android and RAT (Remote Access Tool). It has been developed in a team of 4 for a university project. The goal of the application is to give the control of the android system remotely and retrieve informations from it.
Updated: 2025-11-26
View profile →
Anatsa
Technical ID: apk.anatsa
APT GROUP
Malware family identifying apk.anatsa. Origin and technical characteristics tracked via Malpedia.
Also known as: ReBot • TeaBot • Toddler
Updated: 2025-08-28
View profile →
AmpleBot
Technical ID: apk.amplebot
APT GROUP
This malware was initially named BlackRock and later renamed to AmpleBot.
Also known as: BlackRock
Updated: 2022-03-14
View profile →
AmexTroll
Technical ID: apk.amextroll
APT GROUP
Malware family identifying apk.amextroll. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-08-23
View profile →
Alien
Technical ID: apk.alien
APT GROUPfinancialhigh
According to ThreatFabric, this is a fork of Cerberus v1 (active January 2020+). Alien is a rented banking trojan that can remotely control a phone and achieves RAT functionality by abusing TeamViewer.
Also known as: AlienBot
Updated: 2023-01-05
View profile →
AhMyth
Technical ID: apk.ahmyth
APT GROUPespionageadvanced
According to PCrisk, Ahmyth is a Remote Access Trojan (RAT) targeting Android users. It is distributed via trojanized (fake) applications. Ahmyth RAT steals cryptocurrency and banking credentials, 2FA codes, lock screen passcodes, and captures screenshots.
Updated: 2024-01-31
View profile →
Agent Smith
Technical ID: apk.agentsmith
APT GROUP
Malware family identifying apk.agentsmith. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-06
View profile →
AdultSwine
Technical ID: apk.adultswine
APT GROUP
Malware family identifying apk.adultswine. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-23
View profile →
AdoBot
Technical ID: apk.adobot
APT GROUP
Malware family identifying apk.adobot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-06-09
View profile →
ActionSpy
Technical ID: apk.actionspy
POISON CARP
APT GROUP
Malware family identifying apk.actionspy. Origin and technical characteristics tracked via Malpedia.
Also known as: AxeSpy
Updated: 2022-09-12
View profile →
AbstractEmu
Technical ID: apk.abstract_emu
APT GROUP
According to PCrisk, AbstractEmu is the name of rooting malware that can gain privileged access to the Android operating system. Threat actors behind AbstractEmu are using legitimate-looking apps (like password managers, app launchers, data savers) to trick users into downloading and opening/executing this malware.
Updated: 2023-05-15
View profile →
Aberebot
Technical ID: apk.aberebot
APT GROUP
Malware family identifying apk.aberebot. Origin and technical characteristics tracked via Malpedia.
Also known as: Escobar
Updated: 2025-01-27
View profile →
888 RAT
Technical ID: apk.888_rat
APT GROUP
According to ESET, this is a commercial, multiplatform RAT, originally developed for Windows and extended to Android. In short, it can steal and delete files from a device, take screenshots, get device location, phish Facebook credentials, get a list of installed apps, steal user photos, take photos, record surrounding audio and phone calls, make calls, steal SMS messages, steal the device’s contact list, send text messages, etc.
Updated: 2025-01-27
View profile →
FastCash
Technical ID: aix.fastcash
Lazarus Group
APT GROUP
Malware family identifying aix.fastcash. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-09
View profile →
SocksProxyGo
Technical ID: win.socksproxygo
MALWARE
Malware family identifying win.socksproxygo. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-11
View profile →
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
[Medusa Group](https://attack.mitre.org/groups/G1051) has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that certain attacks may still be conducted directly by the ransomware’s core developers. Public sources have also referred to the group as “Spearwing” or “Medusa Actors.” (Citation: CISA Medusa Group Medusa Ransomware March 2025) (Citation: Broadcom Medusa Ransomware Medusa Group March 2025) [Medusa Group](https://attack.mitre.org/groups/G1051) employs living-off-the-land techniques, frequently leveraging publicly available tools and common remote management software to conduct operations. The group engages in double extortion tactics, exfiltrating data prior to encryption and threatening to publish stolen information if ransom demands are not met. (Citation: Security Scorecard Medusa Ransomware January 2024) For initial access, [Medusa Group](https://attack.mitre.org/groups/G1051) has exploited publicly known vulnerabilities, conducted phishing campaigns, and used credentials or access purchased from Initial Access Brokers (IABs). The group is opportunistic and has targeted a wide range of sectors globally. (Citation: Intel471 Medusa Ransomware May 2025)
T1027.002T1608.002T1046
Updated: N/A
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
aka xoriste
RSLUpdated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
No detailed intelligence profile available.
Updated: N/A
View profile →
APT GROUP
This malware is written in Java and is named after references in the code. Tycoon has been in the wild since December 2019 and has targeted organizations in the education, SMBs, and software industries. Tycoon is a multi-platform Java ransomware that targets Windows and Linux systems. This ransomware denies access to the system administrator following an attack on the domain controller and file servers. The initial intrusion occurs through an internet-facing remote desktop protocol (RDP) jump-server.
Updated: 2026-08-10
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUP
Ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim's data to the darknet and they announced that any victim that will not contact them will suffer from a data leak and they will not delete hist files for future usage.
Infra: 🔗 ransomocmou6mnbquqz4🔗 ransomoefralti2zh5nr📁 2vqamwfdpis5rkjtpkut+4 more
RLUpdated: N/A
View profile →
APT GROUP
ransomware
Updated: 2026-08-10
View profile →
APT GROUPfinancial
FreeWorld is a ransomware variant first observed in September 2023, and is believed to be derived from the Mimic ransomware family. It is deployed through coordinated campaigns dubbed DB#JAMMER, which exploit poorly secured Microsoft SQL (MSSQL) servers exposed to the internet. Attackers gain initial access via brute force, leverage the xp_cmdshell feature to execute shell commands, disable defenses, deploy remote access tools like Cobalt Strike and AnyDesk, and eventually deliver the FreeWorld payload. The ransomware encrypts files using hybrid encryption and appends the .FreeWorldEncryption extension. Victims receive a ransom note titled FreeWorld-Contact.txt, directing them on payment and data recovery steps.
RSLUpdated: 2026-08-10
View profile →
← PreviousPage 213 / 269Next →