Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
According to Mandiant, SUGARDUMP is a credential harvesting utility, capable of password collection from Chromium-based browsers. There are also versions to exfiltrate data via SMTP and HTTP.
APT GROUPfinancial
Ransomware, written in Delphi.
Infra: 💬 chat5sqrnzqewampznyb🔗 sugarpanel.space
RSLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.suceful
APT GROUP
Malware family tracked by Malpedia. ID: win.subzero
APT GROUP
Malware family tracked by Malpedia. ID: win.stuxnet
Malware family tracked by Malpedia. ID: win.strikesuit_gift
Malware family tracked by Malpedia. ID: win.strifewater_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.stresspaint
APT GROUP
According to PCRisk, StrelaStealer seeks to extract email account log-in credentials. At the time of writing, this program targets Microsoft Outlook and Mozilla Thunderbird email clients. Following successful infiltration, StrelaStealer searches for "logins.json" (account/password) and "key4.db" (password database) within the "%APPDATA%\Thunderbird\Profiles\" directory - by doing so, it can acquire the credentials for Thunderbird. Alternatively, if Outlook credentials are targeted - StrelaStealer seeks out the Windows Registry from where it can retrieve the program's key and "IMAP User", "IMAP Server", as well as the "IMAP Password" values. Since the latter is kept in an encrypted form, the malicious program employs the Windows CryptUnprotectData feature to decrypt it prior to exfiltration.
APT GROUP
Malware family tracked by Malpedia. ID: win.stratofear
APT GROUP
Malware family tracked by Malpedia. ID: win.stration
Updated: 2018-07-24
View profile →
APT GROUP
According to Mandiant, STOWAWAY is a publicly available backdoor and proxy. The project supports several types of communication like SSH, socks5. Backdoor component supports upload and download of files, remote shell and basic information gathering.
APT GROUP
Malware family tracked by Malpedia. ID: win.stormwind
APT GROUP
According to unpac.me, StormKitty is a Remote Access Trojan (RAT), written in C#, primarily designed to perform extensive system reconnaissance and data collection. It leverages Windows Management Instrumentation for execution and conducts a thorough discovery of system information, including querying the registry, identifying system owners and users, and discovering network configurations. StormKitty is also capable of collecting data from information repositories and performing file and directory discovery. For defense evasion, it employs techniques such as obfuscating files or information and checks for virtualization or sandbox environments to avoid detection. These capabilities enable StormKitty to maintain persistence and gather sensitive information from compromised systems.
APT GROUPfinancialhigh
STOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name. It is not used to encrypt the entire file but only the first 5 MB. In its original version it was able to run offline and, in that case, it used a hard-coded key which could be extracted to decrypt files.
APT GROUP
Malware family tracked by Malpedia. ID: win.stonedrill
APT GROUP
According to Mandiant, STONEBOAT is an installer for DICELOADER. It is written in .NET and drops its payload in-memory.
APT GROUP
Malware family tracked by Malpedia. ID: win.stinger
Updated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.stegoloader
APT GROUP
Malware written in .NET that hides in Steam profile pictures. Tries to evade virtualization through detection if it is executed within VMWare or VirtualBox.
APT GROUPespionageadvanced
Check Point Research observed a wave of highly-targeted espionage attacks in Libya that utilize a new custom modular backdoor. Stealth Soldier malware is an undocumented backdoor that primarily operates surveillance functions such as file exfiltration, screen and microphone recording, keystroke logging and stealing browser information.
According to Fortinet, StealthWorker is a brute-force malware that has been linked to a compromised e-commerce website with an embedded skimmer that steals personal information and payment details. Before hackers can embed a skimmer, however, the first requirement is for hackers to gain access to their target’s backend. Hacker’s commonly take advantage of vulnerabilities in the Content Management System (CMS) or its plugins to gain entry into the target’s system. Another, simpler option is to use brute force attacks. Though quite slow, this method is still effective against administrators using weak or commonly used passwords.
APT GROUP
Malware family tracked by Malpedia. ID: win.stealhook
APT GROUP
According to PTSecurity, this stealer harvests system information which is then RC4 encrypted and Base64 encoded before sending it to the C2 server.
APT GROUP
According to SecurityScorecard, Stealerium is an open-source stealer available on GitHub. The malware steals information from browsers, cryptocurrency wallets, and applications such as Discord, Pidgin, Outlook, Telegram, Skype, Element, Signal, Tox, Steam, Minecraft, and VPN clients. The binary also gathers data about the infected host, such as the running processes, Desktop and webcam screenshots, Wi-Fi networks, the Windows product key, and the public and private IP address. The stealer employs multiple anti-analysis techniques, such as detecting virtual machines, sandboxes, and malware analysis tools and checking if the process is being debugged. The malware also embedded a keylogger module and a clipper module that replaces cryptocurrency wallet addresses with the threat actor’s addresses if the victim makes a transaction. The stolen information is sent to a Discord channel using a Discord Webhook.
APT GROUP
Stealc is an information stealer advertised by its presumed developer Plymouth on Russian-speaking underground forums and sold as a Malware-as-a-Service since January 9, 2023. According to Plymouth's statement, stealc is a non-resident stealer with flexible data collection settings and its development is relied on other prominent stealers: Vidar, Raccoon, Mars and Redline. Stealc is written in C and uses WinAPI functions. It mainly targets date from web browsers, extensions and Desktop application of cryptocurrency wallets, and from other applications (messengers, email clients, etc.). The malware downloads 7 legitimate third-party DLLs to collect sensitive data from web browsers, including sqlite3.dll, nss3.dll, vcruntime140.dll, mozglue.dll, freebl3.dll, softokn3.dll and msvcp140.dll. It then exfiltrates the collected information file by file to its C2 server using HTTP POST requests.
APT GROUP
This is a stealer used by LockBit 2.0.
APT GROUP
According to Google, this is a digitally signed downloader written in Delphi, used for in-memory deployment of Mustang Panda's PlugX.
APT GROUPfinancialhigh
This malicious software gains access to a victim’s data by appearing like an authentic Google advertisement. Once the victim clicks on the advertisement, their operating system is infected with malicious code that steals sensitive data like credentials from web browsers, credit card information, and cryptocurrency wallet details. Unauthorized access to a victim’s computer system can have enormous personal and professional repercussions. Victims become easy targets for identity theft, cryptojacking, and other forms of malware attacks. At the enterprise level, a Statc Stealer breach can result in financial loss, reputational damage, legal liabilities, and regulatory penalties.
APT GROUP
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
APT GROUP
Potentially unwanted program that changes the startpage of browsers to induce ad impressions.
APT GROUP
Malware family tracked by Malpedia. ID: win.starsypound
APT GROUP
Malware family tracked by Malpedia. ID: win.starloader
APT GROUP
Malware family tracked by Malpedia. ID: win.starcruft
APT GROUP
Malware family tracked by Malpedia. ID: win.stampedo
APT GROUP
According to BI.ZONE, StallionRAT allows attackers to execute arbitrary commands, load additional files, and exfiltrate collected data. The malware uses a Telegram bot as their C2 server.
APT GROUP
Malware family tracked by Malpedia. ID: win.stalin_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.stabuniq
APT GROUP
SSLoad is a Rust-based downloader that first emerged in January 2024 and is used to deliver secondary payloads. Early versions of the malware used a first-stage DLL that connected to a Telegram channel named 'SSLoad' to retrieve another URL. It then downloaded a compressed PE file using a hardcoded User-Agent (SSLoad/1.x) and Content-Type over HTTP. The downloaded file was then decompressed and executed directly in memory. The malware has since undergone several updates, including changes to the command-and-control (C2) communication and the supporting executables that load the malware. Recent versions of the malware bypass the first-stage DLL by loading SSLoad directly onto the victim's machine.
APT GROUP
Malware family tracked by Malpedia. ID: win.sslmm