Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,719 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.sshnet
APT GROUP
sRDI allows for the conversion of DLL files to position independent shellcode. It attempts to be a fully functional PE loader supporting proper section permissions, TLS callbacks, and sanity checks. It can be thought of as a shellcode PE loader strapped to a packed DLL.
APT GROUP
According to PaloAlto, SquirtDanger is a commodity botnet malware family that comes equipped with a number of characteristics and capabilities. The malware is written in C# (C Sharp) and has multiple layers of embedded code. Once run on the system, it will persist via a scheduled task that is set to run every minute. SquirtDanger uses raw TCP connections to a remote command and control (C2) server for network communications.
APT GROUP
According to Sophos, Squirrelwaffle is a malware loader that is distributed as a malicious Office document in spam campaigns. It provides attackers with an initial foothold in a victim’s environment and a channel to deliver and infect systems with other malware. When a recipient opens a Squirrelwaffle-infected document and enables macros, a visual basic script typically downloads and executes malicious files and scripts, giving further control of the computer to an attacker. Squirrelwaffle operators also use DocuSign to try and trick the user into enabling macros in Office documents.
APT GROUP
Malware family tracked by Malpedia. ID: win.squidloader
APT GROUP
A backdoor, capable of providing shell access, loading additional payloads, interacting remotely with the file system and processes, and taking screenshots.
APT GROUP
SpyEye is a malware targeting both Microsoft Windows browsers and Apple iOS Safari. Originated in Russia, it was available in dark forums for $500+ claiming to be the "The Next Zeus Malware". It performed many functionalities typical from bankers trojan such as keyloggers, auto-fill credit card modules, email backups, config files (encrypted), http access, Pop3 grabbers and FTP grabbers. SpyEye allowed hackers to steal money from online bank accounts and initiate transactions even while valid users are logged into their bank account.
APT GROUP
Malware family tracked by Malpedia. ID: win.spyder_patchwork
APT GROUP
Malware family tracked by Malpedia. ID: win.spyder
APT GROUP
Malware family tracked by Malpedia. ID: win.spybot
APT GROUP
Malware family tracked by Malpedia. ID: win.spora_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.splitloader
APT GROUP
According to Unit 42, Splinter is a post-exploitation red team tool, written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: win.spider_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.spicyhotpot
APT GROUP
Malware family tracked by Malpedia. ID: win.spica
APT GROUP
According to Trend Micro, this is a tool designed to disable security products, adopting two approaches to achieve this purpose. One approach terminates the security product process by using a vulnerable driver, zamguard64.sys, published by Zemana (vulnerability designated as CVE-2018-5713). Meanwhile, another approach disables process launching by using a new technique that they named stack rumbling.
APT GROUP
Malware family tracked by Malpedia. ID: win.spedear
APT GROUP
Mixed RAT and Botnet malware sold in underground forums. In march 2021 it was advertised with the Spectre 2.0, it reached version 3 in June 2021 and then quickly version 4. This crimeware tool was being abused in malicious campaigns targeting European users in September 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.spectralviper
APT GROUP
Malware family tracked by Malpedia. ID: win.spearal
APT GROUPfinancialhigh
Spartacus is ransomware written in .NET and emerged in the first half of 2018.
APT GROUP
Malware family tracked by Malpedia. ID: win.sparrow_door
APT GROUP
SparkRAT is a cross-platform, open-source Remote Administration Tool (RAT) written in Go and released on GitHub in 2022. Compatible with Windows, macOS, and Linux systems, it offers extensive remote access capabilities, including file and process management, file transfer, remote desktop monitoring, system information collection, and command execution via terminal access.
APT GROUP
Malware family tracked by Malpedia. ID: win.sparksrv
APT GROUP
Malware family tracked by Malpedia. ID: win.sparkle
APT GROUP
Malware family tracked by Malpedia. ID: win.spark
APT GROUP
SPACESHIP searches for files with a specified set of file extensions and copies them to
a removable drive. FireEye believes that SHIPSHAPE is used to copy SPACESHIP to a removable drive,
which could be used to infect another victim computer, including an air-gapped computer. SPACESHIP is
then used to steal documents from the air-gapped system, copying them to a removable drive inserted
into the SPACESHIP-infected system
APT GROUP
According to ESET, Spacecolon is a collection of malware written in Delphi, consisting of ScRansom, ScHackTool, ScInstaller, ScService, and ScPatcher.
APT GROUP
Malware family tracked by Malpedia. ID: win.soundbite
APT GROUP
According to Cisco Talos, this is a customized shellcode loader that has been observed to stage Mimikatz and CobaltStrike.
APT GROUP
SoulSearcher is a second-stage loader responsible for executing the Soul backdoor main module and parsing its configuration. SoulSearcher has multiple variants based on where the configuration and payload are located and on the type of configuration.
APT GROUP
Malware family tracked by Malpedia. ID: win.soul
APT GROUP
Malware family tracked by Malpedia. ID: win.sorgu
APT GROUP
Malware family tracked by Malpedia. ID: win.sorefang
APT GROUP
Malware family tracked by Malpedia. ID: win.soraya
APT GROUP
Malware family tracked by Malpedia. ID: win.sorano
APT GROUP
Malware family tracked by Malpedia. ID: win.somnia
APT GROUP
Malware family tracked by Malpedia. ID: win.sombrat
APT GROUPfinancial
Ransomware, written in .NET.
Infra: 🔗 solidb2jco63vbhx4sfi…
RSLUpdated: N/A
View profile →