Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.slickshoes
APT GROUP
Malware family tracked by Malpedia. ID: win.slave
APT GROUPfinancial
slam — tracked by MISP Galaxy (ransomware).
Infra: 💬 encr9djfOJdew92nfjK9💬 encrKdm13nfKJNdwf7kd💬 encr5RhdkjNNJdwq62df+2 more
RSLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.skyplex
Updated: 2017-02-15
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.skynet
APT GROUP
Skuld, also known as TMPN Stealer, is an information-stealing malware written in Golang (Go) that emerged in May 2023.
APT GROUP
Malware family tracked by Malpedia. ID: win.skipper
APT GROUP
A Microsoft SQL Server backdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.skinnyboy
APT GROUP
Malware family tracked by Malpedia. ID: win.skimer
APT GROUP
Malware family tracked by Malpedia. ID: win.sisfader
APT GROUP
Malware family tracked by Malpedia. ID: win.sinowal
Malware family tracked by Malpedia. ID: win.simplefilemover
APT GROUP
Malware family tracked by Malpedia. ID: win.simda
APT GROUP
Malware family tracked by Malpedia. ID: win.siluhdur
Updated: 2018-07-24
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.silon
APT GROUP
Malware family tracked by Malpedia. ID: win.silent_sweeper
According to Mandiant, SILENTUPLOADER is an uploader written in MSIL that is dropped by DOSTEALER and is designed to work specifically in tandem with it. It checks for files in a specified folder every 30 seconds and uploads them to a remote server.
APT GROUP
Malware family tracked by Malpedia. ID: win.silentgh0st
APT GROUP
Malware family tracked by Malpedia. ID: win.sihost
APT GROUP
Malware family tracked by Malpedia. ID: win.sigloader
APT GROUP
Malware family tracked by Malpedia. ID: win.siggen6
Updated: 2016-12-28
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.siesta_graph
Malware family tracked by Malpedia. ID: win.sierras
APT GROUPfinancialhigh
Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
APT GROUPfinancialhigh
Ransomware used by threat actor group DEV-0530, attributed by MSTIC to North Korean origin.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sidewalk
APT GROUP
Malware family tracked by Malpedia. ID: win.sidetwist
APT GROUP
Malware family tracked by Malpedia. ID: win.shylock
APT GROUP
Malware family tracked by Malpedia. ID: win.shurl0ckr
APT GROUP
Malware family tracked by Malpedia. ID: win.shurk
APT GROUP
Malware family tracked by Malpedia. ID: win.shujin
APT GROUP
Malware family tracked by Malpedia. ID: win.shrinklocker
APT GROUPespionageadvanced
According to STRIKE, ShortLeash is a custom backdoor used to create an ORB network. It generates unique, self-signed TLS certificates with spoofed metadata for each node. Analysis of these certificates revealed over 1000 active nodes globally and victimology supports attribution to China-Nexus APTs.
APT GROUPespionageadvanced
SHIPSHAPE is malware developed by APT30 that allows propagation and exfiltration of data over removable devices. APT30 may use this capability to exfiltrate data across air-gaps.
APT GROUP
Malware family tracked by Malpedia. ID: win.shimrat
APT GROUPfinancialhigh
Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.
APT GROUP
According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine. It uses the Dropbox API for C2 and data exfiltration.
APT GROUPfinancialhigh
PCRIsk states that ShellLocker is a ransomware-type virus developed using .NET framework. It was first discovered by Jakub Kroustek and is virtually identical to another ransomware virus called Exotic. Following infiltration, this virus encrypts stored data (video, audio, etc.) and renames encrypted files using the "[random_characters].L0cked" pattern (e.g., "sample.jpg" might be renamed to "gd&=AA0fgoi.L0cked"). Following successful encryption, ShellLocker opens a pop-up window containing ransom-demand message.
Malware family tracked by Malpedia. ID: win.shellclient