Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
According to Zscaler, SHEETCREEP is a lightweight backdoor written in C# that uses Google Sheets for C2 communication.
APT GROUPfinancialhigh
Kaspersky Labs observed Andariel to drop this ransomware in one case within a series of attacks carried out against targets in South Korea in April 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.sharp_rhino
APT GROUP
SharPyShell is a tiny and obfuscated ASP.NET webshell that executes commands received by an encrypted channel compiling them in memory at runtime. SharPyShell supports only C# web applications that runs on .NET Framework >= 2.0 VB is not supported atm.
APT GROUP
According to its Github repository, SharpWMI is a C# implementation of various WMI functionality.
APT GROUP
Malware family tracked by Malpedia. ID: win.sharpstats
APT GROUP
The SharpStage backdoor is a .NET malware with backdoor capabilities. Its name is a derivative of the main activity class called “Stage_One”. SharpStage can take screenshots, run arbitrary commands and downloads additional payloads. It exfiltrates data from the infected machine to a dropbox account by implementing a dropbox client in its code. SharpStage was seen used by the Molerats group in targeted attacks in the middle east.
APT GROUP
This tool is made to simplify penetration testing of networks and to create a Swiss-army knife that is made for running on Windows which is often a requirement during insider threat simulation engagements.
APT GROUP
Malware family tracked by Malpedia. ID: win.sharpknot
APT GROUP
According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
APT GROUP
.NET reimplementation of Cobalt Strike beacon/stager
APT GROUP
Malware family tracked by Malpedia. ID: win.shark
APT GROUP
Malware family tracked by Malpedia. ID: win.shareip
APT GROUP
Malware family tracked by Malpedia. ID: win.shapeshift
APT GROUP
Malware family tracked by Malpedia. ID: win.shakti
APT GROUP
Malware family tracked by Malpedia. ID: win.shady_hammock
APT GROUP
Malware family tracked by Malpedia. ID: win.shadow_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.shadowpad
APT GROUP
Malware family tracked by Malpedia. ID: win.shadowhammer
APT GROUPfinancialhigh
Ransomware
A malicious IIS module that allows up/download of files, remote command execution, and using the compromised server as a hop into the network behind.
APT GROUP
ServHelper is written in Delphi and according to ProofPoint best classified as a backdoor. ProofPoint noticed two distinct variant - "tunnel" and "downloader" (citation): "The 'tunnel' variant has more features and focuses on setting up reverse SSH tunnels to allow the threat actor to access the infected host via Remote Desktop Protocol (RDP). Once ServHelper establishes remote desktop access, the malware contains functionality for the threat actor to 'hijack' legitimate user accounts or their web browser profiles and use them as they see fit. The 'downloader' variant is stripped of the tunneling and hijacking functionality and is used as a basic downloader."
APT GROUP
Malware family tracked by Malpedia. ID: win.serpico
Updated: 2026-08-04
View profile →
Malware family tracked by Malpedia. ID: win.serpent
APT GROUP
This malware is protected using VMProtect and related to the loading of KEYPLUG.
APT GROUP
Malware family tracked by Malpedia. ID: win.sepulcher
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.sendsafe
Malware family tracked by Malpedia. ID: win.selfmake
APT GROUPfinancialhigh
According to PCrisk, Sekhmet is ransomware. This malicious program operates by encrypting data and demanding ransom payments for decryption. During the encryption process, all affected files are appended with an extension, consisting of random characters (e.g. ".HrUSsw", ".WNgh", ".NdWfEr", etc.).
APT GROUP
Malware family tracked by Malpedia. ID: win.seinup
APT GROUP
simple tool to facilitate download and persistence of a next-stage tool; collects system information and metadata probably in an attempt to tell sandbox-environments apart from real targets on the server-side; uses domains of search engines like Google to check for Internet connectivity; XOR-based string obfuscation with a 16-byte key
APT GROUP
Malware family tracked by Malpedia. ID: win.sedreco
APT GROUP
Malware family tracked by Malpedia. ID: win.sedll
APT GROUP
SectopRAT, aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.
APT GROUPfinancialhigh
SecondHandTea is a full-featured Remote Access Trojan (RAT), closely related to BackbitingTea, the flagship backdoor used in the DangerousPassword campaigns (also known as SnatchCrypto). Both malware families appear to share a common codebase and are compiled within the same build environment. While they share most core functionality and supported commands, SecondHandTea differs from BackbitingTea variants in several technical aspects: - Configuration file paths - Network libraries: OpenSSL 1.1.0f vs. wolfSSL or Winsock TCP/IP - Encryption algorithms: AES-256 vs. RC4 - Compression methods: LZ4 vs. ZIP These differences suggest active development and customization efforts tailored to specific operational needs. The malware's name was inferred from its internal filename: SecondT_x64.exe. Between H2 2022 and Q1 2023, SecondHandTea was observed in targeted attacks against entities involved in cryptotrading and blockchain technology, indicating a continued focus on financially motivated cyber operations.
APT GROUP
Malware family tracked by Malpedia. ID: win.seasalt
APT GROUP
Backdoor written in Python 2, deployed with PyInstaller.
APT GROUP
Malware family tracked by Malpedia. ID: win.sdbbot
APT GROUP
ScrubCrypt is the rebranded "Jlaive" crypter, with a unique capability of .BAT packing