Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
According to ESET Research, this is a loader that has the Mandarin Chinese symbol (yang in the Pinyin transliteration) as an icon in the resources. It also contains the string SampleIMESimplifiedQuanPin.txt, which suggests that it is probably based on the open-source project Sample IME, a TSF-based input method editor demo.
APT GROUP
Malware family tracked by Malpedia. ID: win.quantloader
APT GROUP
Malware family tracked by Malpedia. ID: win.qtbot
APT GROUP
According to F-Secure, this is a network worm with backdoor capabilities, which spreads itself under Win32 systems. The worm was reported in-the-wild in July-August, 2000. The worm itself is a Win32 executable file and about 120K long, written in MS Visual C++.
APT GROUPfinancialhigh
QBot is a modular information stealer also known as Qakbot or Pinkslipbot. It has been active for years since 2007. It has historically been known as a banking Trojan, meaning that it steals financial data from infected systems, and a loader using C2 servers for payload targeting and download.
APT GROUP
Malware family tracked by Malpedia. ID: win.qadars
APT GROUP
Malware family tracked by Malpedia. ID: win.qaccel
APT GROUP
Full-featured Python RAT compiled into an executable.
PyXie RAT functionality includes:
* Man-in-the-middle (MITM) Interception
* Web-injects
* Keylogging
* Credential harvesting
* Network Scanning
* Cookie theft
* Clearing logs
* Recording video
* Running arbitrary payloads
* Monitoring USB drives and exfiltrating data
* WebDav server
* Socks5 proxy
* Virtual Network Connection (VNC)
* Certificate theft
* Inventorying software
* Enumerating the domain with Sharphound
APT GROUPfinancialhigh
PyLocky is a ransomware that tries to pass off as Locky in its ransom note. It is written in Python and packaged with PyInstaller.
APT GROUP
According to Akamai, Pykspa is a worm that spreads via Skype by sending messages to other Skype users with download links. Once downloaded, Pykspa extracts personal information and communicates with its command and control servers (C2) using a domain generation algorithm (DGA).
APT GROUP
Malware family tracked by Malpedia. ID: win.pwnpos
APT GROUP
Malware family tracked by Malpedia. ID: win.pvzout
APT GROUP
The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS. One of these files (%SYSTEM%\WmiPrvMon.exe) is registered as a service and is used as a launcher for the second executable. This second executable (%SYSTEM%\wmimon.dll) has the functionality of a remote shell and can be considered the main payload of the attack.
APT GROUP
Malware family tracked by Malpedia. ID: win.putabmow
APT GROUP
Pushdo is usually classified as a "downloader" trojan - meaning its true purpose is to download and install additional malicious software. There are dozens of downloader trojan families out there, but Pushdo is actually more sophisticated than most, but that sophistication lies in the Pushdo control server rather than the trojan.
APT GROUP
ZScaler reported on a new Infostealer called PurpleWave, which is written in C++ and silently installs itself onto a user’s system. It connects to a command and control (C&C) server to send system information and installs new malware onto the infected system.
The author of this malware is advertising and selling PurpleWave stealer on Russian cybercrime forums for 5,000 RUB (US$68) with lifetime updates and 4,000 RUB (US$54) with only two updates.
APT GROUP
Malware family tracked by Malpedia. ID: win.purpleink
APT GROUP
Purple Fox uses msi.dll function, 'MsiInstallProductA', to download and execute its payload. The payload is a .msi file that contains encrypted shellcode including 32-bit and 64-bit versions. once executed the system will be restarted and uses the 'PendingFileRenameOperations' registry to rename it's components.
Upon restart the rootkit capability of Purple Fox is invoked. It creates a suspended svchost process and injects a DLL that will create a driver with the rootkit capability.
The latest version of Purple Fox abuses open-source code to enable it's rootkit components, which includes hiding and protecting its files and registry entries. It also abuses a file utility software to hide its DLL component, which deters reverse engineering.
APT GROUP
According to Morphisec, this RAT combines advanced in-memory execution, API and resource resolution at runtime, and layered evasion techniques. They have named it ‘Resolver’ due to its heavy reliance on runtime resolution mechanisms and dynamic resource handling, which make static and behavioral analysis significantly more difficult.
APT GROUP
PureLogs, also known as PureLog Stealer, is an infostealer malware from the Pure family that aims to steal sensitive information from infected devices.
APT GROUP
According to zscaler, PureCrypter is a fully-featured loader being sold since at least March 2021
The malware has been observed distributing a variety of remote access trojans and information stealers
The loader is a .NET executable obfuscated with SmartAssembly and makes use of compression, encryption and obfuscation to evade antivirus software products
PureCrypter features provide persistence, injection and defense mechanisms that are configurable in Google’s Protocol Buffer message format
APT GROUP
Pupy is an open-source, cross-platform RAT and post-exploitation framework mainly written in python. Pupy can be loaded from various loaders, including PE EXE, reflective DLL, Linux ELF, pure python, powershell and APK. Most of the loaders bundle an embedded python runtime, python library modules in source/compiled/native forms as well as a flexible configuration. They bootstrap a python runtime environment mostly in-memory for the later stages of pupy to run in. Pupy can communicate using various transports, migrate into processes, load remote python code, python packages and python C-extensions from memory.
APT GROUP
Malware family tracked by Malpedia. ID: win.punkey_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.pulsepack
APT GROUP
According to Broadcom, Pulsar RAT is a derivation of Quasar RAT, which has miscellaneous functionality including keylogging, cryptocurrency wallet clipping, infostealing, file management, remote shell and command execution, among others. The data theft capabilities of this malware include collection and exfiltration of sensitive information such as credentials, cookies, cryptowallets, session files and data stored in the system web browsers, etc.
APT GROUP
Malware family tracked by Malpedia. ID: win.pulsartea
APT GROUP
Malware family tracked by Malpedia. ID: win.pubnubrat
APT GROUP
Malware family tracked by Malpedia. ID: win.pubload
APT GROUP
According to Seqrite, this is a loader for a follow-up side-loaded and in memory-staged Cobalt Strike Beacon. It uses API hashing (SDBM) and pulls the next stage from Google Drive using hardcoded access credentials.
APT GROUP
Malware family tracked by Malpedia. ID: win.pteranodon
APT GROUP
Citizenlab notes that PC Surveillance System (PSS) is a commercial spyware product offered by Cyberbit and marketed to intelligence and law enforcement agencies.
APT GROUP
Malware family tracked by Malpedia. ID: win.pslogger
APT GROUPfinancialhigh
According to Matthew Mesa, this is a modular bot. The name stems from the string PsiXMainModule in binaries until mid of September 2018.
In binaries, apart from BotModule and MainModule, references to the following Modules have be observed:
BrowserModule
BTCModule
ComplexModule
KeyLoggerModule
OutlookModule
ProcessModule
RansomwareModule
SkypeModule
APT GROUP
According to PCrisk, PseudoManuscrypt is the name of the malware that spies on victims. It is similar to another malware called Manuscrypt. We have discovered PseudoManuscrypt while checking installers for pirated software (one of the examples is a fake pirated installer for SolarWinds - a network monitoring software).
APT GROUP
Malware family tracked by Malpedia. ID: win.prynt_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.protonbot
APT GROUP
Malware family tracked by Malpedia. ID: win.proto8_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.proteus
APT GROUP
Malware family tracked by Malpedia. ID: elf.prometei
APT GROUP
Malware family tracked by Malpedia. ID: win.project_wood