Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
Malware family tracked by Malpedia. ID: win.project_hook
APT GROUP
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
APT GROUP
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads. The loader implements anti-analysis techniques, fingerprints the compromised host and reports statistics to its C2 server.
Malware family tracked by Malpedia. ID: win.princess_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.prilex
APT GROUP
Malware family tracked by Malpedia. ID: win.prikormka
APT GROUPfinancialhigh
According to PCrisk, Prestige is ransomware - malware that prevents victims from accessing (opening) their files by encrypting them. Additionally, Prestige appends the ".enc" extension to filenames and drops the "README" file containing a ransom note. An example of how this ransomware modifies filenames: it renames "1.jpg" to "1.jpg.enc", "2.png" to "2.png.enc", and so forth.
Predator is a feature-rich information stealer. It is sold on hacking forums as a bundle which includes: Payload builder and Command and Control web panel. It is able to grab passwords from browsers, replace cryptocurrency wallets, and take photos from the web-camera. It is developed by using a modular approach so that criminals may add more sophisticated tools on top of the it.
prb backdoor
Technical ID: prb_backdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.prb_backdoor
APT GROUP
QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor. Its payloads are often saved to C:\windows\temp\
APT GROUP
A malware of the gozi group, developed on the base of isfb. It uses Office Macros and PowerShell in documents distributed in e-mail messages.
Malware family tracked by Malpedia. ID: win.powershellrunner
APT GROUP
Malware family tracked by Malpedia. ID: win.powerloader
APT GROUP
Malware family tracked by Malpedia. ID: win.powerkatz
APT GROUP
Malware family tracked by Malpedia. ID: win.powerduke
APT GROUP
Malware family tracked by Malpedia. ID: win.powercat
APT GROUP
.NET variant of ps1.powerton.
APT GROUP
Malware family tracked by Malpedia. ID: win.poweliks
APT GROUPfinancialhigh
According to Trend Micro, Povlsomware (Ransom.MSIL.POVLSOM.THBAOBA) is a proof-of-concept (POC) ransomware first released in November 2020 which, according to their Github page, is used to “securely” test the ransomware protection capabilities of security vendor products.
Malware family tracked by Malpedia. ID: win.poulight_stealer
APT GROUPespionageadvanced
PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project. In 2022-2023, it was deployed against targets like a newspaper organization, agriculture-related entity or a software vendor. The initial access was usually achieved by exploiting vulnerabilities in widely-used software in South Korea. It collects various information about the victim’s computer, such as computer name, product name, OS details, system uptime, CPU information, system locale, time zone, network status, and malware configuration. PostNapTea uses AES for encryption and decryption ot network traffic. There is a constant prefix SIGNBT occuring in its HTTP POST requests. The prefix is concatenated with 2 characters that identify the communication stage: • LG: logging into the C&C server • KE: acknowledging the succesful login to the C&C • FI: sending the status of a failed operation • SR: sending the status of a successful operation • GC: getting the next command There are five classes that represent command groups: • CCButton: for file manipulation and screen capturing • CCBitmap: for network commands, implementing functionality of Windows commands often abused by attackers, like sc, reg, arp, net, ver, wmic, ping, whoami, netstat, tracert, lookup, ipconfig, systeminfo, and netsh advfirewall. • CCComboBox: for file system management • CCList: for process management • CCBrush: for control of the malware itself It stores its configuration in JSON format. It resolves the Windows APIs it requires during runtime, via the Fowler–Noll–Vo (FNV) hash function. Its internal name in the version-information resource is usually ppcsnap.dll or pconsnap.dll, which loosely inspired its code name.
APT GROUP
Malware family tracked by Malpedia. ID: win.poslurp
APT GROUP
PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python3 implants with payloads written in PowerShell v2 and v4, C++ and C# source code, a variety of executables, DLLs and raw shellcode in addition to a Python3 payload. These enable C2 functionality on a wide range of devices and operating systems, including Windows, *nix and OSX.
Malware family tracked by Malpedia. ID: win.poscardstealer
APT GROUP
Malware family tracked by Malpedia. ID: win.portstarter
APT GROUP
Malware family tracked by Malpedia. ID: win.portless
APT GROUP
Malware family tracked by Malpedia. ID: win.portdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.popcorn_time
Updated: 2017-02-15
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.poorweb
APT GROUP
According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode signature. This malware has been observed being used by UNC3944.
Malware family tracked by Malpedia. ID: win.poohmilk
APT GROUP
According to KnowBe4, Pony Stealer is a password stealer that can decrypt or unlock passwords for over 110 different applications including VPN, FTP, email, instant messaging, web browsers and much more. Pony Stealer is very dangerous and once it infects a PC it will turn the device into a botnet, allowing it to use the PCs it infects to infect other PCs.
APT GROUP
Malware family tracked by Malpedia. ID: win.polyglotduke
APT GROUP
Malware family tracked by Malpedia. ID: win.polpo
APT GROUP
Malware family tracked by Malpedia. ID: win.poldat
APT GROUP
Malware family tracked by Malpedia. ID: win.poison_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.poison_ivy
APT GROUP
According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities. The malware is capable of registry or service persistence, self-removal, plug-in execution, and network connection forwarding. POISONPLUG has been observed using social platforms to host encoded C&C commands.
APT GROUP
Malware family tracked by Malpedia. ID: win.poco_rat
APT GROUP
uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure overlap with X-Agent, probably in use since mid-2018