Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,719 entities
APT GROUPfinancial
SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
Infra: 🔗 nj5qix45sxnl4h4og6hc…🔗 nz4z6ruzcekriti5cjji…📁 qkzxzeabulbbaevqkoy2…+10 more
RSLUpdated: 2026-08-04
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.safenet
APT GROUP
Malware family tracked by Malpedia. ID: win.saefko
APT GROUP
According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various injection techniques to execute malicious payloads. SADBRIDGE abuses legitimate applications such as x64dbg.exe and MonitoringHost.exe to load malicious DLLs like x64bridge.dll and HealthServiceRuntime.dll, which leads to subsequent stages and shellcodes.
APT GROUP
Information Stealer that searches for sensitive documents and uploads its results to an FTP server. Skips files with known Ryuk extensions.
APT GROUPfinancialhigh
Ryuk is a ransomware which encrypts its victim's files and asks for a ransom via bitcoin to release the original files. It is has been observed being used to attack companies or professional environments. Cybersecurity experts figured out that Ryuk and Hermes ransomware shares pieces of codes. Hermes is commodity ransomware that has been observed for sale on dark-net forums and used by multiple threat actors.
APT GROUP
According to Proofpoint, RustyClaw is a downloader written in Rust
APT GROUP
Written in Rust and
designed for both Windows and Linux environments, RustyRocket enables WorldLeaks affiliates to steal data
through heavily obfuscated, multi-layered encrypted tunnels that can be exceptionally difficult to detect using
traditional network monitoring.
APT GROUPespionageadvanced
Rustonotto, active since June 2025, is a Rust-compiled malware, representing the first known instance of APT37 leveraging Rust-based malware to target Windows systems.
APT GROUP
Malware family tracked by Malpedia. ID: win.rustock
APT GROUP
Malware family tracked by Malpedia. ID: osx.rustbucket
APT GROUP
Malware family tracked by Malpedia. ID: win.rurktar
APT GROUPfinancialhigh
RURansom shows characteristics of typical ransomware, but despite its name, TrendMicro's assumptions after analysis showed that this malware is more a wiper than ransomware, because the irreversible destruction of encrypted files.
APT GROUP
NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files. When the trojan is loaded onto a system, it executes the first DLL. This is used to disable anti-malware solutions, unpack and execute the main RAT DLL, and gain persistence. The trojan installs a Windows batch file dx.bat that attempts to kill the daumcleaner.exe task, a Korean security program. The file then attempts to remove itself. Once the second DLL is loaded into memory, the first DLL overwrites the IP address for the control server to change the address the trojan communicates with. The second DLL gathers information about the victim's system, including its operating system and driver and processor information. The RAT can log user keystrokes, copy the clipboard, delete files, compress files, clear event logs, shut down the machine, and more. The second DLL also uses several anti-bugging techniques.
APT GROUP
Malware family tracked by Malpedia. ID: win.rumish
APT GROUP
Malware family tracked by Malpedia. ID: win.rugmi
APT GROUP
Malware family tracked by Malpedia. ID: win.ruckguv
APT GROUP
Rubeus is a C# toolset for raw Kerberos interaction and abuses.
APT GROUP
Malware family tracked by Malpedia. ID: win.rtpos
APT GROUPfinancial
rtm locker — tracked by MISP Galaxy (ransomware).
Infra: 🔗 nv4addu4insb7x6aagdv…💬 3wugtklp46ufx7dnr6j5…💬 nvfutdbq3ubteaxj4m2j…
RSLUpdated: 2026-08-04
View profile →APT GROUP
[RTM](https://attack.mitre.org/groups/G0048) is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the same name ([RTM](https://attack.mitre.org/software/S0148)). (Citation: ESET RTM Feb 2017)
T1102.001T1219.002T1189
APT GROUP
Malware family tracked by Malpedia. ID: win.rozena
APT GROUPfinancialhigh
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.
APT GROUPespionageadvanced
RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
APT GROUP
RoyalCli is a backdoor which appears to be an evolution of BS2005 and uses familiar encryption and encoding routines. The name RoyalCli was chosen by us due to a debugging path left in the binary. RoyalCli and BS2005 both communicate with the attacker's command and control (C2) through Internet Explorer (IE) by using the COM interface IWebBrowser2.
APT GROUP
Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves. It is part of the Carberp source code leak (https://github.com/nyx0/Rovnix). Rovnix has been used to protect Gozi ISFB, ReactorBot and Rerdom (at least).
APT GROUP
Malware family tracked by Malpedia. ID: win.rover
APT GROUPfinancialhigh
Ransomware that was discovered over the last months of 2016 and likely based on Gomasom, another ransomware family.
APT GROUP
A DLL backdoor distributed by Raspberry Robin. According to Avast Decoded, Roshtyak belongs to one of the best-protected malware strains they have ever seen.
APT GROUP
Malware family tracked by Malpedia. ID: win.roseam
APT GROUP
Malware family tracked by Malpedia. ID: win.rorschach
APT GROUP
Malware family tracked by Malpedia. ID: win.roopy
APT GROUP
Malware family tracked by Malpedia. ID: win.roopirs
APT GROUPfinancial
According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them. It also modifies filenames and creates a text file/ransom note (HowToRestoreYourFiles.txt). Rook renames files by appending the .Rook extension. For example, it renames 1.jpg to 1.jpg.Rook, 2.jpg to 2.jpg.Rook.
Infra: 🔗 gamol6n6p2p4c3ad7gxm…
RSLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.roningloader
APT GROUP
Malware family tracked by Malpedia. ID: win.romeos
APT GROUPfinancialhigh
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.
APT GROUP
Malware family tracked by Malpedia. ID: win.rombertik
APT GROUP
Malware family tracked by Malpedia. ID: win.roll_sling