Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or PowHeartBeat. PNGLoad has capabilities to download and execute additional payloads from a C&C server, which is likely how the attackers have deployed PNGLoad on systems compromised with PowHeartBeat. PNGLoad is a loader that uses bytes from PNG files to create a payload to execute. It is a 64-bit .NET executable - obfuscated with .NET Reactor - that masquerades as legitimate software.
APT GROUP
Malware family tracked by Malpedia. ID: win.pngdowner
APT GROUP
Malware family tracked by Malpedia. ID: win.plurox
APT GROUP
Malware family tracked by Malpedia. ID: win.ployx
APT GROUP
Malware family tracked by Malpedia. ID: win.ploutus_atm
APT GROUP
Malware family tracked by Malpedia. ID: elf.plead
APT GROUP
Malware family tracked by Malpedia. ID: win.playwork
APT GROUP
Malware family tracked by Malpedia. ID: win.plaintee
APT GROUP
Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref: fortinet). In the beginning of 2015, webinject capability was added according to /Kleissner/Kafeine/iSight using the infamous ATS.
APT GROUP
Malware family tracked by Malpedia. ID: win.pittytiger_rat
APT GROUP
According to TG Soft, Pitou has beeen released on April 2014. It maybe an evolution of the rootkit "Srzizbi" developed on 2008. Pitou is a spambot, the main goal is send spam form the computer of victim.
APT GROUP
Malware family tracked by Malpedia. ID: win.pirpi
APT GROUP
Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.
APT GROUP
Malware family tracked by Malpedia. ID: win.pipemon
APT GROUP
Malware family tracked by Malpedia. ID: win.pipemagic
APT GROUP
Malware family tracked by Malpedia. ID: win.pipcreat
APT GROUP
Malware family tracked by Malpedia. ID: win.pingback
APT GROUP
Malware family tracked by Malpedia. ID: win.pinegrove
APT GROUP
According to F-Secure, the PinchDuke information stealer gathers system configuration information, steals user credentials, and collects user files from the compromised host transferring these via HTTP(S) to a C&C server. F-Secure believes that PinchDuke’s credential stealing functionality is based on the source code of the Pinch credential stealing malware (also known as LdPinch) that was developed in the early 2000s and has later been openly distributed on underground forums.
APT GROUP
According to FireEye, PILLOWMINT is a Point-of-Sale malware tool used to scrape track 1 and track 2 payment card data from memory.
Scraped payment card data is encrypted and stored in the registry and as plaintext in a file (T1074: Data Staged)
Contains additional backdoor capabilities including:
Running processes
Downloading and executing files (T1105: Remote File Copy)
Downloading and injecting DLLs (T1055: Process Injection)
Communicates with a command and control (C2) server over HTTP using AES encrypted messages
(T1071: Standard Application Layer Protocol)
(T1032: Standard Cryptographic Protocol)
APT GROUP
Introducing Pikabot, an emerging malware family that comprises a downloader/installer, a loader, and a core backdoor component. Despite being in the early stages of development, it already demonstrates advanced techniques in evasion, injection, and anti-analysis. Notably, the loader component incorporates an array of sophisticated anti-debugging and anti-VM measures inspired by the open-source Al-Khaser project, while leveraging steganography to conceal its payload. Additionally, Pikabot utilizes a proprietary C2 framework and supports a diverse range of commands, encompassing host enumeration and advanced secondary payload injection options.
APT GROUP
Malware family tracked by Malpedia. ID: win.pierogi
APT GROUP
According to Mandiant, PIEHOP is a disruption tool written in Python and packaged with PyInstaller version 2.1+ that has the capability to connect to a user supplied remote MSSQL server for uploading files and issuing remote commands to a RTU.
PIEHOP expects its main function to be called via another Python file, supplying either the argument control=True or upload=True. At a minimum, it requires the following arguments: oik, user, and pwd, and if called with control=True, it must also be supplied with iec104.
APT GROUPespionageadvanced
PICKPOCKET is a credential theft tool that dumps the user's website login credentials from Chrome, Firefox, and Internet Explorer to a file. This tool was previously observed solely utilized by APT34.
APT GROUP
Malware family tracked by Malpedia. ID: win.picasso_loader
APT GROUP
A loader used to deliver IcedID, fetching a fake image from which payloads are extracted.
APT GROUPfinancialhigh
PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e. for example it does not have any functionality to exfiltrate the host information. This new variant is observed as a follow-on payload in a TA542 Emotet campaign back in November'22. contains a static URL to download a "Bot Pack" file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud.
APT GROUP
PHOTOFORK is a downloader which is a modified version of GZIPLOADER. It was first detected in February 2023 and was distributed by TA581 along with an unattributed threat activity cluster that facilitated initial access. In this version, the configuration file is no longer encrypted using a simple XOR algorithm with a 64-byte key. Instead, it uses a custom algorithm previously used by the Standard core loader. This algorithm decrypts DLL strings that are needed to resolve handles to the necessary DLLs later on. The strings are decrypted using an algorithm that splits the data into DWORDs and XORs it against a random key. The main objective of PHOTOFORK remains the same as GZIPLOADER, i.e. to deliver an encrypted bot and core DLL loader (forked) that loads the Forked ICEDID bot into memory using a custom PE format.
APT GROUP
Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers. The name Trik is derived from PDB strings.
APT GROUP
Phoreal is a very simple backdoor that is capable of creating a reverse shell, performing simple file I/O and top-level window enumeration. It communicates to a list of four preconfigured C2 servers via ICMP on port 53
APT GROUP
Malware family tracked by Malpedia. ID: win.phonk
APT GROUP
Malware family tracked by Malpedia. ID: win.phoenix_locker
APT GROUP
Keylogger, information stealer.
APT GROUP
Malware family tracked by Malpedia. ID: win.philadelphia_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.phemedrone_stealer
APT GROUP
According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
APT GROUP
PhantomVAI Loader is a malicious multi-stage infection chain used to distribute the Katz Stealer information-stealing malware or other malicious payloads.
APT GROUPfinancialhigh
According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare. It has been active since 2023 and is known for consistently targeting Russia. PhantomCore collects the victim’s information, including the public IP address, to gain detailed insights into the target before deploying the final-stage payload or executing additional commands on the compromised system. PhantomCore is known to deploy ransomware payloads such as LockBit and Babuk, inflicting significant damage on the victim’s systems.
APT GROUP
Malware family tracked by Malpedia. ID: win.phandoor