Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Information gathering and downloading tool used to deliver second stage malware to the infected system
APT GROUPfinancialhigh
The PetrWrap Trojan is written in C and compiled in MS Visual Studio. It carries a sample of the Petya ransomware v3 inside its data section and uses Petya to infect the victim’s machine. What’s more, PetrWrap implements its own cryptographic routines and modifies the code of Petya in runtime to control its execution. This allows the criminals behind PetrWrap to hide the fact that they are using Petya during infection.
APT GROUP
Malware family tracked by Malpedia. ID: win.petit_potato
APT GROUP
Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson appearances. Peppy communicates to its C&C over HTTP and utilizes SQLite for much of its internal functionality and tracking of exfiltrated files. The primary purpose of Peppy may be the automated exfiltration of potentially interesting files and keylogs. Once Peppy successfully communicates to its C&C, the keylogging and exfiltration of files using configurable search parameters begins. Files are exfiltrated using HTTP POST requests.
APT GROUP
Malware family tracked by Malpedia. ID: win.pennywise
APT GROUP
Malware family tracked by Malpedia. ID: win.penco
APT GROUP
Malware family tracked by Malpedia. ID: win.pekraut
APT GROUP
PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks. In May 2020, ESET mentioned that they found mysterious samples of PeddleCheap packed with a custom packer so far exclusively attributed to Winnti.
APT GROUP
Malware family tracked by Malpedia. ID: win.pebbledash
APT GROUP
PcShare is a open-source backdoor which has been seen modified and used by Chinese threat actors, mainly attacking countries in South East Asia.
APT GROUP
According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly. It identifies connected storage media, creates one thread per drive and volume for every path recorded and overwrites artifacts with randomly generated bytes. The wiper also reads multiple file systems attributes from NTFS and overwrites them as well. PathWiper additionally destroys files on disk by overwriting them with randomized bytes.
APT GROUP
Malware family tracked by Malpedia. ID: win.pathloader
APT GROUPfinancialhigh
PartyTicket is a Go-written ransomware, which was described as a poorly designed one by Zscaler. According to Brett Stone-Gross this malware is likely intended to be a diversion from the Hermetic wiper (aka. KillDisk.NCV, DriveSlayer) attack.
APT GROUP
According to Microsoft, Parite is a family of polymorphic file infectors that targets computers running Microsoft Windows. The virus infects .exe and .scr executable files on the local file system and on writeable network shares. In turn, the infected executable files perform operations that cause other .exe and .scr files to become infected.
parasite http
Technical ID: parasite_http
APT GROUP
Malware family tracked by Malpedia. ID: win.parasite_http
APT GROUP
Parallax is a Remote Access Trojan used by attackers to gain access to a victim's machine. It was involved in one of the many infamous "coronamalware" campaigns. Basically, the attackers abused the COVID-19 pandemic news to lure victims into opening themed emails spreading parallax.
APT GROUP
Malware family tracked by Malpedia. ID: win.paradies_clipper
APT GROUP
A multi-platform RAT written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.pandora_rat
APT GROUP
According to PCrisk, Panda is the name of a malicious program, which is classified as a stealer. It is a new variant of CollectorStealer.
The aim of this malware is to extract and exfiltrate sensitive and personal information from infected devices. Panda primarily targets data relating to cryptocurrency wallets.
This piece of malicious software has been observed being actively distributed via spam campaigns - large-scale operations during which thousands of scam emails are sent. The spam mail proliferating Panda stealer heavily targeted users from the United States, Germany, Japan, and Australia.
The deceptive email letters concerned business-related topics (e.g., fake product quote requests, etc.). Panda stealer is a dangerous program, and as such - its infections must be removed immediately upon detection.
APT GROUPfinancialhigh
According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*). Fox IT discovered it in February 2016.
This banking trojan uses the infamous ATS (Automatic Transfer System/Scripts) to automate online bank portal actions.
The baseconfig (c2, crypto material, botnet name, version) is embedded in the malware itself. It then obtains a dynamic config from the c2, with further information about how to grab the webinjects and additional modules, such as vnc, backsocks and grabber.
Panda does have some DGA implemented, but according to Arbor, a bug prevents it from using it.
APT GROUP
Paladin RAT is a variant of Gh0st RAT used by PittyPanda active since at least 2011.
APT GROUP
Malware family tracked by Malpedia. ID: win.ozone
APT GROUP
Malware family tracked by Malpedia. ID: win.ozh_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.oxtarat
APT GROUP
Kaspersky describes this as a OWA add-on that has credential stealing capabilities.
APT GROUP
Malware family tracked by Malpedia. ID: win.owlproxy
APT GROUP
Malware family tracked by Malpedia. ID: win.owaauth
APT GROUP
Malware family tracked by Malpedia. ID: win.ovidiystealer
APT GROUP
Malware family tracked by Malpedia. ID: win.overlay_rat
APT GROUP
According to MITRE, OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Ember Bear since at least March 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.outlook_backdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.ousaban
APT GROUP
Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums. It collects different types of data (cryptocurrency wallets, saved passwords, files matching an attacker-defined pattern etc) and it exfiltrates it in a zip file uploaded to the attacker's panel.
APT GROUP
Malware family tracked by Malpedia. ID: win.orpcbackdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.originlogger
APT GROUP
OriginBot is a modular information stealer which can also download and execute other malicious payloads.