Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,486 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.avoslocker
APT GROUPfinancialhigh
ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.
APT GROUP
Malware family tracked by Malpedia. ID: apk.titan
APT GROUP
Malware family tracked by Malpedia. ID: apk.luckycat
APT GROUP
Malware family tracked by Malpedia. ID: aix.fastcash
APT GROUP
Malware family tracked by Malpedia. ID: elf.rhysida
APT GROUPespionageadvanced
ELF version of win.revil targeting VMware ESXi hypervisors.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ragnarlocker
APT GROUPfinancialhigh
According to ThreatFabric, this is an Android banking trojan under active development as of July 2020. It is using TCP for C&C communication and targets Turkish banks.
APT GROUPfinancialhigh
According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024 conducting Big Game Hunting and double extortion campaigns.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: elf.gwisin
APT GROUP
According proofpoint, EvilNum is a backdoor that can be used for data theft or to load additional payloads. The malware includes multiple interesting components to evade detection and modify infection paths based on identified antivirus software.
APT GROUPfinancialhigh
According to MalwareBytes, the Dharma Ransomware family is installed manually by attackers hacking into computers over Remote Desktop Protocol Services (RDP). The attackers will scan the Internet for computers running RDP, usually on TCP port 3389, and then attempt to brute force the password for the computer.
Once they gain access to the computer they will install the ransomware and let it encrypt the computer. If the attackers are able to encrypt other computers on the network, they will attempt to do so as well.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: elf.darkside
APT GROUP
Malware family tracked by Malpedia. ID: elf.bqtlock
APT GROUPfinancialhigh
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: elf.blackmatter
APT GROUPespionageadvanced
ESXi encrypting ransomware, using a combination of the stream cipher ChaCha20 and RSA.
APT GROUPfinancialhigh
ESX and NAS modules for Babuk ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: elf.tsunami
APT GROUP
Malware family tracked by Malpedia. ID: elf.kuiper
APT GROUP
Malware family tracked by Malpedia. ID: js.tonrat
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: apk.bianlian
APT GROUP
Malware family tracked by Malpedia. ID: win.revstealer
APT GROUP
According to Proofpoint, IceCube is a JavaScript-based stealer likely developed with the assistance of a large language model, targeting Roundcube webmail instances. It escapes the webmail's iFrame context via DOM traversal to access the full document and the authentication session, then exfiltrates usernames, passwords, two-factor authentication material, cookies, and browser reconnaissance data (such as language, screen size, and form field values) via HTTP POST to its command-and-control server. The malware is heavily commented with well-marked execution phases, and incorporates self-cleanup routines, "fallbacks" for failed exploitation steps, and "deferred triggers" that hook browser events such as tab changes, mouse leaving the window, and the logout button to re-attempt exploitation. After successful server-side exploitation, it destroys both user and malware-initiated sessions to remove forensic evidence from the Roundcube server.
APT GROUP
According to Cisco Talos, JARLEASH is a JAVA-based backdoor deployed on attacker infrastructure and compromised systems with JAVA available, providing a web-based file management interface, FTP and SFTP servers, and a netcat server, with configuration comments written in Simplified Chinese.
APT GROUP
According to Cisco Talos, LONGLEASH is a new version of the previously disclosed SHORTLEASH backdoor, built from the same C++ codebase and compiled for Linux on MIPS using the Boost.Asio asynchronous networking library along with open-source components for protobuf processing and TLS, and it offers extensive proxying and tunneling capabilities such as reverse shells, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxies, SMTP, packet redirection, and the ability to act as an intermediate command and control server while self-removing if tampering is detected.
APT GROUP
According to Cisco Talos, DOGLEASH is a C-based passive backdoor for Linux networking devices that binds and listens on a hardcoded port, decodes incoming TCP data with a hardcoded password, spawns threads to run actions such as executing shell commands, reading and renaming files, reporting OS information, and executing code in memory.
APT GROUP
According to Acronis, MINIRECON is a shellcode-based implant derived from the Toneshell8 family, written in C/C++ and deployed in memory by SHARDLOADER after reconstruction from an obfuscated, XOR-decrypted payload. It retains core Toneshell characteristics such as PEB-walking to resolve kernel32.dll, a 13131313 hash multiplier for API resolution, an LCG-based session key, a 256-byte XOR beacon scheme, and an opcode-driven dispatcher supporting two parallel reverse shells, file upload/download, remote command execution, and a drop-and-execute chain. Its main evolution is in command-and-control communications, shifting to WebSocket-over-HTTPS beaconing via the native WinHTTP API with self-signed certificate handling and a proxy fallback to blend into enterprise environments.
APT GROUP
According to Acronis, ZOHOMURK is a newly identified DLL implant written in C/C++ that abuses the legitimate Zoho WorkDrive cloud storage service for command-and-control, data exfiltration and remote task execution. It is sideloaded via a signed Citrix Receiver binary dropped by its SHARDLOADER parent, with a single export function serving as the implant's entry point and timing-based anti-debug checks guarding key steps such as registry writes and initial beaconing. Capabilities include an interactive shell via a pipe, file upload/download handled through a small opcode-driven dispatcher, victim registration by creating folders on the operator's WorkDrive account, OAuth-based authentication with hardcoded credentials, a heartbeat/re-registration thread, and Run-key persistence established only after passing environment and timing checks
APT GROUP
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
APT GROUPespionageadvanced
According to Rapid7, this RAT loaded by Donut is a native 32-bit C++ remote access implant that is mapped and executed entirely in memory by a shellcode-based loader. It features extensive obfuscation and stealth characteristics, including control-flow flattening, dynamic API resolution, static CRT linking, and multiple anti-analysis checks for debuggers, sandboxes, virtualized environments, and geolocation. The malware fingerprints the host by collecting system and user information plus a full process list, then communicates with its command-and-control over HTTPS with fields protected using Salsa20-based encryption and layered encoding. Its core capabilities include recursive directory listing, downloading and executing additional payloads, interactive shell command execution, on-demand screenshot capture, and exfiltration of arbitrary files.
APT GROUPfinancialhigh
According to Zscaler, MLTBackdoor is a Windows post-exploitation backdoor likely written in C/C++ and compiled with an LLVM-based obfuscator that applies heavy mixed boolean-arithmetic and control-flow flattening, plus DJB2-based API hashing and indirect system calls to hinder analysis and evade hooks. It uses a custom binary protocol over TLS with elliptic-curve Diffie-Hellman key exchange and AES-GCM for encrypted C2 traffic, and includes a date-based domain generation algorithm (DGA) to maintain contact if primary C2 domains are unavailable. Natively, it provides a focused set of filesystem commands for uploading, downloading, listing, deleting, renaming, and creating files and folders. Its key feature is a built-in Beacon Object File loader compatible with a subset of Cobalt Strike-style BOF imports and its own syscall wrappers, allowing operators to dynamically extend capabilities for activities such as discovery, credential access, and lateral movement, which Zscaler links to ransomware-oriented operations.
APT GROUP
According to SentinelLabs, Gaslight is a DPRK-aligned macOS backdoor and infostealer written in Rust that communicates over the Telegram Bot API, using AES-GCM encryption layered on certificate-pinned TLS. The implant provides an interactive remote shell with generic capabilities for command execution, file exfiltration, process management, and configuration-driven persistence, and it can stage a Python-based stealer via a bundled installer that fetches a standalone CPython runtime at execution time. It collects browser data, system and process information, and keychain contents, packaging and uploading them through the same hardened command-and-control channel. A distinctive characteristic is its embedded multi-message prompt-injection payload designed to manipulate LLM-assisted analysis pipelines, along with runtime self-redaction of its bot token to prevent credential leakage in logs or crash artifacts.
APT GROUP
According to Picus Security, Showboat is a modular post-exploitation framework implemented as a 64-bit ELF binary targeting AMD x86-64 Linux systems, used for long-term, covert access rather than initial compromise or encryption. It retrieves an XOR-encrypted configuration from its command-and-control server, uses randomized sleep intervals, and wraps host telemetry (including system information, running processes, and screenshots) in an encrypted, base64-encoded JSON blob disguised inside PNG metadata for beaconing. The framework provides standard remote access capabilities such as file transfer, directory and filesystem manipulation, and configurable persistence. For stealth, it can download and compile an additional C-based component on the victim and leverage dynamic linker preload mechanisms to hook system-level functions and hide selected processes from userland monitoring tools.
APT GROUP
Malware family tracked by Malpedia. ID: win.solaris_loader
APT GROUP
According to Elastic Security Labs, CASTLESTEALER is a .NET-based information-stealing malware family that is delivered in-memory by the OXLOADER loader using DonutLoader-generated shellcode. It is embedded as an encrypted and compressed .NET assembly that is decrypted, decompressed, and reflectively executed in memory to minimize on-disk artifacts. The family uses AES-encrypted communications with its command-and-control infrastructure, with a characteristic hard-coded key that has been reused across samples. As an infostealer targeting Windows environments, it is designed to collect sensitive data (such as user credentials and other information) and interacts with the system in memory to support discovery and data exfiltration while evading conventional detection.
APT GROUP
Malware family tracked by Malpedia. ID: win.oxloader
APT GROUP
Malware family tracked by Malpedia. ID: win.sisron