Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.raton_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.ratel
APT GROUP
Malware family tracked by Malpedia. ID: win.ratankbapos
APT GROUP
This is a backdoor that establishes persistence using the Startup folder. It communicates to its C&C server using HTTPS and a static HTTP User-Agent string. QUICKRIDE is capable of gathering information about the system, downloading and loading executables, and uninstalling itself. It was leveraged against banks in Poland.
Worm spread by external drives that leverages Windows Installer to reach out to QNAP-associated domains and download a malicious DLL.
APT GROUPfinancialhigh
This ransomware encrypts all user’s data on the PC (photos, documents, excel tables, music, videos, etc), adds its specific extension to every file, and creates the HOW_TO_DECYPHER_FILES.txt files in every folder which contains encrypted files.
APT GROUP
Malware family tracked by Malpedia. ID: win.rarog
APT GROUP
A spy trojan is a type of malware that has the capability to gather information from the infected system without consent from the user. This information is then sent to a remote attacker.
APT GROUPfinancialhigh
InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems and also encrypts any new files that are created. It does this by creating auto-runs that are designed to launch the ransomware and display the ransom note every time the infected system is started.
APT GROUPfinancialhigh
Ransomware SNC is a ransomware who encrypts files and asks for a variable amount of Bitcoin before releasing the decryption key to your files. The threat actor asks to be contacted for negotiating the right ransom fee.
APT GROUP
Malware family tracked by Malpedia. ID: win.ransomlock
APT GROUPfinancial
The group emerged in mid-February 2024 and has already listed several organizations as alleged victims of their attacks, resulting from extortion through encryption and data leaks.<br> <br> The announcement of the sale of the new Ransomware-as-a-Service (RaaS) by RansomHub was published on one of the Russian-origin forums used by cybercrime to advertise malicious services, known as RAMP4U (or RAMP). A user with the nickname and persona of 'koley' announced the affiliate program on February 2, 2024.<br> <br> In the new RaaS announcement, it was mentioned that the money laundering operation of the paid ransoms is the responsibility of the affiliate. This means that all communication and sending of the decryptor to the victim are done through chat. The split of this RaaS would be 90% of the value for the affiliate and 10% for the developer, who in this case would be the persona of Koley.<br> <br> Furthermore, according to the publication, the ransomware payload is written in Golang language, uses the asymmetric algorithm based on x25519, and encryption algorithms AES256, ChaCha20, and xChaCha20, standing out for its speed. The encryption is obfuscated using AST.<br> <br> The payload would support network propagation and encryption of data both in secure and local mode. According to Koley, the ransomware is designed to operate on platforms such as Windows, Linux, and ESXi, as well as other architectures such as ARM and MIPS.<br> <br> As pointed out by the panel and already highlighted by the intelligence team, Koley stated that the panel uses a .onion domain, allowing the affiliate to organize and manage targets and chat rooms, view access logs, automatically respond when offline, and create private blog pages.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 ransomxifxwc5eteopdo📁 mjmru3yz65o5szsp4rmk📁 an2ce4pqpf2ipvba2dju+43 more
RLUpdated: 2026-08-04
View profile →
APT GROUPfinancial
RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
Infra: 🔗 rnsm777cdsjrsdlbs4v5🔗 zubllg7o774lgc4rdxmf💬 jbdg4buq6jd7ed3rd6cy+1 more
RLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.ransoc
APT GROUP
Malware family tracked by Malpedia. ID: win.ranscam
APT GROUPfinancial
Ranion is a ransomware-as-a-service operation first observed in April 2017 that offers a low-barrier, pay-upfront model where affiliates keep 100% of ransom payments, with packages ranging from $150 to $1,900, making it a popular entry point for less experienced attackers.
Infra: 🔗 ranionv3j2o7wrn3um6d🔗 ssg3qvvuilseciagm4ni
RLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.ranbyus
APT GROUP
Malware family tracked by Malpedia. ID: win.ramsay
APT GROUPfinancialhigh
According to Check Point, Ramnit is primarily a banking trojan, meaning that its purpose is to steal login credentials for online banking, which cybercriminals can sell or use in future attacks. For this reason, Ramnit primarily targets individuals rather than focusing on particular industries. Ramnit campaigns have been observed to target organizations in particular industries. For example, a 2019 campaign targeted financial organizations in the United Kingdom, Italy, and Canada.
APT GROUP
Malware family tracked by Malpedia. ID: win.ramdo
Updated: 2016-04-20
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rambo
APT GROUPfinancial
RALord is a ransomware group identified in March 2025 operating within the NOVA RaaS platform, targeting healthcare, education, hospitality, and IT sectors across multiple continents, using a Rust-based payload with an 85/15 affiliate revenue split; it later rebranded as "Nova."
Infra: 🔗 ralordqe33mpufkpsr6z🔗 ralord3htj7v2dkavss2🔗 ralordt7gywtkkkkq2su+1 more
RLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rakhni
APT GROUP
Raindrop is a loader for Cobalt Strike that was observed in the SolarWinds attack.
APT GROUP
According to Trend Micro, RAILSETTER is a persistence installer component designed to work with RAILLOAD. Its main functions include: Copying and renaming RAILLOAD’s intended host from System32 to the intended target directory; Timestomping RAILLOAD and its host’s create, access, and modify time; Creating a scheduled task for persistence.
APT GROUPfinancial
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.
Infra: 🔗 wobpitin77vdsdiswr43🔗 sushlnty2j7qdzy64qnv
RLUpdated: N/A
View profile →
APT GROUPfinancial
Ragnar Locker was an elite ransomware group active from December 2019 to October 2023 that targeted large enterprises and critical infrastructure — including Capcom and Campari — claiming at least 168 victims before being taken down by a Europol-led international law enforcement operation in October 2023.
Infra: 🔗 rgleak7op734elep.oni🔗 rgleaktxuey67yrgspmh📁 p6o7m73ujalhgkiv.oni+7 more
RLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.radrat
APT GROUP
Malware family tracked by Malpedia. ID: win.radamant
Updated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rad
Racket Downloader is an HTTP(S) downloader. It uses a custom substitution cipher for decryption of its character strings, and RC5 with a 256-bit key for encryption and decryption of network traffic. It sends an HTTP POST request containing a particular value that inspired its name, like "?product_field=racket" or "prd_fld=racket". Racket Downloader was deployed against South Korean targets running the Initech INISAFE CrossWeb EX software in Q2 2021 and Q1 2022.
APT GROUP
Raccoon Stealer is a malware reportedly sold for $75 a week or $200 a month. It gathers personal information including passwords, browser cookies and autofill data, as well as cryptowallet details. Additionally, Raccoon Stealer records system information such as IP addresses and geo-location data.
APT GROUP
Malware family tracked by Malpedia. ID: win.r980
APT GROUP
According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys & values * Services * TCP & UDP connections * Junctions, named pipes, scheduled tasks
APT GROUP
Malware family tracked by Malpedia. ID: win.qvoidstealer
APT GROUP
Qulab is an AutoIT Malware focusing on stealing & clipping content from victim's machines.
APT GROUP
QuiteRAT is a simple remote access trojan written with the help of Qt libraries. After sending preliminary system information to its C&C server, it expects a response containing either a supported command code or an actual Windows command (like systeminfo or ipconfig with parameters) to execute. It was deployed in a campaign exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966).
APT GROUP
According to X-Force, this is a loader module written in .NET languages for which ahead-of-time (AOT) compilation is used.
APT GROUP
According to Microsoft, this is a heavily obfuscated .NET malware, primarily geared towards the exfiltration of data from the compromised host. But it can also receive and execute a remote payload from the operator.
APT GROUP
Malware family tracked by Malpedia. ID: win.quietcanary