Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.nibiru
APT GROUP
According to Unit42, NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ngioweb
APT GROUP
Malware family tracked by Malpedia. ID: win.nexus_logger
APT GROUP
Malware family tracked by Malpedia. ID: win.nexster_bot
APT GROUP
Malware family tracked by Malpedia. ID: win.new_ct
APT GROUP
Malware family tracked by Malpedia. ID: win.newsreels
APT GROUP
Malware family tracked by Malpedia. ID: win.newposthings
APT GROUP
Malware family tracked by Malpedia. ID: win.newpass
APT GROUP
Malware family tracked by Malpedia. ID: win.newcore_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.newbounce
APT GROUP
Malware family tracked by Malpedia. ID: win.newbot_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.neutrino_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.neutrino
APT GROUP
Malware family tracked by Malpedia. ID: win.neuron
APT GROUP
According to Unit 42, NET-STAR is a .NET malware suite designed to target Internet Information Services (IIS) web servers. It was named based on the use of the string in the malware’s program database (PDB) paths. The suite consists of three distinct web-based backdoors, each serving a specific role in the attack chain while maintaining persistence within the target’s IIS environment: A fileless modular backdoor that supports in-memory execution of command-line arguments, arbitrary commands and payloads, a loader for additional Assemblies, and improved version of the Assembly loader that is also equipped with Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypass capabilities.
APT GROUP
Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well.
Keylog files are stored on the infected machine in an obfuscated form. The algorithm is:
for i in range(0,num_read):
buffer[i] = ((buffer[i]-0x24)^0x9D)&0xFF
APT GROUP
Malware family tracked by Malpedia. ID: win.nettraveler
APT GROUP
Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago. The purpose of the NetSupport Manager tool is to enable users to receive remote technical support or provide remote computer assistance. However, cyber crooks have hijacked this useful application and misappropriated it to use it in their harmful campaigns. The name of the modified version of the NetSupport Manager has been labeled the NetSupport Manager RAT.
APT GROUP
Freely available network reconnaissance tool.
APT GROUP
Malware family tracked by Malpedia. ID: win.netrepser_keylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.netkey
APT GROUP
Malware family tracked by Malpedia. ID: win.netflash
APT GROUP
NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility program. It was first discovered by Karsten Hahn. His team submitted the malware to Microsoft, which allowed Microsoft to start an investigation.
After Karsten Hahn published tweets and an article about the rootkit, Microsoft quickly responded with their own article. Their investigation revealed Chinese gamers as targets of the malware. The rootkit redirects traffic to the threat actor's IP. The threat actor can use the driver to spoof their geo-location to cheat, but it also allows account compromise of targeted players.
While this particular rootkit is not significant anymore, similar rootkits have been created since that are also signed by Microsoft via the Windows Hardware Compatibility program.
APT GROUP
Malware family tracked by Malpedia. ID: win.neteagle
APT GROUP
A RAT written in .NET, delivered with a driver to protect it from deletion. Observed being dropped by PrivateLoader.
APT GROUP
Malware family tracked by Malpedia. ID: win.netc
APT GROUP
NESTEGG is a memory-only backdoor that can proxy commands to other
infected systems using a custom routing scheme. It accepts commands to
upload and download files, list and delete files, list and terminate processes, and
start processes. NESTEGG also creates Windows Firewall rules that allows the
backdoor to bind to a specified port number to allow for inbound traffic.
APT GROUP
Neshta is a 2005 Belarusian file infector virus written in Delphi. The name of the virus comes from the Belarusian word "nesta" meaning "something."
APT GROUP
Proofpoint observed distribution of this RAT since late April 2022, it is written on Go and incorporates code from various open-source Git repositories.
APT GROUP
Malware family tracked by Malpedia. ID: win.nemim
APT GROUP
Malware family tracked by Malpedia. ID: win.nemesis
APT GROUP
NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption.
It sends detailed information about the victim's environment, like computer name, user name, type and free disk space of all drives, and a list of currently running processes. It uses three typical parameter names for HTTP POST requests: ned, gl, hl. The usual payload downloaded with NedDnLoader is Torisma.
The internal DLL name of NedDnLoader is usually Dn.dll, Dn64.dll or DnDll.dll. It is deployed either as a standalone payload or within a trojanized MFC application project. It contains specific RTTI symbols like ".?AVCWininet_Protocol@@" or ".?AVCMFC_DLLApp@@".
APT GROUP
Malware family tracked by Malpedia. ID: win.necurs
APT GROUP
Malware family tracked by Malpedia. ID: win.neconyd
APT GROUP
Malware family tracked by Malpedia. ID: win.nebulae
APT GROUP
Malware family tracked by Malpedia. ID: win.ncctrojan
APT GROUP
Malware family tracked by Malpedia. ID: win.navrat
APT GROUP
Malware family tracked by Malpedia. ID: win.nautilus
APT GROUP
Malware family tracked by Malpedia. ID: win.narilam