Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.prynt_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.protonbot
APT GROUP
Malware family tracked by Malpedia. ID: win.proto8_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.proteus
APT GROUPfinancial
First known AI-powered ransomware. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly
RLUpdated: N/A
View profile →
APT GROUPfinancial
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Infra: 🔗 promethw27cbrcot.oni💬 promethw27cbrcot.oni
RSLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: elf.prometei
APT GROUP
Malware family tracked by Malpedia. ID: win.project_wood
Malware family tracked by Malpedia. ID: win.project_hook
APT GROUP
Malware that abuses the Common Log File System (CLFS) to store/hide a second stage payload via registry transaction files.
APT GROUP
According to sekoia, PrivateLoader is a modular malware whose main capability is to download and execute one or several payloads. The loader implements anti-analysis techniques, fingerprints the compromised host and reports statistics to its C2 server.
Malware family tracked by Malpedia. ID: win.princess_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.prilex
APT GROUP
Malware family tracked by Malpedia. ID: win.prikormka
APT GROUPfinancialhigh
According to PCrisk, Prestige is ransomware - malware that prevents victims from accessing (opening) their files by encrypting them. Additionally, Prestige appends the ".enc" extension to filenames and drops the "README" file containing a ransom note. An example of how this ransomware modifies filenames: it renames "1.jpg" to "1.jpg.enc", "2.png" to "2.png.enc", and so forth.
Predator is a feature-rich information stealer. It is sold on hacking forums as a bundle which includes: Payload builder and Command and Control web panel. It is able to grab passwords from browsers, replace cryptocurrency wallets, and take photos from the web-camera. It is developed by using a modular approach so that criminals may add more sophisticated tools on top of the it.
prb backdoor
Technical ID: prb_backdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.prb_backdoor
APT GROUP
QUICKRIDE.POWER is a PowerShell variant of the QUICKRIDE backdoor. Its payloads are often saved to C:\windows\temp\
APT GROUP
A malware of the gozi group, developed on the base of isfb. It uses Office Macros and PowerShell in documents distributed in e-mail messages.
Malware family tracked by Malpedia. ID: win.powershellrunner
APT GROUP
Malware developers have started to use the zero-day exploit for Task Scheduler component in Windows, two days after proof-of-concept code for the vulnerability appeared online. A security researcher who uses the online name SandboxEscaper on August 27 released the source code for exploiting a security bug in the Advanced Local Procedure Call (ALPC) interface used by Windows Task Scheduler. More specifically, the problem is with the SchRpcSetSecurity API function, which fails to properly check user's permissions, allowing write privileges on files in C:\Windows\Task. The vulnerability affects Windows versions 7 through 10 and can be used by an attacker to escalate their privileges to all-access SYSTEM account level. A couple of days after the exploit code became available (source and binary), malware researchers at ESET noticed its use in active malicious campaigns from a threat actor they call PowerPool, because of their tendency to use tools mostly written in PowerShell for lateral movement. The group appears to have a small number of victims in the following countries: Chile, Germany, India, the Philippines, Poland, Russia, the United Kingdom, the United States, and Ukraine. The researchers say that PowerPool developers did not use the binary version of the exploit, deciding instead to make some subtle changes to the source code before recompiling it.
APT GROUP
Malware family tracked by Malpedia. ID: win.powerloader
APT GROUP
Malware family tracked by Malpedia. ID: win.powerkatz
APT GROUP
Malware family tracked by Malpedia. ID: win.powerduke
APT GROUP
Malware family tracked by Malpedia. ID: win.powercat
APT GROUP
.NET variant of ps1.powerton.
APT GROUP
Malware family tracked by Malpedia. ID: win.poweliks
APT GROUPfinancialhigh
According to Trend Micro, Povlsomware (Ransom.MSIL.POVLSOM.THBAOBA) is a proof-of-concept (POC) ransomware first released in November 2020 which, according to their Github page, is used to “securely” test the ransomware protection capabilities of security vendor products.
Malware family tracked by Malpedia. ID: win.poulight_stealer
APT GROUPespionageadvanced
PostNapTea aka SIGNBT is an HTTP(S) RAT that is written as a complex object-oriented project. In 2022-2023, it was deployed against targets like a newspaper organization, agriculture-related entity or a software vendor. The initial access was usually achieved by exploiting vulnerabilities in widely-used software in South Korea. It collects various information about the victim’s computer, such as computer name, product name, OS details, system uptime, CPU information, system locale, time zone, network status, and malware configuration. PostNapTea uses AES for encryption and decryption ot network traffic. There is a constant prefix SIGNBT occuring in its HTTP POST requests. The prefix is concatenated with 2 characters that identify the communication stage: • LG: logging into the C&C server • KE: acknowledging the succesful login to the C&C • FI: sending the status of a failed operation • SR: sending the status of a successful operation • GC: getting the next command There are five classes that represent command groups: • CCButton: for file manipulation and screen capturing • CCBitmap: for network commands, implementing functionality of Windows commands often abused by attackers, like sc, reg, arp, net, ver, wmic, ping, whoami, netstat, tracert, lookup, ipconfig, systeminfo, and netsh advfirewall. • CCComboBox: for file system management • CCList: for process management • CCBrush: for control of the malware itself It stores its configuration in JSON format. It resolves the Windows APIs it requires during runtime, via the Fowler–Noll–Vo (FNV) hash function. Its internal name in the version-information resource is usually ppcsnap.dll or pconsnap.dll, which loosely inspired its code name.
APT GROUP
Malware family tracked by Malpedia. ID: win.poslurp
APT GROUP
PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework. Out-of-the-box PoshC2 comes PowerShell/C# and Python3 implants with payloads written in PowerShell v2 and v4, C++ and C# source code, a variety of executables, DLLs and raw shellcode in addition to a Python3 payload. These enable C2 functionality on a wide range of devices and operating systems, including Windows, *nix and OSX.
Malware family tracked by Malpedia. ID: win.poscardstealer
APT GROUP
Malware family tracked by Malpedia. ID: win.portstarter
APT GROUP
Malware family tracked by Malpedia. ID: win.portless
APT GROUP
Malware family tracked by Malpedia. ID: win.portdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.popcorn_time
Updated: 2017-02-15
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.poorweb
APT GROUP
According to Mandiant, POORTRY is a malware written as a driver, signed with a Microsoft Windows Hardware Compatibility Authenticode signature. This malware has been observed being used by UNC3944.
Malware family tracked by Malpedia. ID: win.poohmilk