Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.naplistener
APT GROUPespionageadvanced
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
APT GROUPfinancialhigh
According to Orange Cybwerdefense, NailaoLocker is a ransomware using AES-256-CTR mode, which conveniently logs its encryption activities into a log file.
APT GROUP
Malware family tracked by Malpedia. ID: win.nagini
APT GROUP
According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.
APT GROUP
Malware family tracked by Malpedia. ID: win.nabucur
APT GROUP
Botnet with focus on banks in Latin America and South America.
Relies on DLL Sideloading attacks to execute malicious DLL files.
Uses legitimate VMWare executable in attacks.
As of March 2019, the malware is under active development with updated versions coming out on persistent basis.
APT GROUP
Malware family tracked by Malpedia. ID: win.mzrevenge
APT GROUP
According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40 web browsers and more than 70 browser extensions, also targeting cryptocurrency wallets, Steam, and Telegram. The code is heavily obfuscated making use of polymorphic string obfuscation, hash-based import resolution, and runtime calculation of constants.
Mystic implements a custom binary protocol that is encrypted with RC4.
APT GROUP
Malware family tracked by Malpedia. ID: win.mystery_snail
APT GROUP
According to PCrisk, MyloBot is a high-risk trojan-type virus that allows cyber criminals to control the infected machine. MyloBot can be considered as a botnet, since all infected computers are connected to a single network. Depending on cyber criminals' goals, infected machines might be misused or have additional infections applied.
APT GROUP
Malware family tracked by Malpedia. ID: win.mykings_spreader
APT GROUP
When executed, the worm opens up Windows' Notepad with garbage data in it. When spreading, the infectious email used to distribute the worm copies use variable subjects, bodies and attachment names.
The worm encrypts most of the strings in it's UPX-packed body with ROT13 method, i.e. the characters are rotated 13 locations to the right in the abecedary, starting from the beginning if the position is beyond the last letter.
Mydoom also performs a Distributed Denial-of-Service attack on www.sco.com. This attack starts on 1st of February.
The worm opens up a backdoor to infected computers. This is done by planting a new SHIMGAPI.DLL file to system32 directory and launching it as a child process of EXPLORER.EXE.
Mydoom is programmed to stop spreading on February 12th.
APT GROUP
Malware family tracked by Malpedia. ID: win.mydogs
APT GROUP
Malware family tracked by Malpedia. ID: win.mutabaha
APT GROUP
According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family. It uses a Domain Generation Algorithm (DGA) to determine the current C2 domain names.
APT GROUP
a command-line reconnaissance tool. It can be used to execute files as a different user, move, and delete files locally, schedule remote AT jobs, perform host discovery on connected networks, scan for open ports on hosts in a connected network, and retrieve information about the OS, users, groups, and shares on remote hosts.
APT GROUP
Malware family tracked by Malpedia. ID: win.multigrain_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.mulcom
APT GROUP
Malware family tracked by Malpedia. ID: win.muddyc2go
APT GROUP
Malware family tracked by Malpedia. ID: win.msupedge
APT GROUP
Malware family tracked by Malpedia. ID: win.mr_peter
APT GROUP
Malware family tracked by Malpedia. ID: win.mqsttang
APT GROUP
Malware family tracked by Malpedia. ID: win.mpkbot
APT GROUP
According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected computer through the DNS protocol. This communication method helps cyber criminals to avoid detection via security software. Mozart is categorized as a malware loader and executes commands that cause download and installation of malicious software.
APT GROUP
Malware family tracked by Malpedia. ID: win.moure
APT GROUP
According to Fortinet, this malware is written in Easy Programming Language (EPL), a Simplified-Chinese-based programming language designed to be beginner-friendly and easy to understand, especially for native Chinese speakers.
APT GROUP
Malware family tracked by Malpedia. ID: win.mosquito
APT GROUP
Malware family tracked by Malpedia. ID: win.moserpass
APT GROUP
Malware family tracked by Malpedia. ID: win.mosaic_regressor
APT GROUP
Malware family tracked by Malpedia. ID: win.morto
APT GROUP
Malware family tracked by Malpedia. ID: win.mortis
APT GROUP
Malware family tracked by Malpedia. ID: win.morphine
APT GROUP
Malware family tracked by Malpedia. ID: win.morpheus_loader
APT GROUP
This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that are marked as designated for the malware and respond to them. This forms a covert channel over which attackers are able to issue shell commands and receive back their outputs.
APT GROUP
Malware family tracked by Malpedia. ID: win.moriagent
APT GROUP
Malware family tracked by Malpedia. ID: win.moonwind
APT GROUP
Malware family tracked by Malpedia. ID: win.moonwalk