Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
According to KnowBe4, Pony Stealer is a password stealer that can decrypt or unlock passwords for over 110 different applications including VPN, FTP, email, instant messaging, web browsers and much more. Pony Stealer is very dangerous and once it infects a PC it will turn the device into a botnet, allowing it to use the PCs it infects to infect other PCs.
APT GROUPfinancial
polyvice — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.polyglot_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.polyglotduke
APT GROUP
Malware family tracked by Malpedia. ID: win.polpo
APT GROUP
Malware family tracked by Malpedia. ID: win.poldat
APT GROUP
Malware family tracked by Malpedia. ID: win.poison_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.poison_ivy
APT GROUP
According to FireEye, POISONPLUG is a highly obfuscated modular backdoor with plug-in capabilities. The malware is capable of registry or service persistence, self-removal, plug-in execution, and network connection forwarding. POISONPLUG has been observed using social platforms to host encoded C&C commands.
APT GROUP
Malware family tracked by Malpedia. ID: win.poco_rat
APT GROUP
uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure overlap with X-Agent, probably in use since mid-2018
APT GROUP
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or PowHeartBeat. PNGLoad has capabilities to download and execute additional payloads from a C&C server, which is likely how the attackers have deployed PNGLoad on systems compromised with PowHeartBeat. PNGLoad is a loader that uses bytes from PNG files to create a payload to execute. It is a 64-bit .NET executable - obfuscated with .NET Reactor - that masquerades as legitimate software.
APT GROUP
Malware family tracked by Malpedia. ID: win.pngdowner
APT GROUP
Malware family tracked by Malpedia. ID: win.plurox
APT GROUP
Malware family tracked by Malpedia. ID: win.ployx
APT GROUP
Malware family tracked by Malpedia. ID: win.ploutus_atm
APT GROUP
Malware family tracked by Malpedia. ID: elf.plead
APT GROUP
Malware family tracked by Malpedia. ID: win.playwork
APT GROUPfinancial
Initially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 mbrlkbtq5jonaqkurjwm🔗 k7kg3jqxang3wh7hnmai🔗 k7kg3jqzffsxe2z53jjx+29 more
T1560.001T1059.001T1587.001
RLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.plaintee
APT GROUP
Pkybot is a trojan, which has its roots as a downloader dubbed Bublik in 2013 and was seen distributing GameoverZeus in 2014 (ref: fortinet). In the beginning of 2015, webinject capability was added according to /Kleissner/Kafeine/iSight using the infamous ATS.
Malware family tracked by Malpedia. ID: win.pittytiger_rat
APT GROUP
According to TG Soft, Pitou has beeen released on April 2014. It maybe an evolution of the rootkit "Srzizbi" developed on 2008. Pitou is a spambot, the main goal is send spam form the computer of victim.
APT GROUP
Malware family tracked by Malpedia. ID: win.pirpi
APT GROUP
Infostealer
APT GROUP
Cisco Talos states that PipeSnoop can accept arbitrary shellcode from a named pipe and execute it on the infected endpoint.
APT GROUP
Malware family tracked by Malpedia. ID: win.pipemon
APT GROUP
Malware family tracked by Malpedia. ID: win.pipemagic
APT GROUP
Malware family tracked by Malpedia. ID: win.pipcreat
APT GROUP
Malware family tracked by Malpedia. ID: win.pingback
APT GROUP
Malware family tracked by Malpedia. ID: win.pinegrove
APT GROUP
According to F-Secure, the PinchDuke information stealer gathers system configuration information, steals user credentials, and collects user files from the compromised host transferring these via HTTP(S) to a C&C server. F-Secure believes that PinchDuke’s credential stealing functionality is based on the source code of the Pinch credential stealing malware (also known as LdPinch) that was developed in the early 2000s and has later been openly distributed on underground forums.
APT GROUP
According to FireEye, PILLOWMINT is a Point-of-Sale malware tool used to scrape track 1 and track 2 payment card data from memory. Scraped payment card data is encrypted and stored in the registry and as plaintext in a file (T1074: Data Staged) Contains additional backdoor capabilities including: Running processes Downloading and executing files (T1105: Remote File Copy) Downloading and injecting DLLs (T1055: Process Injection) Communicates with a command and control (C2) server over HTTP using AES encrypted messages (T1071: Standard Application Layer Protocol) (T1032: Standard Cryptographic Protocol)
APT GROUP
Introducing Pikabot, an emerging malware family that comprises a downloader/installer, a loader, and a core backdoor component. Despite being in the early stages of development, it already demonstrates advanced techniques in evasion, injection, and anti-analysis. Notably, the loader component incorporates an array of sophisticated anti-debugging and anti-VM measures inspired by the open-source Al-Khaser project, while leveraging steganography to conceal its payload. Additionally, Pikabot utilizes a proprietary C2 framework and supports a diverse range of commands, encompassing host enumeration and advanced secondary payload injection options.
APT GROUP
Malware family tracked by Malpedia. ID: win.pierogi
APT GROUP
According to Mandiant, PIEHOP is a disruption tool written in Python and packaged with PyInstaller version 2.1+ that has the capability to connect to a user supplied remote MSSQL server for uploading files and issuing remote commands to a RTU. PIEHOP expects its main function to be called via another Python file, supplying either the argument control=True or upload=True. At a minimum, it requires the following arguments: oik, user, and pwd, and if called with control=True, it must also be supplied with iec104.
APT GROUPespionageadvanced
PICKPOCKET is a credential theft tool that dumps the user's website login credentials from Chrome, Firefox, and Internet Explorer to a file. This tool was previously observed solely utilized by APT34.
APT GROUP
Malware family tracked by Malpedia. ID: win.picasso_loader
APT GROUP
A loader used to deliver IcedID, fetching a fake image from which payloads are extracted.
APT GROUPfinancialhigh
PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e. for example it does not have any functionality to exfiltrate the host information. This new variant is observed as a follow-on payload in a TA542 Emotet campaign back in November'22. contains a static URL to download a "Bot Pack" file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud.