Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
PHOTOFORK is a downloader which is a modified version of GZIPLOADER. It was first detected in February 2023 and was distributed by TA581 along with an unattributed threat activity cluster that facilitated initial access. In this version, the configuration file is no longer encrypted using a simple XOR algorithm with a 64-byte key. Instead, it uses a custom algorithm previously used by the Standard core loader. This algorithm decrypts DLL strings that are needed to resolve handles to the necessary DLLs later on. The strings are decrypted using an algorithm that splits the data into DWORDs and XORs it against a random key. The main objective of PHOTOFORK remains the same as GZIPLOADER, i.e. to deliver an encrypted bot and core DLL loader (forked) that loads the Forked ICEDID bot into memory using a custom PE format.
APT GROUP
Proofpoint describes Phorpiex/Trik as a SDBot fork (thus IRC-based) that has been used to distribute GandCrab, Pushdo, Pony, and coinminers. The name Trik is derived from PDB strings.
APT GROUP
Phoreal is a very simple backdoor that is capable of creating a reverse shell, performing simple file I/O and top-level window enumeration. It communicates to a list of four preconfigured C2 servers via ICMP on port 53
APT GROUP
Malware family tracked by Malpedia. ID: win.phonk
Malware family tracked by Malpedia. ID: win.phoenix_locker
Keylogger, information stealer.
APT GROUPespionageadvanced
MalwareBytes states that Phobos is one of the ransomware families that are distributed via hacked Remote Desktop (RDP) connections. This isn't surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost efficient dissemination vector for threat groups.
Malware family tracked by Malpedia. ID: win.philadelphia_ransom
Malware family tracked by Malpedia. ID: win.phemedrone_stealer
According to Proofpoint, this is a fork of Stealerium that has high overlap with its originating codebase.
APT GROUP
PhantomVAI Loader is a malicious multi-stage infection chain used to distribute the Katz Stealer information-stealing malware or other malicious payloads.
APT GROUPfinancialhigh
According to Cyble, PhantomCore is a backdoor utilized by the hacktivist group Head Mare. It has been active since 2023 and is known for consistently targeting Russia. PhantomCore collects the victim’s information, including the public IP address, to gain detailed insights into the target before deploying the final-stage payload or executing additional commands on the compromised system. PhantomCore is known to deploy ransomware payloads such as LockBit and Babuk, inflicting significant damage on the victim’s systems.
APT GROUP
Malware family tracked by Malpedia. ID: win.phandoor
APT GROUP
Information gathering and downloading tool used to deliver second stage malware to the infected system
Updated: 2018-01-25
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.petya
APT GROUPfinancialhigh
The PetrWrap Trojan is written in C and compiled in MS Visual Studio. It carries a sample of the Petya ransomware v3 inside its data section and uses Petya to infect the victim’s machine. What’s more, PetrWrap implements its own cryptographic routines and modifies the code of Petya in runtime to control its execution. This allows the criminals behind PetrWrap to hide the fact that they are using Petya during infection.
APT GROUP
Malware family tracked by Malpedia. ID: win.petit_potato
APT GROUP
Peppy is a Python-based RAT with the majority of its appearances having similarities or definite overlap with MSIL/Crimson appearances. Peppy communicates to its C&C over HTTP and utilizes SQLite for much of its internal functionality and tracking of exfiltrated files. The primary purpose of Peppy may be the automated exfiltration of potentially interesting files and keylogs. Once Peppy successfully communicates to its C&C, the keylogging and exfiltration of files using configurable search parameters begins. Files are exfiltrated using HTTP POST requests.
Malware family tracked by Malpedia. ID: win.pennywise
APT GROUP
Malware family tracked by Malpedia. ID: win.penco
Updated: 2018-07-24
View profile →
APT GROUP
Wrapper for Kazuar.
APT GROUP
Malware family tracked by Malpedia. ID: win.pekraut
APT GROUP
PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks. In May 2020, ESET mentioned that they found mysterious samples of PeddleCheap packed with a custom packer so far exclusively attributed to Winnti.
APT GROUP
Malware family tracked by Malpedia. ID: win.pebbledash
APT GROUP
PcShare is a open-source backdoor which has been seen modified and used by Chinese threat actors, mainly attacking countries in South East Asia.
APT GROUPfinancial
PayloadBIN is a ransomware strain deployed in 2021 by Evil Corp as a rebranding of their WastedLocker/Hades/Phoenix lineage, specifically designed to evade US Treasury OFAC sanctions by impersonating the unrelated Babuk gang's rebrand rather than operating as an independent group.
Affiliates: Wazawaka
Infra: 🔗 vbmisqjshn4yblehk2vb
RLUpdated: N/A
View profile →
APT GROUPfinancial
Pay2Key is ransomware that has been used by the threat actor Fox Kitten. The group seems to operate since July 2020, targetting mainly Israeli companies. Pay2Key has a darknet leak site to public stolen and sensitive information of their victims. Some of their victims: Intel - Habana Labs, IAI - Israel Aerospace Industries, Portnox - Network Security Solutions.
Infra: 🔗 pay2key2zkg7arp3kv3c🔗 pay2keys7rgdzrhgzxyd
RLUpdated: N/A
View profile →
APT GROUP
According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly. It identifies connected storage media, creates one thread per drive and volume for every path recorded and overwrites artifacts with randomly generated bytes. The wiper also reads multiple file systems attributes from NTFS and overwrites them as well. PathWiper additionally destroys files on disk by overwriting them with randomized bytes.
APT GROUP
Malware family tracked by Malpedia. ID: win.pathloader
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
PartyTicket is a Go-written ransomware, which was described as a poorly designed one by Zscaler. According to Brett Stone-Gross this malware is likely intended to be a diversion from the Hermetic wiper (aka. KillDisk.NCV, DriveSlayer) attack.
APT GROUP
According to Microsoft, Parite is a family of polymorphic file infectors that targets computers running Microsoft Windows. The virus infects .exe and .scr executable files on the local file system and on writeable network shares. In turn, the infected executable files perform operations that cause other .exe and .scr files to become infected.
parasite http
Technical ID: parasite_http
APT GROUP
Malware family tracked by Malpedia. ID: win.parasite_http
APT GROUP
Parallax is a Remote Access Trojan used by attackers to gain access to a victim's machine. It was involved in one of the many infamous "coronamalware" campaigns. Basically, the attackers abused the COVID-19 pandemic news to lure victims into opening themed emails spreading parallax.
APT GROUPfinancial
paradise — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-04
View profile →
Malware family tracked by Malpedia. ID: win.paradies_clipper
APT GROUP
A multi-platform RAT written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.pandora_rat
APT GROUPfinancial
Pandora ransomware was obtained by vx-underground at 2022-03-14.
Infra: 🔗 vbfqeh5nugm6r2u2qvgh🔗 pandoraxyz.xyz
RLUpdated: N/A
View profile →
APT GROUP
According to PCrisk, Panda is the name of a malicious program, which is classified as a stealer. It is a new variant of CollectorStealer. The aim of this malware is to extract and exfiltrate sensitive and personal information from infected devices. Panda primarily targets data relating to cryptocurrency wallets. This piece of malicious software has been observed being actively distributed via spam campaigns - large-scale operations during which thousands of scam emails are sent. The spam mail proliferating Panda stealer heavily targeted users from the United States, Germany, Japan, and Australia. The deceptive email letters concerned business-related topics (e.g., fake product quote requests, etc.). Panda stealer is a dangerous program, and as such - its infections must be removed immediately upon detection.