Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.minijunk
APT GROUP
The MiniDuke toolset consists of multiple downloader and backdoor components
APT GROUP
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
APT GROUP
Malware family tracked by Malpedia. ID: win.minibrowse
miniBlindingCan is an HTTP(S) orchestrator. It is a variant of the BlindingCan RAT, having the same command parsing logic, but supporting only a small subset of commands available previously. The main operations are the update of the malware configuration, and the download and execution of additional payloads from the attackers' C&C. The miniBlindingCan malware was used in Operation DreamJob attacks against aerospace and media companies in Q2-Q3 2022.
APT GROUP
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
APT GROUP
Malware family tracked by Malpedia. ID: win.miniasp
APT GROUP
Malware family tracked by Malpedia. ID: win.minebridge
APT GROUP
Varonis summarizes Mimikatz as an open-source application that allows users to view and save authentication credentials like Kerberos tickets. Benjamin Delpy continues to lead Mimikatz developments, so the toolset works with the current release of Windows and includes the most up-to-date attacks. Attackers commonly use Mimikatz to steal credentials and escalate privileges: in most cases, endpoint protection software and anti-virus systems will detect and delete it. Conversely, pentesters use Mimikatz to detect and exploit vulnerabilities in your networks so you can fix them.
APT GROUPfinancialhigh
According to PCrisk, Mimic is a ransomware-type program. Malware within this classification is designed to encrypt data and demand ransoms for decryption. Evidence suggests that Mimic is based on the leaked CONTI ransomware builder. Mimic campaigns have been observed targeting English and Russian speaking users.
APT GROUP
Malware family tracked by Malpedia. ID: win.mim221
APT GROUP
In August 2019, Kaspersky Labs discovered a malware they dubbed Milum (naming based on internal file name fragments) when investigating an operation they named WildPressure. It is written in C++ using STL, primarily to parse JSON. Functionality includes bidirectional file transmission and remote command execution.
APT GROUP
Malware family tracked by Malpedia. ID: win.milkmaid
APT GROUP
Malware family tracked by Malpedia. ID: win.milan
APT GROUP
Malware family tracked by Malpedia. ID: win.mikoponi
APT GROUP
This malware written in Delphi is an information stealing malware family dubbed "MICROPSIA". It has s wide range of data theft functionality built in.
APT GROUP
Malware family tracked by Malpedia. ID: win.microcin
APT GROUP
Open-source lightweight backdoor for C2 communication. GitHub: https://github.com/Cr4sh/MicroBackdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.micrass
APT GROUP
Malware family tracked by Malpedia. ID: win.miancha
Updated: 2017-05-21
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.mgbot
APT GROUP
Malware family tracked by Malpedia. ID: win.mewsei
Updated: 2016-04-19
View profile →
APT GROUP
A botnet that used Tor .onion links for C&C.
APT GROUP
Malware family tracked by Malpedia. ID: apk.meterpreter
APT GROUP
A wiper used in an attack against the Iranian train system.
APT GROUP
On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available for sale for USD125 per month or USD1000 for unlimited use. The actor claimed it has the same functionality, code, and panel as the Redline stealer, but with several improvements.
APT GROUPfinancialhigh
According to BitDefender, Metamorfo is a family of banker Trojans that has been active since mid-2018. It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments. Metamorfo is a potent piece of malware, whose primary capability is theft of banking information and other personal data from the user and exfiltration of it to the C2 server.
APT GROUP
Malware family tracked by Malpedia. ID: win.metaljack
APT GROUP
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
APT GROUP
Malware family tracked by Malpedia. ID: win.merdoor
Malware family tracked by Malpedia. ID: win.mercurialgrabber
APT GROUP
Malware family tracked by Malpedia. ID: win.meltingclaw
APT GROUP
Malware family tracked by Malpedia. ID: win.melcoz
APT GROUP
Malware family tracked by Malpedia. ID: win.mekotio
APT GROUP
Megumin Trojan, is a malware focused on multiple fields (DDoS, Miner, Loader, Clipper).
APT GROUP
Malware family tracked by Malpedia. ID: win.megacreep
Malware family tracked by Malpedia. ID: win.meduza
APT GROUPespionageadvanced
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
APT GROUP
Malware family tracked by Malpedia. ID: win.medre
APT GROUP
Malware family tracked by Malpedia. ID: win.mediapi