Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.mechanical
APT GROUP
Malware family tracked by Malpedia. ID: win.mebromi
APT GROUPfinancialhigh
Ransomware overwriting the system's MBR, making it impossible to boot into Windows.
APT GROUPfinancialhigh
This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
APT GROUP
Malware family tracked by Malpedia. ID: win.mayberobot
APT GROUPfinancialhigh
Banking trojan written in Delphi, targeting customers of European and South American banks.
Malware family tracked by Malpedia. ID: win.maui
APT GROUP
Specialized PoisonIvy Sideloader.
APT GROUP
Malware family tracked by Malpedia. ID: win.matsnu
Malware family tracked by Malpedia. ID: win.matryoshka_rat
APT GROUPfinancialhigh
Matrix is a ransomware that encrypts a victim's files and demands a ransom in cryptocurrency to decrypt them. It is distributed through phishing emails, hacking toolkits, and software downloaders. Matrix is a serious threat and can cause significant damage to a victim's data.
APT GROUP
Malware family tracked by Malpedia. ID: win.matrix_banker
APT GROUP
Matiex Keylogger is being sold in the underground forums, due to their gained popularity, and can also be used as MaaS (Malware-as-a-service) because of their ease of use, competitive pricing and immediate response from support.
APT GROUP
According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS). This piece of software is designed to cause chain infections. Since it is used as a MaaS, both the malware it infiltrates into systems, and the attack reasons can vary - depending on the cyber criminals operating it. Matanbuchus has been observed being used in attacks against US universities and high schools, as well as a Belgian high-tech organization.
APT GROUP
MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed when identified. This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload.
Malware family tracked by Malpedia. ID: win.maskgramstealer
APT GROUP
Malware family tracked by Malpedia. ID: win.masad_stealer
APT GROUP
3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto currencies and 2FA plugins.
APT GROUP
Malware family tracked by Malpedia. ID: win.markirat
APT GROUP
Malware family tracked by Malpedia. ID: win.mariposa
APT GROUP
Marap is a downloader, named after its command and control (C&C) phone home parameter "param" spelled backwards. It is written in C and contains a few notable anti-analysis features.
APT GROUP
Malware family tracked by Malpedia. ID: win.mapiget
APT GROUP
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: win.manitsme
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.manifestus_ransomware
APT GROUP
Malware family tracked by Malpedia. ID: win.mangzamel
APT GROUP
Malware family tracked by Malpedia. ID: win.mango
APT GROUP
Malware family tracked by Malpedia. ID: win.manamecrypt
APT GROUPfinancialhigh
According to PCrisk, Mamba is an updated variant of high-risk ransomware called Phobos. After successful infiltration, Mamba encrypts stored files and appends filenames with the ".mamba" extension plus the victim's unique ID and developer's email address.
APT GROUP
Malware family tracked by Malpedia. ID: win.malumpos
APT GROUPfinancialhigh
According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.
APT GROUPfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
APT GROUP
Malware family tracked by Malpedia. ID: win.makloader
APT GROUP
Malware family tracked by Malpedia. ID: win.makadocs
APT GROUP
Malware family tracked by Malpedia. ID: win.majik_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.mail_o
APT GROUP
According to Zscaler, MAILCREEP is a Golang-based backdoor leveraging the Microsoft Graph API for its C2 communications.
APT GROUPfinancialhigh
According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to conduct malvertising attacks against users in South Korea. However, it has remained active since then, continually updating its tactics by employing new obfuscation techniques and methods of evasion. In April 2022, Magniber gained notoriety for disguising itself as a Windows update file to lure victims into installing it. It then began spreading via JavaScript in September 2022.
APT GROUP
According to Talos, MagicRAT is programmed in C++ programming language and uses the Qt Framework by statically linking it to the RAT on 32- and 64-bit versions. The Qt Framework is a programming library for developing graphical user interfaces, of which this RAT has none. Talos thinks that the objective was to increase the complexity of the code, thus making human analysis harder. On the other hand, since there are very few examples (if any) of malware programmed with Qt Framework, this also makes machine learning and heuristic analysis detection less reliable. The RAT uses the Qt classes throughout its entire code. The configuration is dynamically stored in a QSettings class eventually being saved to disk, a typical functionality provided by that class. MagicRAT provides the operator with a remote shell on the victim's system for arbitrary command execution, along with the ability to rename, move and delete files on the endpoint. The operator can determine the timing for the implant to sleep, change the C2 URLs and delete the implant from the infected system.
APT GROUP
According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server. The backdoor has capabilities to bruteforce logins to other MSSQL servers, adding a special hardcoded backdoor user in the case of successfully bruteforcing admin logins.