Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,719 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.odinaff
APT GROUP
Spam bot that was active around 2007 and after, one of the first malware families to use a domain generation algorithm.
APT GROUP
Malware family tracked by Malpedia. ID: win.oddjob
APT GROUPespionageadvanced
Octowave Loader is a malware loader used to run other families of malware. This is often made up of an MSI or Inno Setup installer for a legitimate piece of software that has been trojanised to include a number of malicious DLLs which inevitably load and run malicious code often stored within a WAV file that is also delivered to an endpoint. In the wild this has been seen delivered through fake software installers and ClickFix / Fake Captcha campaigns. Families of malware deployed often include information stealers, NetSupport RAT, and potentially bots like Danabot.
APT GROUP
Malware family tracked by Malpedia. ID: win.octorat
APT GROUP
The author describes Octopus as an "open source, pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S."
It is different from the malware win.octopus written in Delphi and attributed to DustSquad by Kaspersky Labs.
APT GROUP
Emanuele De Lucia summarizes that this wiper was sent to potential targets in phishing mails that impersonated ESET as a follow up to a breach of its Israeli distributor Comsecure.
APT GROUP
Malware family tracked by Malpedia. ID: win.oceansalt
APT GROUP
Malware family tracked by Malpedia. ID: win.oceanmap
APT GROUP
Malware family tracked by Malpedia. ID: win.observer_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.obscene
APT GROUP
Malware family tracked by Malpedia. ID: win.oblique_rat
APT GROUP
OATBOAT is a loader that loads and executes shellcode payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.nyxem
APT GROUP
According to bin.re, in April 2018 a new version of Nymaim appeared, that has dropped previous obfuscation, and uses a new wordlist based DGA (Domain Generation Algorithm).
APT GROUP
Nymaim is a trojan downloader. It downloads (and runs) other malware on affected systems and was one of the primary malware families hosted on Avalanche. Nymaim is different in that it displays a localized lockscreen while it downloads additional malware. Nymaim is usually delivered by exploit kits and malvertising.
APT GROUP
Malware family tracked by Malpedia. ID: win.nworm
APT GROUP
Malware family tracked by Malpedia. ID: win.nvisospit
APT GROUPfinancialhigh
According to PCrisk, Numando is a banking trojan written in the Delphi programming language. As the malicious program's classification implies, it is designed to steal banking information. Numando primarily targets Brazil, with seldom campaigns occurring in Mexico and Spain.
APT GROUP
Nullmixer is a dropper/loader for additional malware. It is known to drop a vast amount of different malware, such as info stealers, rats and additional loaders. Samples observed contained up to 8 additional payloads.
APT GROUP
NSFOCUS describes PhantomNugget as a modularized malware toolkit, that was spread using EternalBlue. Payloads included a RAT and a XMRig miner.
APT GROUPespionageadvanced
Ntospy is a credential stealer leveraging a well-established technique of abusing the Windows Network Provider interface, a method documented as early as 2004 and exemplified by tools like NPPSpy. Posing as a legitimate Network Provider DLL, Ntospy injects itself into the Windows authentication process, hijacking login attempts to harvest user credentials. It achieves this by registering a malicious Network Provider, typically named "credman," which intercepts authentication requests and redirects them to it malicious DLL.
Instead of immediately exfiltrating the stolen data, Ntospy employs a form of local storage, writing the captured credentials in cleartext to files disguised as harmless Microsoft Update packages using the .msu file extension. These files are often planted in system directories with believable names like "c:/programdata/package cache/windows10.0-kb5009543-x64.msu," further masking their malicious purpose.
Adding to its stealth, Ntospy incorporates obfuscation techniques to evade detection. This includes using seemingly innocuous filenames for its DLL, often mimicking critical system files like "ntoskrnl.dll" to blend in. Some variants even go a step further by encrypting the credential storage file path within the DLL, requiring analysis and decryption to uncover its full functionality.
APT GROUP
Malware family tracked by Malpedia. ID: win.nspx30
APT GROUP
Malware family tracked by Malpedia. ID: win.nransom
APT GROUP
Malware family tracked by Malpedia. ID: win.no_justice
APT GROUP
Malware family tracked by Malpedia. ID: win.nozelesn_decryptor
APT GROUP
Malware family tracked by Malpedia. ID: win.noxplayer
APT GROUP
Nova Stealer is a new information stealer that is offered as Malware-as-a-Service by a new French-speaking actor called "Nova Sentinel". Its capabilities include password stealing, browser injections, crypto wallet stealing, discord injections, and screen recordings. Parts of its source code have been made available on GitHub, with certain "Premium" features missing.
APT GROUP
According to PCrisk, Nosu is the name of a malicious program classified as a stealer. This malware is designed to steal information from infected machines. The Nosu stealer can extract a wide variety of data from devices and installed applications. The most active campaigns associated with Nosu were noted in North and South America, as well as Southeast Asia.
APT GROUP
An open source C2 framework intended for pentest and red teaming activities.
APT GROUP
Malware family tracked by Malpedia. ID: win.norobot
APT GROUP
Malware family tracked by Malpedia. ID: win.noopdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.noneuclid_rat
APT GROUP
A wiper that overwrites target files with itself, thus spreading in virus-fashion.
APT GROUP
Malware family tracked by Malpedia. ID: win.nokoyawa
APT GROUPespionageadvanced
Nokki is a RAT type malware which is believe to evolve from Konni RAT. This malware has been tied to attacks containing politically-motivated lures targeting Russian and Cambodian speaking individuals or organizations. Researchers discovered a tie to the threat actor group known as Reaper also known as APT37.
APT GROUP
Malware family tracked by Malpedia. ID: win.node_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.nocturnalstealer
APT GROUP
It's .NET Rat with harcoded key