Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUP
RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives." It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
Malware family tracked by Malpedia. ID: win.nixscare
APT GROUP
A Turkish cryptominer campaign.
APT GROUPfinancialhigh
This ransomware has much in common with the LukaLocker ransomware. [1](https://streamscan.ai/en/ressources/analyse-du-rancongiciel-nitrogen/) Analysis of the files reveals strong correlations between the Nitrogen, LukaLocker and Cactus families. These similarities lead us to believe that these ransomware families are administered by the same people, or that the files were developed using a common framework. [2](https://www.glimps.re/en/resource/nitrogen-correlation-with-lukalocker-cactus/)
Malware family tracked by Malpedia. ID: win.nitrogen
APT GROUPfinancialhigh
These attackers were the subject of an extensive report by Symantec in 2011, which termed the attackers Nitro and stated: 'The goal of the attackers appears to be to collect intellectual property such as design documents, formulas, and manufacturing processes. In addition, the same attackers appear to have a lengthy operation history including attacks on other industries and organizations. Attacks on the chemical industry are merely their latest attack wave. As part of our investigations, we were also able to identify and contact one of the attackers to try and gain insights into the motivations behind these attacks.' Palo Alto Networks reported on continued activity by the attackers in 2014.
🇨🇳 CN
APT GROUP
Malware family tracked by Malpedia. ID: win.nitol
APT GROUP
Malware family tracked by Malpedia. ID: win.nitlove
APT GROUP
NirCmd is a benign tool by NirSoft that provides various functionalities. Among these is e.g. a capability to start regedit as SYSTEM, which is sometimes abused for privilege escalation, or other functionality abusable for other malicious purposes. It is also frequently flagged by AV engines.
APT GROUP
Malware family tracked by Malpedia. ID: win.ninerat
APT GROUPespionageadvanced
According to its author, NimBlackout is an adaptation of the @Blackout project originally developed in C++ by @ZeroMemoryEx, which consists of removing AV/EDRs using the gmer (BYOVD) driver. The main reason for this project was to understand how BYOVD attacks work, and then to provide a valid PoC developed in Nim.
APT GROUP
Backdoor written in Nim.
APT GROUP
Part of Mythic C2, written in Nim. Considered deprecated, as it is only compatible with Mythic 2.1.
APT GROUP
Malware written in Nim, stealing data including discord tokens from browsers, exfiltrating the results via a Discord webhook.
APT GROUP
According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework. The agent currently supports Windows x64 and Linux. It's written in Nim, with some usage of .NET (by dynamically loading the CLR to the process).
APT GROUP
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn. It uses guardrails to ensure that victims are within the TA's target region. It is written in C# and delivered as an obfuscated .NET executable. One seen obfuscator is SmartAssembly.
APT GROUPespionageadvanced
NikiTeaR is a sophisticated, custom-developed RAT, which is a rewritten variant of the NikiHTTP (aka NikiTea) RAT. It supports the following commands: - srun <EXEC> <ARGS>: Executing arbitrary commands with elevated privileges. - up/down <FILENAME>: Performing remote file operations (upload/download). - screen: Capturing screenshots for reconnaissance. - conn <IP_ADDRESS> <PORT>: Establishing a reverse shell - memload <EXPORT>: Loading additional DLL into memory. - die <COMMAND>: Terminates the process and remove trace It is delivered via a multi-staged execution chain, beginning with a Golang-based dropper that executes a loader, a DLL with the internal name MemLoad_V3.dll, capable of loading DLL reflectively. Its internal DLL name is httptroy_dll.dll. To resist analysis, the backdoor is heavily obfuscated; it utilizes custom hashing to conceal Windows API calls, and employs a combined Base64+XOR encryption for C&C traffic and internal character strings, which are dynamically reconstructed at runtime.
APT GROUP
NikiHTTP is a versatile backdoor and has multiple capabilities such as download of files, executing them, performing commands, take screenshots and so on.
APT GROUPfinancial
Night Sky is a China-nexus ransomware group (attributed to the "Emperor Dragonfly" cluster) that emerged in late 2021, gaining notoriety in early 2022 by exploiting the Log4Shell vulnerability (CVE-2021-44228) to target corporate networks across healthcare, finance, government, and manufacturing using multi-extortion tactics.
Infra: 🔗 gg5ryfgogainisskdvh4
RSLUpdated: N/A
View profile →
APT GROUPespionageadvanced
According to eSentire, NightshadeC2 demonstrates an extensive capability set, including: Reverse shell via Command Prompt/PowerShell; Download and execute DLL or EXE; Self-deletion; Remote control; Screen capture; Hidden web browsers; Keylogging; clipboard content capturing. Certain variants have been found with stealing capabilities that enable the extraction of browser passwords and cookies from victim systems for both Gecko and Chromium based browsers.
APT GROUP
C2 framework.
APT GROUP
Malware family tracked by Malpedia. ID: win.nightdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.nightclub
APT GROUP
Malware family tracked by Malpedia. ID: win.nibiru
APT GROUP
According to Unit42, NGLite is a backdoor Trojan that is only capable of running commands received through its C2 channel. While the capabilities are standard for a backdoor, NGLite uses a novel C2 channel that leverages a decentralized network based on the legitimate NKN to communicate between the backdoor and the actors.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ngioweb
APT GROUP
Malware family tracked by Malpedia. ID: win.nexus_logger
APT GROUP
Malware family tracked by Malpedia. ID: win.nexster_bot
APT GROUP
Malware family tracked by Malpedia. ID: win.new_ct
APT GROUP
Malware family tracked by Malpedia. ID: win.newsreels
APT GROUP
Malware family tracked by Malpedia. ID: win.newposthings
APT GROUP
Malware family tracked by Malpedia. ID: win.newpass
APT GROUP
Malware family tracked by Malpedia. ID: win.newcore_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.newbounce
APT GROUP
Malware family tracked by Malpedia. ID: win.newbot_loader
APT GROUPfinancial
Nevada Ransomware is a RaaS operation written in Rust that emerged on the RAMP dark web forum in late 2022, offering affiliates favorable revenue splits (85/15 or 90/10) and conducting opportunistic mass attacks against a wide range of industries worldwide.
Infra: 🔗 nevcorps5cvivjf6i2gm🔗 nevbackvzwfu5yu3gsza🔗 nevaffcwswjosddmw55q
RSLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.neutrino_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.neutrino
APT GROUP
Malware family tracked by Malpedia. ID: win.neuron
APT GROUP
According to Unit 42, NET-STAR is a .NET malware suite designed to target Internet Information Services (IIS) web servers. It was named based on the use of the string in the malware’s program database (PDB) paths. The suite consists of three distinct web-based backdoors, each serving a specific role in the attack chain while maintaining persistence within the target’s IIS environment: A fileless modular backdoor that supports in-memory execution of command-line arguments, arbitrary commands and payloads, a loader for additional Assemblies, and improved version of the Assembly loader that is also equipped with Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypass capabilities.