Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well. Keylog files are stored on the infected machine in an obfuscated form. The algorithm is: for i in range(0,num_read): buffer[i] = ((buffer[i]-0x24)^0x9D)&0xFF
APT GROUP
Malware family tracked by Malpedia. ID: win.nettraveler
Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago. The purpose of the NetSupport Manager tool is to enable users to receive remote technical support or provide remote computer assistance. However, cyber crooks have hijacked this useful application and misappropriated it to use it in their harmful campaigns. The name of the modified version of the NetSupport Manager has been labeled the NetSupport Manager RAT.
APT GROUP
Freely available network reconnaissance tool.
APT GROUP
Malware family tracked by Malpedia. ID: win.netrepser_keylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.netkey
APT GROUP
Malware family tracked by Malpedia. ID: win.netflash
NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility program. It was first discovered by Karsten Hahn. His team submitted the malware to Microsoft, which allowed Microsoft to start an investigation. After Karsten Hahn published tweets and an article about the rootkit, Microsoft quickly responded with their own article. Their investigation revealed Chinese gamers as targets of the malware. The rootkit redirects traffic to the threat actor's IP. The threat actor can use the driver to spoof their geo-location to cheat, but it also allows account compromise of targeted players. While this particular rootkit is not significant anymore, similar rootkits have been created since that are also signed by Microsoft via the Windows Hardware Compatibility program.
APT GROUP
Malware family tracked by Malpedia. ID: win.neteagle
APT GROUP
A RAT written in .NET, delivered with a driver to protect it from deletion. Observed being dropped by PrivateLoader.
APT GROUP
Malware family tracked by Malpedia. ID: win.netc
APT GROUP
NESTEGG is a memory-only backdoor that can proxy commands to other infected systems using a custom routing scheme. It accepts commands to upload and download files, list and delete files, list and terminate processes, and start processes. NESTEGG also creates Windows Firewall rules that allows the backdoor to bind to a specified port number to allow for inbound traffic.
APT GROUP
Neshta is a 2005 Belarusian file infector virus written in Delphi. The name of the virus comes from the Belarusian word "nesta" meaning "something."
APT GROUP
Proofpoint observed distribution of this RAT since late April 2022, it is written on Go and incorporates code from various open-source Git repositories.
APT GROUPfinancial
Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed through similar ways as Sodinokibi and also noted artfifacts they had seen before in Gandcrab.
Infra: 🔗 zjoxyw5mkacojk5ptn2i
RSLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.nemim
APT GROUP
Malware family tracked by Malpedia. ID: win.nemesis
APT GROUPfinancial
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
Infra: 🔗 hxt254aygrsziejn.oni
RSLUpdated: N/A
View profile →
APT GROUP
NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption. It sends detailed information about the victim's environment, like computer name, user name, type and free disk space of all drives, and a list of currently running processes. It uses three typical parameter names for HTTP POST requests: ned, gl, hl. The usual payload downloaded with NedDnLoader is Torisma. The internal DLL name of NedDnLoader is usually Dn.dll, Dn64.dll or DnDll.dll. It is deployed either as a standalone payload or within a trojanized MFC application project. It contains specific RTTI symbols like ".?AVCWininet_Protocol@@" or ".?AVCMFC_DLLApp@@".
APT GROUP
Malware family tracked by Malpedia. ID: win.necurs
APT GROUP
Malware family tracked by Malpedia. ID: win.neconyd
APT GROUP
Malware family tracked by Malpedia. ID: win.nebulae
APT GROUP
Malware family tracked by Malpedia. ID: win.ncctrojan
APT GROUP
Malware family tracked by Malpedia. ID: win.navrat
APT GROUP
Malware family tracked by Malpedia. ID: win.nautilus
APT GROUP
Malware family tracked by Malpedia. ID: win.narilam
APT GROUP
Malware family tracked by Malpedia. ID: win.naplistener
APT GROUP
Malware family tracked by Malpedia. ID: win.nano_locker
Updated: 2026-08-05
View profile →
APT GROUPespionageadvanced
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
APT GROUPfinancialhigh
According to Orange Cybwerdefense, NailaoLocker is a ransomware using AES-256-CTR mode, which conveniently logs its encryption activities into a log file.
APT GROUPespionage
[Naikon](https://attack.mitre.org/groups/G0019) is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).(Citation: CameraShy) Active since at least 2010, [Naikon](https://attack.mitre.org/groups/G0019) has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).(Citation: CameraShy)(Citation: Baumgartner Naikon 2015) While [Naikon](https://attack.mitre.org/groups/G0019) shares some characteristics with [APT30](https://attack.mitre.org/groups/G0013), the two groups do not appear to be exact matches.(Citation: Baumgartner Golovkin Naikon 2015)
🇨🇳 CNT1053.005T1204.002T1046
APT GROUP
Malware family tracked by Malpedia. ID: win.nagini
APT GROUP
According to FireEye, NACHOCHEESE is a command-line tunneler that accepts delimited C&C IPs or domains via command-line and gives actors shell access to a victim's system.
APT GROUP
Malware family tracked by Malpedia. ID: win.nabucur
Updated: 2016-05-31
View profile →
APT GROUP
Botnet with focus on banks in Latin America and South America. Relies on DLL Sideloading attacks to execute malicious DLL files. Uses legitimate VMWare executable in attacks. As of March 2019, the malware is under active development with updated versions coming out on persistent basis.
APT GROUP
Malware family tracked by Malpedia. ID: win.mzrevenge
According to ZScaler, a new information stealer that was first advertised in April 2023, capable of stealing credentials from nearly 40 web browsers and more than 70 browser extensions, also targeting cryptocurrency wallets, Steam, and Telegram. The code is heavily obfuscated making use of polymorphic string obfuscation, hash-based import resolution, and runtime calculation of constants. Mystic implements a custom binary protocol that is encrypted with RC4.
APT GROUP
Malware family tracked by Malpedia. ID: win.mystery_snail
APT GROUP
According to PCrisk, MyloBot is a high-risk trojan-type virus that allows cyber criminals to control the infected machine. MyloBot can be considered as a botnet, since all infected computers are connected to a single network. Depending on cyber criminals' goals, infected machines might be misused or have additional infections applied.
Malware family tracked by Malpedia. ID: win.mykings_spreader