Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
When executed, the worm opens up Windows' Notepad with garbage data in it. When spreading, the infectious email used to distribute the worm copies use variable subjects, bodies and attachment names.
The worm encrypts most of the strings in it's UPX-packed body with ROT13 method, i.e. the characters are rotated 13 locations to the right in the abecedary, starting from the beginning if the position is beyond the last letter.
Mydoom also performs a Distributed Denial-of-Service attack on www.sco.com. This attack starts on 1st of February.
The worm opens up a backdoor to infected computers. This is done by planting a new SHIMGAPI.DLL file to system32 directory and launching it as a child process of EXPLORER.EXE.
Mydoom is programmed to stop spreading on February 12th.
APT GROUP
Malware family tracked by Malpedia. ID: win.mydogs
APT GROUP
Malware family tracked by Malpedia. ID: win.mutabaha
APT GROUP
According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family. It uses a Domain Generation Algorithm (DGA) to determine the current C2 domain names.
APT GROUP
a command-line reconnaissance tool. It can be used to execute files as a different user, move, and delete files locally, schedule remote AT jobs, perform host discovery on connected networks, scan for open ports on hosts in a connected network, and retrieve information about the OS, users, groups, and shares on remote hosts.
APT GROUP
Malware family tracked by Malpedia. ID: win.multigrain_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.mulcom
APT GROUP
Malware family tracked by Malpedia. ID: win.muddyc2go
APT GROUP
Malware family tracked by Malpedia. ID: win.msupedge
APT GROUP
Malware family tracked by Malpedia. ID: win.mr_peter
APT GROUP
Malware family tracked by Malpedia. ID: win.mqsttang
APT GROUP
Malware family tracked by Malpedia. ID: win.mpkbot
APT GROUP
According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected computer through the DNS protocol. This communication method helps cyber criminals to avoid detection via security software. Mozart is categorized as a malware loader and executes commands that cause download and installation of malicious software.
APT GROUP
Malware family tracked by Malpedia. ID: win.moure
APT GROUPfinancial
MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions.
Updated: 2026-08-05
View profile →APT GROUP
According to Fortinet, this malware is written in Easy Programming Language (EPL), a Simplified-Chinese-based programming language designed to be beginner-friendly and easy to understand, especially for native Chinese speakers.
APT GROUP
Malware family tracked by Malpedia. ID: win.mosquito
APT GROUP
Malware family tracked by Malpedia. ID: win.moserpass
APT GROUP
Malware family tracked by Malpedia. ID: win.mosaic_regressor
APT GROUP
Malware family tracked by Malpedia. ID: win.morto
APT GROUP
Malware family tracked by Malpedia. ID: win.mortis
APT GROUPfinancial
mortalkombat — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.morphine
APT GROUP
Malware family tracked by Malpedia. ID: win.morpheus_loader
APT GROUPfinancial
Morpheus emerged in late 2024 as a semi-private RaaS operation whose affiliates share identical payloads with the HellCat ransomware group, targeting pharmaceutical, manufacturing, legal, and Italian ESXi environments with ransom demands reaching up to 32 BTC (~$3M USD).
Infra: 🔗 izsp6ipui4ctgxfugbgt…
Updated: 2026-08-05
View profile →APT GROUP
This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that are marked as designated for the malware and respond to them. This forms a covert channel over which attackers are able to issue shell commands and receive back their outputs.
APT GROUP
Malware family tracked by Malpedia. ID: win.moriagent
APT GROUP
Malware family tracked by Malpedia. ID: win.moonwind
APT GROUP
Malware family tracked by Malpedia. ID: win.moonwalk
APT GROUP
The malware, potentially named "MOON_TAG" by its developer as indicated by the strings within, is derived from code shared in a Google Group (https://groups.google.com/g/ph4nt0m/c/2J3_1XPeKD8/m/AYPoWudRcTAJ?pli=1). Each variant discovered possesses capabilities to communicate via the Microsoft Graph API. At this moment, it appears to be in development.
APT GROUP
According to Cisco Talos, this RAT is derived from the open source XenoRAT.
APT GROUP
MoonBounce is a malware embedded into a modified UEFI firmware. Placed into SPI flash, it can provide persistence across full reinstall and even disk replacements. MoonBounce deploys user-mode malware through in-memory staging with a small footprint.
APT GROUP
Malware family tracked by Malpedia. ID: win.montysthree
APT GROUP
Malware family tracked by Malpedia. ID: win.monsterv2
APT GROUP
Malware family tracked by Malpedia. ID: win.mongall
APT GROUPfinancial
Money Message emerged in March 2023 targeting Windows and Linux systems across banking, transportation, and professional services sectors, demanding ransoms in the millions and publishing stolen data on their blog if unpaid, with most known victims based in the US.
RLUpdated: N/A
View profile →APT GROUP
According to ESET, first seen in-the-wild on 26th May, 2017, the malicious mining software is a fork of a legitimate open source Monero CPU miner called xmrig.
APT GROUP
Malware family tracked by Malpedia. ID: win.molerat_loader