Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
MoleNet is a .NET downloader malware used by the Molerats group in targeted attacks in the Middle East. Before downloading additional payloads, it first collects information about the infected machine using WMI queries and sends the data to its operators. It was first discovered in 2020, however, Cybereason researchers showed that it has been in use since at least 2019, with infrastructure that operated since 2017.
APT GROUP
Malware family tracked by Malpedia. ID: win.mole
APT GROUP
Malware family tracked by Malpedia. ID: elf.mokes
APT GROUP
Malware family tracked by Malpedia. ID: win.moker
APT GROUPfinancialhigh
Moisha is a .NET-based ransomware that employs double extortion techniques to encrypt and exfiltrate data from victims. Upon execution, it creates a global mutex to ensure only one instance of the malware runs on the affected system. It then stops services such as backup and antivirus to avoid interference during the encryption process. Moisha disables real-time protection in Microsoft Defender and removes shadow copies using PowerShell and Vssadmin. It encrypts files on the system using RSA and AES encryption algorithms and places a ransom note in the affected directory. The note instructs victims to contact the attackers via a Moisha ID on TOX Messenger to negotiate the ransom. Additionally, Moisha spreads to other machines on the network and self-deletes using PowerShell command line.
APT GROUP
Malware family tracked by Malpedia. ID: win.mofksys
APT GROUP
Malware family tracked by Malpedia. ID: win.modpos
APT GROUP
ModPipe is point-of-sale (POS) malware capable of accessing sensitive information stored in devices running ORACLE MICROS Restaurant Enterprise Series (RES) 3700 POS – a management software suite used by hundreds of thousands of bars, restaurants, hotels and other hospitality establishments worldwide. ModPipe uses modular architecture consisting of basic components and downloadable modules. One of them – named GetMicInfo – contains an algorithm designed to gather database passwords by decrypting them from Windows registry values. Exfiltrated credentials allow ModPipe's operators access to database contents, including various definitions and configuration, status tables and information about POS transactions.
APT GROUP
Malware family tracked by Malpedia. ID: win.modirat
APT GROUP
According to PCrisk, ModernLoader, also known as Avatar Bot and AvatarLoader, is a malicious program that has minimalistic loader and RAT (Remote Access Trojan) functionalities. Loader-type malware is designed to infect devices with additional malicious programs, while RATs enable remote access/control over infected machines. ModernLoader is capable of executing basic commands and injecting malicious modules into systems.
APT GROUP
Malware family tracked by Malpedia. ID: win.mocton
Updated: 2016-04-19
View profile →
APT GROUP
LNK files used to lure and orchestrate execution of various scripts, interacting with the Mocky API service.
APT GROUP
Malware family tracked by Malpedia. ID: win.mobi_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.mm_core
Updated: 2017-04-06
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.mmon
APT GROUP
According to Proofpoint, MiyaRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. It is possibly authored by the same developer(s) as WmRAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.miuref
Updated: 2016-04-19
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.mistyveal
APT GROUP
According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable Executable (PE) files. The backdoor is a modification of the open-source Notepad++ binhex plugin v2.0.0.1 where the creation of a thread that executes the malicious code has been added to the DllMain function.
APT GROUP
Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW.
APT GROUPfinancialhigh
According to ESET Research, Mispadu is an ambitious Latin American banking trojan that utilizes McDonald’s malvertising and extends its attack surface to web browsers. It is used to target the general public and its main goals are monetary and credential theft. In Brazil, ESET has seen it distributing a malicious Google Chrome extension that attempts to steal credit card data and online banking data, and that compromises the Boleto payment system.
APT GROUP
Undocumented information stealer targeting multiple browsers and cryptocurrences. Internal project name appears to be "misha".
APT GROUP
Malware family tracked by Malpedia. ID: win.misfox
Updated: 2024-06-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.misdat
APT GROUP
According to Trend Micro, this is a loader for win.transbox, used by threat actor Earth Yako.
APT GROUP
According to Minerva Labs, MirrorBlast malware is a trojan that is known for attacking users’ browsers. It usually pretends to be a legitimate browser add-on however it has now evolved additional capabilities, whereby other malwares are installed simultaneously. Recently, this trojan is thought to have tentative links to TA505 and PYSA groups.
APT GROUP
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.
APT GROUP
Malware family tracked by Malpedia. ID: win.miragefox
APT GROUP
Malware family tracked by Malpedia. ID: win.mintstealer
APT GROUP
miniTYPEFRAME is a variant of TYPEFRAME, a RAT for Windows. Its functionality is reduced to serve mostly as a proxy module. Its commands are indexed by 16-bit integers, usually in the range 0x8027–0x8044.
APT GROUP
Malware family tracked by Malpedia. ID: win.ministealer
APT GROUP
Malware family tracked by Malpedia. ID: win.minipocket
APT GROUP
Malware family tracked by Malpedia. ID: win.minijunk
APT GROUP
The MiniDuke toolset consists of multiple downloader and backdoor components
APT GROUP
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
APT GROUP
Malware family tracked by Malpedia. ID: win.minibrowse
miniBlindingCan is an HTTP(S) orchestrator. It is a variant of the BlindingCan RAT, having the same command parsing logic, but supporting only a small subset of commands available previously. The main operations are the update of the malware configuration, and the download and execution of additional payloads from the attackers' C&C. The miniBlindingCan malware was used in Operation DreamJob attacks against aerospace and media companies in Q2-Q3 2022.
APT GROUP
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
APT GROUP
Malware family tracked by Malpedia. ID: win.miniasp
APT GROUP
Malware family tracked by Malpedia. ID: win.minebridge