Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUPfinancial
Ransomware, potential rebranding of win.sfile.
Infra: 🔗 dfpc7yvle5kxmgg6sbcp
RLUpdated: 2026-08-05
View profile →
APT GROUP
Varonis summarizes Mimikatz as an open-source application that allows users to view and save authentication credentials like Kerberos tickets. Benjamin Delpy continues to lead Mimikatz developments, so the toolset works with the current release of Windows and includes the most up-to-date attacks. Attackers commonly use Mimikatz to steal credentials and escalate privileges: in most cases, endpoint protection software and anti-virus systems will detect and delete it. Conversely, pentesters use Mimikatz to detect and exploit vulnerabilities in your networks so you can fix them.
APT GROUPfinancialhigh
According to PCrisk, Mimic is a ransomware-type program. Malware within this classification is designed to encrypt data and demand ransoms for decryption. Evidence suggests that Mimic is based on the leaked CONTI ransomware builder. Mimic campaigns have been observed targeting English and Russian speaking users.
APT GROUP
Malware family tracked by Malpedia. ID: win.mim221
APT GROUP
In August 2019, Kaspersky Labs discovered a malware they dubbed Milum (naming based on internal file name fragments) when investigating an operation they named WildPressure. It is written in C++ using STL, primarily to parse JSON. Functionality includes bidirectional file transmission and remote command execution.
APT GROUP
Malware family tracked by Malpedia. ID: win.milkmaid
APT GROUP
Malware family tracked by Malpedia. ID: win.milan
APT GROUP
Malware family tracked by Malpedia. ID: win.mikoponi
APT GROUPfinancial
This malware written in C# is a variant of the Thanos ransomware family and emerged in October 2021 and is obfuscated using SmartAssembly. In 2022, ThreatLabz analysed a report of Midas ransomware was slowly deployed over a two month period (ZScaler). This ransomware features also its own data leak site as part of its double extortion strategy.
Infra: 🔗 midasbkic5eyfox4dhni
RLUpdated: N/A
View profile →
APT GROUP
This malware written in Delphi is an information stealing malware family dubbed "MICROPSIA". It has s wide range of data theft functionality built in.
APT GROUP
Malware family tracked by Malpedia. ID: win.microcin
APT GROUP
Open-source lightweight backdoor for C2 communication. GitHub: https://github.com/Cr4sh/MicroBackdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.micrass
APT GROUP
Malware family tracked by Malpedia. ID: win.miancha
Updated: 2017-05-21
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.mgbot
APT GROUP
Malware family tracked by Malpedia. ID: win.mewsei
Updated: 2016-04-19
View profile →
APT GROUP
A botnet that used Tor .onion links for C&C.
APT GROUP
Malware family tracked by Malpedia. ID: apk.meterpreter
APT GROUP
A wiper used in an attack against the Iranian train system.
APT GROUP
On March 7, 2022, KELA observed a threat actor named _META_ announcing the launch of META – a new information-stealing malware, available for sale for USD125 per month or USD1000 for unlimited use. The actor claimed it has the same functionality, code, and panel as the Redline stealer, but with several improvements.
APT GROUPfinancialhigh
According to BitDefender, Metamorfo is a family of banker Trojans that has been active since mid-2018. It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments. Metamorfo is a potent piece of malware, whose primary capability is theft of banking information and other personal data from the user and exfiltration of it to the C2 server.
APT GROUP
Malware family tracked by Malpedia. ID: win.metaljack
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
Mespinosa is a ransomware which encrypts file using an asymmetric encryption and adds .pysa as file extension. According to dissectingmalware the extension "pysa" is probably derived from the Zanzibari Coin with the same name.
APT GROUP
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
APT GROUP
Malware family tracked by Malpedia. ID: win.merdoor
Malware family tracked by Malpedia. ID: win.mercurialgrabber
APT GROUPfinancial
Meow emerged in 2022 (resurfacing aggressively in 2024), initially operating as a RaaS using the Conti v2 codebase before transitioning to a data-extortion-only model — selling stolen data rather than encrypting files — with a heavy focus on US healthcare and medical research organizations.
Infra: 🔗 meow6xanhzfci2gbkn3l🔗 totos7fquprkecvcsl2j📁 ikjht3url3tvx6itf2eg+2 more
RLUpdated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.meltingclaw
APT GROUP
Malware family tracked by Malpedia. ID: win.melcoz
APT GROUP
Malware family tracked by Malpedia. ID: win.mekotio
APT GROUP
Megumin Trojan, is a malware focused on multiple fields (DDoS, Miner, Loader, Clipper).
APT GROUP
Malware family tracked by Malpedia. ID: win.megacreep
APT GROUPfinancialhigh
Megacortex is a ransomware used in targeted attacks against corporations. Once the ransomware is run it tries to stop security related services and after that it starts its own encryption process adding a .aes128ctr or .megac0rtx extension to the encrypted files. It is used to be carried from downloaders and trojans, it has no own propagation capabilities.
Malware family tracked by Malpedia. ID: win.meduza
APT GROUPespionageadvanced
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
APT GROUPfinancial
Medusa is a DDoS bot written in .NET 2.0. In its current incarnation its C&C protocol is based on HTTP, while its predecessor made use of IRC.
RLUpdated: N/A
View profile →
APT GROUPfinancial
Medusa is a ransomware-as-a-service operation active since June 2021 that has targeted over 300 victims across critical infrastructure sectors including healthcare, education, legal, and manufacturing using double-extortion, with attacks surging 42% between 2023 and 2024 and a formal CISA advisory issued in early 2025.
Infra: 🔗 medusaxko7jxtrojdkxo🔗 xfv4jzckytb4g3ckwemc🔗 dlmfciajg5s4vliyo5dh+14 more
RLUpdated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.medre
APT GROUP
Malware family tracked by Malpedia. ID: win.mediapi