Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.mechanical
APT GROUP
Malware family tracked by Malpedia. ID: win.mebromi
APT GROUPfinancialhigh
Ransomware overwriting the system's MBR, making it impossible to boot into Windows.
APT GROUPfinancialhigh
This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
APT GROUPfinancial
Maze ransomware group is one of the most known ransomware gangs, they targeted organizations worldwide across many industries. Security researchers believed that Maze operates as an affiliated network model. MAZE was one of the first groups that made a 'Double Extortion Attack' involved Allied Universal, in November 2019, the group leaks their victim's data in the darknet. On November 1, 2020, MAZE announced an official press release that they are closing their operation. is malware targeting organizations worldwide across many industries. Security researchers claim that the threat actor behind the MAZE group is 'TA2101'.
Infra: 🔗 xfr3txoorcyy7tikjgj5…💬 aoacugmutagkwctu.oni…💬 mazedecrypt.top…+4 more
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.mayberobot
APT GROUPfinancialhigh
Banking trojan written in Delphi, targeting customers of European and South American banks.
APT GROUP
Malware family tracked by Malpedia. ID: win.maui
APT GROUP
Malware family tracked by Malpedia. ID: win.matsnu
APT GROUP
Malware family tracked by Malpedia. ID: win.matryoshka_rat
APT GROUPfinancialhigh
Matrix is a ransomware that encrypts a victim's files and demands a ransom in cryptocurrency to decrypt them. It is distributed through phishing emails, hacking toolkits, and software downloaders. Matrix is a serious threat and can cause significant damage to a victim's data.
APT GROUP
Malware family tracked by Malpedia. ID: win.matrix_banker
APT GROUP
Matiex Keylogger is being sold in the underground forums, due to their gained popularity, and can also be used as MaaS (Malware-as-a-service) because of their ease of use, competitive pricing and immediate response from support.
APT GROUP
According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS). This piece of software is designed to cause chain infections.
Since it is used as a MaaS, both the malware it infiltrates into systems, and the attack reasons can vary - depending on the cyber criminals operating it. Matanbuchus has been observed being used in attacks against US universities and high schools, as well as a Belgian high-tech organization.
APT GROUP
MassLogger is a .NET credential stealer. It starts with a launcher that uses simple anti-debugging techniques which can be easily bypassed when identified. This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload.
APT GROUP
Malware family tracked by Malpedia. ID: win.maskgramstealer
APT GROUP
Malware family tracked by Malpedia. ID: win.masad_stealer
APT GROUP
3xp0rt describes Mars Stealer as an improved successor of Oski Stealer, supporting stealing from current browsers and targeting crypto currencies and 2FA plugins.
APT GROUPfinancialhigh
Ransomware written in Delphi.
APT GROUP
Malware family tracked by Malpedia. ID: win.marracrypt
APT GROUP
Malware family tracked by Malpedia. ID: win.markirat
APT GROUP
Malware family tracked by Malpedia. ID: win.mariposa
APT GROUP
Marap is a downloader, named after its command and control (C&C) phone home parameter "param" spelled backwards. It is written in C and contains a few notable anti-analysis features.
APT GROUP
Malware family tracked by Malpedia. ID: win.mapiget
APT GROUPfinancialhigh
Ransomware family closely related to GlobeImposter, notable for its use of SHACAL-2 encryption algorithm.
APT GROUP
Cisco Talos compared this RAT to Cobalt Strike and Sliver. Written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: win.manitsme
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.manifestus_ransomware
APT GROUP
Malware family tracked by Malpedia. ID: win.mangzamel
APT GROUP
Malware family tracked by Malpedia. ID: win.mango
APT GROUP
Malware family tracked by Malpedia. ID: win.manamecrypt
APT GROUPfinancialhigh
According to PCrisk, Mamba is an updated variant of high-risk ransomware called Phobos. After successful infiltration, Mamba encrypts stored files and appends filenames with the ".mamba" extension plus the victim's unique ID and developer's email address.
APT GROUP
Malware family tracked by Malpedia. ID: win.malumpos
APT GROUPfinancialhigh
According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.
APT GROUPfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
APT GROUPfinancialhigh
BeforeCrypt describes that MAKOP Ransomware first appeared in 2020 as an offshoot of the PHOBOS variant, and that it has infected a number of computers since then. Files encrypted by MAKOP often have the extension “.makop”. You may also notice that your desktop wallpaper has changed. MAKOP uses RSA encryption. There are no known free decryption tools capable of decrypting files encrypted by MAKOP.
APT GROUP
Malware family tracked by Malpedia. ID: win.makloader
APT GROUP
Malware family tracked by Malpedia. ID: win.makadocs
APT GROUP
Malware family tracked by Malpedia. ID: win.majik_pos