Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the infected endpoint.
APT GROUP
Malware family tracked by Malpedia. ID: win.httpdropper
APT GROUP
Malware family tracked by Malpedia. ID: win.httpbrowser
APT GROUP
Malware family tracked by Malpedia. ID: win.htran
APT GROUP
Malware family tracked by Malpedia. ID: win.htprat
APT GROUP
Malware family tracked by Malpedia. ID: win.htbot
Updated: 2017-05-29
View profile →
APT GROUP
Houdini is a VBS-based RAT dating back to 2013. Past in the days, it used to be wrapped in an .exe but started being spamvertized or downloaded by other malware directly as .vbs in 2018. In 2019, WSHRAT appeared, a Javascript-based version of Houdini, recoded by the name of Kognito.
APT GROUP
HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file. HOTWAX decrypts a payload using the Spritz algorithm with a hard-coded key and then searches the target process and attempts to inject the decrypted payload module from the CHM file into the address space of the target process.
APT GROUP
Malware family tracked by Malpedia. ID: win.hotcroissant
APT GROUP
Remote Acess Tool Written in VB.NET.
APT GROUP
According to Check Point Research, this is a custom-built agent for Mythic, the open-source red teaming C2 framework. Written in C++, the implant shows no significant overlap with known C-based Mythic agents, aside from commonalities in the generic logic related to Mythic C2 communications.
APT GROUP
Hopscotch is part of the Regin framework.
APT GROUP
Malware family tracked by Malpedia. ID: win.hoplight
APT GROUP
Malware family tracked by Malpedia. ID: win.hookinjex
APT GROUP
a 64-bit Windows password dumper/cracker that has previously been used in conjunction with AIRBREAK and BADFLICK backdoors. Some strings are obfuscated with XOR x56. The malware accepts up to two arguments at the command line: one to display cleartext credentials for each login session, and a second to display cleartext credentials, NTLM hashes, and malware version for each login session.
APT GROUP
Malware family tracked by Malpedia. ID: win.holerun
Adware, tied to eGobbler and Nephos7 campaigns,
APT GROUP
Malware family tracked by Malpedia. ID: win.hodur
APT GROUP
Malware family tracked by Malpedia. ID: win.hlux
Updated: 2016-04-26
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.hi_zor_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.hisoka
APT GROUP
Malware family tracked by Malpedia. ID: win.himera_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.himan
APT GROUPfinancialhigh
A new ransomware family was discovered in August 2019. Called HILDACRYPT, it is named after the Netflix cartoon “Hilda” because the TV show’s YouTube trailer was included in the ransom note of the original version of the malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.hikit
APT GROUP
According to Rapid7, this is a loader first spotted in July 2023. It implements several evasion techniques including Process Doppelgänging, DLL Search Order Hijacking, and Heaven's Gate. It has been observed to store its malicious payload in the IDAT chunk of PNG file format.
APT GROUP
Malware family tracked by Malpedia. ID: win.highnote
APT GROUP
Malware family tracked by Malpedia. ID: win.highnoon_bin
APT GROUP
According to FireEye, HIGHNOON is a backdoor that may consist of multiple components. The components may include a loader, a DLL, and a rootkit. Both the loader and the DLL may be dropped together, but the rootkit may be embedded in the DLL. The HIGHNOON loader may be designed to run as a Windows service.
APT GROUP
Malware family tracked by Malpedia. ID: win.hidedrv
APT GROUP
Malware family tracked by Malpedia. ID: win.hiddenbee
APT GROUP
Malware family tracked by Malpedia. ID: win.hiasm
APT GROUP
Malware family tracked by Malpedia. ID: win.heyoka
APT GROUPfinancialhigh
On August 9th, 2024, the HexaLocker team advertised a new Windows ransomware on its Telegram channel. The message included a demonstration video and text promoting a Golang ransomware that implements a proprietary algorithm.
APT GROUP
Malware family tracked by Malpedia. ID: win.hesperbot
APT GROUP
Malware family tracked by Malpedia. ID: win.herpes
Updated: 2016-05-31
View profile →
Malware family tracked by Malpedia. ID: win.hermeticwizard
APT GROUP
According to SentinelLabs, HermeticWiper is a custom-written application with very few standard functions. It abuses a signed driver called "empntdrv.sys" which is associated with the legitimate Software "EaseUS Partition Master Software" to enumerate the MBR and all partitions of all Physical Drives connected to the victims Windows Device and overwrite the first 512 Bytes of every MBR and Partition it can find, rendering them useless. This malware is associated to the malware attacks against Ukraine during Russians Invasion in February 2022.
APT GROUP
Malware family tracked by Malpedia. ID: win.heriplor
APT GROUP
Malware family tracked by Malpedia. ID: win.hemigate