Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.mail_o
APT GROUP
According to Zscaler, MAILCREEP is a Golang-based backdoor leveraging the Microsoft Graph API for its C2 communications.
APT GROUPfinancialhigh
According to TXOne, The Magniber ransomware was first identified in late 2017 when it was discovered using the Magnitude Exploit Kit to conduct malvertising attacks against users in South Korea. However, it has remained active since then, continually updating its tactics by employing new obfuscation techniques and methods of evasion. In April 2022, Magniber gained notoriety for disguising itself as a Windows update file to lure victims into installing it. It then began spreading via JavaScript in September 2022.
APT GROUP
According to Talos, MagicRAT is programmed in C++ programming language and uses the Qt Framework by statically linking it to the RAT on 32- and 64-bit versions. The Qt Framework is a programming library for developing graphical user interfaces, of which this RAT has none. Talos thinks that the objective was to increase the complexity of the code, thus making human analysis harder. On the other hand, since there are very few examples (if any) of malware programmed with Qt Framework, this also makes machine learning and heuristic analysis detection less reliable. The RAT uses the Qt classes throughout its entire code. The configuration is dynamically stored in a QSettings class eventually being saved to disk, a typical functionality provided by that class.
MagicRAT provides the operator with a remote shell on the victim's system for arbitrary command execution, along with the ability to rename, move and delete files on the endpoint. The operator can determine the timing for the implant to sleep, change the C2 URLs and delete the implant from the infected system.
APT GROUP
According to DCSO, this malware is written as a Extended Stored Procedure for a MSSQL server. The backdoor has capabilities to bruteforce logins to other MSSQL servers, adding a special hardcoded backdoor user in the case of successfully bruteforcing admin logins.
APT GROUP
Malware family tracked by Malpedia. ID: win.magala
APT GROUP
Malware family tracked by Malpedia. ID: win.madmax
APT GROUP
Malware family tracked by Malpedia. ID: win.macaw
APT GROUP
Malware family tracked by Malpedia. ID: win.macamax
APT GROUPfinancialhigh
Modular x86/x64 file infector created/used by Maze ransomware developer. According to the author, it has been mistakenly tagged by AVs as Expiro.
APT GROUPespionageadvanced
According Zscaler, M00nD3V Logger has the ability to steal confidential information, such as browser passwords, FTP client passwords, email client passwords, DynDNS credentials, JDownloader credentials; capture Windows keystrokes; and gain access to the webcam and hook the clipboard. In all, it has the ability to steal passwords from 42 applications.
APT GROUP
Malware family tracked by Malpedia. ID: win.lyposit
APT GROUPfinancial
Lynx is a ransomware-as-a-service operation that emerged in mid-2024 as a rebrand of INC Ransomware (whose source code was sold for $300,000 on the RAMP forum), claiming ~300 victims across manufacturing, business services, technology, and transportation with an 80/20 profit split for affiliates.
Infra: 🔗 lynxblog.net…🔗 lynxbllrfr5262yvbgtq…💬 lynxch2k5xi35j7hlbmw…+34 more
RLUpdated: 2026-08-05
View profile →APT GROUP
This Golang written malware is used as backdoor using the http protocol by a state sponsored threat actor (TA). This backdoor is running in a loop of three stages:
- Check the connectivity
- Registration of the victim
- Retrieval and execution of commands
This TA is using also variants .NET backdoors utilizing HTTP and DNS.
APT GROUP
This .Net written malware is used as backdoor using the http protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using DNS (.Net) and also one written in Golang.
APT GROUP
This .NET written malware is used as backdoor using the dns protocol by a state sponsored threat actor. It implements additional capabilities (e.g. execution of commands, taking screenshots, listing diles/directories/installed applications, and uploading/downloading/execution of files). There are also variants using HTTP (.Net) and also one written in Golang.
APT GROUP
Malware family tracked by Malpedia. ID: win.luzo
APT GROUP
Malware family tracked by Malpedia. ID: win.luxy
APT GROUP
Malware family tracked by Malpedia. ID: win.lurk
APT GROUP
An uploader that can exfiltrate files to Dropbox.
APT GROUP
According to ESET Research, this is a Outlook Add-In that can use email messages for its C&C communication.
APT GROUP
Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell.
APT GROUP
Malware family tracked by Malpedia. ID: win.luminosity_rat
APT GROUP
This family was previously tracked as PovertyStealer until it's actual name was identified via crime forums.
APT GROUP
Malware family tracked by Malpedia. ID: win.lukalocker
APT GROUP
Malware family tracked by Malpedia. ID: win.lucifer
APT GROUP
According to PCRisk, The Luca stealer can extract a variety of information from compromised machines. It targets data related to the following: operating system, device name, CPUs, desktop environment, network interface, user account name, preferred system language, running processes, etc.
This malicious program can steal information from over thirty Chromium-based browsers. From these applications, Luca can obtain Internet cookies, account log-in credentials (usernames/passwords), and credit card numbers. Additionally, the stealer can extract data from password manager and cryptowallet browser extensions compatible with over twenty browsers.
This malware also targets various messaging applications like Telegram, Discord, ICQ, Skype, Element, etc. It likewise aims to acquire information from gaming-related software such as Steam and Uplay (Ubisoft Connect). Furthermore, some versions of Luca can take screenshots and download the files stored on victims' devices.
APT GROUP
Malware family tracked by Malpedia. ID: win.luadream
APT GROUP
According to PCrisk, Lu0bot es un software malicioso. El malware es ligero, por lo que su uso de los recursos del sistema es bajo. Esto complica la detección de Lu0bot, ya que no causa síntomas significativos, como una grave disminución del rendimiento del sistema.
El programa malicioso funciona como un recolector de telemetría.
APT GROUP
This in Go written malware is lsass process memory dumper, which was custom developed by threat actors according to Security Joes. It has the capability to automatically exfiltrate the results to the free file transfer service "transfer.sh".
APT GROUP
LPEClient is an HTTP(S) downloader that expects two command line parameters: an encrypted string containing two URLs (a primary and a secondary C&C server), and the path on the victim's file system to store the downloaded payload.
It sends detailed information about the victim's environment, like computer name, type and number of processors, computer manufacturer, product name, major and minor Windows versions, architecture, memory information, installed security software and the version of the ntoskrnl.exe from its version-information resource.
LPEClient uses specific 32-bit values to represent its execution state (0x59863F09 when connecting via the WinHTTP interface, 0xA9348B57 via WinINet), or the nature of HTTP requests to the C&C servers (0xF07D6B34 when sending system information, 0xEF8C0D51 when requesting a DLL payload, 0xCB790A25 when reporting the successful loading of the DLL, 0xD7B20A96 when reporting the state of the the DLL execution). As the final step, malware looks for the export CloseEnv and executes it.
APT GROUP
Malware family tracked by Malpedia. ID: win.lowzero
APT GROUP
Malware family tracked by Malpedia. ID: win.lowkey
APT GROUP
LOWBALL, uses the legitimate Dropbox cloud-storage
service to act as the CnC server. It uses the Dropbox API with a hardcoded bearer access token and has the ability to download, upload, and execute files. The communication occurs via HTTPS over port 443.
APT GROUP
Malware family tracked by Malpedia. ID: win.loupeloader
APT GROUP
Frank Boldewin describes Loup as a small cli-tool to cash out NCR devices (ATM).
APT GROUPfinancial
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
Infra: 🔗 lorenzmlwpzgxq736jzs…🔗 woe2suafeg6ehxivgvvn…💬 lorenzedzyzyjhzxvlcv…+1 more
RLUpdated: 2026-08-05
View profile →APT GROUP
L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018. Out of the box, L0rdix supports eight commands, although custom commands can be defined and added. These include:
Download and execute
Update
Open page (visible)
Open page (invisible)
Cmd
Kill process
Upload file
HTTP Flood
L0rdix can extract credentials from common web browsers and steal data from crypto wallets and a target's clipboard. Optionally, L0rdix can deploy a cryptominer (XMRig) to its bots.
APT GROUP
Malware family tracked by Malpedia. ID: win.lookback