Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.heloag
APT GROUP
Malware family tracked by Malpedia. ID: win.helminth
APT GROUP
Malware family tracked by Malpedia. ID: elf.hellobot
APT GROUP
Malware family tracked by Malpedia. ID: win.helauto
APT GROUP
Malware family tracked by Malpedia. ID: win.headlace
APT GROUP
The Chinese threat actor "Scarab" is using a custom backdoor dubbed "HeaderTip" according to SentinelLABS. This malware may be the successor of "Scieron".
APT GROUP
Malware family tracked by Malpedia. ID: win.hdroot
APT GROUPfinancialhigh
HDMR is a ransomware which encrypts user files and adds a .DMR64 extension. It also drops a ransom note named: "!!! READ THIS !!!.hta".
APT GROUP
Malware family tracked by Malpedia. ID: win.hazy_load
APT GROUP
Malware family tracked by Malpedia. ID: win.hawking
HawKeye is a keylogger that is distributed since 2013. Discovered by IBM X-Force, it is currently spread over phishing campaigns targeting businesses on a worldwide scale. It is designed to steal credentials from numerous applications but, in the last observed versions, new "loader capabilities" have been spotted. It is sold by its development team on dark web markets and hacking forums.
APT GROUP
HAWKBALL is a backdoor that attackers can use to collect information from the victim, as well as to deliver payloads. HAWKBALL is capable of surveying the host, creating a named pipe to execute native Windows commands, terminating processes, creating, deleting and uploading files, searching for files, and enumerating drives.
APT GROUPespionageadvanced
Havex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control systems (ICS) used across numerous industries and attributed to a hacking group referred to as "Dragonfly" and "Energetic Bear". Havex is estimated to have impacted thousands of infrastructure sites, a majority of which were located in Europe and the United States. Within the energy sector, Havex specifically targeted energy grid operators, major electricity generation firms, petroleum pipeline operators, and industrial equipment providers. Havex also impacted organizations in the aviation, defense, pharmaceutical, and petrochemical industries. Once installed, Havex scanned the infected system to locate any Supervisory Control and Data Acquisition (SCADA) or ICS devices on the network and sent the data back to command and control servers. To do so, the malware leveraged the Open Platform Communications (OPC) standard, which is a universal communication protocol used by ICS components across many industries that facilitates open connectivity and vendor equipment interoperability. Havex used the Distributed Component Object Model (DCOM) to connect to OPC servers inside of an ICS network and collect information such as CLSID, server name, Program ID, OPC version, vendor information, running state, group count, and server bandwidth. Havex was an intelligence-collection tool used for espionage and not for the disruption or destruction of industrial systems. However, the data collected by Havex would have aided efforts to design and develop attacks against specific targets or industries.
APT GROUP
Malware family tracked by Malpedia. ID: win.havana_crypt
APT GROUP
According to Intezer, this is a wiper.
Malware family tracked by Malpedia. ID: win.haron
APT GROUP
Malware family tracked by Malpedia. ID: win.harnig
APT GROUP
Malware family tracked by Malpedia. ID: apk.hardrain
Malware family tracked by Malpedia. ID: win.happy_locker
Updated: 2017-04-29
View profile →
APT GROUP
Hancitor(aka Chanitor) emerged in 2013 which spread via social engineering techniques mainly through phishing mails embedded with malicious link and weaponized Microsoft office document contains malicious macro in it.
APT GROUP
Malware family tracked by Malpedia. ID: win.hamweq
APT GROUPespionageadvanced
A stager used by APT29 to deploy CobaltStrike.
APT GROUPfinancialhigh
Ransomware written in C#.
APT GROUP
Py2Exe based tool as found on github.
APT GROUP
Malware family tracked by Malpedia. ID: win.hacksfase
Browser information stealer, written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: elf.habitsrat
APT GROUP
Malware family tracked by Malpedia. ID: win.h1n1
Malware family tracked by Malpedia. ID: win.gup_proxy
APT GROUP
Malware family tracked by Malpedia. ID: win.guidloader
APT GROUP
According to haxrob, GTPDOOR is the name of Linux based malware that is intended to be deployed on systems in telco networks adjacent to the GRX (GRPS eXchange Network) with the novel feature of communicating C2 traffic over GTP-C (GPRS Tunnelling Protocol - Control Plane) signalling messages. This allows the C2 traffic to blend in with normal traffic and to reuse already permitted ports that maybe open and exposed to the GRX network.
APT GROUP
A malware family with a DGA.
APT GROUP
Malware family tracked by Malpedia. ID: win.gsecdump
APT GROUP
Malware family tracked by Malpedia. ID: win.grunt
APT GROUPespionageadvanced
According to PCrisk, Growtopia (also known as CyberStealer) is an information stealer written in the C# programming language. It can obtain system information, steal information from various applications, and capture screenshots. Its developer claims that it has created this software for educational purposes only. This stealer uses the name of a legitimate online game.
APT GROUP
Malware family tracked by Malpedia. ID: win.ground_peony
APT GROUP
Malware family tracked by Malpedia. ID: win.grok
APT GROUP
This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).
APT GROUPfinancialhigh
GRIMAGENT is a backdoor that can execute arbitrary commands, download files, create and delete scheduled tasks, and execute programs via scheduled tasks or via the ShellExecute API. The malware persists via a randomly named scheduled task and a registry Run key. The backdoor communicates to hard-coded C&C servers via HTTP requests with portions of its network communications encrypted using both asymmetric and symmetric cryptography. GRIMAGENT was used during some Ryuk Ransomware intrusions in 2020.
APT GROUP
This is a proxy-aware HTTP backdoor that is implemented as a service and uses the compromised system's proxy settings to access the internet. C&C traffic is base64 encoded and the files sent to the server are compressed with aPLib.