Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
LgoogLoader is an installer that drops three files: a batch file, an AutoIt interpreter, and an AutoIt script. After downloading, it executes the batch file.
APT GROUP
Malware family tracked by Malpedia. ID: win.letmeout
APT GROUP
Lethic is a spambot dating back to 2008. It is known to be distributing low-level pharmaceutical spam.
APT GROUP
Leslieloader is a loader written in Golang, named after the observed AES decryption key referencing deceased actor, Leslie Cheung. The loader assists in the initial infection and deployment of the malicious payload, enabling execution on a system. The loader achieves its goal by decoding and decrypting a secondary payload binary, then injecting it into another process.
APT GROUP
Malware family tracked by Malpedia. ID: win.leouncia
APT GROUP
Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network. The malware runs its payload mainly in memory. Internal network spreading is performed by SMB RCE Vulnerability (CVE-2017-0144), or brute-force attacks.
APT GROUP
Malware family tracked by Malpedia. ID: win.lechiket
APT GROUP
Malware family tracked by Malpedia. ID: win.leash
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
A further branch of the URSNIF collection of malware families. According to Mandiant, it no longer has focus on banking fraud but generic backdoor capabilities instead.
APT GROUP
Malware family tracked by Malpedia. ID: win.lcpdot
APT GROUP
Malware family tracked by Malpedia. ID: win.lazycat
APT GROUP
Malware family tracked by Malpedia. ID: win.laziok
Malware family tracked by Malpedia. ID: win.lazarus_killdisk
APT GROUP
Malware family tracked by Malpedia. ID: win.lazarloader
APT GROUP
Malware family tracked by Malpedia. ID: win.lazardoor
Malware family tracked by Malpedia. ID: win.laturo
APT GROUP
First discovered in October 2023, BLACKWIDOW is a backdoor written in C that communicates over HTTP using RC4 encrypted requests. The malware has the capability to execute discovery commands, query information about the victim's machine, update itself, as well as download and execute an EXE, DLL, or shellcode. The malware is believed to have been developed by LUNAR SPIDER, the creators of IcedID (aka BokBot) Malware.
APT GROUPfinancialhigh
FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless. Using Dynamic Threat Intelligence, they have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which they named LATENTBOT – caught attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations.
According to Seqrite, this is a TLS-based reverse shell.
APT GROUP
Clipboard stealer.
APT GROUP
Malware family tracked by Malpedia. ID: win.lamdelin
APT GROUP
According to Microsoft, this is a downloader used in a supply chain attack involving a malicious variant of an application developed by CyberLink. It is centered around a legitimate CyberLink application installer that has been modified to include malicious code that downloads, decrypts, and loads a second-stage payload. The file, which was signed using a valid certificate issued to CyberLink Corp., is hosted on legitimate update infrastructure owned by CyberLink and includes checks to limit the time window for execution and evade detection by security products.
APT GROUP
Malware family tracked by Malpedia. ID: osx.lambert
Malware family tracked by Malpedia. ID: win.lalala_stealer
APT GROUP
According to its self-description, Ladon is a multi-threaded plug-in comprehensive scanning artifact for large-scale network penetration, including port scanning, service identification, network assets, password blasting, high-risk vulnerability detection and one click getshell. It supports batch a segment / b segment / C segment and cross network segment scanning, as well as URL, host and domain name list scanning.
APT GROUP
Kwampirs is a family of malware which uses SMB to spread. It typically will not execute or deploy in environments in which there is no publicly available admin$ share. It is a fully featured backdoor which can download additional modules. Typical C2 traffic is over HTTP and includes "q=[ENCRYPTED DATA]" in the URI.
APT GROUP
Cofense characterizes Kutaki as a data stealer that uses old-school techniques to detect sandboxes and debugging. Kutaki however works quite well against unhardened virtual machines and other analysis devices. By backdooring a legitimate application, it can fool unsophisticated detection methodologies.
APT GROUP
Malware family tracked by Malpedia. ID: win.kurton
APT GROUP
Malware family tracked by Malpedia. ID: win.kuluoz
Updated: 2017-11-23
View profile →
APT GROUPfinancial
kuiper — tracked by MISP Galaxy (ransomware).
RSLUpdated: 2026-08-05
View profile →
APT GROUP
According to Threatray, KugelBlitz is a shellcode loader discovered in late 2024. It loads shellcode into memory from a file specified via command line. If no file is specified, it defaults to run.bin.
APT GROUP
Malware family tracked by Malpedia. ID: win.kuaibu8
Updated: 2017-03-29
View profile →
APT GROUP
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning.
APT GROUP
A keylogger used by Turla.
APT GROUP
Malware family tracked by Malpedia. ID: win.kryptocibule
APT GROUPespionageadvanced
Kronos malware is a sophisticated banking Trojan that first emerged in 2014. It is designed to target financial institutions and steal sensitive banking information. The malware is primarily spread through phishing campaigns and exploit kits. Once installed on a victim's computer, Kronos can capture login credentials, credit card details, and other personal information by keylogging and form grabbing techniques. It can also bypass security measures such as two-factor authentication. Kronos employs advanced evasion techniques to avoid detection by antivirus software and actively updates itself to evade security patches. It has been known to target a wide range of banking systems and has affected numerous organizations worldwide. The malware continues to evolve, making it a significant threat to online banking security.
APT GROUP
According to Trend Micro, this is a rootkit with capabilities of a full-featured backdoor with various capabilities, including process manipulation, file hiding, shellcode execution, traffic concealment, and C&C communication. It is controlled through a range of IOCTL codes.
APT GROUP
Malware family tracked by Malpedia. ID: win.krdownloader
Updated: 2017-05-12
View profile →
APT GROUPfinancialhigh
ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking institutions. It was discovered in early 2014 and since then has adopted a variety of infection and credential stealing techniques.