Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
Gomorrah is a stealer with no or little obfuscation that appeared around March 2020. It is sold for about 150$ lifetime for v4 (originally 400$ for v3) or 100$ per month by its developer called "th3darkly / lucifer" (which is also the developer of CosaNostra botnet). The malware's main functionalities are stealing (passwords, cryptocurrency wallets) and loading of tasks and other payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.gomet
APT GROUP
Malware family tracked by Malpedia. ID: win.golroted
APT GROUP
GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less, PowerShell-based attack leveraging steganography was executed. The initial attack was observed first in December 2017, when a Korean-language spear phishing campaing targeted organizations linked with Pyeongchang Winter Olympics 2018. GoldDragon was delivered once the attacker had gained an initial foothold in the targeted environment. The malware was capable of a basic reconnaissance, data exfiltration and downloading of additional components from its C&C server.
APT GROUP
Gold Max is a Golang written command and control backdoor used by the NOBELIUM threat actor group. It uses several different techniques to obfuscate its actions and evade detection. The malware writes an encrypted configuration file to disk, where the file name and AES-256 cipher keys are unique per implant and based on environmental variables and information about the network where it is running.
APT GROUP
According securityweek, GoldenSpy, the malware was observed as part of a campaign that supposedly started in April 2020, but some of the identified samples suggest the threat has been around since at least December 2016. One of the compromised organizations, a global technology vendor that conducts government business in the US, Australia and UK, and which recently opened offices in China, became infected after installing “Intelligent Tax,” a piece of software from the Golden Tax Department of Aisino Corporation, which a local bank required for paying local taxes. Although it worked as advertised, the software was found to install a hidden backdoor to provide remote operators with the possibility to execute Windows commands or upload and run files.
APT GROUP
Malware family tracked by Malpedia. ID: win.goldenhelper
APT GROUP
Malware family tracked by Malpedia. ID: win.goldeneye
APT GROUP
Malware family tracked by Malpedia. ID: win.goldbackdoor
APT GROUP
Malware family tracked by Malpedia. ID: osx.golangghost
APT GROUP
According to Symantec, a previously unseen backdoor that was deployed against a media organization in South Asia in November, 2023. GoGra is written in Go and uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services.
APT GROUP
Malware family tracked by Malpedia. ID: win.goggles
APT GROUP
A file infector written in Go, discovered by Karsten Hahn in February 2022. According to Karsten, despite its internal naming, it is not polymorphic and the virus body is not encrypted. Gofing uses the Coldfire Golang malware development library.
Malware family tracked by Malpedia. ID: win.godzilla_loader
APT GROUPespionageadvanced
GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities. GodRAT is likely connected with Winnty APT activities. Old implant codebases, such as Gh0st RAT, which are nearly two decades old, continue to be used today. These are often customized and rebuilt to target a wide range of victims. These old implants are known to have been used by various threat actors for a long time, and the GodRAT discovery demonstrates that legacy codebases like Gh0st RAT can still maintain a long lifespan in the cybersecurity landscape.
APT GROUP
Proof of concept for data exfiltration via DoH, written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.godlike12
Malware family tracked by Malpedia. ID: win.gocryptolocker
APT GROUP
Malware family tracked by Malpedia. ID: win.gobotkr
APT GROUP
Glupteba is a trojan horse malware that is one of the top ten malware variants of 2021. After infecting a system, the Glupteba malware can be used to deliver additional malware, steal user authentication information, and enroll the infected system in a cryptomining botnet.
APT GROUP
Malware family tracked by Malpedia. ID: win.glooxmail
APT GROUP
Malware family tracked by Malpedia. ID: win.glitch_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.glassrat
APT GROUP
Malware family tracked by Malpedia. ID: win.glasses
Updated: 2016-12-29
View profile →
APT GROUP
An information stealer written in .NET.
APT GROUP
Malware family tracked by Malpedia. ID: win.ginwui
APT GROUP
This multi-platform malware is a ObjectiveC written macOS variant dubbed GIMMICK by Volexity. This malware is a file-based C2 implant used by Storm Cloud.
APT GROUP
According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data exfiltration.
APT GROUP
Malware family tracked by Malpedia. ID: win.giffy
APT GROUP
Malware family tracked by Malpedia. ID: win.ghost_secret
APT GROUP
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks on Earth. Below is a list of Gh0st RAT capabilities. Take full control of the remote screen on the infected bot. Provide real time as well as offline keystroke logging. Provide live feed of webcam, microphone of infected host. Download remote binaries on the infected remote host. Take control of remote shutdown and reboot of host. Disable infected computer remote pointer and keyboard input. Enter into shell of remote infected host with full control. Provide a list of all the active processes. Clear all existing SSDT of all existing hooks.
APT GROUP
Malware family tracked by Malpedia. ID: win.ghost_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.ghost_admin
APT GROUP
GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in October 2023. It uses back-connect socket secure internet protocol (SOCKS5) connections and is available for rent for US $100 per month. In February 2024, the author of Lumma Stealer released an update introducing the integration of proxying capabilities. This feature, developed in partnership with GhostSocks, allows the use of infected hosts as SOCKS5 proxies and is available to all subscribers who purchase the "Professional" or higher tier plan. This integration allows Lumma Stealer users to establish a network of residential IP addresses for various purposes, including credential checking, spam distribution, or as general-purpose proxies.
APT GROUP
Malware family tracked by Malpedia. ID: win.ghostnet
APT GROUP
Malware family tracked by Malpedia. ID: win.ghole
APT GROUPespionageadvanced
According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP. Its capabilities include filesystem manipulation, file upload and download, shell command execution, keylogging, screen capture, clipboard monitoring, and additional plugin execution.
APT GROUP
Custom RAT developed by the BlackTech actor, based on the Gh0st RAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.gh0stbins
get pwd
Technical ID: get_pwd
APT GROUP
Malware family tracked by Malpedia. ID: win.get_pwd