Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
KrakenKeylogger is a .NET based Infostealer malware sold in Underground hacking forums
APT GROUPfinancial
Kraken is a Russian-speaking ransomware group that emerged in February 2025, believed to have links to the HelloKitty operation, employing a RaaS model notable for a benchmarking step that measures victim machine speed to optimize encryption, and in September 2025 launched an underground criminal forum called "The Last Haven Board."
Infra: 🔗 krakenccj3wr23452a4i…📁 zq3k4odlfpbzc5y4sxqg…📁 t3uouzfvsaqurb2rzoe2…+16 more
RSLUpdated: 2026-08-05
View profile →APT GROUPfinancialhigh
According to ESET, this malware family is a banking trojan and was active in Brazil until the middle of 2019. Its most noticeable characteristic was its usage of well-known cryptographic methods to encrypt strings, as opposed to the majority of Latin American banking trojans that mainly use custom encryption schemes.
APT GROUP
KPOT is an information-stealing Trojan horse that can steal information from infected computers. It is distributed through phishing emails and malicious websites. Once executed on a computer, KPOT can steal passwords, credit card numbers, and other personal information.
APT GROUPfinancialhigh
Kovter is a Police Ransomware
Feb 2012 - Police Ransomware
Aug 2013 - Became AD Fraud
Mar 2014 - Ransomware to AD Fraud malware
June 2014 - Distributed from sweet orange exploit kit
Dec 2014 - Run affiliated node
Apr 2015 - Spread via fiesta and nuclear pack
May 2015 - Kovter become fileless
2016 - Malvertising campaign on Chrome and Firefox
June 2016 - Change in persistence
July 2017 - Nemucod and Kovter was packed together
Jan 2018 - Cyclance report on Persistence
APT GROUP
Malware family tracked by Malpedia. ID: win.korlia
APT GROUP
Malware family tracked by Malpedia. ID: win.koobface
APT GROUPespionageadvanced
KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management, Creating a reverse shell, running WMI queries, retrieving information about the infected system.
APT GROUP
Malware family tracked by Malpedia. ID: win.kokokrypt
APT GROUP
Malware family tracked by Malpedia. ID: win.koistealer
APT GROUP
Malware family tracked by Malpedia. ID: win.koiloader
APT GROUP
Koadic is an open-source post-exploitation framework for Windows, created by zerosum0x0 and available on GitHub. The framework is written in Python and can generate JScript and VBScript payloads which can be written to disk or mapped directly into memory. Its capabilities include remote desktop access, command execution, lateral movement via SMB, file transfer, credential theft using Mimikatz, port scanning, and system information collection. It can also collect specific system information and targeted files based on their name or extension.
APT GROUPfinancial
[Cyclops](group/cyclops) rebrand
Infra: 🔗 knight3xppu263m7g4ag…💬 3r7zqtidvujbmfhx52sb…📁 uzfrntnmwojla5v4w3xv…+3 more
RSLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.klrd
APT GROUP
Malware family tracked by Malpedia. ID: win.klogexe
APT GROUP
Malware family tracked by Malpedia. ID: win.klingon_rat
APT GROUP
KleptoParasite Stealer is advertised on Hackforums as a noob-friendly stealer. It is modular and comes with a IP retriever module, a Outlook stealer (32bit/64bit) and a Chrome/Firefox stealer (32bit/64bit). Earlier versions come bundled (loader plus modules), newer versions come with a loader (167k) that grabs the modules.
PDB-strings suggest a relationship to JogLog v6 and v7.
APT GROUP
Microsoft describes that threat actor ZINC is using Klackring as a malware dropped by ComeBacker, both being used to target security researchers.
APT GROUP
According to Zscaler, a malware sharing similarities with GhostRAT and Big Bad Wolf. The RAT’s features include clipboard manipulation to replace cryptocurrency addresses and the deployment of remote monitoring tools (i.e. Sunlogin, GotoHTTP).
APT GROUP
According to Threatray, KiwiStealer is a simple file stealer first discovered in late 2024. It starts by gathering the computer name and username. It also retrieves the current system time, which will be used later to check the last modification time of files on the machine. KiwiStealer searches through a predefined list of directories to gather files and only exfiltrates files that are smaller than 50MB and have been modified within the past year. It targets these extensions: z7, .txt, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .jpg, .zip, .rar, .apk, .neat, .err, .eln, .ppi, .er9, .azr, .pfx, .ovpn.
APT GROUP
Malware family tracked by Malpedia. ID: elf.kivars
APT GROUP
Malware family tracked by Malpedia. ID: win.kins
APT GROUP
According to Sophis, the botnet has been active since 2018, initially, the botmasters operated DDoS tools and backdoors, but later moved on to cryptocurrency miners. They use a DGA to automatically change the hosting
domains every week.
APT GROUP
Malware family tracked by Malpedia. ID: win.kimjongrat
APT GROUP
Malware family tracked by Malpedia. ID: win.killsomeone
APT GROUP
KillDisk is a generic detection name used by ESET to refer to destructive malware with disk wiping capabilities, such as damaging boot sectors and overwriting then deleting (system) files, followed by a reboot to render the machine unusable. Although all KillDisk malware has similar functionality, as a generic detection, individual samples do not necessarily have strong code similarities or relationships. Such generic malware detections usually have many “sub-families”, distinguished by the detection suffix (e.g. KillDisk.NBO, KillDisk.NCV, and KillDisk.NCX). Sub-family variants that do have strong code similarities, are sometimes seen in separate cyberattacks and thus can help researchers make connections between them.
APT GROUP
Malware family tracked by Malpedia. ID: win.killav
APT GROUP
Malware family tracked by Malpedia. ID: win.kikothac
APT GROUP
According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address. KHRAT provides the threat actors typical RAT features and access to the victim system, including keylogging, screenshot capabilities, remote shell access and so on.
APT GROUPfinancialhigh
A compact ransomware written in .NET and delivered as follow-up to Log4J exploitation, targeting Windows servers.
KGH SPY
Technical ID: KGH_SPY
APT GROUP
Malware family tracked by Malpedia. ID: win.kgh_spy
APT GROUP
Malware family tracked by Malpedia. ID: win.keymarble
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: win.keylogger_apt3
APT GROUP
According to Walmart Global Tech, Keyhole is a multi-functional VNC/Backconnect component used extensively by IcedID/Anubis. While the malware contains functionality that has been previously reported on as typical VNC and HDESK capabilities, a general lack of technical information appears to exist around some of the expanded functionality currently present.
APT GROUP
KeyBase is a .NET credential stealer and keylogger that first emerged in February 2015. It often incorporates Nirsoft tools such as MailPassView and WebBrowserPassView for additional credential grabbing.
APT GROUP
Intezer found this family mid May 2020, which appears to be a merger of the family Ketrican and Okrum.
APT GROUPespionageadvanced
Ketrican is a backdoor trojan used by APT 15.
APT GROUP
Malware family tracked by Malpedia. ID: win.kerrdown