Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.getmypass
APT GROUP
Malware family tracked by Malpedia. ID: win.getmail
APT GROUP
Malware family tracked by Malpedia. ID: win.get2
APT GROUP
Malware family tracked by Malpedia. ID: win.geminiduke
APT GROUP
According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key. GEMCUTTER checks for the presence of the mutex MicrosoftGMMZJ to ensure only one copy of GEMCUTTER is executing. If the mutex doesn't exist, the malware creates it and continues execution; otherwise, the malware signals the MicrosoftGMMExit event.
APT GROUP
According to FireEye, GEARSHIFT is a memory-only dropper for two keylogger DLLs. It is designed to replace a legitimate Fax Service DLL.
APT GROUP
Malware family tracked by Malpedia. ID: win.gearinformer
APT GROUP
According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim information uploaded and payloads delivered.
APT GROUP
Malware family tracked by Malpedia. ID: win.gcleaner
APT GROUP
Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff. Functionality includes: - Loading other executables - Load hash cracking plugin - Load DMSniff plugin - Perform webinjection and webfakes - Form grabbing - Command execution - Download file from infected system - Convert infection into proxy - DDOS - Spreading and EXE infecting
APT GROUP
Malware family tracked by Malpedia. ID: win.gauss
APT GROUP
Gaudox is a http loader, written in C/C++. The author claims to have put much effort into making this bot efficient and stable. Its rootkit functionality hides it in Windows Explorer (32bit only).
APT GROUPfinancialhigh
A backdoor used by Mespinoza ransomware gang to maintain access to a compromised network.
APT GROUPfinancialhigh
GandCrab was a Ransomware-as-a-Service (RaaS) emerged in January 28, 2018, managed by a criminal organization known to be confident and vocal, while running a rapidly evolving ransomware campaign. Through their aggressive, albeit unusual, marketing strategies and constant recruitment of affiliates, they were able to globally distribute a high volume of their malware. In a surprising announcement on May 31, 2019, the GandCrab’s operators posted on a dark web forum, announced the end of a little more than a year of ransomware operations, citing staggering profit figures. However, If there’s one thing that sets these threat actors apart from other groups, it is that they are unpredictable; so there is always the possibility that they might re-surface in one form or another.
APT GROUP
GAMYBEAR A software tool developed using the Go programming language. Its main functionality is to receive (“listener”), execute (‘executor’) commands, and send (“sender”) results to the control server in BASE64-encoded form using the HTTP protocol. When launched, it generates a unique identifier (UUID), receives basic information about the computer (“whoami”, “wmic nicconfig where IPEnabled=true get IPAddress”), creates a helper file %APPDATA%\ updater.json, where the URL of the control server is stored in JSON format (key “update_server”), as well as other listed data in BASE64-encoded form (keys: “uuid”, ‘hostname’, “ip”, respectively). During operation, the software regularly sends requests to the control server (URI: “/c2/get_commands/”) and waits for a response in JSON format with the ‘command’ and “arguments” fields. If the “Nop” command is received, a 15-second pause is initiated. After the commands are executed, the result and other data are encoded using BASE64, stored in a JSON structure (keys: “uuid”, “command”, ‘output’) and sent to the control server with a request to the URI “/c2/command_out/”. The consistency of the launch is ensured by another program (script) at the stage of the initial infection of the computer by creating a key in the “Run” branch of the operating system registry.
APT GROUP
Malware family tracked by Malpedia. ID: win.gamotrol
Updated: 2018-07-24
View profile →
Malware family tracked by Malpedia. ID: win.game_player_framework
APT GROUPespionageadvanced
Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan. According to a report by Symantec, Gameover Zeus has largely been used for banking fraud and distribution of the CryptoLocker ransomware. In early June 2014, the U.S. Department of Justice announced that an international inter-agency collaboration named Operation Tovar had succeeded in temporarily cutting communication between Gameover ZeuS and its command and control servers.
APT GROUP
Malware family tracked by Malpedia. ID: win.gameover_dga
Updated: 2016-04-18
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.gamapos
APT GROUP
GalaxyLoader is a simple .NET loader. Its name stems from the .pdb and the function naming. It seems to make use of iplogger.com for tracking. It employed WMI to check the system for - IWbemServices::ExecQuery - SELECT * FROM Win32_Processor - IWbemServices::ExecQuery - select * from Win32_VideoController - IWbemServices::ExecQuery - SELECT * FROM AntivirusProduct
Updated: 2018-03-26
View profile →
APT GROUP
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
APT GROUP
Malware family tracked by Malpedia. ID: win.gacrux
APT GROUP
According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless stages. Additionally, it has the tendency to camouflage itself as a legitimate application, going so far as to mimic legitimate applications in its decompiled code. It also includes a steganographic image used to prepare further payloads. GaboonGrabber's final stage can deploy various types of malware, including Snake Keylogger, AgentTesla, Redline, Lokibot, and more.
APT GROUP
FuxSocy has some similarities to win.cerber but is tracked as its own family for now.
APT GROUP
FuwuqiDrama is a server-side RAT. It manages client connections by utilizing I/O completion ports, which are usually used in high-performance server applications as an elegant solution to manage many clients at once. It contains two distinguishing hardcoded lists. First is a list of ~50 video files of South Korean TV series, having their titles translated to Mandarin Chinese, but encoded in the form of Pinyin romanization. That means the sounds are spelled in Latin alphabet without tone marks, for example meiyounihuobuxiaqu.avi represents Can't Live Without You (a K-drama from 2012) or wulalafufu.avi translates to Ohlala Couple (also from 2012). Second is the list of the following corporations: NVIDIA, Amazon, Intel, Skype, 360Safe, Rising, Tencent, Mozilla, Adobe, Yahoo, Google. The same list is contained in some of the WannaCryptor samples. FuwuqiDrama stores its configuration in the INI file data\package_con_x86.cat. It contains the port number and a bot identifier, all within a single section called Fuwuqi – the romanized Chinese word for server.
APT GROUP
Malware family tracked by Malpedia. ID: win.fusiondrive
APT GROUP
Malware family tracked by Malpedia. ID: win.furtim
APT GROUP
Malware family tracked by Malpedia. ID: win.funny_dream
APT GROUP
Malware family tracked by Malpedia. ID: win.funnyswitch
APT GROUP
Malware family tracked by Malpedia. ID: win.fullmetal
APT GROUP
FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.
APT GROUP
Malware family tracked by Malpedia. ID: win.fs0ciety
APT GROUP
FROZENHILL is a launcher written in C++ that is configured to utilize existing files for execution and also infects newly attached storage volumes with additional malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.frostygoop
APT GROUP
Malware family tracked by Malpedia. ID: win.friedex
Malware family tracked by Malpedia. ID: win.freenki
APT GROUP
A RAT employing Node.js, Sails, and Socket.IO to collect information on a target
APT GROUP
Malware family tracked by Malpedia. ID: win.fpspy
APT GROUP
Malware family tracked by Malpedia. ID: win.foxsocket