Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.keona
APT GROUP
Stealer written in Python, available as open source on Github.
APT GROUP
Malware family tracked by Malpedia. ID: win.kelihos
APT GROUP
Malware family tracked by Malpedia. ID: win.kegotip
APT GROUP
Malware family tracked by Malpedia. ID: win.kdcsponge
APT GROUP
According to Karsten Hahn, a straightforward loader that runs assemblies from images.
APT GROUP
Malware family tracked by Malpedia. ID: win.kazuar
APT GROUP
Malware family tracked by Malpedia. ID: win.katz_stealer
APT GROUPfinancial
Kasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatter/LockBit ransomware codebase. The malware appends the .kasseika extension to encrypted files and uses a double-extortion model, combining file encryption with threats to publish stolen data on a Tor-based leak site. Early analysis revealed that Kasseika shares several traits with LockBit 3.0, including encryption routines, obfuscation methods, and ransom note structure, but with modified branding and negotiation portals. Initial access vectors have not been widely confirmed, though patterns from related ransomware suggest the use of compromised credentials, RDP exploitation, and vulnerabilities in public-facing services. Victims have been observed in North America, Europe, and Asia, spanning industries like manufacturing, logistics, and professional services.
RSLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.kasperagent
APT GROUP
Malware family tracked by Malpedia. ID: win.karsto_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.karkoff
APT GROUPfinancialhigh
According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently implementing webinject attacks only.
It comes with an injector that loads an intermediate "proxy" component, which in turn loads the actual banker component.
Communication with the c2 are in json format and encrypted with RC4 with a hardcoded key.
In the initial version, observed in March 2018, the webinjects were hardcoded in the binary, while in subsequent versions, they were received by the c2.
APT GROUPfinancialhigh
According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg. banking trojans/credential theft etc.This malware has been on sale by an actor under the username Yattaze, starting in late April. The actor offers the sale of the malware as a standalone build with charges for each additional rebuild, or the ability to set up a botshop in which case any customer can establish their own operation and further sell access to a new customer base.
APT GROUP
Malware family tracked by Malpedia. ID: win.karagany
APT GROUP
Malware family tracked by Malpedia. ID: win.kapeka
APT GROUP
Kaolin RAT is a complex modular RAT, with Release_TMain_x64.dll as its internal DLL name.
The malware provides standard backdoor functionality, including manipulation and listing of files and processes, exchanging the configuration, collecting the victim’s system info, opening a TCP connection, and executing local commands and collecting their outputs.
Also, it is designed to execute additional DLL payloads in memory via specific exported functions:
- _DoMyFunc,
- _DoMyFunc2,
- _DoMyThread,
- _DoMyCommandWork.
Functionally, Kaolin RAT relies on an accompanying trojanized curl library to handle network and exfiltration operations, by importing functions such as:
- SendDataFromURL,
- ZipFolder,
- UnzipStr,
- curl wrappers.
For C&C communication, it employs AES encryption and attempts to evade network detection by randomly selecting words from a hardcoded custom dictionary to populate POST request parameters. The malware's name is derived from one of these dictionary words ("kaolin").
The Kaolin RAT has been observed in Lazarus campaigns as a late-stage payload — typically following loaders like RollFling, RollSling, and RollMid — and serves also as a delivery vector for the FudModule rootkit with a 0-day exploit.
APT GROUP
A Telegram bot with browser stealing capabilities, written using the .NET framework.
APT GROUP
Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to download files, receive commands, and execute files, allowing it to perform HTTP and DNS flooding attacks. The bot is also used to access sensitive files.
The bot has been seen to be communicating with third-party platforms such as Telegram, Discord, and GitHub, using these platforms as backup C2 servers.
APT GROUP
Malware family tracked by Malpedia. ID: win.kagent
APT GROUP
Malware family tracked by Malpedia. ID: win.jupiter
APT GROUP
According to FireEye, JUMPALL is a malware dropper that has been observed
dropping HIGHNOON/ZXSHELL/SOGU.
APT GROUP
As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM".
APT GROUP
Malware family tracked by Malpedia. ID: win.jssloader
APT GROUP
JSOutProx is a sophisticated attack framework built using both Javascript and .NET. It uses the .NET (de)serialization feature to interact with a Javascript file which is the core module running on a victim machine. Once the malware is run on the victim, the framework can load several plugins performing additional malicious activities on the target.
APT GROUP
Malware family tracked by Malpedia. ID: win.jripbot
APT GROUP
Malware family tracked by Malpedia. ID: win.jqjsnicker
APT GROUP
Malware family tracked by Malpedia. ID: win.jolob
win.JobCrypter
Technical ID: win.jobcrypter
MALWARE
Malware family identifying win.jobcrypter. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family tracked by Malpedia. ID: win.joao
APT GROUP
Malware family tracked by Malpedia. ID: win.joanap
APT GROUP
Malware family tracked by Malpedia. ID: win.jlorat
APT GROUP
Malware family tracked by Malpedia. ID: win.jinxloader
APT GROUP
Malware family tracked by Malpedia. ID: win.jimmy
APT GROUPfinancialhigh
According to PCrisk, Jigsaw is ransomware that uses the AES algorithm to encrypt various files stored on computers. Targeted files include .jpg, .docx, .mp3, .mp4, and many others.
APT GROUP
Cisco Talos identified JhoneRAT in January 2020. The RAT is delivered through cloud services (Google Drive) and also submits stolen data to them (Google Drive, Twitter, ImgBB, GoogleForms). The actors using JhoneRAT target Saudi Arabia, Iraq, Egypt, Libya, Algeria, Morocco, Tunisia, Oman, Yemen, Syria, UAE, Kuwait, Bahrain and Lebanon.
APT GROUP
JessieConTea is a remote access trojan that uses HTTP(S) for communication. It supports around 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration (both plain and zipped), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 32-bit integers, starting with the value 0x60D49D97.
The malware was delivered in-the-wild via trojanized applications like DeFi Wallet or Citrix Workspace.
JessieConTea generates POST parameters with a specific parameter name, jsessid, from which the initial part of its name is derived. Also, it contains a specific RTTI symbol ".?AVCHttpConn@@", which inspired the second part of the name. It uses RC4 for C&C traffic encryption.
APT GROUP
Malware family tracked by Malpedia. ID: win.jelus_rat