Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.fortunecrypt
Malware family tracked by Malpedia. ID: win.former_first_rat
APT GROUP
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
APT GROUP
Malware family tracked by Malpedia. ID: win.forest_tiger
APT GROUP
Malware family tracked by Malpedia. ID: win.fonix
APT GROUP
Malware family tracked by Malpedia. ID: win.fobber
APT GROUP
According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#. FoalShell allows attackers to execute arbitrary commands in the cmd.exe command line interpreter on a compromised host.
APT GROUP
Malware family tracked by Malpedia. ID: win.flystudio
Malware family tracked by Malpedia. ID: win.flying_dutchman
APT GROUP
Available since 2015, Flusihoc is a versatile C++ malware capable of a variety of DDoS attacks as directed by a Command and Control server. Flusihoc communicates with its C2 via HTTP in plain text.
APT GROUP
Malware family tracked by Malpedia. ID: win.floxif
APT GROUP
Malware family tracked by Malpedia. ID: win.flowershop
APT GROUP
Malware family tracked by Malpedia. ID: win.flowcloud
APT GROUP
Malware family tracked by Malpedia. ID: win.floki_bot
APT GROUP
Malware family tracked by Malpedia. ID: apk.flexispy
APT GROUP
According to M4lcode, FleshStealer is a sophisticated, modular, and obfuscated .NET-based information-stealing malware designed for comprehensive data exfiltration from Windows systems. Its architecture is built for scale and stealth, utilizing multithreading to simultaneously run multiple data harvesting routines with minimal system disruption. The malware targets a wide range of applications and services, including browsers, messaging apps, email clients, VPNs, cryptocurrency wallets, FTP clients, game launchers, and local file storage.
APT GROUP
According to ProofPoint, FlawedGrace is written in C++ and can be categorized as a Remote Access Trojan (RAT). It seems to have been developed in the second half of 2017 mainly. FlawedGrace uses a series of commands: FlawedGrace also uses a series of commands, provided below for reference: * desktop_stat * destroy_os * target_download * target_module_load * target_module_load_external * target_module_unload * target_passwords * target_rdp * target_reboot * target_remove * target_script * target_servers * target_update * target_upload
APT GROUP
FlawedAmmyy is a well-known Remote Access Tool (RAT) attributed to criminal gang TA505 and used to get the control of target machines. The name reminds the strong link with the leaked source code of Ammyy Admin from which it took the main structure.
APT GROUP
According to Intezer, this is a shellcode loader.
APT GROUP
FLASHFLOOD will scan inserted removable drives for targeted files, and copy those files from the removable drive to the FLASHFLOOD-infected system. FLASHFLOOD may also log or copy additional data from the victim computer, such as system information or contacts.
APT GROUP
Malware family tracked by Malpedia. ID: win.flame
APT GROUP
According to PICUS, Flagpro is malware that collects information from the victim and executes commands in the victim’s environment. It targets Japan, Taiwan, and English-speaking countries. When a victim is infected with Flagpro malware, the malware can do the following: Download and execute a tool Execute OS commands and send results Collect and send Windows authentication information
FK Undead
Technical ID: FK_Undead
APT GROUP
This malware family is mainly spread through various private server clients in bundles, and mainly tamper with user system network data packets through technical means such as TDI filtering, DNS hijacking, HTTP(s) injection, and HOSTS redirection, hijacking normal web page access to designated private server websites, and using security software cloud detection and killing data packet shielding, shutdown callback rewriting and other means to achieve counter-detection.
APT GROUP
Malware family tracked by Malpedia. ID: win.fivehands
APT GROUP
A custom loader for CobaltStrike.
APT GROUP
Malware family tracked by Malpedia. ID: win.first_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.firemalv
APT GROUP
The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g. files, processes, registry keys and network connections). According to Fortguard Labs, this malware uses Direct Kernel Object Modification (DKOM), which involves undocumented kernel structures and objects, for its operations, why this malware has to rely on specific OS builds.
APT GROUP
Malware family tracked by Malpedia. ID: win.firebird_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.fireball
APT GROUP
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer. This is achieved by sideloading another DLL among the legit TeamViewer.
APT GROUP
FinFisher is a commercial software used to steal information and spy on affected victims. It began with few functionalities which included password harvesting and information leakage, but now it is mostly known for its full Remote Access Trojan (RAT) capabilities. It is mostly known for being used in governmental targeted and lawful criminal investigations. It is well known for its anti-detection capabilities and use of VMProtect.
APT GROUP
Malware family tracked by Malpedia. ID: win.findpos
APT GROUP
Malware family tracked by Malpedia. ID: elf.finaldraft
APT GROUP
Malware family tracked by Malpedia. ID: win.final1stspy
APT GROUP
Filerase is a .net API-based utility capable of propagating and recursively deleting files.
APT GROUP
Malware family tracked by Malpedia. ID: win.fileice_ransom
Malware family tracked by Malpedia. ID: win.fickle
According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information, cryptocurrency wallets and browser information from applications such as WinSCP, Discord, Google Chrome, Electrum, etc. It does all that by implementing a different approach than other stealers (we’ll cover it later). Additionally, FickerStealer can function as a File Grabber and collect additional files from the compromised machine, and it can act as a Downloader to download and execute several second-stage malware.
APT GROUP
According to PCrisk, FFDroider is a malicious program classified as a stealer. It is designed to extract and exfiltrate sensitive data from infected devices. FFDroider targets popular social media and e-commerce platforms in particular.