Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUPfinancialhigh
Ransomware written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.jasus
APT GROUP
Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails and accounts information. Distributed in a ZIP container the interface is quite intuitive: the Microsoft exchange address and its version shall be provided. Three brute-force methods could be selected: EWS (Exchange Web Service), OAB (Offline Address Book) or both (All). Username and password list can be selected and threads number should be provided in order to optimize the attack balance.
APT GROUP
Malware family tracked by Malpedia. ID: win.janeleiro
APT GROUPespionageadvanced
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. Its focus is set on harvesting LATAM financial data and its method of extracting window titles for transmission underscores its targeted and stealthy nature. With an adaptive approach utilizing dynamic socket configuration and exploiting DLL side-loading from trusted sources, JanelaRAT poses a significant threat.
APT GROUP
Malware family tracked by Malpedia. ID: win.jaku
Malware family tracked by Malpedia. ID: win.jager_decryptor
Updated: 2016-12-28
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.jaff
APT GROUP
Malware family tracked by Malpedia. ID: win.jackpos
Updated: 2018-04-26
View profile →
APT GROUPespionageadvanced
According to Kaspersky Labs, this malware tool set has been used by APT group GoldenJackal, which has been observed since 2019 and which usually targets government and diplomatic entities in the Middle East and South Asia with espionage. It consists of multiple components and is written in .NET.
APT GROUP
Malware family tracked by Malpedia. ID: win.ixware
APT GROUP
Malware family tracked by Malpedia. ID: win.isspace
APT GROUP
ISR Stealer is a modified version of the Hackhound Stealer. It is written in VB and often comes in a .NET-wrapper. ISR Stealer makes use of two Nirsoft tools: Mail PassView and WebBrowserPassView. Incredibly, it uses an hard-coded user agent string: HardCore Software For : Public
APT GROUP
Malware family tracked by Malpedia. ID: win.israbye
Malware family tracked by Malpedia. ID: win.ispy_keylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.ismdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.ismagent
APT GROUPespionageadvanced
2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest. The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version. There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information. ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled. In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim. See win.gozi for additional historical information.
APT GROUP
According to Recorded Future, IsaacWiper is a destructive malware that overwrites all physical disks and logical volumes on a victim’s machine.
APT GROUP
Malware family tracked by Malpedia. ID: win.ironzero
APT GROUP
Malware family tracked by Malpedia. ID: win.ironwind
According to Mitre, IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.
APT GROUP
IRONHALO is a downloader that uses the HTTP protocol to retrieve a Base64 encoded payload from a hard-coded command-and-control (CnC) server and uniform resource locator (URL) path. The encoded payload is written to a temporary file, decoded and executed in a hidden window. The encoded and decoded payloads are written to files named igfxHK[%rand%].dat and igfxHK[%rand%].exe respectively, where [%rand%] is a 4-byte hexadecimal number based on the current timestamp. It persists by copying itself to the current user’s Startup folder.
APT GROUP
Malware family tracked by Malpedia. ID: win.ironcat
APT GROUP
Android variant of IPStorm (InterPlanetary Storm).
APT GROUP
A maliciously abused open source tool for port forwarding & intranet proxy.
APT GROUPespionageadvanced
Adversary group targeting diplomatic missions, governmental and military organisations, mainly in Ukraine.
According to Cyble, The Invicta Stealer can collect system information, system hardware details, wallet data, and browser data and extract information from applications like Steam and Discord.
APT GROUPfinancial
Interlock is a ransomware group first observed in September 2024 that targets critical infrastructure sectors including healthcare, government, education, and technology across North America and Europe using double-extortion, with 57+ claimed victims including a major US dialysis provider exposing over two million patient records.
Infra: 🔗 ebhmkoohccl45qesdbvr🔗 ebhmkoohccl45qesdbvr📁 zmqolc6yrdgn24w7eaaf+180 more
RLUpdated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: osx.interception
APT GROUP
InnaputRAT, a RAT capable of exfiltrating files from victim machines, was distributed by threat actors using phishing and Godzilla Loader. The RAT has evolved through multiple variants dating back to 2016. Recent campaigns distributing InnaputRAT beaconed to live C2 as of March 26, 2018.
APT GROUP
Malware family tracked by Malpedia. ID: win.inlock
APT GROUPespionage
Infy is a group of suspected Iranian origin. Since early 2013, we have observed activity from a unique threat actor group, which we began to investigate based on increased activities against human right activists in the beginning of 2015. In line5with other research on the campaign, released prior to publication of this document, we have adopted the name “Infy”, which is based on labels used in the infrastructure and its two families of malware agents. Thanks to information we have been able to collect during the course of our research, such as characteristics of the group’s malware and development cycle, our research strongly supports the claim that the Infy group is of Iranian origin and potentially connected to the Iranian state. Amongst a backdrop of other incidents, Infy became one of the most frequently observed agents for attempted malware attacks against Iranian civil society beginning in late 2014, growing in use up to the February 2016 parliamentary election in Iran. After the conclusion of the parliamentary election, the rate of attempted intrusions and new compromises through the Infy agent slowed, but did not end. The trends witnessed in reports from recipients are reinforced through telemetry provided by design failures in more recent versions of the Infy malware.
🇮🇷 IR
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
InfinityLock ransomware is a type of malicious software that encrypts a victim's files and demands a ransom payment in order to decrypt them. It is spread through phishing emails and malicious websites. Once a computer is infected with InfinityLock, it encrypts all important files, such as documents, photos, and videos. It then displays a message that demands the victim pay a ransom of $1,000 in Bitcoin in order to decrypt the files. If the victim does not pay the ransom, the files will be lost permanently.
APT GROUP
Malware family tracked by Malpedia. ID: win.inferno
APT GROUP
Malware family tracked by Malpedia. ID: win.industroyer2
APT GROUP
Industroyer is a malware framework considered to have been used in the cyberattack on Ukraine’s power grid on December 17, 2016. The attack cut a fifth of Kiev, the capital, off power for one hour. It is the first ever known malware specifically designed to attack electrical grids.
APT GROUPfinancialhigh
A ransomware that emerged in April 2022.
APT GROUP
Malware family tracked by Malpedia. ID: win.indigodrop