Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUPfinancialhigh
Feodo (also known as Cridex or Bugat) is a Trojan used to commit e-banking fraud and to steal sensitive information from the victims computer, such as credit card details or credentials.
APT GROUP
Malware family tracked by Malpedia. ID: win.fenix
APT GROUP
Malware family tracked by Malpedia. ID: win.fengine
APT GROUP
Malware family tracked by Malpedia. ID: win.felixroot
APT GROUP
Malware family tracked by Malpedia. ID: win.felismus
APT GROUP
Malware family tracked by Malpedia. ID: win.feed_load
APT GROUP
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta. It functions as a simple malware downloader and is based on the TouchSocket framework over the Duplex Message Transport Protocol (DMTP). In one campaign, threat actors embedded FDMTP in the data section of a DLL. This allows it to be launched through DLL side-loading. The embedded network configurations are encoded and encrypted to enhance security and evade detection, utilizing Base64 and DES encryption methods. It has been observed to serve as a secondary control tool, often deployed by the PUBLOAD backdoor.
APT GROUP
Malware family tracked by Malpedia. ID: win.fauppod
APT GROUPespionageadvanced
According to ESET Research, FatDuke is the current flagship backdoor of APT29 and is only deployed on the most interesting machines. It is generally dropped by the MiniDuke backdoor, but ESET also have seen the operators dropping FatDuke using lateral movement tools such as PsExec.The operators regularly repack this malware in order to evade detections. The most recent sample of FatDuke that ESET have seen was compiled on May 24, 2019. They have seen them trying to regain control of a machine multiple times in a few days, each time with a different sample. Their packer, described in a later section, adds a lot of code, leading to large binaries. While the effective code should not be larger than 1MB, ESET have seen one sample weighing in at 13MB, hence our name for this backdoor component: FatDuke.
APT GROUP
FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels. FatalRAT executes various anti-virtual machine tests to avoid detection before fully infecting systems. Upon successful infiltration, it decrypts configuration strings, disables the CTRL+ALT+DELETE function, and activates a keylogger. The malware can establish persistence via registry modifications or service creation, collect sensitive data, and communicate with its command and control (C&C) server using encrypted methods. FatalRAT also employs techniques like brute-force attacks against weak passwords to propagate within networks.
APT GROUP
Malware family tracked by Malpedia. ID: win.fast_pos
APT GROUP
FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples. It typically downloads TrickBot. It may create a list of processes and uploads it together with screenshot(s). In more recent versions, it employs simple anti-analysis checks (VM detection) and comes with string obfuscations.
APT GROUP
Malware family tracked by Malpedia. ID: win.farseer
APT GROUPfinancialhigh
According to PCrisk, Fantom is a ransomware-type virus that imitates the Windows update procedure while encrypting files. This is unusual, since most ransomware encrypts files stealthily without showing any activity. During encryption, Fantom appends the names of encrypted files with the ".locked4", ".fantom" or ".locked" extension.
APT GROUP
Malware family tracked by Malpedia. ID: win.fanny
APT GROUP
FancyFilter is a piece of code that documents code overlap between frameworks used by Regin and Equation Group.
APT GROUP
Malware family tracked by Malpedia. ID: win.fakeword
APT GROUP
Malware family tracked by Malpedia. ID: win.faketc
APT GROUP
Malware family tracked by Malpedia. ID: win.fakerean
APT GROUP
Malware written in .NET that mimics WannaCry.
APT GROUP
Fabookie is facebook account info stealer.
APT GROUPespionageadvanced
EYService is the main part of the backdoor used by Nazar APT. This a passive backdoor that relies on, now discontinued, Packet Sniffer SDK (PSSDK) from Microolap.
APT GROUP
Malware family tracked by Malpedia. ID: win.eye_pyramid
APT GROUPespionageadvanced
According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information. This RAT has been used in attacks targeting Israeli and Syrian governments last 2012. This malware family of backdoors has the capability to receive commands such as File Management (Download, Upload, and Execute Files), Registry Management (Add, Delete, Query, and Modify Registry), Perform Shell Command, Computer Control (Shutdown, Log on/off), and Screen capture from a remote attacker. In addition, it can also log keystrokes of the infected systems.
APT GROUP
Malware family tracked by Malpedia. ID: win.explosive_rat
APT GROUP
Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features. Also the infection routine was changed in samples fround in 2017 (described by McAfee). Expiro "infiltrates" executables on 32- and 64bit Windows OS versions. It has capabilities to install browser extensions, change security behaviour/settings on the infected system, and steal information (e.g. account credentials). There is a newly described EPO file infector source code called m0yv in 2022, which is wrongly identified as expiro by some AVs.
APT GROUPfinancialhigh
Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
APT GROUPespionageadvanced
ExileRAT is a simple RAT platform capable of getting information on the system (computer name, username, listing drives, network adapter, process name), getting/pushing files and executing/terminating processes.
Malware family tracked by Malpedia. ID: win.exchange_tool
APT GROUP
Malware family tracked by Malpedia. ID: win.excalibur
APT GROUPfinancialhigh
ExByte is a custom data exfiltration tool and infostealer observed being used during BlackByte ransomware attacks.
APT GROUP
Malware family tracked by Malpedia. ID: elf.exaramel
APT GROUP
Malware family tracked by Malpedia. ID: win.evrial
APT GROUP
Privately modded version of the Pony stealer.
APT GROUP
A wiper used against in an attack against Iran’s state broadcaster. Using campaign name coined by Check Point in lack of a better name for the wiper component.
APT GROUP
Malware family tracked by Malpedia. ID: win.evilgrab
APT GROUP
Malware family tracked by Malpedia. ID: win.evilextractor
APT GROUP
EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise. This software is a remote access software. Threat actors modify the configuration extensively so that any signs of an active remote connection are removed. EvilConwi often pretends to perform a Windows update by using fake Windows update images embedded in the config. The purpose is to keep the system running while the threat actor connect remotely. Other EvilConwi signs are fake application icons. E.g., it may pretend to be an installer for Zoom and use its icons and application titles in the ConnectWise config.
APT GROUP
Malware family tracked by Malpedia. ID: win.evilbunny
APT GROUP
Malware family tracked by Malpedia. ID: win.etumbot