Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,713 entities
APT GROUPfinancialhigh
ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies. ShinyHunters typically uses phishing attacks and exploit kits to gain access to victim networks, where they deploy malware to steal sensitive data, such as names, addresses, phone numbers, Social Security numbers, and credit card information.
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
RansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware. They have been linked to attacks exploiting the Zerologon vulnerability to gain initial access. RansomHub has attracted former affiliates of the ALPHV ransomware group and operates as a Ransomware-as-a-Service with a unique affiliate prepayment model. The group has been active in extorting victims and leaking sensitive data to pressure for ransom payments.
APT GROUP
This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear if they conducted the attacks themselves, or if they bought leaked databases from third parties.
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
NullBulge is a cybercriminal threat group targeting AI and gaming focused entities. They weaponize code in publicly available repositories to distribute malware, including LockBit ransomware. The group claims to be motivated by a pro-art, anti-AI cause, but their activities indicate a financial focus. NullBulge uses obfuscated code in public repositories and malicious mods to target their victims.
Updated: 2026-08-03
View profile →
APT GROUP
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies by leaking sensitive, stolen data.
🇮🇷 IRT1505.003T1021.002T1087.001
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
Mogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs, offering stolen data for sale without providing proof of the attacks. They operate as an extortion group, targeting high-profile victims and demanding payment for the data they claim to have stolen. Despite their claims, security researchers have noted that Mogilevich's tactics and website design suggest they may not be a sophisticated threat actor.
Updated: 2026-08-03
View profile →
APT GROUP
An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements.
T1136.003T1578.003T1589
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails to pressure victims. The group has claimed 17+ victims across France, Romania, Thailand, Malaysia, Egypt, and the UAE within its first weeks of activity, targeting energy, pharmaceutical, retail, hospitality, and film sectors, with confirmed exfiltration totaling 760+ GB.
Updated: 2026-08-03
View profile →
APT GROUPhacktivism
KelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and private organizations globally. The group sells and leaks databases, documents, and access belonging to their victims, often on the dark web or their own platforms. They have been involved in attacks against various sectors, including telecommunications, political parties, and healthcare.
ES
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group has claimed responsibility for multiple high-profile breaches, including those of Manage My Health and the Defensoría del Pueblo de Colombia, exfiltrating sensitive data through techniques like exploiting unpatched vulnerabilities and credential reuse. Kazu has demanded ransoms ranging from $60,000 to $500,000, threatening public disclosure of stolen data if payments are not made. Their operations have primarily focused on entities in Latin America, Asia, and the Middle East, with a notable presence on dark web leak sites.
Updated: 2026-08-03
View profile →
APT GROUP
Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt victims have not reported encryption of compromised machines or files; rather, Karakurt actors have claimed to steal data and threatened to auction it off or release it to the public unless they receive payment of the demanded ransom. Known ransom demands have ranged from $25,000 to $13,000,000 in Bitcoin, with payment deadlines typically set to expire within a week of first contact with the victim.
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare sector. The group is financially motivated, demanding Bitcoin payments for the secure deletion of stolen files and threatening to leak data if victims do not comply. While no specific TTPs are publicly known, common techniques among extortion groups include phishing and scanning for exposed internet-facing devices. There is a potential link to a user on a Russian-language cybercriminal forum who shares a post-exploitation script, but attribution remains uncertain.
Updated: 2026-08-03
View profile →
APT GROUPhacktivism
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive attacks using custom wiper malware. The group utilizes a multi-stage loading process, including a Delphi-coded second-stage loader and an AutoIT injector, to deliver wiper malware that specifically targets Windows and Linux environments. Their phishing campaigns often exploit major events and critical vulnerabilities, masquerading as legitimate organizations to gain initial access. Handala operates a data leak site to publicize stolen data, although claims of successful attacks are sometimes disputed by targeted organizations.
PS
APT GROUPfinancialhigh
Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS to centralize its ransomware activities. The group advertises a free DDoS tool and may develop its own ransomware binary, indicating significant technical capability. The DLS was likely created in late November to early December 2024, with the first advertisement titled “Funksec Ransomware” posted on 3 December 2024. Currently, there is limited publicly available information on Funksec's TTPs, and it is not known to be associated with any other threat groups.
APT GROUPfinancialhigh
FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited vulnerabilities such as hardcoded credentials and misconfigured cloud permissions to gain access to targets, including Novo Nordisk and Arup Group. Their operations involve extensive dwell time, with claims of spending months analyzing stolen data before contacting victims. FulcrumSec has demonstrated a targeted approach, often demanding ransoms that are strategically calculated based on the victim's financial profile.
Updated: 2026-08-03
View profile →
APT GROUPespionageadvanced
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.
MY
APT GROUPfinancialhigh
Coinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 victims, primarily in the healthcare, technology, and transportation sectors. The group employs TTPs such as social engineering, credential harvesting, and collaboration with Initial Access Brokers to gain initial access. They operate a data leak site where they publish victim names and issue ransom demands, requiring payment via Bitcoin.
Updated: 2026-08-03
View profile →
APT GROUP
The Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configurations and plaintext VPN credentials. Their leaked data, organized by country and IP address, primarily consists of configurations from FortiOS 7.0.6 and 7.2.1, which were the last vulnerable versions before patches were issued. Security researcher Kevin Beaumont confirmed that the group leveraged this vulnerability to gain unauthorized access and warned of potential exploitation of CVE-2024-55591 by similar threat actors. Fortinet has stated that the leaked data originates from older campaigns and not from any recent incidents.
Updated: 2026-08-03
View profile →
APT GROUPfinancialhigh
AzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various cyberattacks targeting Israel and pro-Israel countries. Additionally, AzzaSec has engaged in ransomware activities and has been known to collaborate with other cybercriminal groups.
IT
Updated: 2026-08-03
View profile →
APT GROUPespionageadvanced
APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that of LockBit, likely to leverage LockBit's reputation and attract potential affiliates. The rationale for this design mimicry is unclear, but it may be intended to signal operational parity with LockBit to inspire trust among low-level criminals. APT73 was formed by an alleged former LockBit affiliate following law enforcement's "Operation Cronos" in February 2024.
Updated: 2026-08-03
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.revstealer
APT GROUP
According to Proofpoint, IceCube is a JavaScript-based stealer likely developed with the assistance of a large language model, targeting Roundcube webmail instances. It escapes the webmail's iFrame context via DOM traversal to access the full document and the authentication session, then exfiltrates usernames, passwords, two-factor authentication material, cookies, and browser reconnaissance data (such as language, screen size, and form field values) via HTTP POST to its command-and-control server. The malware is heavily commented with well-marked execution phases, and incorporates self-cleanup routines, "fallbacks" for failed exploitation steps, and "deferred triggers" that hook browser events such as tab changes, mouse leaving the window, and the logout button to re-attempt exploitation. After successful server-side exploitation, it destroys both user and malware-initiated sessions to remove forensic evidence from the Roundcube server.
APT GROUP
According to Cisco Talos, JARLEASH is a JAVA-based backdoor deployed on attacker infrastructure and compromised systems with JAVA available, providing a web-based file management interface, FTP and SFTP servers, and a netcat server, with configuration comments written in Simplified Chinese.
APT GROUP
According to Cisco Talos, LONGLEASH is a new version of the previously disclosed SHORTLEASH backdoor, built from the same C++ codebase and compiled for Linux on MIPS using the Boost.Asio asynchronous networking library along with open-source components for protobuf processing and TLS, and it offers extensive proxying and tunneling capabilities such as reverse shells, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxies, SMTP, packet redirection, and the ability to act as an intermediate command and control server while self-removing if tampering is detected.
APT GROUP
According to Cisco Talos, DOGLEASH is a C-based passive backdoor for Linux networking devices that binds and listens on a hardcoded port, decodes incoming TCP data with a hardcoded password, spawns threads to run actions such as executing shell commands, reading and renaming files, reporting OS information, and executing code in memory.
Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
Updated: 2026-08-03
View profile →
APT GROUP
Microsoft threat actor profile. Origin/Threat: Group in development.
Updated: 2026-08-03
View profile →
Microsoft threat actor profile from the public naming mapping feed.
Updated: 2026-08-03
View profile →
Microsoft threat actor profile. Origin/Threat: China.
🇨🇳 CN
Updated: 2026-08-03
View profile →
APT GROUP
Microsoft threat actor profile. Origin/Threat: Lebanon.
LBT1595.002T1190T1105
Updated: 2026-08-03
View profile →
APT GROUP
According to Acronis, MINIRECON is a shellcode-based implant derived from the Toneshell8 family, written in C/C++ and deployed in memory by SHARDLOADER after reconstruction from an obfuscated, XOR-decrypted payload. It retains core Toneshell characteristics such as PEB-walking to resolve kernel32.dll, a 13131313 hash multiplier for API resolution, an LCG-based session key, a 256-byte XOR beacon scheme, and an opcode-driven dispatcher supporting two parallel reverse shells, file upload/download, remote command execution, and a drop-and-execute chain. Its main evolution is in command-and-control communications, shifting to WebSocket-over-HTTPS beaconing via the native WinHTTP API with self-signed certificate handling and a proxy fallback to blend into enterprise environments.
APT GROUP
According to Acronis, ZOHOMURK is a newly identified DLL implant written in C/C++ that abuses the legitimate Zoho WorkDrive cloud storage service for command-and-control, data exfiltration and remote task execution. It is sideloaded via a signed Citrix Receiver binary dropped by its SHARDLOADER parent, with a single export function serving as the implant's entry point and timing-based anti-debug checks guarding key steps such as registry writes and initial beaconing. Capabilities include an interactive shell via a pipe, file upload/download handled through a small opcode-driven dispatcher, victim registration by creating folders on the operator's WorkDrive account, OAuth-based authentication with hardcoded credentials, a heartbeat/re-registration thread, and Run-key persistence established only after passing environment and timing checks
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
According to Rapid7, this RAT loaded by Donut is a native 32-bit C++ remote access implant that is mapped and executed entirely in memory by a shellcode-based loader. It features extensive obfuscation and stealth characteristics, including control-flow flattening, dynamic API resolution, static CRT linking, and multiple anti-analysis checks for debuggers, sandboxes, virtualized environments, and geolocation. The malware fingerprints the host by collecting system and user information plus a full process list, then communicates with its command-and-control over HTTPS with fields protected using Salsa20-based encryption and layered encoding. Its core capabilities include recursive directory listing, downloading and executing additional payloads, interactive shell command execution, on-demand screenshot capture, and exfiltration of arbitrary files.
APT GROUPfinancialhigh
According to Zscaler, MLTBackdoor is a Windows post-exploitation backdoor likely written in C/C++ and compiled with an LLVM-based obfuscator that applies heavy mixed boolean-arithmetic and control-flow flattening, plus DJB2-based API hashing and indirect system calls to hinder analysis and evade hooks. It uses a custom binary protocol over TLS with elliptic-curve Diffie-Hellman key exchange and AES-GCM for encrypted C2 traffic, and includes a date-based domain generation algorithm (DGA) to maintain contact if primary C2 domains are unavailable. Natively, it provides a focused set of filesystem commands for uploading, downloading, listing, deleting, renaming, and creating files and folders. Its key feature is a built-in Beacon Object File loader compatible with a subset of Cobalt Strike-style BOF imports and its own syscall wrappers, allowing operators to dynamically extend capabilities for activities such as discovery, credential access, and lateral movement, which Zscaler links to ransomware-oriented operations.
APT GROUP
According to SentinelLabs, Gaslight is a DPRK-aligned macOS backdoor and infostealer written in Rust that communicates over the Telegram Bot API, using AES-GCM encryption layered on certificate-pinned TLS. The implant provides an interactive remote shell with generic capabilities for command execution, file exfiltration, process management, and configuration-driven persistence, and it can stage a Python-based stealer via a bundled installer that fetches a standalone CPython runtime at execution time. It collects browser data, system and process information, and keychain contents, packaging and uploading them through the same hardened command-and-control channel. A distinctive characteristic is its embedded multi-message prompt-injection payload designed to manipulate LLM-assisted analysis pipelines, along with runtime self-redaction of its bot token to prevent credential leakage in logs or crash artifacts.
APT GROUP
According to Picus Security, Showboat is a modular post-exploitation framework implemented as a 64-bit ELF binary targeting AMD x86-64 Linux systems, used for long-term, covert access rather than initial compromise or encryption. It retrieves an XOR-encrypted configuration from its command-and-control server, uses randomized sleep intervals, and wraps host telemetry (including system information, running processes, and screenshots) in an encrypted, base64-encoded JSON blob disguised inside PNG metadata for beaconing. The framework provides standard remote access capabilities such as file transfer, directory and filesystem manipulation, and configurable persistence. For stealth, it can download and compile an additional C-based component on the victim and leverage dynamic linker preload mechanisms to hook system-level functions and hide selected processes from userland monitoring tools.
APT GROUP
Malware family tracked by Malpedia. ID: win.solaris_loader
APT GROUP
According to Elastic Security Labs, CASTLESTEALER is a .NET-based information-stealing malware family that is delivered in-memory by the OXLOADER loader using DonutLoader-generated shellcode. It is embedded as an encrypted and compressed .NET assembly that is decrypted, decompressed, and reflectively executed in memory to minimize on-disk artifacts. The family uses AES-encrypted communications with its command-and-control infrastructure, with a characteristic hard-coded key that has been reused across samples. As an infostealer targeting Windows environments, it is designed to collect sensitive data (such as user credentials and other information) and interacts with the system in memory to support discovery and data exfiltration while evading conventional detection.
APT GROUP
Malware family tracked by Malpedia. ID: win.oxloader