Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
Keylogger written in Visual Basic dating back to at least 2012.
APT GROUP
INCONTROLLER (aka PIPEDREAM) is a set of tools built to target machine automation devices. The tools can interact with specific industrial equipment embedded in different types of machinery leveraged across multiple industries. This tool set is very likely state sponsored and contains capabilities related to disruption, sabotage, and potentially physical destruction.
APT GROUP
ImprudentCook is an HTTP(S) downloader. It was delivered in the Operation DreamJob type of activity targeting aerospace and defense companies in South Africa (in Q2 2022) and in Central Europe (in H1 2023), and against an unknown sector in South Korea back in Q2 2021. It uses the AES cipher implemented through Windows Cryptographic Providers for decryption of its binary configuration, and also for encryption and decryption of the client-server communication. It’s hidden in an ADS stream (:dat or :zone) of its dropper, together with its configuration (:rsrc) and an AES-128 CBC key with an initialization vector for its decryption (:kgb or :data). It contains two characteristic arrays of strings that represent cookie names for web services, including Bing, Daum and GitHub: 1. iKc;__uid;OAX;DMP_UID;PCID;_gid;_gat;csrftoken;NID;1P_JAR;JSESSIONID;WLS;SNID;__ utma;BID;SRCHD;GsCK_AC;spintop;eader;XSRF-TOKEN;_gat_gtag_UA;webid_ enabled;EDGE_V;dtck_channel;dtmulti;UUID;XUID;ZIA;IUID;SSID;_gh_sess;_octo 2. channel;post_titles;xfw_exp;wiht_clkey;SGPCOUPLE;NRTK;fbp;uaid;SRCHUSR;GUC;HPVN;dtck_ blog;dtck_media;MUIDB;SRCHHPGUSR;SiteMain It contains a string, "5.40" or "5.60", looking like version information.
ZScaler describes Immortal Stealer as a windows malware written in .NET designed to steal sensitive information from an infected machine. The Immortal stealer is sold on the dark web with different build-based subscriptions.
MITRE describes Imminent Monitor as a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.
APT GROUP
Malware family tracked by Malpedia. ID: win.imecab
APT GROUP
Malware family tracked by Malpedia. ID: win.imap_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.iispy
APT GROUP
Malware family tracked by Malpedia. ID: win.iisniff
APT GROUP
Malware family tracked by Malpedia. ID: win.idkey
APT GROUP
Malware family tracked by Malpedia. ID: win.icyheart
APT GROUP
Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and browser using an embedded copy of the SQLite3 library.
APT GROUP
Malware family tracked by Malpedia. ID: win.icondown
APT GROUPfinancialhigh
The ICE IX bot is a banking trojan derived of the Zeus botnet because it uses significant parts of Zeus’s source code. ICE IX communicates using the HTTP protocol, so it can be considered to be a third-generation botnet. While it has been used for a variety of purposes, a primary threat of ICE IX comes from its manipulation of banking operations on compromised machines. As with any bot, execution of the bot results in establishing a master-slave relationship between the botmaster and the compromised computer.
APT GROUP
According to nao_sec, this malware is a simple passive-mode backdoor that is installed as a service.
APT GROUP
According to nao_sec, this malware is an IIS backdoor.
APT GROUP
Malware family tracked by Malpedia. ID: win.icefog
Malware family tracked by Malpedia. ID: win.icedid_downloader
APT GROUPfinancialhigh
According to Proofpoint, IcedID (aka BokBot) is a malware originally classified as a banking malware and was first observed in 2017. It also acts as a loader for other malware, including ransomware. The well-known IcedID version consists of an initial loader which contacts a Loader C2 server, downloads the standard DLL Loader, which then delivers the standard IcedID Bot. IcedID is developed and operated by the actor named LUNAR SPIDER. As previously published, historically there has been just one version of IcedID that has remained constant since 2017. * In November 2022, Proofpoint researchers observed the first new variant of IcedID Proofpoint dubbed 'IcedID Lite' distributed as a follow-on payload in a TA542 Emotet campaign. It was dropped by the Emotet malware soon after the actor returned to the e-crime landscape after a nearly four-month break. * The IcedID Lite Loader observed in November 2022 contains a static URL to download a 'Bot Pack' file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud. * Starting in February 2023, Proofpoint observed the new Forked variant of IcedID. This variant was distributed by TA581 and one unattributed threat activity cluster which acted as initial access facilitators. The campaigns used a variety of email attachments such as Microsoft OneNote attachments and somewhat rare to see .URL attachments, which led to the Forked variant of IcedID.
APT GROUPfinancial
icarus — tracked by MISP Galaxy (ransomware).
Infra: 🔗 e6ujsppajgb756x7x5yk
RSLUpdated: 2026-08-05
View profile →
APT GROUPespionageadvanced
According to Cofense, this malware is notable for having several unique tactics, techniques, and procedures (TTPs), such as Secure Email Gateway (SEG) evasion by proxying emails through legitimate infrastructure, fake CAPTCHAs, abusing hardcoded Windows functionality to hide dropped files, and C2 capabilities over Invisible Internet Project (I2P), a peer-to-peer anonymous network with end-to-end encryption. Upon installation, I2Parcae is capable of disabling Windows Defender, enumerating Windows Security Accounts Manager (SAM) for accounts/groups, stealing browser cookies, and remote access to infected hosts. As of November 2024, I2Parcae appears to be delivered via automated spam messages targeting customer support contact forms on multiple websites. The messages deliver an embedded link purporting to be pornography.
APT GROUP
Malware family tracked by Malpedia. ID: osx.hz_rat
APT GROUP
Malware family tracked by Malpedia. ID: elf.hyperssl
APT GROUP
Malware family tracked by Malpedia. ID: win.hyperscrape
APT GROUP
HyperBro is a RAT that has been observed to target primarily within the gambling industries, though it has been spotted in other places as well. The malware typically consists of 3 or more components: a) a genuine loader typically with a signed certification b) a malicious DLL loader loaded from the former component via DLL hijacking c) an encrypted and compressed blob that decrypts to a PE-based payload which has its C2 information hardcoded within.
APT GROUP
Malware family tracked by Malpedia. ID: win.hxdef
APT GROUP
Malware family tracked by Malpedia. ID: win.hussar
APT GROUP
Malware family tracked by Malpedia. ID: win.huskloader
APT GROUP
Malware family tracked by Malpedia. ID: win.hupigon
APT GROUPespionageadvanced
Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet controversial threat actor in the cybercrime ecosystem. While initial analysis revealed a code overlap with the dismantled Hive ransomware, the group claims independence, asserting it purchased Hive’s source code rather than directly rebranding. This operational lineage enables advanced double-extortion campaigns prioritizing data exfiltration over encryption, with confirmed theft of medical records, financial data, and proprietary business information. The group's ransomware is written in Rust, a programming language favored for its resilience to reverse engineering and cross-platform compatibility.
Malware family tracked by Malpedia. ID: win.hunter
APT GROUP
A loader that has been used by multiple threat actor groups since 2015.
http troy
Technical ID: http_troy
APT GROUP
Malware family tracked by Malpedia. ID: win.http_troy
The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols. It accepts up to 10 command line parameters: a 29-byte decryption key, a C&C for data exfiltration, the name of a local RAR split volume, the name of the multivolume archive on the server side, the size of a RAR split (max 200,000 kB), the starting index of a split, the ending index of a split, and the switch -p with a proxy IP address and port
APT GROUP
Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the infected endpoint.
APT GROUP
Malware family tracked by Malpedia. ID: win.httpdropper
APT GROUP
Malware family tracked by Malpedia. ID: win.httpbrowser
APT GROUP
Malware family tracked by Malpedia. ID: win.htran
APT GROUP
Malware family tracked by Malpedia. ID: win.htprat
APT GROUP
Malware family tracked by Malpedia. ID: win.htbot
Updated: 2017-05-29
View profile →