Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
This malware is part of the Eternity Malware "Framework".
APT GROUP
This Stealer is part of the eternity malware project.
APT GROUPfinancialhigh
Eternity Framework Ransomware Payload
APT GROUP
This malware is part of the Eternity Malware "Framework".
APT GROUPfinancialhigh
According to proofpoint, Bad Rabbit is a strain of ransomware that first appeared in 2017 and is a suspected variant of Petya. Like other strains of ransomware, Bad Rabbit virus infections lock up victims’ computers, servers, or files preventing them from regaining access until a ransom—usually in Bitcoin—is paid.
APT GROUP
Malware family tracked by Malpedia. ID: win.eternalrocks
APT GROUP
Malware family tracked by Malpedia. ID: win.especter
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.erica_ransomware
APT GROUP
Eredel Stealer is a low price malware that allows for extracting passwords, cookies, screen desktop from browsers and programs.
According to nulled[.]to:
Supported browsers
Chromium Based: Chromium, Google Chrome, Kometa, Amigo, Torch, Orbitum, Opera, Opera Neon, Comodo Dragon, Nichrome (Rambler), Yandex Browser, Maxthon5, Sputnik, Epic Privacy Browser, Vivaldi, CocCoc and other Chromium Based browsers.
- Stealing FileZilla
- Stealing an account from Telegram
- Stealing AutoFill
- Theft of wallets: Bitcoin | Dash | Monero | Electrum | Ethereum | Litecoin
- Stealing files from the desktop. Supports any formats, configurable via telegram-bot
APT GROUP
Malware family tracked by Malpedia. ID: elf.erebus
APT GROUP
Erbium is an information stealer advertised and sold as a Malware-as-a-Service on cybercrime forums and Telegram since at least July 2022. Its capabilities are those of a classic information stealer, with a focus on cryptocurrency wallets, and file grabber capabilities.
APT GROUP
Rough collection EQGRP samples, to be sorted
APT GROUP
Malware family tracked by Malpedia. ID: win.equationdrug
APT GROUP
Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon". This malware is distributed as a game, mainly on discord, but steals user credentials, crypto wallets, and stored cookies. It evades static detection by being packed with NSIS, which then launches a malicious Electron package.
APT GROUPfinancialhigh
According to PCrisk, Epsilon is a ransomware-type program. This malware is designed to encrypt the data of infected systems in order to demand payment for decryption.
APT GROUP
Malware family tracked by Malpedia. ID: win.envyscout
APT GROUP
According to Microsoft, Enviserv is a malicious program that is unable to spread of its own accord. It may perform a number of actions of an attacker's choice on an affected computer.
APT GROUP
Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old KeyBoy samples. The embedded malware config was encrypted with a unique algorithm.
APT GROUP
According to Trend Micro, this is a downloader, dedicated to stage execution of a second stage malware called Enigma Stealer.
APT GROUP
Malware family tracked by Malpedia. ID: win.enfal
APT GROUP
Supposedly a worm that was active around 2012-2013.
APT GROUP
Malware family tracked by Malpedia. ID: win.empire_downloader
APT GROUPespionageadvanced
While Emotet historically was a banking malware organized in a botnet, nowadays Emotet is mostly seen as infrastructure as a service for content delivery. For example, since mid 2018 it is used by Trickbot for installs, which may also lead to ransomware attacks using Ryuk, a combination observed several times against high-profile targets.
It is always stealing information from victims but what the criminal gang behind it did, was to open up another business channel by selling their infrastructure delivering additional malicious software. From malware analysts it has been classified into epochs depending on command and control, payloads, and delivery solutions which change over time.
Emotet had been taken down by authorities in January 2021, though it appears to have sprung back to life in November 2021.
APT GROUP
Emmenhtal is a malicious loader likely distributed since early 2024, and publicly detailed by Orange Cyberdefense CERT in August 2024.
Emmenhtal is an obfuscated multistage payload that spawns an execution of the LOLBIN mshta.exe to read a first HTA stage that embeds a malicious JavaScript code. Once interpreted and executed, the JavaScript decodes and runs a PowerShell script. The latter decrypts an obfuscated PowerShell loader which finally downloads and runs final-stage stealers and commodity RATs.
As of March 2025, Orange Cyberdefense CERT has identified three versions of the loader, all actively distributed.
APT GROUP
Malware family tracked by Malpedia. ID: win.emissary
APT GROUP
Malware family tracked by Malpedia. ID: win.emdivi
APT GROUP
ELMER is a non-persistent proxy-aware HTTP backdoor written in Delphi, and is capable of performing file uploads and downloads, file execution, and process and directory listings. To retrieve commands, ELMER sends HTTP GET requests to a hard-coded CnC server, and parses the HTTP response packets received from the CnC server for an integer string corresponding to the command that needs to be executed.
APT GROUP
This dropper masquerades itself as Adobe software, titled as Adobe.msi. It is used to executes the python written Backdoor used by this threat actor.
APT GROUP
Malware family tracked by Malpedia. ID: win.eliza_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.elise
APT GROUP
Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. Mostly attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. Multiple Elirks variants using Japanese blog services for the last couple of years.
APT GROUP
Malware family tracked by Malpedia. ID: win.electric_powder
APT GROUPespionageadvanced
The application is a command-line utility and its primary purpose is to tunnel traffic between two IP addresses. The application accepts command-line arguments allowing it to be configured with a destination IP address and port, a source IP address and port, a proxy IP address and port, and a user name and password, which can be utilized to authenticate with a proxy server. It will attempt to establish TCP sessions with the source IP address and the destination IP address. If a connection is made to both the source and destination IPs, this malicious utility will implement a custom protocol, which will allow traffic to rapidly and efficiently be tunneled between two machines. If necessary, the malware can authenticate with a proxy to be able to reach the destination IP address. A configured proxy server is not required for this utility.
APT GROUP
Malware family tracked by Malpedia. ID: win.ekipa
APT GROUP
Malware family tracked by Malpedia. ID: win.ehdevel
APT GROUP
Trend Micro describes EDRSilencer as a red team tool originally designed to interfere with endpoint detection and response solutions via the Windows Filtering Platform, which is actively being used by threat actors.
APT GROUP
According to Elastic Security Labs, this is a newly discovered Rust infostealer targeting Windows hosts, which receives a task list from the C2 server identifying data to target.
APT GROUP
According to Orange Cyberdefense, Edam is written in C++ and its PDB path indicates it is called "droper_dll". It is capable of establishing persistence by setting up a Run key as Setting App which points towards its own file and then of downloading from another C2 a final stage using HTTP GET.
APT GROUPfinancialhigh
EDA2 is a successor of HiddenTear. Just like HiddenTear it was developed as an open-source project by a security researcher and published on Github. It was meant as "educational ransomware" and purposefully had flaws in the encryption process that allow decryption of ransomed files.
This backfired, when threat actors began to modify HiddenTear and EDA2 source code. Some modifications introduced bugs where encrypted files were destroyed, others fixed the encryption flaws and made decryption without a key impossible.