Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
Houdini is a VBS-based RAT dating back to 2013. Past in the days, it used to be wrapped in an .exe but started being spamvertized or downloaded by other malware directly as .vbs in 2018. In 2019, WSHRAT appeared, a Javascript-based version of Houdini, recoded by the name of Kognito.
APT GROUP
HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file. HOTWAX decrypts a payload using the Spritz algorithm with a hard-coded key and then searches the target process and attempts to inject the decrypted payload module from the CHM file into the address space of the target process.
APT GROUP
Malware family tracked by Malpedia. ID: win.hotcroissant
APT GROUP
Remote Acess Tool Written in VB.NET.
APT GROUP
According to Check Point Research, this is a custom-built agent for Mythic, the open-source red teaming C2 framework. Written in C++, the implant shows no significant overlap with known C-based Mythic agents, aside from commonalities in the generic logic related to Mythic C2 communications.
APT GROUP
Hopscotch is part of the Regin framework.
APT GROUP
Malware family tracked by Malpedia. ID: win.hoplight
APT GROUP
Malware family tracked by Malpedia. ID: win.hookinjex
APT GROUP
a 64-bit Windows password dumper/cracker that has previously been used in conjunction with AIRBREAK and BADFLICK backdoors. Some strings are obfuscated with XOR x56. The malware accepts up to two arguments at the command line: one to display cleartext credentials for each login session, and a second to display cleartext credentials, NTLM hashes, and malware version for each login session.
APT GROUP
Malware family tracked by Malpedia. ID: win.holerun
APT GROUP
Adware, tied to eGobbler and Nephos7 campaigns,
APT GROUP
Malware family tracked by Malpedia. ID: win.hodur
APT GROUP
Malware family tracked by Malpedia. ID: win.hlux
APT GROUP
Malware family tracked by Malpedia. ID: win.hi_zor_rat
APT GROUPfinancial
Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe.
In 2022 there was a switch from GoLang to Rust.
Affiliates: Wazawaka
Infra: 🔗 hiveleakdbtnp76ulyhi…💬 hivecust6vhekztbqgdn…🔗 hiveapi4nyabjdfz2hxd…
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.hisoka
APT GROUP
Malware family tracked by Malpedia. ID: win.himera_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.himan
APT GROUPfinancialhigh
A new ransomware family was discovered in August 2019. Called HILDACRYPT, it is named after the Netflix cartoon “Hilda” because the TV show’s YouTube trailer was included in the ransom note of the original version of the malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.hikit
APT GROUP
According to Rapid7, this is a loader first spotted in July 2023. It implements several evasion techniques including Process Doppelgänging, DLL Search Order Hijacking, and Heaven's Gate. It has been observed to store its malicious payload in the IDAT chunk of PNG file format.
APT GROUP
Malware family tracked by Malpedia. ID: win.highnote
APT GROUP
Malware family tracked by Malpedia. ID: win.highnoon_bin
APT GROUP
According to FireEye, HIGHNOON is a backdoor that may consist of multiple components. The components may include a loader, a DLL, and a rootkit. Both the loader and the DLL may be dropped together, but the rootkit may be embedded in the DLL. The HIGHNOON loader may be designed to run as a Windows service.
APT GROUP
Malware family tracked by Malpedia. ID: win.hidedrv
APT GROUPfinancialhigh
HiddenTear is an open source ransomware developed by a Turkish programmer and later released as proof of concept on GitHub. The malware generates a local symmetric key in order to encrypt a configurable folder (/test was the default one) and it sends it to a centralized C&C server. Due to its small payload it was used as real attack vector over email phishing campaigns. Variants are still used in attacks.
APT GROUP
Malware family tracked by Malpedia. ID: win.hiddenbee
APT GROUP
Malware family tracked by Malpedia. ID: win.hiasm
APT GROUP
Malware family tracked by Malpedia. ID: win.heyoka
APT GROUPfinancialhigh
On August 9th, 2024, the HexaLocker team advertised a new Windows ransomware on its Telegram channel. The message included a demonstration video and text promoting a Golang ransomware that implements a proprietary algorithm.
APT GROUP
Malware family tracked by Malpedia. ID: win.hesperbot
APT GROUP
Malware family tracked by Malpedia. ID: win.herpes
APT GROUP
Malware family tracked by Malpedia. ID: win.hermeticwizard
APT GROUP
According to SentinelLabs, HermeticWiper is a custom-written application with very few standard functions. It abuses a signed driver called "empntdrv.sys" which is associated with the legitimate Software "EaseUS Partition Master Software" to enumerate the MBR and all partitions of all Physical Drives connected to the victims Windows Device and overwrite the first 512 Bytes of every MBR and Partition it can find, rendering them useless.
This malware is associated to the malware attacks against Ukraine during Russians Invasion in February 2022.
APT GROUPfinancial
Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group operating out of Asia. It originally appeared as a Ransomware-as-a-Service (RaaS) offering on underground forums but later saw deployment in targeted attacks. Hermes uses AES-256 encryption to lock victim files and appends a variety of extensions (including .hrm and campaign-specific variants). The ransom note, often named DECRYPT_INFORMATION.html or DECRYPT_INFORMATION.txt, provides payment instructions via email. The ransomware gained notoriety in 2018 when it was used as a destructive wiper in the Far Eastern International Bank (FEIB) heist in Taiwan, where attackers deployed Hermes to cover their tracks after a SWIFT fraud operation. Over time, Hermes code has been re-used and integrated into other ransomware families, including some Ryuk builds, suggesting code sharing or purchase from the original developer. Distribution vectors have included phishing campaigns, malicious attachments, and exploitation of RDP services.
RSLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.heriplor
APT GROUP
Malware family tracked by Malpedia. ID: win.herbst
APT GROUP
Malware family tracked by Malpedia. ID: win.hemigate
APT GROUP
Malware family tracked by Malpedia. ID: win.heloag
APT GROUP
Malware family tracked by Malpedia. ID: win.helminth