Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUPfinancial
Unit42 states that HelloKitty is a ransomware family that first surfaced at the end of 2020, primarily targeting Windows systems. The malware family got its name due to its use of a Mutex with the same name: HelloKittyMutex. The ransomware samples seem to evolve quickly and frequently, with different versions making use of the .crypted or .kitty file extensions for encrypted files. Some newer samples make use of a Golang packer that ensures the final ransomware code is only loaded in memory, most likely to evade detection by security solutions.
Infra: 🔗 3r6n77mpe737w4sbxxxr💬 gunyhng6pabzcurl7ipx
RLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: elf.hellobot
APT GROUP
Malware family tracked by Malpedia. ID: win.helauto
APT GROUP
Malware family tracked by Malpedia. ID: win.headlace
APT GROUP
The Chinese threat actor "Scarab" is using a custom backdoor dubbed "HeaderTip" according to SentinelLABS. This malware may be the successor of "Scieron".
APT GROUP
Malware family tracked by Malpedia. ID: win.hdroot
APT GROUPfinancialhigh
HDMR is a ransomware which encrypts user files and adds a .DMR64 extension. It also drops a ransom note named: "!!! READ THIS !!!.hta".
APT GROUP
Malware family tracked by Malpedia. ID: win.hazy_load
APT GROUP
Malware family tracked by Malpedia. ID: win.hawking
HawKeye is a keylogger that is distributed since 2013. Discovered by IBM X-Force, it is currently spread over phishing campaigns targeting businesses on a worldwide scale. It is designed to steal credentials from numerous applications but, in the last observed versions, new "loader capabilities" have been spotted. It is sold by its development team on dark web markets and hacking forums.
APT GROUP
HAWKBALL is a backdoor that attackers can use to collect information from the victim, as well as to deliver payloads. HAWKBALL is capable of surveying the host, creating a named pipe to execute native Windows commands, terminating processes, creating, deleting and uploading files, searching for files, and enumerating drives.
APT GROUP
First released in October 2022, the Havoc C2 Framework is a flexible post-exploitation framework written in Golang, C++, and Qt, with agents called 'Demons' written in C and ASM, created by @C5pider. Designed to support red team engagements and adversary emulation, it offers a robust set of capabilities tailored for offensive security operations. The framework, which is under active development, utilizes HTTP(s) and SMB as communication protocols for its implants. Havoc can generate implants, known as Demons, in several formats including EXE, DLL, and Shellcode. A notable feature of Havoc is its ability to bypass EDR by employing advanced evasion techniques such as sleep obfuscation, return address stack spoofing, and indirect syscalls. This capability enhances its effectiveness in evading detection and circumventing security measures.
APT GROUPespionageadvanced
Havex is a remote access trojan (RAT) that was discovered in 2013 as part of a widespread espionage campaign targeting industrial control systems (ICS) used across numerous industries and attributed to a hacking group referred to as "Dragonfly" and "Energetic Bear". Havex is estimated to have impacted thousands of infrastructure sites, a majority of which were located in Europe and the United States. Within the energy sector, Havex specifically targeted energy grid operators, major electricity generation firms, petroleum pipeline operators, and industrial equipment providers. Havex also impacted organizations in the aviation, defense, pharmaceutical, and petrochemical industries. Once installed, Havex scanned the infected system to locate any Supervisory Control and Data Acquisition (SCADA) or ICS devices on the network and sent the data back to command and control servers. To do so, the malware leveraged the Open Platform Communications (OPC) standard, which is a universal communication protocol used by ICS components across many industries that facilitates open connectivity and vendor equipment interoperability. Havex used the Distributed Component Object Model (DCOM) to connect to OPC servers inside of an ICS network and collect information such as CLSID, server name, Program ID, OPC version, vendor information, running state, group count, and server bandwidth. Havex was an intelligence-collection tool used for espionage and not for the disruption or destruction of industrial systems. However, the data collected by Havex would have aided efforts to design and develop attacks against specific targets or industries.
APT GROUP
Malware family tracked by Malpedia. ID: win.havana_crypt
APT GROUP
According to Intezer, this is a wiper.
Malware family tracked by Malpedia. ID: win.haron
APT GROUP
Malware family tracked by Malpedia. ID: win.harnig
APT GROUP
Malware family tracked by Malpedia. ID: apk.hardrain
Malware family tracked by Malpedia. ID: win.happy_locker
Updated: 2017-04-29
View profile →
APT GROUPfinancial
Not a Ransomware Group
Infra: 🔗 handala.to🔗 handala-hack.to🔗 vmjfieomxhnfjba57sd6+1 more
PS
RLUpdated: 2026-08-05
View profile →
APT GROUP
Hancitor(aka Chanitor) emerged in 2013 which spread via social engineering techniques mainly through phishing mails embedded with malicious link and weaponized Microsoft office document contains malicious macro in it.
APT GROUP
Malware family tracked by Malpedia. ID: win.hamweq
APT GROUPespionageadvanced
A stager used by APT29 to deploy CobaltStrike.
APT GROUPfinancialhigh
Ransomware written in C#.
APT GROUPfinancialhigh
Hakbit ransomware is written in .NET. It uploads (some) files to be encrypted to a ftp-server. The ransom note is embedded - in earlier versions as plain string, then as base64 string. In some versions, these strings are slightly obfuscated. Contact is via an email address hosted on protonmail. Hakbit (original) had hakbit@, more recent "KiraLock" has kiraransom@ (among others of course).
APT GROUPfinancial
According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension.
Infra: 🔗 ixltdyumdlthrtgx.oni💬 m6s6axasulxjkhzh.oni
RLUpdated: N/A
View profile →
APT GROUP
Py2Exe based tool as found on github.
APT GROUP
Malware family tracked by Malpedia. ID: win.hacksfase
Browser information stealer, written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: elf.habitsrat
APT GROUP
Malware family tracked by Malpedia. ID: win.h1n1
APT GROUPfinancial
Gwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South Korea. The group’s name means “ghost” in Korean, reflecting its stealthy approach. Gwisin has been observed conducting attacks on critical sectors, including healthcare, pharmaceutical, and manufacturing industries. It uses custom-built payloads tailored for each victim, capable of encrypting both Windows and Linux/VMware ESXi environments, and often executes attacks during national holidays to maximize operational disruption. Gwisin employs a double-extortion model—exfiltrating sensitive data before encryption—and communicates with victims in Korean-language ransom notes. Initial access vectors are not fully confirmed in open-source reporting, but suspected methods include exploiting vulnerable VPN appliances and leveraging stolen administrative credentials. The group is known for extensive pre-encryption reconnaissance to identify high-value systems and backups.
Infra: 💬 gwisin4yznpdtzq424i3
RSLUpdated: 2026-08-05
View profile →
Malware family tracked by Malpedia. ID: win.gup_proxy
APT GROUP
Malware family tracked by Malpedia. ID: win.guidloader
APT GROUP
According to haxrob, GTPDOOR is the name of Linux based malware that is intended to be deployed on systems in telco networks adjacent to the GRX (GRPS eXchange Network) with the novel feature of communicating C2 traffic over GTP-C (GPRS Tunnelling Protocol - Control Plane) signalling messages. This allows the C2 traffic to blend in with normal traffic and to reuse already permitted ports that maybe open and exposed to the GRX network.
APT GROUP
A malware family with a DGA.
APT GROUP
Malware family tracked by Malpedia. ID: win.gsecdump
APT GROUP
Malware family tracked by Malpedia. ID: win.grunt
APT GROUPespionageadvanced
According to PCrisk, Growtopia (also known as CyberStealer) is an information stealer written in the C# programming language. It can obtain system information, steal information from various applications, and capture screenshots. Its developer claims that it has created this software for educational purposes only. This stealer uses the name of a legitimate online game.
APT GROUP
Malware family tracked by Malpedia. ID: win.ground_peony