Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.grok
APT GROUP
This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).
APT GROUPfinancialhigh
GRIMAGENT is a backdoor that can execute arbitrary commands, download files, create and delete scheduled tasks, and execute programs via scheduled tasks or via the ShellExecute API. The malware persists via a randomly named scheduled task and a registry Run key. The backdoor communicates to hard-coded C&C servers via HTTP requests with portions of its network communications encrypted using both asymmetric and symmetric cryptography. GRIMAGENT was used during some Ryuk Ransomware intrusions in 2020.
APT GROUP
This is a proxy-aware HTTP backdoor that is implemented as a service and uses the compromised system's proxy settings to access the internet. C&C traffic is base64 encoded and the files sent to the server are compressed with aPLib.
APT GROUPespionageadvanced
ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks
APT GROUP
A malware that modifies every JPG file found on a computer by adding a string in its bottom corner spelling out 'I am Sorry'. Grenam is a companion virus, which is a form of file infection. It infects by prepending the letter 'g' in front of host files and placing itself with the original name of the host.
APT GROUPespionageadvanced
This information-stealing malware exfiltrates data from its victims and uploads this information to its web server for publication. It can capture data from browsers, the clipboard and the local disk to steal sensitive data such as credit card details, browser cookies, crypto wallet information, File Transfer Protocol (FTP) and virtual private network (VPN) credentials.
APT GROUP
Malware family tracked by Malpedia. ID: win.greetingghoul
Malware family tracked by Malpedia. ID: win.green_dispenser
APT GROUP
Malware family tracked by Malpedia. ID: win.greenshaitan
APT GROUP
Malware family tracked by Malpedia. ID: win.grease
APT GROUP
According to Mandiant, GRAYRABBIT is a lightweight and simple backdoor that supports simple file operation, system information collection, running modularized plugins, and executing a remote command shell.
APT GROUP
Malware family tracked by Malpedia. ID: apk.gravity_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.gratem
Updated: 2017-04-06
View profile →
APT GROUP
POS malware targets systems that run physical point-of-sale device and operates by inspecting the process memory for data that matches the structure of credit card data (Track1 and Track2 data), such as the account number, expiration date, and other information stored on a card’s magnetic stripe. After the cards are first scanned, the personal account number (PAN) and accompanying data sit in the point-of-sale system’s memory unencrypted while the system determines where to send it for authorization. Masked as the LogMein software, the GratefulPOS malware appears to have emerged during the fall 2017 shopping season with low detection ratio according to some of the earliest detections displayed on VirusTotal. The first sample was upload in November 2017. Additionally, this malware appears to be related to the Framework POS malware, which was linked to some of the high-profile merchant breaches in the past.
APT GROUP
This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).
APT GROUP
Malware family tracked by Malpedia. ID: win.graphon
APT GROUP
Trellix describes Graphite as a malware using the Microsoft Graph API and OneDrive for C&C. It was found being deployed in-memory only and served as a downloader for Empire.
APT GROUP
Downloader / information stealer used by UAC-0056, observed since at least October 2022.
APT GROUPespionageadvanced
According to Symantec, Graphican is an evolution of the known APT15 backdoor Ketrican, which itself was based on a previous malware - BS2005 - also used by APT15. Graphican has the same basic functionality as Ketrican, with the difference between them being Graphican’s use of the Microsoft Graph API and OneDrive to obtain its command-and-control (C&C) infrastructure.
This loader abuses the benign service Notion for data exchange.
APT GROUP
PANW Unit 42 describes this malware as capable of up and downloading files as well as loading additional shellcode payloads into selected target processes. It uses the Microsoft Graph API and Dropbox API as C&C channel.
APT GROUP
According to Checkpoint Research, GRAPELOADER is a newly observed initial-stage tool used for fingerprinting, persistence, and payload delivery. Despite differing roles, it shares similarities in code structure, obfuscation, and string decryption with WINELOADER. GRAPELOADER refines WINELOADER’s anti-analysis techniques while introducing more advanced stealth methods.
APT GROUP
Malware family tracked by Malpedia. ID: win.grandsteal
APT GROUPfinancialhigh
According to ESET Research, Grandoreiro is a Latin American banking trojan targeting Brazil, Mexico, Spain and Peru. As such, it shows unusual effort by its authors to evade detection and emulation, and progress towards a modular architecture.
APT GROUP
Malware family tracked by Malpedia. ID: win.gramdoor
APT GROUP
Grager is a backdoor deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of this backdoor revealed that it uses the Graph API to communicate with a command and control (C&C) server hosted on Microsoft OneDrive. The backdoor decrypts a client ID and refresh token for OneDrive from a blob contained within its file body. It supports the following commands: - Retrieve machine information, including machine name, user, IP address, and machine architecture - Download or upload a file - Execute a file - Gather file system information, including available drives, their sizes, and types of drives
APT GROUP
Malware family tracked by Malpedia. ID: win.graftor
APT GROUP
Malware family tracked by Malpedia. ID: win.grabbot
APT GROUP
Malware family tracked by Malpedia. ID: win.gpcode
APT GROUP
Malware family tracked by Malpedia. ID: win.go_red
APT GROUPespionageadvanced
2000 Ursnif aka Snifula 2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) -> 2010 Gozi Prinimalka -> Vawtrak/Neverquest In 2006, Gozi v1.0 ('Gozi CRM' aka 'CRM') aka Papras was first observed. It was offered as a CaaS, known as 76Service. This first version of Gozi was developed by Nikita Kurmin, and he borrowed code from Ursnif aka Snifula, a spyware developed by Alexey Ivanov around 2000, and some other kits. Gozi v1.0 thus had a formgrabber module and often is classified as Ursnif aka Snifula. In September 2010, the source code of a particular Gozi CRM dll version was leaked, which led to Vawtrak/Neverquest (in combination with Pony) via Gozi Prinimalka (a slightly modified Gozi v1.0) and Gozi v2.0 (aka 'Gozi ISFB' aka 'ISFB' aka Pandemyia). This version came with a webinject module.
APT GROUP
Malware family tracked by Malpedia. ID: win.govrat
APT GROUP
Malware family tracked by Malpedia. ID: win.gotroj
APT GROUP
According to ESET Research, GoToHTTP is a benign tool that allows establishing a remote connection that can be accessed from a browser. It has been observed being abused for malicious purposes by threat actor GhostRedirector.
APT GROUP
According to Elastic, this is a rewrite of Quasar RAT in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.gopuram
APT GROUP
Malware family tracked by Malpedia. ID: win.gopher_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.gophe
APT GROUPfinancialhigh
Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts. The loader downloads the payload, stores it in registry and injects it in a copy of the loader process. The loader also contains two encrypted DLLs intended to be injected into each browser process launched in order to place the payload in man in the browser and allow it to apply the webinjects received from the command and control server on HTTPx exchanges. This allows Gootkit to intercept HTTPx requests and responses, steal their content or modify it according to the webinjects.