Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.gooseegg
Malware family tracked by Malpedia. ID: win.goopic
Malware family tracked by Malpedia. ID: win.google_drive_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.goodor
APT GROUP
The malware consists of a dropper DLL and an obfuscated, password protected VbaProject.OTM file, which houses macros written for Microsoft Outlook. The malware was originally written by Greg Linares as a backdoor POC called Cordyceps, and presented at Hushcon in 2017.
Gomorrah is a stealer with no or little obfuscation that appeared around March 2020. It is sold for about 150$ lifetime for v4 (originally 400$ for v3) or 100$ per month by its developer called "th3darkly / lucifer" (which is also the developer of CosaNostra botnet). The malware's main functionalities are stealing (passwords, cryptocurrency wallets) and loading of tasks and other payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.gomet
APT GROUP
Malware family tracked by Malpedia. ID: win.golroted
APT GROUP
GoldDragon was a second-stage backdoor which established a permanent presence on the victim’s system once the first-stage, file-less, PowerShell-based attack leveraging steganography was executed. The initial attack was observed first in December 2017, when a Korean-language spear phishing campaing targeted organizations linked with Pyeongchang Winter Olympics 2018. GoldDragon was delivered once the attacker had gained an initial foothold in the targeted environment. The malware was capable of a basic reconnaissance, data exfiltration and downloading of additional components from its C&C server.
APT GROUP
Gold Max is a Golang written command and control backdoor used by the NOBELIUM threat actor group. It uses several different techniques to obfuscate its actions and evade detection. The malware writes an encrypted configuration file to disk, where the file name and AES-256 cipher keys are unique per implant and based on environmental variables and information about the network where it is running.
APT GROUP
According securityweek, GoldenSpy, the malware was observed as part of a campaign that supposedly started in April 2020, but some of the identified samples suggest the threat has been around since at least December 2016. One of the compromised organizations, a global technology vendor that conducts government business in the US, Australia and UK, and which recently opened offices in China, became infected after installing “Intelligent Tax,” a piece of software from the Golden Tax Department of Aisino Corporation, which a local bank required for paying local taxes. Although it worked as advertised, the software was found to install a hidden backdoor to provide remote operators with the possibility to execute Windows commands or upload and run files.
APT GROUP
Malware family tracked by Malpedia. ID: win.goldenhelper
APT GROUP
Malware family tracked by Malpedia. ID: win.goldeneye
APT GROUP
Malware family tracked by Malpedia. ID: win.goldbackdoor
APT GROUP
Malware family tracked by Malpedia. ID: osx.golangghost
APT GROUP
According to Symantec, a previously unseen backdoor that was deployed against a media organization in South Asia in November, 2023. GoGra is written in Go and uses the Microsoft Graph API to interact with a command-and-control (C&C) server hosted on Microsoft mail services.
APT GROUP
Malware family tracked by Malpedia. ID: win.gogoogle
APT GROUP
Malware family tracked by Malpedia. ID: win.goggles
APT GROUP
A file infector written in Go, discovered by Karsten Hahn in February 2022. According to Karsten, despite its internal naming, it is not polymorphic and the virus body is not encrypted. Gofing uses the Coldfire Golang malware development library.
Malware family tracked by Malpedia. ID: win.godzilla_loader
APT GROUPespionageadvanced
GodRAT shares a common origin with AwesomePuppet RAT, alongside Gh0st RAT code similarities. GodRAT is likely connected with Winnty APT activities. Old implant codebases, such as Gh0st RAT, which are nearly two decades old, continue to be used today. These are often customized and rebuilt to target a wide range of victims. These old implants are known to have been used by various threat actors for a long time, and the GodRAT discovery demonstrates that legacy codebases like Gh0st RAT can still maintain a long lifespan in the cybersecurity landscape.
APT GROUP
Proof of concept for data exfiltration via DoH, written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.godlike12
Malware family tracked by Malpedia. ID: win.gocryptolocker
APT GROUP
Malware family tracked by Malpedia. ID: win.gobotkr
APT GROUP
Glupteba is a trojan horse malware that is one of the top ten malware variants of 2021. After infecting a system, the Glupteba malware can be used to deliver additional malware, steal user authentication information, and enroll the infected system in a cryptomining botnet.
APT GROUP
Malware family tracked by Malpedia. ID: win.glooxmail
APT GROUPfinancial
Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note text, encryption algorithms, and file extensions. Globe uses symmetric encryption (RC4 or AES) to lock files and typically appends custom extensions such as .GLOBE, .PURPLE, .HNY, or others set by the attacker. The malware is distributed through malicious spam emails with infected attachments, compromised websites, and exploit kits. Globe’s flexibility made it attractive to low-skilled actors, resulting in many different variants in the wild. The family has primarily targeted small to medium-sized businesses and individual users across multiple regions, with no clear geographic focus.
RSLUpdated: 2026-08-05
View profile →
APT GROUPfinancialhigh
GlobeImposter is a ransomware application which is mainly distributed via "blank slate" spam (the spam has no message content and an attached ZIP file), exploits, malicious advertising, fake updates, and repacked installers. GlobeImposter mimics the Globe ransomware family. This malware may prevent execution of Anti-Virus solutions and other OS related security features and may prevent system restoration.
APT GROUPfinancial
GLOBAL GROUP is a ransomware-as-a-service operation that emerged in June 2025, reportedly launched by a known Russian-speaking threat actor, featuring AI-driven ransom negotiation and a mobile control panel for affiliates, targeting healthcare, oil and gas, industrial engineering, and automotive sectors.
Infra: 🔗 vg6xwkmfyirv3l6qtqus💬 panelqbinglxczi2gqkw💬 gdbkvfe6g3whrzkdlbyt+1 more
RSLUpdated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.glitch_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.glassrat
APT GROUP
Malware family tracked by Malpedia. ID: win.glasses
Updated: 2016-12-29
View profile →
APT GROUP
An information stealer written in .NET.
APT GROUP
Malware family tracked by Malpedia. ID: win.ginwui
APT GROUP
This multi-platform malware is a ObjectiveC written macOS variant dubbed GIMMICK by Volexity. This malware is a file-based C2 implant used by Storm Cloud.
APT GROUP
According to CERT-UA, this stealer used by UAC-0226 is written in C/C++, targeting browser databases and using telegram for data exfiltration.
APT GROUP
Malware family tracked by Malpedia. ID: win.giffy
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.ghost_secret