Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUP
According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks on Earth. Below is a list of Gh0st RAT capabilities. Take full control of the remote screen on the infected bot. Provide real time as well as offline keystroke logging. Provide live feed of webcam, microphone of infected host. Download remote binaries on the infected remote host. Take control of remote shutdown and reboot of host. Disable infected computer remote pointer and keyboard input. Enter into shell of remote infected host with full control. Provide a list of all the active processes. Clear all existing SSDT of all existing hooks.
APT GROUP
Malware family tracked by Malpedia. ID: win.ghost_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.ghost_admin
APT GROUP
GhostSocks, a Golang-based proxy malware, was first advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in October 2023. It uses back-connect socket secure internet protocol (SOCKS5) connections and is available for rent for US $100 per month. In February 2024, the author of Lumma Stealer released an update introducing the integration of proxying capabilities. This feature, developed in partnership with GhostSocks, allows the use of infected hosts as SOCKS5 proxies and is available to all subscribers who purchase the "Professional" or higher tier plan. This integration allows Lumma Stealer users to establish a network of residential IP addresses for various purposes, including credential checking, spam distribution, or as general-purpose proxies.
APT GROUP
Malware family tracked by Malpedia. ID: win.ghostnet
APT GROUP
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a significant period of time and continue to pose a threat to their targets.
🇨🇳 CNT1588.002T1110.002T1040
APT GROUP
Malware family tracked by Malpedia. ID: win.ghole
APT GROUPespionageadvanced
According to Mandiant, GHAMBAR is a remote administration tool (RAT) that communicates with its C2 server using SOAP requests over HTTP. Its capabilities include filesystem manipulation, file upload and download, shell command execution, keylogging, screen capture, clipboard monitoring, and additional plugin execution.
APT GROUP
Custom RAT developed by the BlackTech actor, based on the Gh0st RAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.gh0stbins
get pwd
Technical ID: get_pwd
APT GROUP
Malware family tracked by Malpedia. ID: win.get_pwd
APT GROUP
Malware family tracked by Malpedia. ID: win.getmypass
APT GROUP
Malware family tracked by Malpedia. ID: win.getmail
APT GROUP
Malware family tracked by Malpedia. ID: win.get2
APT GROUP
Malware family tracked by Malpedia. ID: win.geminiduke
APT GROUP
According to FireEye, GEMCUTTER is used in a similar capacity as BACKBEND (downloader), but maintains persistence by creating a Windows registry run key. GEMCUTTER checks for the presence of the mutex MicrosoftGMMZJ to ensure only one copy of GEMCUTTER is executing. If the mutex doesn't exist, the malware creates it and continues execution; otherwise, the malware signals the MicrosoftGMMExit event.
APT GROUP
According to FireEye, GEARSHIFT is a memory-only dropper for two keylogger DLLs. It is designed to replace a legitimate Fax Service DLL.
APT GROUP
Malware family tracked by Malpedia. ID: win.gearinformer
APT GROUP
According to Unit 42, this is a .NET X64 malware that is capable of interaction with GoogleDrive, allowing an attacker to have victim information uploaded and payloads delivered.
APT GROUP
[GCMAN](https://attack.mitre.org/groups/G0036) is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)
🇷🇺 RUT1021.005T1021.004
Updated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.gcleaner
APT GROUP
Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff. Functionality includes: - Loading other executables - Load hash cracking plugin - Load DMSniff plugin - Perform webinjection and webfakes - Form grabbing - Command execution - Download file from infected system - Convert infection into proxy - DDOS - Spreading and EXE infecting
APT GROUP
Malware family tracked by Malpedia. ID: win.gauss
APT GROUP
Gaudox is a http loader, written in C/C++. The author claims to have put much effort into making this bot efficient and stable. Its rootkit functionality hides it in Windows Explorer (32bit only).
APT GROUPfinancialhigh
A backdoor used by Mespinoza ransomware gang to maintain access to a compromised network.
APT GROUPfinancialhigh
GandCrab was a Ransomware-as-a-Service (RaaS) emerged in January 28, 2018, managed by a criminal organization known to be confident and vocal, while running a rapidly evolving ransomware campaign. Through their aggressive, albeit unusual, marketing strategies and constant recruitment of affiliates, they were able to globally distribute a high volume of their malware. In a surprising announcement on May 31, 2019, the GandCrab’s operators posted on a dark web forum, announced the end of a little more than a year of ransomware operations, citing staggering profit figures. However, If there’s one thing that sets these threat actors apart from other groups, it is that they are unpredictable; so there is always the possibility that they might re-surface in one form or another.
APT GROUP
GAMYBEAR A software tool developed using the Go programming language. Its main functionality is to receive (“listener”), execute (‘executor’) commands, and send (“sender”) results to the control server in BASE64-encoded form using the HTTP protocol. When launched, it generates a unique identifier (UUID), receives basic information about the computer (“whoami”, “wmic nicconfig where IPEnabled=true get IPAddress”), creates a helper file %APPDATA%\ updater.json, where the URL of the control server is stored in JSON format (key “update_server”), as well as other listed data in BASE64-encoded form (keys: “uuid”, ‘hostname’, “ip”, respectively). During operation, the software regularly sends requests to the control server (URI: “/c2/get_commands/”) and waits for a response in JSON format with the ‘command’ and “arguments” fields. If the “Nop” command is received, a 15-second pause is initiated. After the commands are executed, the result and other data are encoded using BASE64, stored in a JSON structure (keys: “uuid”, “command”, ‘output’) and sent to the control server with a request to the URI “/c2/command_out/”. The consistency of the launch is ensured by another program (script) at the stage of the initial infection of the computer by creating a key in the “Run” branch of the operating system registry.
APT GROUP
Malware family tracked by Malpedia. ID: win.gamotrol
Updated: 2018-07-24
View profile →
Malware family tracked by Malpedia. ID: win.game_player_framework
APT GROUPespionageadvanced
Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan. According to a report by Symantec, Gameover Zeus has largely been used for banking fraud and distribution of the CryptoLocker ransomware. In early June 2014, the U.S. Department of Justice announced that an international inter-agency collaboration named Operation Tovar had succeeded in temporarily cutting communication between Gameover ZeuS and its command and control servers.
APT GROUP
Malware family tracked by Malpedia. ID: win.gameover_dga
Updated: 2016-04-18
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.gamapos
APT GROUP
GalaxyLoader is a simple .NET loader. Its name stems from the .pdb and the function naming. It seems to make use of iplogger.com for tracking. It employed WMI to check the system for - IWbemServices::ExecQuery - SELECT * FROM Win32_Processor - IWbemServices::ExecQuery - select * from Win32_VideoController - IWbemServices::ExecQuery - SELECT * FROM AntivirusProduct
Updated: 2018-03-26
View profile →
APT GROUP
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
APT GROUP
Malware family tracked by Malpedia. ID: win.gacrux
APT GROUP
According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless stages. Additionally, it has the tendency to camouflage itself as a legitimate application, going so far as to mimic legitimate applications in its decompiled code. It also includes a steganographic image used to prepare further payloads. GaboonGrabber's final stage can deploy various types of malware, including Snake Keylogger, AgentTesla, Redline, Lokibot, and more.
APT GROUP
FuxSocy has some similarities to win.cerber but is tracked as its own family for now.
APT GROUP
FuwuqiDrama is a server-side RAT. It manages client connections by utilizing I/O completion ports, which are usually used in high-performance server applications as an elegant solution to manage many clients at once. It contains two distinguishing hardcoded lists. First is a list of ~50 video files of South Korean TV series, having their titles translated to Mandarin Chinese, but encoded in the form of Pinyin romanization. That means the sounds are spelled in Latin alphabet without tone marks, for example meiyounihuobuxiaqu.avi represents Can't Live Without You (a K-drama from 2012) or wulalafufu.avi translates to Ohlala Couple (also from 2012). Second is the list of the following corporations: NVIDIA, Amazon, Intel, Skype, 360Safe, Rising, Tencent, Mozilla, Adobe, Yahoo, Google. The same list is contained in some of the WannaCryptor samples. FuwuqiDrama stores its configuration in the INI file data\package_con_x86.cat. It contains the port number and a bot identifier, all within a single section called Fuwuqi – the romanized Chinese word for server.
APT GROUP
Malware family tracked by Malpedia. ID: win.fusiondrive
APT GROUP
Malware family tracked by Malpedia. ID: win.furtim