Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,720 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.funny_dream
APT GROUP
Malware family tracked by Malpedia. ID: win.funnyswitch
APT GROUPfinancial
FunkSec is an AI-assisted ransomware-as-a-service group that launched its data leak site in December 2024 and rapidly claimed over 85 victims across government, technology, finance, and education sectors globally, demanding unusually low ransoms and using AI tooling to lower the technical bar for affiliates.
Infra: 🔗 7ixfdvqb4eaju5lzj4gg…🔗 pke2vht5jdeninupk7i2…🔗 ykqjcrptcai76ru5u7jh…+10 more
RSLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.fullmetal
APT GROUP
FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.
APT GROUP
Malware family tracked by Malpedia. ID: win.fs0ciety
APT GROUP
FROZENHILL is a launcher written in C++ that is configured to utilize existing files for execution and also infects newly attached storage volumes with additional malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.frostygoop
APT GROUP
Malware family tracked by Malpedia. ID: win.friedex
APT GROUP
Malware family tracked by Malpedia. ID: win.freenki
APT GROUP
A RAT employing Node.js, Sails, and Socket.IO to collect information on a target
APT GROUP
Malware family tracked by Malpedia. ID: win.fpspy
APT GROUP
Malware family tracked by Malpedia. ID: win.foxsocket
APT GROUP
Malware family tracked by Malpedia. ID: win.fortunecrypt
APT GROUP
Malware family tracked by Malpedia. ID: win.former_first_rat
APT GROUP
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
APT GROUP
Malware family tracked by Malpedia. ID: win.forest_tiger
APT GROUP
Malware family tracked by Malpedia. ID: win.fonix
APT GROUPfinancial
Fog, which uses the .flocked extension for encrypted files, was first observed in May in campaigns by Storm-0844, a threat actor known for distributing Akira. By June, Storm-0844 was deploying Fog more than Akira.
Infra: 💬 xql562evsy7njcsngacp…🔗 xbkv2qey6u3gd3qxcojy…🔗 xbkv2qey6u3gd3qxcojy…+3 more
RSLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.fobber
APT GROUP
According to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#. FoalShell allows attackers to execute arbitrary commands in the cmd.exe command line interpreter on a compromised host.
APT GROUP
Malware family tracked by Malpedia. ID: win.flystudio
APT GROUP
Malware family tracked by Malpedia. ID: win.flying_dutchman
APT GROUP
Available since 2015, Flusihoc is a versatile C++ malware capable of a variety of DDoS attacks as directed by a Command and Control server. Flusihoc communicates with its C2 via HTTP in plain text.
APT GROUP
Malware family tracked by Malpedia. ID: win.floxif
APT GROUP
Malware family tracked by Malpedia. ID: win.flowershop
APT GROUP
Malware family tracked by Malpedia. ID: win.flowcloud
APT GROUP
Malware family tracked by Malpedia. ID: win.floki_bot
APT GROUP
Malware family tracked by Malpedia. ID: apk.flexispy
APT GROUP
According to M4lcode, FleshStealer is a sophisticated, modular, and obfuscated .NET-based information-stealing malware designed for comprehensive data exfiltration from Windows systems. Its architecture is built for scale and stealth, utilizing multithreading to simultaneously run multiple data harvesting routines with minimal system disruption. The malware targets a wide range of applications and services, including browsers, messaging apps, email clients, VPNs, cryptocurrency wallets, FTP clients, game launchers, and local file storage.
APT GROUP
According to ProofPoint, FlawedGrace is written in C++ and can be categorized as a Remote Access Trojan (RAT). It seems to have been developed in the second half of 2017 mainly.
FlawedGrace uses a series of commands:
FlawedGrace also uses a series of commands, provided below for reference:
* desktop_stat
* destroy_os
* target_download
* target_module_load
* target_module_load_external
* target_module_unload
* target_passwords
* target_rdp
* target_reboot
* target_remove
* target_script
* target_servers
* target_update
* target_upload
APT GROUP
FlawedAmmyy is a well-known Remote Access Tool (RAT) attributed to criminal gang TA505 and used to get the control of target machines. The name reminds the strong link with the leaked source code of Ammyy Admin from which it took the main structure.
APT GROUP
According to Intezer, this is a shellcode loader.
APT GROUP
FLASHFLOOD will scan inserted removable drives for targeted files, and copy those files from the
removable drive to the FLASHFLOOD-infected system. FLASHFLOOD may also log or copy additional data from the victim computer, such as system information
or contacts.
APT GROUP
Malware family tracked by Malpedia. ID: win.flame
APT GROUP
According to PICUS, Flagpro is malware that collects information from the victim and executes commands in the victim’s environment. It targets Japan, Taiwan, and English-speaking countries. When a victim is infected with Flagpro malware, the malware can do the following:
Download and execute a tool
Execute OS commands and send results
Collect and send Windows authentication information
FK Undead
Technical ID: FK_Undead
APT GROUP
This malware family is mainly spread through various private server clients in bundles, and mainly tamper with user system network data packets through technical means such as TDI filtering, DNS hijacking, HTTP(s) injection, and HOSTS redirection, hijacking normal web page access to designated private server websites, and using security software cloud detection and killing data packet shielding, shutdown callback rewriting and other means to achieve counter-detection.
APT GROUP
Malware family tracked by Malpedia. ID: win.fivehands
APT GROUP
A custom loader for CobaltStrike.
APT GROUP
Malware family tracked by Malpedia. ID: win.first_ransom