Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,721 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.firemalv
APT GROUP
Malware family tracked by Malpedia. ID: win.firecrypt
APT GROUP
The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g. files, processes, registry keys and network connections). According to Fortguard Labs, this malware uses Direct Kernel Object Modification (DKOM), which involves undocumented kernel structures and objects, for its operations, why this malware has to rely on specific OS builds.
APT GROUP
Malware family tracked by Malpedia. ID: win.firebird_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.fireball
APT GROUP
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer. This is achieved by sideloading another DLL among the legit TeamViewer.
APT GROUP
FinFisher is a commercial software used to steal information and spy on affected victims. It began with few functionalities which included password harvesting and information leakage, but now it is mostly known for its full Remote Access Trojan (RAT) capabilities. It is mostly known for being used in governmental targeted and lawful criminal investigations. It is well known for its anti-detection capabilities and use of VMProtect.
APT GROUP
Malware family tracked by Malpedia. ID: win.findpos
APT GROUP
Malware family tracked by Malpedia. ID: elf.finaldraft
APT GROUP
Malware family tracked by Malpedia. ID: win.final1stspy
APT GROUP
Filerase is a .net API-based utility capable of propagating and recursively deleting files.
APT GROUP
Malware family tracked by Malpedia. ID: win.fileice_ransom
Malware family tracked by Malpedia. ID: win.fickle
According to CyberArk, this malware is used to steal sensitive information, including login credentials, credit card information, cryptocurrency wallets and browser information from applications such as WinSCP, Discord, Google Chrome, Electrum, etc. It does all that by implementing a different approach than other stealers (we’ll cover it later). Additionally, FickerStealer can function as a File Grabber and collect additional files from the compromised machine, and it can act as a Downloader to download and execute several second-stage malware.
APT GROUP
According to PCrisk, FFDroider is a malicious program classified as a stealer. It is designed to extract and exfiltrate sensitive data from infected devices. FFDroider targets popular social media and e-commerce platforms in particular.
APT GROUPfinancialhigh
Feodo (also known as Cridex or Bugat) is a Trojan used to commit e-banking fraud and to steal sensitive information from the victims computer, such as credit card details or credentials.
APT GROUP
Malware family tracked by Malpedia. ID: win.fenix
APT GROUP
Malware family tracked by Malpedia. ID: win.fengine
APT GROUP
Malware family tracked by Malpedia. ID: win.felixroot
APT GROUP
Malware family tracked by Malpedia. ID: win.felismus
APT GROUP
Malware family tracked by Malpedia. ID: win.feed_load
APT GROUP
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta. It functions as a simple malware downloader and is based on the TouchSocket framework over the Duplex Message Transport Protocol (DMTP). In one campaign, threat actors embedded FDMTP in the data section of a DLL. This allows it to be launched through DLL side-loading. The embedded network configurations are encoded and encrypted to enhance security and evade detection, utilizing Base64 and DES encryption methods. It has been observed to serve as a secondary control tool, often deployed by the PUBLOAD backdoor.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.fauppod
APT GROUPespionageadvanced
According to ESET Research, FatDuke is the current flagship backdoor of APT29 and is only deployed on the most interesting machines. It is generally dropped by the MiniDuke backdoor, but ESET also have seen the operators dropping FatDuke using lateral movement tools such as PsExec.The operators regularly repack this malware in order to evade detections. The most recent sample of FatDuke that ESET have seen was compiled on May 24, 2019. They have seen them trying to regain control of a machine multiple times in a few days, each time with a different sample. Their packer, described in a later section, adds a lot of code, leading to large binaries. While the effective code should not be larger than 1MB, ESET have seen one sample weighing in at 13MB, hence our name for this backdoor component: FatDuke.
APT GROUP
FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels. FatalRAT executes various anti-virtual machine tests to avoid detection before fully infecting systems. Upon successful infiltration, it decrypts configuration strings, disables the CTRL+ALT+DELETE function, and activates a keylogger. The malware can establish persistence via registry modifications or service creation, collect sensitive data, and communicate with its command and control (C&C) server using encrypted methods. FatalRAT also employs techniques like brute-force attacks against weak passwords to propagate within networks.
APT GROUP
Malware family tracked by Malpedia. ID: win.fast_pos
APT GROUP
FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples. It typically downloads TrickBot. It may create a list of processes and uploads it together with screenshot(s). In more recent versions, it employs simple anti-analysis checks (VM detection) and comes with string obfuscations.
APT GROUP
Malware family tracked by Malpedia. ID: win.farseer
APT GROUPfinancialhigh
According to PCrisk, Fantom is a ransomware-type virus that imitates the Windows update procedure while encrypting files. This is unusual, since most ransomware encrypts files stealthily without showing any activity. During encryption, Fantom appends the names of encrypted files with the ".locked4", ".fantom" or ".locked" extension.
APT GROUP
Malware family tracked by Malpedia. ID: win.fanny
APT GROUP
FancyFilter is a piece of code that documents code overlap between frameworks used by Regin and Equation Group.
APT GROUP
Malware family tracked by Malpedia. ID: win.fakeword
APT GROUP
Malware family tracked by Malpedia. ID: win.faketc
APT GROUP
Malware family tracked by Malpedia. ID: win.fakerean
APT GROUP
Malware written in .NET that mimics WannaCry.
APT GROUP
Fabookie is facebook account info stealer.
APT GROUPespionageadvanced
EYService is the main part of the backdoor used by Nazar APT. This a passive backdoor that relies on, now discontinued, Packet Sniffer SDK (PSSDK) from Microolap.
APT GROUP
Malware family tracked by Malpedia. ID: win.eye_pyramid
APT GROUPespionageadvanced
According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information. This RAT has been used in attacks targeting Israeli and Syrian governments last 2012. This malware family of backdoors has the capability to receive commands such as File Management (Download, Upload, and Execute Files), Registry Management (Add, Delete, Query, and Modify Registry), Perform Shell Command, Computer Control (Shutdown, Log on/off), and Screen capture from a remote attacker. In addition, it can also log keystrokes of the infected systems.