Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,721 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.explosive_rat
APT GROUP
Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features. Also the infection routine was changed in samples fround in 2017 (described by McAfee). Expiro "infiltrates" executables on 32- and 64bit Windows OS versions. It has capabilities to install browser extensions, change security behaviour/settings on the infected system, and steal information (e.g. account credentials). There is a newly described EPO file infector source code called m0yv in 2022, which is wrongly identified as expiro by some AVs.
APT GROUPfinancial
According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a ransom string of characters.For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.
Infra: 🔗 7iulpt5i6whht6zo2r52
RLUpdated: N/A
View profile →
APT GROUPfinancialhigh
Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
APT GROUPespionageadvanced
ExileRAT is a simple RAT platform capable of getting information on the system (computer name, username, listing drives, network adapter, process name), getting/pushing files and executing/terminating processes.
Malware family tracked by Malpedia. ID: win.exchange_tool
APT GROUP
Malware family tracked by Malpedia. ID: win.excalibur
APT GROUPfinancialhigh
ExByte is a custom data exfiltration tool and infostealer observed being used during BlackByte ransomware attacks.
APT GROUP
Malware family tracked by Malpedia. ID: elf.exaramel
APT GROUP
Malware family tracked by Malpedia. ID: win.evrial
APT GROUP
Privately modded version of the Pony stealer.
APT GROUP
A wiper used against in an attack against Iran’s state broadcaster. Using campaign name coined by Check Point in lack of a better name for the wiper component.
APT GROUPespionageadvanced
[Evilnum](https://attack.mitre.org/groups/G0120) is a financially motivated threat group that has been active since at least 2018.(Citation: ESET EvilNum July 2020)
T1204.001T1059.007T1070.004
Updated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.evilgrab
APT GROUP
Malware family tracked by Malpedia. ID: win.evilextractor
APT GROUP
EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise. This software is a remote access software. Threat actors modify the configuration extensively so that any signs of an active remote connection are removed. EvilConwi often pretends to perform a Windows update by using fake Windows update images embedded in the config. The purpose is to keep the system running while the threat actor connect remotely. Other EvilConwi signs are fake application icons. E.g., it may pretend to be an installer for Zoom and use its icons and application titles in the ConnectWise config.
APT GROUP
Malware family tracked by Malpedia. ID: win.evilbunny
APT GROUP
Malware family tracked by Malpedia. ID: win.etumbot
APT GROUP
This malware is part of the Eternity Malware "Framework".
This Stealer is part of the eternity malware project.
APT GROUPfinancialhigh
Eternity Framework Ransomware Payload
This malware is part of the Eternity Malware "Framework".
APT GROUPfinancialhigh
According to proofpoint, Bad Rabbit is a strain of ransomware that first appeared in 2017 and is a suspected variant of Petya. Like other strains of ransomware, Bad Rabbit virus infections lock up victims’ computers, servers, or files preventing them from regaining access until a ransom—usually in Bitcoin—is paid.
APT GROUP
Malware family tracked by Malpedia. ID: win.eternalrocks
APT GROUP
Malware family tracked by Malpedia. ID: win.especter
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.erica_ransomware
APT GROUP
Eredel Stealer is a low price malware that allows for extracting passwords, cookies, screen desktop from browsers and programs. According to nulled[.]to: Supported browsers Chromium Based: Chromium, Google Chrome, Kometa, Amigo, Torch, Orbitum, Opera, Opera Neon, Comodo Dragon, Nichrome (Rambler), Yandex Browser, Maxthon5, Sputnik, Epic Privacy Browser, Vivaldi, CocCoc and other Chromium Based browsers. - Stealing FileZilla - Stealing an account from Telegram - Stealing AutoFill - Theft of wallets: Bitcoin | Dash | Monero | Electrum | Ethereum | Litecoin - Stealing files from the desktop. Supports any formats, configurable via telegram-bot
APT GROUP
Malware family tracked by Malpedia. ID: elf.erebus
Erbium is an information stealer advertised and sold as a Malware-as-a-Service on cybercrime forums and Telegram since at least July 2022. Its capabilities are those of a classic information stealer, with a focus on cryptocurrency wallets, and file grabber capabilities.
Rough collection EQGRP samples, to be sorted
APT GROUP
Malware family tracked by Malpedia. ID: win.equationdrug
Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon". This malware is distributed as a game, mainly on discord, but steals user credentials, crypto wallets, and stored cookies. It evades static detection by being packed with NSIS, which then launches a malicious Electron package.
APT GROUPfinancialhigh
According to PCrisk, Epsilon is a ransomware-type program. This malware is designed to encrypt the data of infected systems in order to demand payment for decryption.
APT GROUP
Malware family tracked by Malpedia. ID: win.envyscout
APT GROUP
According to Microsoft, Enviserv is a malicious program that is unable to spread of its own accord. It may perform a number of actions of an attacker's choice on an affected computer.
APT GROUP
Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old KeyBoy samples. The embedded malware config was encrypted with a unique algorithm.
APT GROUPfinancial
Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomware uses a custom packer to pack itself which has been seen in some early dridex samples.
Infra: 🔗 leaksv7sroztl377bboh
RLUpdated: N/A
View profile →
APT GROUP
According to Trend Micro, this is a downloader, dedicated to stage execution of a second stage malware called Enigma Stealer.
APT GROUP
Malware family tracked by Malpedia. ID: win.enfal