Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,713 entities
APT GROUPfinancial
FulcrumSec is a data extortion group active since approximately September 2025, specializing in high-speed exfiltration of cloud-hosted databases by exploiting unrotated API keys and misconfigured cloud permissions rather than deploying encryption, with known victims including Australian fintech youX and LexisNexis.
Infra: 🔗 gsgot6tua7ffammwdv6v…🔗 fulcrumsec.net…🔗 4e3p3in2bl67hxchuwza…+2 more
RSLUpdated: 2026-08-01
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.sisron
APT GROUP
According to Proofpoint, SilentRunLoader is a Python-based stealer/loader used by TA4922 to quietly download and execute a next-stage payload. It is designed to harvest Chrome data and other browser artifacts and exfiltrate them to a C2 server. The Python code is relatively straightforward and often appears as vibe-coded, with rapid development of new Python-based tooling observed across campaigns. This reflects the actor’s use of Python-based malware to quickly deploy new payloads.
APT GROUP
According to Proofpoint, RomulusLoader is a C-based loader whose purpose is to download and execute further payloads from a C2. It includes a custom PE loader, dynamic API resolution, and RC4 encryption for embedded payloads, and it sideloads legitimate components to blend into the environment. It operates in a multi-stage fashion, spawning workers that run in other processes to maintain persistence and facilitate C2 communications. As a first-stage loader, it is used to drop follow-on payloads, including remote-management software, enabling broader remote access capabilities for the operator.
APT GROUPespionageadvanced
According to Proofpoint, Atlas RAT is a modular backdoor used by the TA4922 actor, delivered in multiple stages with a core module and optional plugins. It can gather system information, enumerate and exfiltrate files, and perform surveillance such as audio/video capture, along with the ability to download and run additional payloads. The loader uses anti-analysis techniques and loads the core module through a shellcode-based process, with capabilities to inject into other processes as part of its operation. The overall toolset is aligned with a Chinese-speaking actor and is designed to be extended through modular plugins fetched from the C2.
APT GROUP
According to HarfangLab, GammaLoad is a second-stage VBScript/HTA payload that serves as a persistent beacon and downloader for the next payload. It runs in a two-layer VBScript framework, with an outer installer enabling RunOnce-style persistence and the inner layer using MSXML2.XMLHTTP to beacon to its C2 over Cloudflare-proxied infrastructure.
APT GROUP
According to HarfangLab, GammaDrop is a VBScript-based downloader that forms the first stage of a two-stage infection chain. It uses obfuscated VBScript stored in a stealthy data stream to fetch a second-stage HTA payload (GammaLoad) and execute it, achieving persistence via the Startup folder.
APT GROUP
According to TeamT5, SoxAgent is a Linux backdoor that covertly converts compromised hosts into SOCKS5 relay nodes. It maintains a persistent reverse connection to a hardcoded C2 and negotiates AES-encrypted tunnels, enabling the attacker to forward TCP traffic through the victim to conceal their origin. It supports remote updates, self-deletion, and heartbeat reporting with falsified tunnel metrics to enhance stealth. The activity associated with SoxAgent is part of a campaign that deployed the backdoor to form an ORB network tracked as GOBLIN14.
APT GROUPfinancialhigh
TA4922 is a Chinese-speaking cybercrime cluster that employs localized HR, payroll, tax, and invoice lures to deliver various malware families, including Atlas RAT, RomulusLoader, and SilentRunLoader. The actor conducts targeted email campaigns, often impersonating trusted authorities, to facilitate credential phishing and fraud. TA4922's operational tempo is high, with a focus on obtaining remote access for financial gain, and it has shown a rapid evolution in its malware arsenal. The group is also noted for using social engineering to shift communications from email to messaging platforms, enhancing their phishing efforts.
🇨🇳 CN
Updated: 2026-08-01
View profile →APT GROUPespionageadvanced
SLIME88 is a China-nexus APT that has exploited the critical vulnerability CVE-2026-34197 in Apache ActiveMQ to deploy SoxAgent RAT, compromising Linux devices and establishing an ORB network tracked as GOBLIN14. The group has targeted IT and manufacturing entities in the US, South Korea, India, and France. Additionally, SLIME88 has aimed at Taiwan’s energy sector using phishing emails and fake certificate installers to deploy backdoor programs like AdaptixC2 and CobaltStrike. They often utilize Cloudflare to obscure their C2 IP addresses, evading detection.
🇨🇳 CN
Updated: 2026-08-01
View profile →APT GROUP
BlackMaskers Team has emerged as a significant threat actor, particularly targeting Jordan amid the Israel-Iran conflict. They have claimed responsibility for cyberattacks on critical Jordanian entities, including the stock exchange and private sector enterprises, leveraging techniques such as website defacement and data breaches. Their operations have raised concerns about the vulnerability of national infrastructure. Additionally, they have successfully hacked Saudi Arabian web platforms, further demonstrating their capabilities.
Updated: 2026-08-01
View profile →APT GROUP
According to Microsoft Incident Response, StilachiRAT is a sophisticated remote access trojan that uses stealth and persistence techniques to evade detection and enable data exfiltration. It performs extensive system reconnaissance, can target cryptocurrency wallet data, and steals browser credentials while monitoring clipboard contents for sensitive information. It maintains a flexible command-and-control channel over TCP with multiple ports, supports a broad set of commands including system manipulation and reboot, and uses Windows services with watchdogs to ensure persistence. It also monitors RDP sessions and can impersonate users.
APT GROUP
According to its author, EDR-Freeze is a tool that exploits the software vulnerability of WerFaultSecure to suspend the processes of EDRs and anti-malware without needing to use the BYOVD (Bring Your Own Vulnerable Driver) attack method as EDR-Freeze operates entirely in user mode.
APT GROUP
According to its author, defendnot uses an undocumented Windows Security Center (WSC) API that is meant for antivirus software to notify Defender of their presence, with the goal of getting Defender to disable itself.
APT GROUP
According to Fox-IT, RemotePE is the final-stage in-memory RAT that operates across multiple threads to handle C2 communication and command execution. It exposes a range of capabilities via a structured command set, including configuration, console access, file and process operations, and plugin support to dynamically load additional payloads. The framework emphasizes memory-only execution and encrypted, compressed exchanges with the C2, aiming to minimize forensic traces and enable long-term, stealthy control managed by an operator.
APT GROUP
According to Proofpoint, Overlord is an open-source RAT written in Go.
APT GROUP
According to Fox-IT, DPAPILoader is a loader implemented as a DLL that decrypts an encrypted payload from disk using DPAPI and then loads it into memory, enabling persistence by starting at boot as a legitimate-appearing service. It uses environment-bound encryption and obfuscation (DPAPI keys tied to the user and a fixed XOR) to tie the payload to the victim and hinder static analysis. The loader then hands off to a second-stage loader, RemotePELoader, as part of a multi-stage chain designed to minimize on-disk artifacts and maximize stealth.
APT GROUP
According to ESET Research, BirdCall is a Windows backdoor written in C++ that provides a wide range of spying capabilities, including taking screenshots, logging keystrokes and clipboard content, stealing credentials and files, and executing shell commands. It is typically deployed in a multistage loading chain with a downloader that fetches and executes shellcode, at times loaded by a RokRAT payload, and then replaces a trojanized library with a clean version to hinder analysis. For C2, BirdCall uses legitimate cloud storage services or compromised websites to enable bidirectional communication and data exfiltration.
APT GROUPespionageadvanced
According to CERT-UA, AGINGFLY is a C#-based remote-control tool that can execute commands, download files, capture screenshots, and run a keylogger, effectively enabling full remote control of an infected host. Its C2 communication uses WebSockets with AES-CBC encryption, and unlike typical implants, command handlers are not embedded in the binary; they are delivered from the C2 as source code and compiled at runtime. The malware also appears in a multi-stage loader chain, with a stager that establishes a remote connection and covert execution, and it can leverage process injection to hide in legitimate system processes.
APT GROUP
According to CERT-UA, SILENTLOOP is a PowerShell-based component that coordinates command execution, automatic configuration updates, and discovery of the C2 address, with the main C2 address obtained from a Telegram channel. It supports fallback mechanisms for locating the C2 to maintain control if the primary channel changes. This tool operates as part of a broader attack toolset, enabling persistent management of compromised hosts and facilitating reconnaissance and lateral movement through the network.
APT GROUP
According to WithSecure, PhantomRelay is a PowerShell-based RAT developed under the GREYVIBE activity cluster. It uses a two-stage execution chain (fingerprinting first, then the main RAT loaded in memory) with C2 communications over WebSockets, and its design is modular to enable additional post-compromise payloads. The family includes several variants, such as PhantomRelayLite and PhantomRelayV1/V2, which feature progressive obfuscation and persistence enhancements. The operators are Russian-speaking and Moscow-time aligned, with the tooling observed across GREYVIBE-related campaigns and related cybercrime activity.
APT GROUP
According to WithSecure, LegionRelay is a lightweight PowerShell-based RAT that talks to its C2 via REST API. The client executes operator-issued PowerShell commands and relies on post-compromise scripts to extend capabilities, including file enumeration, exfiltration, screenshots, browser data theft, and remote access like RDP setup. The tooling is part of GREYVIBE’s broader loader/obfuscator ecosystem, with obfuscation and loader variants used to evolve the malware. Operators are Russian-speaking and Moscow-time aligned, indicating a Russia-nexus influence that coexists with wider cybercrime activity.
APT GROUPespionageadvanced
According to Trend Micro, Banana RAT is a Brazilian banking trojan linked to SHADOW-WATER-063. It employs a fileless, PowerShell-based client that runs in memory, with a polymorphic, AES-wrapped payload delivery pipeline and multiple obfuscation layers to evade detection. Once active, it provides remote fraud capabilities, including screen capture, remote input control, keylogging, overlays that mimic banking interfaces, and a Pix QR interception subsystem to manipulate payments. The operation targets Brazilian financial institutions, uses Brazilian Portuguese artifacts, and appears to operate as a malware-as-a-service style platform with per-victim builds to complicate detection.
APT GROUP
Malware family tracked by Malpedia. ID: js.recjs
APT GROUP
Malware family tracked by Malpedia. ID: elf.compood
APT GROUPespionageadvanced
According to FortiGuard Labs, C0XMO is a newly identified Gafgyt variant that propagates by exploiting CVE-2021-27137 in DD-WRT routers, enabling remote attackers to control vulnerable systems. Unlike traditional Gafgyt, C0XMO modularizes its lateral movement into a standalone Python script, allowing it to efficiently target multiple Linux architectures. The malware is written in both Python and compiled ELF binaries, and features persistence, competitor process termination, and a broad set of DDoS attack methods. Its architecture is more advanced than typical Gafgyt, with separate scanning and propagation components, extensive exploitation capabilities, and improved scalability for botnet deployment.
APT GROUPhacktivism
ZeffSec is a hacktivist collective focused on infrastructure-level disruption and exposing vulnerabilities in centralized digital networks. In March 2026, the group claimed responsibility for a large-scale DDoS attack against ArvanCloud, Iran's primary cloud and CDN provider, causing widespread service outages across platforms including the online education service Skyroom. The group announced the operation via Telegram, stating their goal was disruption of centralized infrastructure rather than data theft.
Updated: 2026-08-01
View profile →APT GROUP
Malware family tracked by Malpedia. ID: js.proslikefan
APT GROUP
Storm-2949 is a sophisticated threat actor that exploited Microsoft’s Self-Service Password Reset process to compromise high-value accounts, primarily targeting IT personnel and senior leadership. They leveraged Azure tools and APIs to conduct reconnaissance, exfiltrate sensitive data from Microsoft 365 applications, and manipulate Azure resources, including Key Vaults and SQL databases. The actor employed social engineering tactics to bypass MFA and utilized custom Python scripts for directory discovery and data exfiltration. Their operations included lateral movement across cloud and endpoint environments while mimicking legitimate administrative behavior.
Updated: 2026-08-01
View profile →APT GROUPfinancialhigh
SnowSoul is a financially motivated threat actor active since at least early 2026, operating a low-ransom extortion scheme primarily targeting Chinese organizations. The actor sends extortion demands of around $2,000 USD, and when victims refuse to pay, leaks stolen data on hacker forums. Operations are tracked through numbered identifiers (e.g., SnowSoul ID-1265, ID-1270), suggesting a systematic, serial campaign.
Updated: 2026-08-01
View profile →APT GROUPfinancialhigh
SHADOW-WATER-063 is a financially motivated threat actor attributed to the Banana RAT banking trojan, primarily targeting Brazilian financial accounts. Analysis of recovered artifacts, including a Python panel and PowerShell stagers, supports a moderate-confidence attribution assessment. The actor's infrastructure and endpoint telemetry indicate a focus on executing fraudulent transactions. Key evidentiary pillars establish their intent to exploit Brazilian financial systems.
🇧🇷 BR
Updated: 2026-08-01
View profile →APT GROUPfinancialhigh
Narketing163 is a financially motivated threat actor named after one of their frequently used email addresses (narketing163@gmail.com). Active since at least July 2023, the actor conducts large-scale phishing campaigns distributing commodity infostealer and keylogger malware disguised as business correspondence such as price quotes, order forms, and payment notices. Targets span multiple countries including Russia, Belarus, Kazakhstan, Azerbaijan, Armenia, Turkey, the USA, Germany, the UK, India, and others, across sectors including e-commerce, retail, chemicals, construction, healthcare, insurance, and food. The actor delivers malware via spearphishing attachments (compressed archives) deploying RedLine Stealer, Agent Tesla, FormBook, and Snake Keylogger against Windows systems. Exfiltration is performed via actor-controlled Roundcube mail servers. Emails are sent in Russian, Azerbaijani, Turkish, and English, with rotating sender IPs and use of anonymization tools such as VPNs and proxies.
Updated: 2026-08-01
View profile →APT GROUPfinancialhigh
JINX-0164 is a financially motivated threat actor active since mid-2025, primarily targeting software developers through recruitment-themed social engineering to steal cryptocurrencies and conduct supply chain attacks. Their operations have focused on macOS devices, utilizing malware such as AUDIOFIX and MINIRAT, with a notable supply chain compromise involving the trojanization of an npm package. The actor employs a shell script for initial system profiling and payload delivery, often spoofing legitimate services like Microsoft Teams and cryptocurrency companies. JINX-0164's infrastructure includes numerous lookalike domains and utilizes VPN exit nodes for accessing victim systems.
🇰🇵 KP
Updated: 2026-08-01
View profile →APT GROUPhacktivism
Inteid is a member of the Russian Legion alliance, which includes groups like Cardinal and The White Pulse, and has been involved in DDoS attacks targeting Denmark's health portal, sundhed.dk. The group has also participated in ICS attacks, primarily affecting the Energy & Utilities, Manufacturing, and Agriculture sectors across Europe. Inteid has demonstrated operational coordination with other hacktivist entities, such as Keymous+, to support Iranian cyberwar efforts against Israeli targets.
Updated: 2026-08-01
View profile →APT GROUP
GREYVIBE is a low-to-moderately sophisticated threat actor associated with Russian state interests, primarily targeting Ukrainian entities. The group employs custom malware like LegionRelay and PhantomRelay, utilizing techniques such as decoy-and-payload execution logic and systematic use of GenAI and LLMs throughout their operations. Their campaigns exhibit operational overlaps with other groups, including shared C2 infrastructure and post-compromise tooling. WithSecure has identified design flaws in their malware that have provided insights into their victimology and operational behavior.
🇷🇺 RU
Updated: 2026-08-01
View profile →APT GROUPfinancialhigh
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor operating a sophisticated phishing campaign across over 300 domains, utilizing a custom React-based phishing kit that closely mimics FIFA's official website and exploits the PingIdentity SSO login flow. The campaign has the potential to generate financial losses estimated between $71 million and $474 million from premium ticket fraud alone, with total losses potentially reaching billions. GHOST STADIUM employs Facebook Ads as a primary traffic acquisition channel and has been linked to 2,513 compromised FIFA credentials available on dark-web markets. The actor is part of a broader fraud ecosystem that includes multiple parallel schemes, such as credential phishing and counterfeit merchandise sales.
🇨🇳 CN
Updated: 2026-08-01
View profile →APT GROUP
DriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and ClickFix-style prompts. This operation resembles an initial-access broker model, where successful infections generate leads for downstream threat actors. The actor employs tactics that avoid detection by site administrators, allowing infections to go unnoticed during routine checks.
Updated: 2026-08-01
View profile →APT GROUPespionageadvanced
CL-UNK-1068 is a Chinese threat actor that has targeted critical infrastructure in Asia, primarily focusing on cyberespionage. They utilize cross-platform tools, including the Xnote Linux backdoor and the GodZilla web shell, to maintain a persistent presence and execute credential theft. Their TTPs involve DLL side-loading, the use of custom malware, and batch scripts to bypass security measures. The group has demonstrated a capability for data exfiltration from SQL servers and has employed tools like DumpIt and Volatility for memory analysis.
🇨🇳 CN
Updated: 2026-08-01
View profile →APT GROUP
CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control communication. The actor has been observed collecting sensitive information from governmental entities, including data on tariffs and trade disputes. An investigation revealed a new Windows backdoor named HazyBeacon, which utilizes this novel C2 technique. This activity cluster has demonstrated significant efforts to remain undetected while executing its operations.
Updated: 2026-08-01
View profile →APT GROUPhacktivism
Chronus Team is a hacktivist group known for defacement attacks and data leaks, primarily targeting public-sector organizations in Mexico. They have been linked to multiple cyber incidents, including a significant breach of the Sonora Ministry of Education and Culture, where they allegedly exfiltrated sensitive data on educators. Their operations involve traditional hacking methods and the distribution of stolen data through channels typical of cybercriminals. The group's activities raise concerns about identity theft, fraud, and the destabilization of public institutions due to the exposure of sensitive information.
Updated: 2026-08-01
View profile →