Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,721 entities
APT GROUP
According to Tony Lambert, this is a malware written in .NET. It was observed to be delivered using the .NET Single File deployment feature.
APT GROUP
Malware family tracked by Malpedia. ID: win.dubrute
APT GROUPespionageadvanced
Kaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits that effectively evade the latest Windows and Adobe defenses, and yet they also imprecisely spread among large numbers of vague targets with peer-to-peer spreading tactics. Moreover, this crews most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world.'
🇰🇷 KRT1203T1566.001T1083
APT GROUP
Malware family tracked by Malpedia. ID: apk.dualtoy
APT GROUP
Dtrack is a Remote Administration Tool (RAT) developed by the Lazarus group. Its core functionality includes operations to upload a file to the victim's computer, download a file from the victim's computer, dump disk volume data, persistence and more. A variant of Dtrack was found on Kudankulam Nuclear Power Plant (KNPP) which was used for a targeted attack.
APT GROUP
Malware family tracked by Malpedia. ID: win.dropshot
APT GROUP
DropBook is a backdoor developed by the Molerats group and first appeared in late 2020. The backdoor abuses Facebook and Dropbox platforms for C2 purposes, where fake Facebook accounts are used by the operators to control the backdoor by posting commands on the accounts.
APT GROUPespionageadvanced
Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure. This makes it difficult to detect and remove, as GitHub is not traditionally associated with malicious activities. Drokbk attacks have been linked to the Iranian APT group Nemesis Kitten. This group is believed to use Drokbk for cyberespionage and financial information theft activities.
APT GROUP
Communicates via Google Drive.
APT GROUP
Malware family tracked by Malpedia. ID: win.dripion
APT GROUP
Driftpin is a small and simple backdoor that enables the attackers to assess the victim. When executed the trojan connects to a C&C server and receives commands to grab screenshots, enumerate running processes and get information about the system and campaign ID.
APT GROUPfinancialhigh
OxCERT blog describes Dridex as "an evasive, information-stealing malware variant; its goal is to acquire as many credentials as possible and return them via an encrypted tunnel to a Command-and-Control (C&C) server. These C&C servers are numerous and scattered all over the Internet, if the malware cannot reach one server it will try another. For this reason, network-based measures such as blocking the C&C IPs is effective only in the short-term." According to MalwareBytes, "Dridex uses an older tactic of infection by attaching a Word document that utilizes macros to install malware. However, once new versions of Microsoft Office came out and users generally updated, such a threat subsided because it was no longer simple to infect a user with this method." IBM X-Force discovered "a new version of the Dridex banking Trojan that takes advantage of a code injection technique called AtomBombing to infect systems. AtomBombing is a technique for injecting malicious code into the 'atom tables' that almost all versions of Windows uses to store certain application data. It is a variation of typical code injection attacks that take advantage of input validation errors to insert and to execute malicious code in a legitimate process or application. Dridex v4 is the first malware that uses the AtomBombing process to try and infect systems."
APT GROUP
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) 2014 Dreambot (Gozi ISFB variant) In 2014, a variant of Gozi ISFB was developed. Mainly, the dropper performs additional anti-vm checks (vmware, vbox, qemu), while the actual bot-dll remains unchanged in most parts. New functionality, such as TOR support, was added though and often, the Fluxxy fast-flux network is used. See win.gozi for additional historical information.
APT GROUP
Malware family tracked by Malpedia. ID: win.dratzarus
APT GROUP
Malware family tracked by Malpedia. ID: win.drat
APT GROUP
Malware family tracked by Malpedia. ID: win.dramnudge
Updated: 2018-07-24
View profile →
APT GROUPfinancial
DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.
Infra: 🔗 z3wqggtxft7id3ibr7sr💬 3pktcrcbmssvrnwe5skb📁 dragonforxxbp3awc7mz+17 more
MY
RLUpdated: 2026-08-05
View profile →
APT GROUPespionageadvanced
Golden Eye Dog targets Chinese-speaking users engaged in online gambling, employing techniques such as SERP poisoning, social engineering, and DDoS attacks. The group utilizes trojanized NSIS installers to deliver RONINGLOADER, which executes complex process-injection workflows and deploys a modified Gh0st RAT for espionage. Their operations have included DLL sideloading and the use of watering hole websites to implant Trojans. The group is noted for its high anti-detection capabilities and has been associated with various malware development languages.
APT GROUP
Cyber Defense Institute stated that this shellcode PE loader was observed staging win.hemigate.
APT GROUPespionageadvanced
DownPaper, sometimes delivered as sami.exe, is a Backdoor trojan. Its main functionality is to download and run a second stage. This malware has been observed in campaigns involving Charming Kitten, an Iranian cyberespionage group.
APT GROUP
According to Bitdefender, this is an exfiltration tool, scanning local and network drives for sensitive files, like documents, archives, certificates, and cryptographic keys.
APT GROUP
Malware family tracked by Malpedia. ID: win.downeks
APT GROUP
Malware family tracked by Malpedia. ID: win.downdelph
APT GROUP
A wiper identified by CERT-UA on March 17th, written in C#.
APT GROUP
Malware family tracked by Malpedia. ID: win.doublepulsar
APT GROUP
Malware family tracked by Malpedia. ID: win.doubleloader
APT GROUP
Malware family tracked by Malpedia. ID: win.doublefinger
APT GROUP
Malware family tracked by Malpedia. ID: elf.doublefantasy
APT GROUP
DOUBLEBACK is a newly discovered fileless malware deployed as part of an attack campaign that took place in December 2020. The threat actors responsible for the operations are tracked as UNC2529 by researchers. According to their findings, DOUBLEBACK is the final payload delivered onto the compromised systems. Its task is to establish and maintain a backdoor on the victim's machine.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.dot_ransomware
APT GROUP
According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data. It is also capable of taking screenshots and logging keystrokes.
APT GROUP
Infrastructure and programs used for, as its name suggests, DDoSing. It used to be written in Python, nowadays it's written in Go. Clients: - Are written in Go. (Used to be written in Python.) - Do not seem to differ significantly across OS deployments. (Confirmed on Windows, MacOS, Linux, Android) - Seem to be partly run by NoName themselves. - Partly also run voluntarily, recruited via dedicated Telegram channels. Participants are rewarded with cryptocurrency. Prints a suggestion to use a VPN for Russia-based launches. (This yields IP-based blocking as rather ineffective, consider behavioral analysis instead.) Configuration: - Rotates near-daily. Can be browsed on https://witha.name/ (also reachable via http://withanamemwesdvodfhthjq25a5a3uas24cpgoa7qm6gchcerzpis6qd.onion/). - Is sent encrypted between C2 and Client. - Specifies target hostname, subpath, vector protocols, methods, ports, whether SSL is used, headers for HTTP, request bodies. - Any given config property can be randomly generated with per-use constraints. - Is provided by a multi-level hierarchy of C2 servers.
APT GROUP
Malware family tracked by Malpedia. ID: win.dorshel
APT GROUP
Malware family tracked by Malpedia. ID: win.dorkbot_ngrbot
APT GROUPfinancial
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Infra: 🔗 hpoo4dosa3x4ognfxpqc💬 qkbbaxiuqqcqb5nox4np
RLUpdated: N/A
View profile →
APT GROUP
DoppelDridex is a fork of Indrik Spider's Dridex malware. DoppelDridex has been run as a parallel operation to Dridex with a different malware versioning system, different RSA key, and with different infrastructure.
APT GROUP
Malware family tracked by Malpedia. ID: win.doplugs
APT GROUP
Malware family tracked by Malpedia. ID: win.doorme
donut injector
Technical ID: donut_injector
APT GROUP
Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It was used during attacks against U.S. organisations according to Threat Hunter Team (Symantec) and U.S. Defence contractors (Unit42). Github: https://github.com/TheWover/donut
APT GROUP
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.