Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,721 entities
APT GROUPfinancial
DoNex is a ransomware strain that emerged in March 2024 as the latest rebrand of a lineage beginning with Muse (2022) → DarkRace (2023) → DoNex, targeting enterprises in the US and Europe using double-extortion; Avast released a free decryptor in July 2024 after discovering a cryptographic flaw.
Infra: 🔗 g3h3klsev3eiofxhykmt
RLUpdated: 2026-08-05
View profile →
APT GROUP
Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more sophisticated backdoors like Cobalt Strike. This backdoor collects basic system information, which it then transmits to the C2 server. In return, it receives an AES-encrypted payload. Notably, the Minodo Backdoor is designed to contact a different C2 address for domain-joined systems. This suggests that more capable backdoors, such as Cobalt Strike, are downloaded on higher-value targets instead of Project Nemesis.
APT GROUPfinancialhigh
DogHousePower is a PyInstaller-based ransomware targeting web and database servers. It is delivered through a PowerShell downloader and was hosted on Github.
APT GROUP
Malware family tracked by Malpedia. ID: win.dnwipe
APT GROUP
Cisco Talos recently discovered a new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airline company. Based on our research, it's clear that this adversary spent time understanding the victims' network infrastructure in order to remain under the radar and act as inconspicuous as possible during their attacks. Based on this actor's infrastructure and TTPs, we haven't been able to connect them with any other campaign or actor that's been observed recently. This particular campaign utilizes two fake, malicious websites containing job postings that are used to compromise targets via malicious Microsoft Office documents with embedded macros. The malware utilized by this actor, which we are calling "DNSpionage," supports HTTP and DNS communication with the attackers. In a separate campaign, the attackers used the same IP to redirect the DNS of legitimate .gov and private company domains. During each DNS compromise, the actor carefully generated Let's Encrypt certificates for the redirected domains. These certificates provide X.509 certificates for TLS free of charge to the user. We don't know at this time if the DNS redirections were successful. In this post, we will break down the attackers' methods and show how they used malicious documents to attempt to trick users into opening malicious websites that are disguised as "help wanted" sites for job seekers. Additionally, we will describe the malicious DNS redirection and the timeline of the events.
APT GROUP
DNSMessenger makes use of DNS TXT record queries and responses to create a bidirectional Command and Control (C2) channel. This allows the attacker to use DNS communications to submit new commands to be run on infected machines and return the results of the command execution to the attacker.
APT GROUP
Malware family tracked by Malpedia. ID: win.dnschanger
APT GROUPespionageadvanced
DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.
APT GROUP
DMSniff is a point-of-sale malware previously only privately sold. It has been used in breaches of small- and medium-sized businesses in the restaurant and entertainment industries. It uses a domain generation algorithm (DGA) to create lists of command-and-control domains on the fly.
APT GROUP
Malware family tracked by Malpedia. ID: win.dma_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.dlrat
APT GROUP
Malware family tracked by Malpedia. ID: win.dizzyvoid
APT GROUP
Malware family tracked by Malpedia. ID: win.diztakun
APT GROUP
Malware family tracked by Malpedia. ID: win.divergent
APT GROUP
Malware family tracked by Malpedia. ID: win.disttrack
APT GROUP
Malware family tracked by Malpedia. ID: win.dispenserxfs
APT GROUP
Malware family tracked by Malpedia. ID: win.dispcashbr
APT GROUP
Malware family tracked by Malpedia. ID: win.disk_knight
APT GROUP
Malware family tracked by Malpedia. ID: win.dirtymoe
APT GROUP
Malware family tracked by Malpedia. ID: win.dircrypt
APT GROUP
Downloader.
APT GROUP
Malware family tracked by Malpedia. ID: win.dinodas_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.dimnie
APT GROUP
Downloader.
APT GROUPespionageadvanced
APT10's fork of the (open-source) Quasar RAT.
APT GROUP
A RAT written in .NET, used by FIN7 since 2021. In some instances dropped by ps1.powertrash.
APT GROUPfinancial
A ransomware with potential ties to Wizard Spider.
Infra: 💬 7ypnbv3snejqmgce4kbe
RLUpdated: N/A
View profile →
APT GROUP
According to PCrisk, DiamondFox is highly modular malware offered as malware-as-a-service, and is for sale on various hacker forums. Therefore, cyber criminals who are willing to use DiamondFox do not necessarily require any technical knowledge to perform their attacks. Once purchased, this malware can be used to log keystrokes, steal credentials (e.g., usernames, email addresses, passwords), hijack cryptocurrency wallets, perform distributed denial of service (DDoS) attacks, and to carry out other malicious tasks. DiamondFox allows cyber criminals to choose which plug-ins to keep activated and see infection statistics in real-time.
APT GROUPfinancial
Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It operates under a Ransomware-as-a-Service (RaaS) model, allowing affiliates to deploy customized builds with their own contact emails and extensions. Dharma typically appends encrypted files with patterns like .id-[victimID].[email].dharma or other campaign-specific suffixes. Initial access is often gained through exposed Remote Desktop Protocol (RDP) services secured with weak or stolen credentials, sometimes combined with brute-force attacks. The malware encrypts files using AES with RSA to secure the keys and drops ransom notes in text files and pop-up windows. Numerous variants have emerged over time, each linked to different affiliates, making attribution difficult.
RSLUpdated: 2026-08-05
View profile →
APT GROUP
Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security firm Seculert, in December 2012. It infects PoS systems worldwide and steals sensitive information such as Credit Card and Debit Card information.
APT GROUP
Dexphot is a cryptominer Malware attacking windows machines to gain profit from their resources. It implements many techniques to evade common security systems and a file-less technology to become inject malicious behavior. According to Microsoft the Dexphot It hijacked legitimate system processes to disguise malicious activity. If not stopped, Dexphot is equipped by monitoring services and scheduled tasks triggering re-infection when defenders attempt to remove the malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.dexbia
APT GROUP
Malware family tracked by Malpedia. ID: win.devopt
APT GROUPfinancial
Former RansomHub and INC Ransom affiliate.
Infra: 🔗 qljmlmp4psnn3wqskkf3
RLUpdated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.devils_rat
Updated: 2017-09-18
View profile →
APT GROUP
According to Microsoft, DevilsTongue is a complex modular multi-threaded piece of malware written in C and C++ with several novel capabilities. For files on disk, PDB paths and PE timestamps are scrubbed, strings and configs are encrypted, and each file has a unique hash. The main functionality resides in DLLs that are encrypted on disk and only decrypted in memory, making detection more difficult. Configuration and tasking data is separate from the malware, which makes analysis harder. DevilsTongue has both user mode and kernel mode capabilities.
APT GROUP
According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity. DesertBlade is responsible for iteratively overwriting and then deleting overwritten files on all accessible drives (sparing the system if it is a domain controller).
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: elf.derusbi
APT GROUPfinancialhigh
DeroHE is a ransomware that was spread to users after IObit, a Windows utility developer, was hacked. The malware is delivered a DLL that is sideloaded by a legitimate, signed IObit License Manager application.
APT GROUP
Malware family tracked by Malpedia. ID: win.deria_lock