Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,725 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.darkrat
APT GROUP
Malware family tracked by Malpedia. ID: win.darkpulsar
APT GROUP
Malware family tracked by Malpedia. ID: win.darkmoon
APT GROUP
Malware family tracked by Malpedia. ID: win.darkmegi
APT GROUP
Malware family tracked by Malpedia. ID: win.darkme
APT GROUP
Malware family tracked by Malpedia. ID: win.darkloader
APT GROUP
Malware family tracked by Malpedia. ID: win.darkirc
APT GROUP
First documented in 2018, DarkGate is a commodity loader with features that include the ability to download and execute files to memory, a Hidden Virtual Network Computing (HVNC) module, keylogging, information-stealing capabilities, and privilege escalation. DarkGate makes use of legitimate AutoIt files and typically runs multiple AutoIt scripts. New versions of DarkGate have been advertised on a Russian language eCrime forum since May 2023.
APT GROUP
Malware family tracked by Malpedia. ID: win.darkeye
APT GROUP
Mandiant associates this with UNC4191, this malware spreads to removable drives.
APT GROUP
DarkComet is one of the most famous RATs, developed by Jean-Pierre Lesueur in 2008. After being used in the Syrian civil war in 2011, Lesuer decided to stop developing the trojan. Indeed, DarkComet is able to enable control over a compromised system through use of a simple graphic user interface. Experts think that this user friendliness is the key of its mass success.
Stealer is written in Visual Basic.
APT GROUPfinancial
DarkBit is an ideologically motivated ransomware group that appeared in February 2023, primarily targeting Israeli entities — most notably the Technion Institute of Technology — with politically charged ransom notes condemning Israeli government policies, assessed to be linked to Iranian state-sponsored activity.
RLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.daolpu
APT GROUP
According to Kaspersky Labs, Dante is the commercial spyware developed by Memento Labs (formerly Hacking Team).
APT GROUP
Malware family tracked by Malpedia. ID: win.danderspritz
APT GROUP
Danbot is a backdoor malware that is originally written in C#. Recent versions of Danbot are written in C++. Danbot is capable of giving a remote attacker remote access features such as running a cmd command, upload and download files, move and copy files. The backdoor commands are transmitted by either using HTTP or DNS protocols. The commands are encapsulated in an XML file that gets stored in disk. Danbot's backdoor component picks up the XML file where it decodes and decrypts the commands.
APT GROUP
Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be monetized rather than demanding an immediate ransom from victims. The social engineering in the low-volume DanaBot campaigns we have observed so far has been well-crafted, again pointing to a renewed focus on “quality over quantity” in email-based threats. DanaBot’s modular nature enables it to download additional components, increasing the flexibility and robust stealing and remote monitoring capabilities of this banker.
APT GROUP
Malware family tracked by Malpedia. ID: win.dairy
APT GROUP
Malware family tracked by Malpedia. ID: win.dadstache
APT GROUPespionageadvanced
DADJOKE was discovered as being distributed via email, targeting a South-East Asian Ministry of Defense. It is delivered as an embedded EXE file in a Word document using remote templates and a unique macro using multiple GET requests. The payload is deployed using load-order hijacking with a benign Windows Defender executable. Stage 1 has only beacon+download functionality, made to look like a PNG file. Additional analysis by Kaspersky found 8 campaigns over 2019 and no activity prior to January 2019, DADJOKE is attributed with medium confidence to APT40.
APT GROUP
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control infected computers remotely. Research shows that this malware is tied to Lazarus Group (a group of cyber criminals) and targets Linux and the Windows Operating System. Typically, cyber criminals use RATs to steal sensitive, confidential information, infect systems with other malware, and so on. In any case, no RAT is harmless and should be uninstalled immediately.
APT GROUP
Malware family tracked by Malpedia. ID: win.cysxl
APT GROUPfinancialhigh
According to gdatasoftware, Cyrat ransomware uses Fernet to encrypt files. This is a symmetric encryption method meant for small data files that fit into RAM. While Fernet is not unusual itself, it is not common for ransomware and in this case even problematic.
APT GROUPfinancial
Cyclops emerged in May 2023 as a cross-platform RaaS operation targeting Windows, macOS, and Linux systems; it rebranded as "Knight" in August 2023 and its codebase was ultimately sold, with affiliates largely migrating to RansomHub.
Infra: 🔗 nt3rrzq5hcyznvdkpslv💬 wy35mxvqxff4vufq64v4
RSLUpdated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.cycbot
APT GROUP
Malware family tracked by Malpedia. ID: win.cyber_splitter
Updated: 2016-12-27
View profile →
APT GROUP
According to Subex Secure, CyberGate is a Remote Access Trojan (RAT) that allows an attacker to gain unauthorized access to the victim’s system. Attackers can remotely connect to the compromised system from anywhere around the world. The Malware author generally uses this program to steal private information like passwords, files, etc. It might also be used to install malicious software on the compromised systems.
APT GROUP
Malware family tracked by Malpedia. ID: win.cutwail
APT GROUP
Malware family tracked by Malpedia. ID: win.cutlet
CustomerLoader is a .Net-based loader that drops more than 40 different malware families. It appeared in June 2023 and is being distributed via phishing, YouTube videos and malicious websites.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.curlback
APT GROUPfinancialhigh
Profero describes this as a ransomware family using CryptoPP as library to enable file encryption with the Salsa20 algorithm and protecting the encryption keys with RSA2048.
Potential Lazarus sample.
APT GROUP
Malware family tracked by Malpedia. ID: win.cueisfry
APT GROUP
Malware family tracked by Malpedia. ID: win.cuegoe
APT GROUPfinancial
The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.<br> <br> Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.<br> <br> According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.<br> <br> The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.<br> <br> The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.<br> <br> In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 cuba4mp6ximo2zlo.oni🔗 cuba4ikm4jakjgmkezyt📁 i34gbmo5rxx3bxc4yl7f+1 more
RSLUpdated: N/A
View profile →
APT GROUPfinancial
aka Critroni <br/>CTB‑Locker emerged in mid‑2014, introducing a new era of ransomware by leveraging elliptic curve cryptography (ECC), Tor-based C&C communication, and Bitcoin payments—earning its name from “Curve-Tor-Bitcoin Locker.” It was packaged and sold as a ransomware kit for approximately $1,500–$3,000, allowing affiliates to deploy customized campaigns. The malware encrypts user data (including network and removable drives), changes desktop wallpapers, and appends file extensions like .CTBL, .CTB2, or randomized strings. Victims receive instructions for payment, typically within a limited timeframe, or risk permanent data loss. In 2015–2017, law enforcement and cybersecurity firms (including McAfee and Kaspersky) disrupted the network, arrested operators, and facilitated decryption tools.
Infra: 💬 ohmva4gbywokzqso.oni💬 tmc2ybfqzgkaeilm.oni
RSLUpdated: 2026-08-05
View profile →
Malware family tracked by Malpedia. ID: win.csharpstreamer