Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Keylogger.
APT GROUP
Malware family tracked by Malpedia. ID: win.ayegent
Updated: 2016-12-28
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.axlocker
APT GROUP
Malware family tracked by Malpedia. ID: win.avzhan
APT GROUP
Information stealer which uses AutoIT for wrapping.
APT GROUP
Malware family tracked by Malpedia. ID: win.aveo
Cyble Research discovered this .Net written malware dubbed "AvD Crypto Stealer". The name of this malware is misleading, because this is a kind of clipper malware. Assumption of Cyble is, that this malware could target other threat actors as scenario.
APT GROUP
Malware family tracked by Malpedia. ID: win.avast_disabler
First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabilities. The malware targets data from multiple browsers, cryptocurrency wallets, local systems, and act as a loader. During execution, the malware runs several commands through WMIC to collect basic host information, snaps a desktop image, and exfiltrates data to the C2 server within a single base64-encoded JSON file.
APT GROUPfinancialhigh
Ransomware
APT GROUP
Malware family tracked by Malpedia. ID: win.auriga
APT GROUPespionageadvanced
In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription tiers on underground forums. The information stealer targets credentials from over 110 browsers, 70 applications, and 250+ browser extensions, including cryptocurrency wallets and 2FA tools, while using AES-256 encryption for C2 communications. Notable features include seamless Chromium cookie harvesting without process termination, server-side App-Bound data decryption, and a built-in payload loader with custom morphing for detection evasion.
APT GROUPfinancialhigh
According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system.
Malware family tracked by Malpedia. ID: win.august_stealer
APT GROUP
The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either CSCWCNG.dll or MFSXFS.dll. Both libraries are legitimate Windows drivers used to interact with the components of different ATM models.
APT GROUP
Malware family tracked by Malpedia. ID: win.atmosphere
APT GROUP
Malware family tracked by Malpedia. ID: win.atmitch
APT GROUP
Malware family tracked by Malpedia. ID: win.atmii
APT GROUP
Malware family tracked by Malpedia. ID: win.atlas_agent
APT GROUP
Malware family tracked by Malpedia. ID: win.atlantida
APT GROUP
Malware family tracked by Malpedia. ID: win.ati_agent
APT GROUP
Malware family tracked by Malpedia. ID: win.athenago
Updated: 2017-02-13
View profile →
APT GROUP
Part of the Mythic framework, payload in C# (.NET 6), support HTTP, Websockets, Slack, SMB for C2.
APT GROUP
Malware family tracked by Malpedia. ID: win.atharvan
APT GROUP
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victim’s computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques.
APT GROUPfinancialhigh
Astasia is a banking trojan that spreads through phishing emails that contain an executable attachment. Once the attachment is executed, Astasia downloads and installs a trojan that runs in the background. The trojan can steal personal information, such as passwords and credit card numbers, from victims.
APT GROUPfinancialhigh
First spotted in the wild in 2017, Astaroth is a highly prevalent, information-stealing Latin American banking trojan. It is written in Delphi and has some innovative execution and attack techniques. Originally, this malware variant targeted Brazilian users, but Astaroth now targets users both in North America and Europe.
APT GROUP
According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution, with RSA-encrypted C2 communication disguised as application telemetry.
APT GROUP
Malware family tracked by Malpedia. ID: win.asruex
APT GROUP
Malware family tracked by Malpedia. ID: win.asprox
APT GROUP
Malware family tracked by Malpedia. ID: win.aspc
Updated: 2017-05-19
View profile →
APT GROUP
According to Unit 42, Ashen / AshTag is a modular .NET toolset currently in active development, with extensive features, including file exfiltration, content download and in-memory execution of additional modules.
APT GROUP
Malware family tracked by Malpedia. ID: win.ascentloader
Updated: 2018-07-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.asbit
Malware family tracked by Malpedia. ID: win.artra
APT GROUP
Malware family tracked by Malpedia. ID: win.artfulpie
ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via different available commands, acting as a remote access trojan (RAT). Its code is based on ASPC, another Visual Basic Script malware, which at the same time seems to be based on SafeLoader.
APT GROUP
It is available as a service, purchasable by anyone to use in their own campaigns. It’s features are generally fairly typical of a RAT, with its most notable aspect being the hVNC module which basically gives an attacker full remote access with minimal need for technical knowledge to use it.
APT GROUP
Arkei is a stealer that appeared around May 2018. It collects data about browsers (saved passwords and autofill forms), cryptocurrency wallets, and steal files matching an attacker-defined pattern. It then exfiltrates everything in a zip file uploaded to the attacker's panel. Later, it was forked and used as a base to create Vidar stealer.
Malware family tracked by Malpedia. ID: win.arik_keylogger