Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,725 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.csext
APT GROUP
Malware family tracked by Malpedia. ID: win.crystal_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptxxxx
APT GROUP
Malware family tracked by Malpedia. ID: win.crypto_ransomeware
APT GROUP
Malware family tracked by Malpedia. ID: win.crypto_fortress
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptowire
APT GROUPfinancialhigh
CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a Trojan horse to deliver the malicious payload.
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoslay
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoshuffler
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoshield
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptorium
APT GROUPfinancialhigh
CryptoPatronum is a ransomware that encrypts user data through AES-256 (CBC) and it asks for BTC / ETH in order to get back the original files. In the ransom note there is not a title but only a reference to crsss.exe: its original file name. Once the files are encrypted, CryptoPatronum adds a .enc extension.
APT GROUP
A variant of CryptoMix is win.clop.
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoluck
APT GROUP
CryptoLocker is a new sophisticated malware that was launched in the late 2013. It is designed to attack Windows operating system by encrypting all the files from the system using a RSA-2048 public key. To decrypt the mentioned files, the user has to pay a ransom (usually 300 USD/EUR) or 2 BitCoins.
APT GROUPespionageadvanced
CryptoJoker is an open source ransomware written in C#.
CryptoJoker uses a combination of a "custom XOR" encryption and RSA. A private public/private pair key is generated for every computer.
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptodarkrubix
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoclippy
APT GROUPfinancial
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256 bit key and IV.* The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
Infra: 💬 cryptr3fmuv4di5uiczo…🔗 blog6zw62uijolee7e6a…
RLUpdated: 2026-08-05
View profile →APT GROUP
CrypticConvo is a dropper trojan which appears to be embedded in an automatic generator framework to deliver the FakeM trojan. According to PaloaltoNetworks CrypticConvo and several additional trojans are believed to be included in a meta framework used by the "Scarlet Mimic" threat actor in order to quickly evade AV systems.
APT GROUP
A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2.
APT GROUP
Malware family tracked by Malpedia. ID: win.crypt0l0cker
APT GROUP
Malware family tracked by Malpedia. ID: win.crypmic
APT GROUP
Malware family tracked by Malpedia. ID: win.crylocker
APT GROUP
Malware family tracked by Malpedia. ID: win.cryakl
APT GROUP
Malware family tracked by Malpedia. ID: win.crutch
APT GROUP
Malware family tracked by Malpedia. ID: win.cruloader
APT GROUPespionageadvanced
According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
APT GROUP
According to FireEye, CROSSWALK is a skeletal, modular backdoor capable of system survey and adding modules in response to C&C replies.
APT GROUPfinancial
CrossLock is a short-lived Go-based ransomware group that appeared in April 2023 and went dark by July 2023, using Curve25519 and ChaCha20 encryption and double-extortion tactics with only one known confirmed victim in the IT sector in Brazil.
Infra: 🔗 crosslock5cwfljbw4v3…
RLUpdated: 2026-08-05
View profile →APT GROUP
According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017. It enables operators to run command line tools, exfiltrate files, and upload files to the infected machine. CrimsonIAS is notable as it listens for incoming connections only; making it different from typical Windows backdoors that beacons out.
APT GROUP
It was first discovered in 2017 and has since been used to attack organizations around the world. The malware is often distributed through phishing emails or by exploiting vulnerabilities in outdated security software. Once Crimson RAT is installed on a computer, it can be used to steal data, spy on users, and even take control of the infected computers.
Some of the features of Crimson RAT include:
Remote control of infected computers
Data theft, such as passwords, files, and emails
User spying
Takeover of infected computers
Locking of infected computers
Extortion of payments
APT GROUP
Malware family tracked by Malpedia. ID: win.crenufs
APT GROUP
Malware family tracked by Malpedia. ID: win.creep_exfil
APT GROUP
Malware family tracked by Malpedia. ID: win.creepysnail
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: win.credraptor
APT GROUP
Malware family tracked by Malpedia. ID: win.credomap
APT GROUP
A tool that implements the creation of a hidden account on Windows through cloning accounts via the Registry.