Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
4h rat
Technical ID: 4h_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.4h_rat
APT GROUP
Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victim’s sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.
APT GROUP
Malware family tracked by Malpedia. ID: osx.3cx_backdoor
Information stealer, based on strings it seems to target crypto currencies, instant messengers, and browser data.
APT GROUP
Malware family tracked by Malpedia. ID: win.000stealer
APT GROUP
Malware family tracked by Malpedia. ID: vbs.whiteshadow
APT GROUP
Malware family tracked by Malpedia. ID: vbs.wasabiseed
APT GROUP
According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.
Malware family tracked by Malpedia. ID: vbs.unidentified_006
Malware family tracked by Malpedia. ID: vbs.unidentified_005
Lab52 describes this as a light first-stage RAT used by MuddyWater and observed samples between at least November 2020 and January 2022.
Malware family tracked by Malpedia. ID: vbs.unidentified_003
Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up via winrar.
Malware family tracked by Malpedia. ID: vbs.unidentified_001
APT GROUP
TAMECAT is PowerShell-based backdoor with modular components designed to facilitate data exfiltration and remote control
APT GROUP
Malware family tracked by Malpedia. ID: vbs.starwhale
APT GROUP
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on local powershell availability.
APT GROUP
A set of powershell scripts, using services like Google Docs and Dropbox as C2.
Downloads NodeJS when deployed.
APT GROUP
MOUSEISLAND is a Microsoft Word macro downloader used as the first infection stage and is delivered inside a password-protected zip attached to a phishing email. Based on Fireeye intrusion data from responding to ICEDID related incidents, the secondary payload delivered by MOUSEISLAND has been PHOTOLOADER, which acts as an intermediary downloader to install ICEDID.
APT GROUP
According to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.lockscreen
APT GROUP
Malware family tracked by Malpedia. ID: vbs.litterdrifter
APT GROUP
Malware family tracked by Malpedia. ID: vbs.lcryx
APT GROUPfinancialhigh
Malware is delivered by emails, containing links to ZIP files or ZIP attachments. The ZIP contains a VBscript that, when executed, downloads additional files from AWS S3, Google Drive or other cloud hosting services. The downloaded files are encrypted .exe and .dll files. The malware targets banking clients in Portugal.
APT GROUP
According to Patrick Wardle, this malware persists a python script as a cron job. Steps: 1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'. 2. Appends its new job to this file. 3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.iloveyou
APT GROUP
Malware family tracked by Malpedia. ID: vbs.homesteel
APT GROUP
According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server. Once received, HATVIBE uses a simple XOR algorithm to decrypt each module, contact it between two <script> tags before adding it to the HTML body of the HTA file, leading to the automatic execution of the received module.
APT GROUPfinancialhigh
The HALFBAKED malware family consists of multiple components designed to establish and maintain a foothold in victim networks, with the ultimate goal of gaining access to sensitive financial information. HALFBAKED listens for the following commands from the C2 server: info: Sends victim machine information (OS, Processor, BIOS and running processes) using WMI queries processList: Send list of process running screenshot: Takes screen shot of victim machine (using 58d2a83f777688.78384945.ps1) runvbs: Executes a VB script runexe: Executes EXE file runps1: Executes PowerShell script delete: Delete the specified file update: Update the specified file
Malware family tracked by Malpedia. ID: vbs.grinju
APT GROUP
Malware family tracked by Malpedia. ID: vbs.glowspark
APT GROUP
Malware family tracked by Malpedia. ID: vbs.ggldr
APT GROUP
According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880). They assess with medium confidence a link to Gamaredon.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.forbiks
CageyChameleon Malware is a VBS-based backdoor which has the capability to enumerate the list of running processes and check for the presence of several antivirus products. CageyChameleon will collect user host information, system current process information, etc. The collected information is sent back to the C2 server, and continue to initiate requests to perform subsequent operations.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.basicstar
APT GROUP
A backdoor brought into version 5.6.0 and 5.6.1 of compression library/tool xz/liblzma, which was intended to enable access via (Open)SSH on affected servers.
APT GROUP
According to its author, PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.
APT GROUP
Malware family tracked by Malpedia. ID: sh.kv