Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: py.wirefire
APT GROUP
A basic info stealer w/ some capability to inject code into legit applications.
APT GROUP
Malware family tracked by Malpedia. ID: py.vilerat
APT GROUP
Venus Stealer is a python based Infostealer observed early 2023.
APT GROUPfinancialhigh
Ransomware written in Python and delivered as compiled executable created using PyInstaller.
APT GROUP
Malware family tracked by Malpedia. ID: py.upstyle
unidentified 002
Technical ID: unidentified_002
APT GROUP
Malware family tracked by Malpedia. ID: py.unidentified_002
APT GROUP
Malware family tracked by Malpedia. ID: py.stitch
APT GROUP
Malware family tracked by Malpedia. ID: py.stealler
APT GROUP
Malware family tracked by Malpedia. ID: py.spacecow
APT GROUP
According to Proofpoint, this is a backdoor written in Python, used in attacks against French entities in the construction, real estate, and government industries.
APT GROUP
Malware family tracked by Malpedia. ID: py.saphyra
APT GROUP
Malware family tracked by Malpedia. ID: py.rn_stealer
APT GROUP
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Malware family tracked by Malpedia. ID: py.redtiger
APT GROUP
Malware family tracked by Malpedia. ID: py.quietboard
APT GROUP
PyVil RAT
APT GROUP
According to Securonix, this malware exhibits remote access trojan (RAT) behavior, allowing for control of and persistence on the affected host. As with other RATs, PY#RATION possesses a whole host of features and capabilities, including data exfiltration and keylogging. What makes this malware particularly unique is its utilization of websockets for both command and control (C2) communication and exfiltration as well as how it evades detection from antivirus and network security measures.
APT GROUP
According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed binary (e.g. python.exe) by importing their dependencies in memory. It was created to demonstrate a bypass strategy against EDRs based on some blind-spots assumptions.
APT GROUP
Python-version of GolangGhost RAT
APT GROUP
Malware family tracked by Malpedia. ID: py.pyback
APT GROUP
Malware family tracked by Malpedia. ID: py.pyark
APT GROUP
Malware family tracked by Malpedia. ID: py.pyaesloader
APT GROUPfinancialhigh
PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a Vietnamese-speaking threat actor (2024). The stealer targets sensitive data such as credentials for online accounts, VPN and FTP clients, financial information, browser cookies, and gaming-related data. Notably, PXA Stealer is capable of decrypting browser master passwords to exfiltrate stored credentials. The campaign leverages heavily obfuscated batch scripts for delivery and execution. The actor behind this operation is linked to the Telegram channel “Mua Bán Scan MINI,” known to host credential trade and cybercrime activity. While there are connections to the CoralRaider adversary, attribution to this group remains unconfirmed. In q2 2025 PXA stealer was observed to target Italy.
APT GROUP
Malware family tracked by Malpedia. ID: py.powerat
APT GROUP
Cisco Talos has discovered a Python-based RAT they call Poet RAT. It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.
APT GROUP
According to CERT-UA, this malware establishes a connection to the management server using web sockets and/or MQTT, data is transmitted in JSON format. Based on basic information about the computer (MAC address, BIOS serial number, disk and processor ID), it generates a unique device identifier using the SHA-256 algorithm (the first 16 bytes are used). It ensures the execution of the program code received from the server. Persistence is achieved by creating an entry in the Run branch of the operating system registry.
APT GROUP
Malware family tracked by Malpedia. ID: py.pirat
APT GROUP
Malware family tracked by Malpedia. ID: py.networm
APT GROUP
An IRC bot written in (obfuscated) Python code. Distributed in attack campaign FreakOut, written by author Freak/Fl0urite and development potentially dating back as far as 2015.
APT GROUP
Malware family tracked by Malpedia. ID: py.masepie
APT GROUP
Malware family tracked by Malpedia. ID: py.lunagrabber
APT GROUPespionageadvanced
This RAT written in Python is an open-source fork of the Ares RAT. This malware integrates additional modules, like recording, lockscreen, and locate options. It was used in a customized form version by El Machete APT in an ongoing champaign since 2020. The original code can be found at: https://github.com/TheGeekHT/Loki.Rat/
APT GROUP
Malware family tracked by Malpedia. ID: py.lofy
APT GROUP
The author described LaZagne as an open source project used to retrieve lots of passwords stored on a local computer. It has been developed for the purpose of finding these passwords for the most commonly-used software. It is written in Python and provided as compiled standalone binaries for Linux, Mac, and Windows.
APT GROUP
According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.
APT GROUP
Malware family tracked by Malpedia. ID: py.keyplexer
Malware family tracked by Malpedia. ID: py.invisibleferret
APT GROUP
According to Kaspersky Labs, Guard is a malware developed by threat actor WildPressure. It is written in Python and packaged using PyInstaller, both for Windows and macOS operating systems. Its intrinsics resemble parts of how win.milum operates.
APT GROUPfinancialhigh
Ransomware written in Python.