Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Discord Stealer written in Python with Javascript-based inject files.
APT GROUP
Malware family tracked by Malpedia. ID: py.dropboxc2c
APT GROUP
Creal is an open-source grabber/credential stealer that was originally made by a GitHub user named Ayhuuu, who even advertised a "premium" version on his now-deleted Telegram channel @Crealstealer. To the day of release, it was already not FUD, but its open-source nature made it attractive for threat actors to modify the base malware and even obfuscate it for less detection ratios. The base project came with a compiler, and the general source code the compiler used was PyInstaller for compilation into native formats like exe. For C2, Discord webhooks were utilized, which in later versions got protected with a service called https://stealer.to to make deletion not possible.
It Compromised following Data on Execution:
* Discord Information
* Browser Data
* Crypto Related Data
* Steam
* Riot Games
* Telegram
* System Information
* Tokens/Secrets
APT GROUP
According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.
APT GROUP
Malware family tracked by Malpedia. ID: py.brickerbot
APT GROUP
According to K7 Security Labs, Braodo Stealer is written in Python and collects all cookies and saved credentials from the browsers and all services and process information of that particular system as a zip file, which is then exfiltrated to a Telegram Channel.
APT GROUP
Stealer written in Python 3, typically distributed bundled via PyInstaller.
APT GROUP
Malware family tracked by Malpedia. ID: py.archivist
APT GROUP
According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
APT GROUP
According to Laceworks, this is a SMTP cracker, which is primarily intended to scan for and parse Laravel application secrets from exposed .env files. Note: Laravel is an open source PHP framework and the Laravel .env file is often targeted for its various configuration data including AWS, SendGrid and Twilio. AndroxGh0st has multiple features to enable SMTP abuse including scanning, exploitation of exposed creds and APIs, and even deployment of webshells. For AWS specifically, the malware scans for and parses AWS keys but also has the ability to generate keys for brute force attacks. However, the brute force capability is likely a novelty and is a statistically unlikely attack vector.
APT GROUPfinancialhigh
According to Fortinet, Amnesia RAT is written in Python and designed for broad, multi-category data theft combined with real-time surveillance and system control. Its capabilities include: Browser credentials and session data, Telegram Desktop session hijacking, Seed phrase discovery and clipboard monitoring, Discord and Steam data theft, Cryptocurrency wallets and financial assets, System and hardware intelligence, Screen, audio, and activity surveillance, Process and system control, Persistence, multiple exfiltration channels.
APT GROUP
Malware family tracked by Malpedia. ID: py.akira_stealer
APT GROUP
According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.wmimplant
APT GROUP
Malware family tracked by Malpedia. ID: ps1.wannaren_loader
APT GROUP
Malware family tracked by Malpedia. ID: ps1.wannamine
APT GROUP
Malware family tracked by Malpedia. ID: ps1.vipersoftx
APT GROUP
Malware family tracked by Malpedia. ID: ps1.unidentified_005
APT GROUP
Malware family tracked by Malpedia. ID: ps1.unidentified_004
APT GROUP
This malware is a RAT written in PowerShell. It has the following capabilities: Downloading and Uploading files, loading and execution of a PowerShell script, execution of a specific command. It was observed by Malwarebytes LABS Threat Intelligence Team in a newly discovered campaign: this campaigns tries to lure Germans with a promise of updates on the current threat situation in Ukraine according to Malwarebyte LABS.
APT GROUP
A Powershell-based RAT capable of pulling further payloads, delivered through Russia-themed phishing mails.
APT GROUPespionageadvanced
Recon and exfiltration script, dropped from a LNK file. Attributed to APT-C-12.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.thundershell
APT GROUP
Malware family tracked by Malpedia. ID: ps1.tater
APT GROUP
Malware family tracked by Malpedia. ID: ps1.swrort
APT GROUP
Malware family tracked by Malpedia. ID: ps1.subtle_paws
APT GROUP
Malware family tracked by Malpedia. ID: ps1.steelhook
APT GROUP
Malware family tracked by Malpedia. ID: ps1.snugy
APT GROUP
sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.skyrat
APT GROUP
According to Trend Micro, SilentPrism is a backdoor malware designed to achieve persistence, dynamically execute shell commands, and maintain unauthorized remote control of compromised systems. It implements persistence mechanisms differently based on user privileges: for non-administrative users, it leverages the Windows registry to create auto-run entries using mshta.exe combined with VBScript to download and execute remote payloads; for administrative users, it deploys scheduled tasks with similar execution methods. SilentPrism retrieves additional payloads and instructions from a C&C server, ensuring modular functionality. The malware communicates with its C&C server using encrypted channels, employing AES encryption and Base64 encoding to obfuscate data. Commands received are decrypted and executed in various ways, including direct PowerShell script execution, dynamic script block creation, or job-based execution. Each task is tracked using unique identifiers, allowing the malware to monitor execution states and return results to the server. SilentPrism incorporates anti-analysis techniques such as virtual machine detection and randomized sleep intervals (ranging from 300 to 700 milliseconds) between operations, making its behavior less predictable. Additionally, it continuously polls the C&C server for commands, enabling operators to dynamically control infected systems.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.schtasks
APT GROUP
Malware family tracked by Malpedia. ID: ps1.roguerobin
APT GROUP
According to Trellix, this is a first-stage, powershell-based malware dropped via Excel/VBS. It is able to establish a foothold and exfiltrate data. Targets identified include hotels in Macao.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.quadagent
APT GROUP
Malware family tracked by Malpedia. ID: ps1.ptero_graphin
APT GROUPfinancialhigh
The family is adding a fake root certificate authority, sets a proxy.pac-url for local browsers and redirects infected users to fake banking applications (currently targeting Poland). Based on information shared, it seems the PowerShell script is dropped by an exploit kit.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.powruner
APT GROUP
DLL loader that decrypts and runs a powershell-based downloader.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.power_rat