Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,713 entities
APT GROUPhacktivism
Chronus Team is a hacktivist group known for defacement attacks and data leaks, primarily targeting public-sector organizations in Mexico. They have been linked to multiple cyber incidents, including a significant breach of the Sonora Ministry of Education and Culture, where they allegedly exfiltrated sensitive data on educators. Their operations involve traditional hacking methods and the distribution of stolen data through channels typical of cybercriminals. The group's activities raise concerns about identity theft, fraud, and the destabilization of public institutions due to the exposure of sensitive information.
Updated: 2026-08-02
View profile →APT GROUPespionageadvanced
According to Check Point Research, "MiniFast" is a 64-bit Windows DLL backdoor that appears to be under active development and shows multiple signs of AI-assisted coding, including verbose error handling, modular organization, and descriptive function naming. It is designed for long-term access and remote administration, using a structured command-and-control protocol with host registration, task polling, and result reporting capabilities.
MiniFast performs basic system reconnaissance and supports a broad set of post-compromise functions, including file and directory management, command execution, process enumeration and termination, file transfer, archive creation, and dynamic loading of additional code modules. The malware can also modify its communication timing based on operator instructions and execute tasks through an opcode-driven command framework.
It incorporates execution-chain validation and anti-analysis checks to ensure it is running in an expected environment before activating. It is commonly deployed through multi-stage infection chains that abuse legitimate .NET application functionality and trusted software execution flows to blend into normal system activity and establish persistence.
APT GROUPfinancial
MetaEncryptor is a ransomware group first observed in mid-2023, targeting medium-to-large enterprises in legal, technology, logistics, manufacturing, and finance sectors primarily in the UK, Europe, and Southeast Asia, using AES-256/RSA-2048 encryption and double extortion.
Infra: 🔗 metacrptmytukkj7ajwj…🔗 metacrpttdfpbm4qoxzc…
RLUpdated: 2026-08-02
View profile →APT GROUPespionageadvanced
According to PwC Threat Intelligence, JFMBackdoor is a Windows DLL backdoor written in C++ that uses the CppServer library for communication. It is delivered via DLL side-loading and supports extensive capabilities including remote shell access, file system manipulation, network proxying, screenshot capture, registry operations, and self-removal. The malware relies on encrypted configuration files and supports dynamic behavior updates through these configurations. It interacts with system processes generically for actions like shell launching and service management, and uses GDI+ for screenshot capture.
APT GROUPespionageadvanced
Go-based Windows remote-access trojan with credential/browser-theft modules. Capabilities:
* screen capture/H.264 streaming
* keyboard/mouse control
* hidden desktop
* file upload/download/run
* clipboard access
* process listing
* Chrome profile cloning
* cookie extraction/injection
* Chrome App-Bound protection bypass logic
Embeds ChromElevator tool.
APT GROUPfinancial
Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site.
Infra: 🔗 payloadrz5yw227brtbv…💬 payloadynyvabjacbun4…📁 payload6eualw6kni6v2…
RLUpdated: 2026-08-02
View profile →APT GROUPespionageadvanced
According to Acronis, LOTUSLITE is a custom C++ backdoor delivered via DLL sideloading, where a simple loader executable is used to load a malicious DLL that acts as the primary implant. It establishes persistence through filesystem changes and user-run registry entries, and communicates with a hard-coded command-and-control server over HTTP(S) using the Windows HTTP APIs and a custom binary protocol. The malware supports espionage-focused capabilities including system and user enumeration, spawning an interactive command shell with redirected I/O, directory listing, and file read/write operations. Its code shows relatively low development maturity and limited evasive features, emphasizing rapid deployment and operational reliability over sophisticated stealth.
APT GROUPfinancialhigh
According to Elastic Security Labs, TCLBANKER is a Brazilian banking trojan comprised of a native code loader and .NET-based payloads that targets financial institutions in Brazil. Its core capabilities include monitoring browser addresses via UI Automation to trigger WPF full-screen overlays for credential harvesting and operator-driven social engineering, as well as self-propagating worm modules that hijack WhatsApp Web sessions and abuse Outlook through COM automation to send phishing messages. The malware employs robust anti-analysis techniques, such as environment-gated payload decryption that silently fails in sandboxes or incorrect environments, and a comprehensive watchdog subsystem that actively monitors for debuggers, analysis tools, and instrumentation frameworks throughout execution.
APT GROUP
According to BlueVoyant, Lorem Ipsum is a multi-stage malware family written in PowerShell for its loader components, with later stages transitioning to shellcode and DLL-based payloads. The loader chains multiple PowerShell stages that use AES decryption for embedded payloads, followed by gzip decompression and reflective memory loading, with newer versions employing substitution cipher decoding and XOR-encrypted shellcode stubs. The malware achieves persistence via Windows registry Run keys and evolved to use DLL sideloading, where a legitimate executable sideloads a malicious DLL that decodes embedded ciphertext to launch the core loader. Communication with C2 servers is conducted through JFIF image files where additional data is appended beyond image boundaries, allowing bidirectional exchange disguised as image traffic.
APT GROUPfinancialhigh
According to IBM X-Force, Slopoly is a likely LLM-generated PowerShell-based command-and-control framework that functions as a fully functional backdoor, collecting system information and sending it as JSON data to a C2 server via HTTP POST heartbeats while polling for commands to execute through the system shell. The malware includes extensive comments, logging, error handling, and accurately named variables, which are characteristic indicators of AI-generated software, though it lacks advanced techniques and cannot actually modify its own code despite being labeled as polymorphic. It establishes persistence by creating a scheduled task and maintains a rotating log file, allowing the threat actor to retain access to the infected server for an extended period. The malware's quality suggests it was generated by a less advanced large language model, and it was deployed by the Hive0163 threat actor during the later stages of a ransomware attack.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.lalia_ransomware
APT GROUP
Malware family tracked by Malpedia. ID: win.yahoyah
T1020T1547.004T1033
APT GROUP
According to Mitre, StrongPity is an information stealing malware used by PROMETHIUM.
T1078.003T1205.001T1587.002
APT GROUPfinancialhigh
Snake Ransomware is a Golang ransomware reportedly containing obfuscation not typically seen in Golang ransomware. This malware will remove shadow copies and kill processes related to SCADA/ICS devices, virtual machines, remote management tools, network management software, and others. After this, encryption of files on the device commences, while skipping Windows system folders and various system files. A random 5 character string is appended to encrypted files. According to Bleeping Computer, this ransomware takes an especially long time to encrypt files on a targeted machine. This ransomware is reported to target an entire network, rather than individual workstations.
T1025T1059.005T1685
APT GROUP
According to PCrisk, Truebot, also known as Silence.Downloader, is a malicious program that has botnet and loader/injector capabilities. This malware can add victims' devices to a botnet and cause chain system infections (i.e., download/install additional malicious programs/components).
There is significant variation in Truebot's infection chains and distribution. It is likely that the attackers using this malicious software will continue to make such changes.
T1059.007T1588.002T1553.002
APT GROUP
Malware family tracked by Malpedia. ID: win.redcurl
T1020T1537T1059.005
APT GROUPespionageadvanced
RSA describes PlugX as a RAT (Remote Access Trojan) malware family that is around since 2008 and is used as a backdoor to control the victim's machine fully. Once the device is infected, an attacker can remotely execute several kinds of commands on the affected system.
Notable features of this malware family are the ability to execute commands on the affected machine to retrieve:
machine information
capture the screen
send keyboard and mouse events
keylogging
reboot the system
manage processes (create, kill and enumerate)
manage services (create, start, stop, etc.); and
manage Windows registry entries, open a shell, etc.
The malware also logs its events in a text log file.
T1059.005T1046T1574.001
APT GROUP
Malware family tracked by Malpedia. ID: win.mirage
T1588.002T1020T1003.003
APT GROUP
According to ESET, Machete’s dropper is a RAR SFX executable. Three py2exe components are dropped: GoogleCrash.exe, Chrome.exe and GoogleUpdate.exe. A single configuration file, jer.dll, is dropped, and it contains base64‑encoded text that corresponds to AES‑encrypted strings.
GoogleCrash.exe is the main component of the malware. It schedules execution of the other two components and creates Windows Task Scheduler tasks to achieve persistence.
Regarding the geolocation of victims, Chrome.exe collects data about nearby Wi-Fi networks and sends it to the Mozilla Location Service API. In short, this application provides geolocation coordinates when it’s given other sources of data such as Bluetooth beacons, cell towers or Wi-Fi access points. Then the malware takes latitude and longitude coordinates to build a Google Maps URL.
The GoogleUpdate.exe component is responsible for communicating with the remote C&C server. The configuration to set the connection is read from the jer.dll file: domain name, username and password. The principal means of communication for Machete is via FTP, although HTTP communication was implemented as a fallback in 2019.
T1566.001T1218.007T1204.001
APT GROUP
Malware family tracked by Malpedia. ID: win.keyboy
T1020T1547.004T1033
APT GROUPfinancial
Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating double-extortion attacks against enterprises in healthcare, manufacturing, and technology; the group was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains.
Platforms: Windows and Linux
Infra: 🔗 3nvzqyo6l4wkrzumzu5a…
T1123T1566T1125
RLUpdated: 2026-08-02
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.gazer
T1025T1059.005T1685
APT GROUP
Malware family tracked by Malpedia. ID: win.deadwood
T1074.001T1570T1046
APT GROUPfinancialhigh
Wizard Spider is reportedly associated with Grim Spider and Lunar Spider.
The WIZARD SPIDER threat group is the Russia-based operator of the TrickBot banking malware. This group represents a growing criminal enterprise of which GRIM SPIDER appears to be a subset. The LUNAR SPIDER threat group is the Eastern European-based operator and developer of the commodity banking malware called BokBot (aka IcedID), which was first observed in April 2017. The BokBot malware provides LUNAR SPIDER affiliates with a variety of capabilities to enable credential theft and wire fraud, through the use of webinjects and a malware distribution function.
GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past.
🇷🇺 RUT1210T1685T1041
Updated: 2026-08-02
View profile →APT GROUPespionageadvanced
WageMole is a North Korean state-sponsored APT that employs social engineering and technology to secure remote job opportunities in Western countries, leveraging stolen personal data from the Contagious Interview campaign. Threat actors create fake identities, including passports and driver's licenses, and prepare study guides for interviews, often utilizing generative AI for well-structured responses. They target small to mid-sized businesses and utilize job platforms like Upwork and Indeed, while employing automation scripts for account creation. WageMole's activities include sharing code within their group and requesting payments through platforms like PayPal to conceal their identity.
🇰🇵 KPT1589T1059.006T1083
Updated: 2026-08-02
View profile →APT GROUP
According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.
The OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).
T1059.005T1218.010T1216.001
APT GROUP
Reporting regarding activity related to the SolarWinds supply chain injection has grown quickly since initial disclosure on 13 December 2020. A significant amount of press reporting has focused on the identification of the actor(s) involved, victim organizations, possible campaign timeline, and potential impact. The US Government and cyber community have also provided detailed information on how the campaign was likely conducted and some of the malware used. MITRE’s ATT&CK team — with the assistance of contributors — has been mapping techniques used by the actor group, referred to as UNC2452/Dark Halo by FireEye and Volexity respectively, as well as SUNBURST and TEARDROP malware.
🇷🇺 RUT1027.002T1098.002T1685.002
Updated: 2026-08-02
View profile →APT GROUPespionage
A 2014 Guardian article described Turla as: 'Dubbed the Turla hackers, initial intelligence had indicated western powers were key targets, but it was later determined embassies for Eastern Bloc nations were of more interest. Embassies in Belgium, Ukraine, China, Jordan, Greece, Kazakhstan, Armenia, Poland, and Germany were all attacked, though researchers from Kaspersky Lab and Symantec could not confirm which countries were the true targets. In one case from May 2012, the office of the prime minister of a former Soviet Union member country was infected, leading to 60 further computers being affected, Symantec researchers said. There were some other victims, including the ministry for health of a Western European country, the ministry for education of a Central American country, a state electricity provider in the Middle East and a medical organisation in the US, according to Symantec. It is believed the group was also responsible for a much - documented 2008 attack on the US Central Command. The attackers - who continue to operate - have ostensibly sought to carry out surveillance on targets and pilfer data, though their use of encryption across their networks has made it difficult to ascertain exactly what the hackers took.Kaspersky Lab, however, picked up a number of the attackers searches through their victims emails, which included terms such as Nato and EU energy dialogue Though attribution is difficult to substantiate, Russia has previously been suspected of carrying out the attacks and Symantecs Gavin O’ Gorman told the Guardian a number of the hackers appeared to be using Russian names and language in their notes for their malicious code. Cyrillic was also seen in use.'
🇷🇺 RUT1025T1059.005T1685
Updated: 2026-08-02
View profile →APT GROUPespionageadvanced
This threat actor targets organizations in the satellite communications, telecommunications, geospatial-imaging, and defense sectors in the United States and Southeast Asia for espionage purposes.
T1588.002T1112T1074.001
Updated: 2026-08-02
View profile →APT GROUPfinancialhigh
TA505, the name given by Proofpoint, has been in the cybercrime business for at least four years. This is the group behind the infamous Dridex banking trojan and Locky ransomware, delivered through malicious email campaigns via Necurs botnet. Other malware associated with TA505 include Philadelphia and GlobeImposter ransomware families.
🇷🇺 RUT1588.002T1027.002T1059.007
Updated: 2026-08-02
View profile →APT GROUPfinancialhigh
Storm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.
T1482T1486T1567.002
Updated: 2026-08-02
View profile →APT GROUP
Andariel is a threat actor that primarily targets South Korean corporations and institutions. They are believed to collaborate with or operate as a subsidiary organization of the Lazarus threat group. WHOIS utilizes spear phishing attacks, watering hole attacks, and supply chain attacks for initial access. They have been known to exploit vulnerabilities and use malware such as Infostealer and TigerRAT.
🇰🇵 KPT1057T1590.005T1027.003
Updated: 2026-08-02
View profile →APT GROUP
A group targeting UA state organizations using the GraphSteel and GrimPlant malware.
🇷🇺 RUT1027.002T1125T1046
Updated: 2026-08-02
View profile →APT GROUPespionageadvanced
Likely Chinese state-sponsored threat activity group RedDelta targeting organizations within Europe and Southeast Asia using a customized variant of the PlugX backdoor. Since at least 2019, RedDelta has been consistently active within Southeast Asia, particularly in Myanmar and Vietnam, but has also routinely adapted its targeting in response to global geopolitical events. This is historically evident through the group’s targeting of the Vatican and other Catholic organizations in the lead-up to 2021 talks between Chinese Communist Party (CCP) and Vatican officials, as well as throughout 2022 through the group’s shift towards increased targeting of European government and diplomatic entities following Russia’s invasion of Ukraine.
During the 3-month period from September through November 2022, RedDelta has regularly used an infection chain employing malicious shortcut (LNK) files, which trigger a dynamic-link library (DLL) search-order-hijacking execution chain to load consistently updated PlugX versions. Throughout this period, the group repeatedly employed decoy documents specific to government and migration policy within Europe. Of note, we identified a European government department focused on trade communicating with RedDelta command-and-control (C2) infrastructure in early August 2022. This activity commenced on the same day that a RedDelta PlugX sample using this C2 infrastructure and featuring an EU trade-themed decoy document surfaced on public malware repositories. We also identified additional probable victim entities within Myanmar and Vietnam regularly communicating with RedDelta C2 infrastructure.
RedDelta closely overlaps with public industry reporting under the aliases BRONZE PRESIDENT, Mustang Panda, TA416, Red Lich, and HoneyMyte.
T1059.005T1046T1574.001
Updated: 2026-08-02
View profile →APT GROUP
Malware family tracked by Malpedia. ID: elf.iot_reaper
T1123T1059.005T1033
APT GROUPespionageadvanced
This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes.
In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX.
Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.
🇨🇳 CNT1059.005T1046T1574.001
Updated: 2026-08-02
View profile →APT GROUPespionage
Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.
🇨🇳 CNT1588.002T1112T1074.001
Updated: 2026-08-02
View profile →APT GROUPfinancialhigh
INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime banking trojans on the market and, since 2014, those efforts are thought to have netted INDRIK SPIDER millions of dollars in criminal profits. Throughout its years of operation, Dridex has received multiple updates with new modules developed and new anti-analysis features added to the malware.
In August 2017, a new ransomware variant identified as BitPaymer was reported to have ransomed the U.K.’s National Health Service (NHS), with a high ransom demand of 53 BTC (approximately $200,000 USD). The targeting of an organization rather than individuals, and the high ransom demands, made BitPaymer stand out from other contemporary ransomware at the time. Though the encryption and ransom functionality of BitPaymer was not technically sophisticated, the malware contained multiple anti-analysis features that overlapped with Dridex. Later technical analysis of BitPaymer indicated that it had been developed by INDRIK SPIDER, suggesting the group had expanded its criminal operation to include ransomware as a monetization strategy.
🇷🇺 RUT1555.005T1059.007T1112
Updated: 2026-08-02
View profile →APT GROUPfinancialhigh
GOLD PRELUDE is a financially motivated cybercriminal threat group that operates the SocGholish (aka FAKEUPDATES) malware distribution network. GOLD PRELUDE operates a large global network of compromised websites, frequently running vulnerable content management systems (CMS), that redirect into a malicious traffic distribution system (TDS). The TDS, which researchers at Avast have named Parrot TDS, uses opaque criteria to select victims to serve a fake browser update page. These pages, which are customized to the specific visiting browser software, download the JavaScript-based SocGholish payload frequently embedded within a compressed archive.
T1566.002T1608.004T1204.001
Updated: 2026-08-02
View profile →