Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUPespionageadvanced
According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality, including the ability to deliver follow-on modules including an information stealer, keylogger, screen capture collector and more. It also establishes persistence to continue operations following system reboots. The design of this malware framework appears to attempt to minimize artifacts left on infected systems by facilitating the delivery and execution of modules in-memory, without requiring them to be written to disk. Due to similarities in the design and implementation with the malware family AHK Bot, we are referring to this PowerShell-based malware as “PS1Bot.”
Backdoor written in php
APT GROUP
Malware family tracked by Malpedia. ID: php.pas
APT GROUPespionageadvanced
In combination with Parrot TDS the usage of a classical web shell was observed by DECODED Avast.io.
APT GROUP
Malware family tracked by Malpedia. ID: php.p0wnyshell
APT GROUP
According to Xlab, Glutton is a modular PHP fileless attack framework, capable of data exfiltration and running backdoors.
APT GROUP
Malware family tracked by Malpedia. ID: php.ensikology
APT GROUP
PHP/JavaScript malware for WordPress that injects multi-stage scripts, turning compromised sites into distributed TDS/C2 nodes. Delivers signed payloads, maintains persistence via helper files, and redirects traffic to monetized scam networks.
APT GROUP
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.
APT GROUP
C99shell is a PHP backdoor that provides a lot of functionality, for example: * run shell commands; * download/upload files from and to the server (FTP functionality); * full access to all files on the hard disk; * self-delete functionality.
APT GROUP
A webshell for multiple web languages (asp/aspx, jsp/jspx, php), openly distributed through Github.
APT GROUP
ASPXSpy is an open-source web shell written in C# that allows a threat actor to accomplish various post-exploitation tasks, including file access and command execution.
APT GROUP
Antak is a webshell written in ASP.Net which utilizes PowerShell.
APT GROUP
Ani-Shell is a simple PHP shell with some unique features like Mass Mailer, a simple Web-Server Fuzzer, Dosser, Back Connect, Bind Shell, Back Connect, Auto Rooter etc.
APT GROUP
A malware that was observed being embedded alongside legitimate applications (such as iTerm2) offered for download on suspicious websites pushed in search engines. It uses a Python script to perform reconnaissance on the compromised system an pulls additional payload(s).
APT GROUP
Malware family tracked by Malpedia. ID: osx.yort
APT GROUP
Malware family tracked by Malpedia. ID: osx.xslcmd
APT GROUP
Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well. Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent. Not to be confused with apk.xloader or ios.xloader.
APT GROUP
Malware family tracked by Malpedia. ID: osx.xcsset
APT GROUP
Malware family tracked by Malpedia. ID: elf.wirenet
APT GROUP
The iOS malware that is installed over USB by osx.wirelurker
APT GROUP
Malware family tracked by Malpedia. ID: osx.windtail
APT GROUP
According to Mandiant, WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS. The backdoor supports downloading and executing arbitrary payloads retrieved from its command-and-control (C2 or C&C) server, which is provided via the command-line parameters. To communicate with the adversary infrastructure, WAVESHAPER leverages the curl library for either HTTP or HTTPS, depending on the command-line argument provided. WAVESHAPER also runs as a daemon by forking itself into a child process that runs in the background detached from the parent session and collects system information, which is sent to the C&C server in a HTTP POST request.
APT GROUP
Malware family tracked by Malpedia. ID: osx.watchcat
APT GROUP
Malware family tracked by Malpedia. ID: osx.vigram
APT GROUP
Malware family tracked by Malpedia. ID: osx.update_agent
Malware family tracked by Malpedia. ID: osx.unidentified_001
APT GROUP
General purpose backdoor
APT GROUP
Malware family tracked by Malpedia. ID: osx.sugarloader
APT GROUP
Malware family tracked by Malpedia. ID: elf.spectral_blur
APT GROUP
SimpleTea for Linux is an HTTP(S) RAT. It was discovered in Q1 2023 as an instance of the Lazarus group's Operation DreamJob campaign for Linux. It was a payload downloaded in an execution chain which started with an HSBC-themed job offer lure. It shared the same C&C server as payloads from the 3CX incident around the same time. It’s an object-oriented project, which does not run on Linux distributions without a graphical user interface, and decrypts its configuration from /home/%user%/.config/apdl.cf using 0x7E as the XOR key. It uses AES-GCM for encryption and decryption of its network traffic. It supports basic commands that include operations on the victim’s filesystem, manipulation with its configuration, file exfiltration (via ZIP archives), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 16-bit integers, starting with the value 0x27C3. SimpleTea for Linux seems like an updated version of BadCall for Linux, rewritten from C to C++, as there are similarities in class names and function names between the two.
According to Red Canary, Silver Sparrow is an activity cluster that includes a binary compiled to run on Apple’s new M1 chips but has been distributed without payload so far.
APT GROUP
According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote fake search engines. It is typically disguised as a Adobe Flash Player installer and various software cracking tools. In most cases, users encounter this virus when visiting dubious Torrent websites that are full of intrusive advertisements and deceptive downloads.
APT GROUPfinancialhigh
Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an app bundle within a DMG disk image, posing as a document. The primary purpose of the dropper is to install a Tor client as well as a malicious CA certificate and proxy pac URL, in order to redirect traffic to targeted sites through their Tor node, effectively carrying out a MITM attack against selected web traffic. It also installs a custom hosts file to prevent access to Apple and VirusTotal. The macOS version shares its MO, many TTPs and infrastructure with the Windows counterpart.
APT GROUP
Cryptocurrency miner that was distributed masquerading as a Counter-Strike: Global Offensive hack.
APT GROUP
According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.
APT GROUPespionageadvanced
Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems. It is known for providing attackers with complete remote control over the infected system, allowing the execution of commands, keystroke capturing, access to the camera and microphone, and the ability to steal credentials stored in browsers and other password managers. This malware typically spreads through malicious or modified applications, which, when downloaded and installed by unsuspecting users, trigger its payload. Proton RAT is notorious for its sophistication and evasion capabilities, including techniques to bypass detection by installed security solutions.
macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which when executed spawns osascript executing an AppleScript with the actual infostealer payload. The AppleScript payload will steal files by packing them in a ZIP archive and uploading them to a hardcoded C2 via HTTP.
APT GROUP
Part of Mythic C2, written in Golang.
APT GROUP
Malware family tracked by Malpedia. ID: osx.poolrat