Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: osx.pirrit
APT GROUP
Backdoor as a fork of OpenSSH_6.0 with no logging, and “-P” and “-z” hidden command arguments. “PuffySSH_5.8p1” string.
APT GROUP
Malware family tracked by Malpedia. ID: osx.pearl_stealer
APT GROUP
Malware family tracked by Malpedia. ID: osx.osaminer
APT GROUP
SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.
APT GROUP
Malware family tracked by Malpedia. ID: osx.olyx
APT GROUP
Malware family tracked by Malpedia. ID: osx.odyssey_stealer
APT GROUP
Malware family tracked by Malpedia. ID: osx.netwire
APT GROUP
Malware family tracked by Malpedia. ID: osx.mughthesec
APT GROUP
Malware family tracked by Malpedia. ID: osx.manuscrypt
APT GROUP
Malware family tracked by Malpedia. ID: osx.mami
APT GROUP
Malware family tracked by Malpedia. ID: osx.macvx
APT GROUP
Malware family tracked by Malpedia. ID: osx.macspy
APT GROUP
Malware family tracked by Malpedia. ID: osx.macinstaller
APT GROUP
Malware family tracked by Malpedia. ID: osx.macdownloader
APT GROUP
Malware family tracked by Malpedia. ID: ios.lightspy
APT GROUP
Malware family tracked by Malpedia. ID: osx.leverage
APT GROUP
Malware family tracked by Malpedia. ID: osx.laoshu
APT GROUP
Malware family tracked by Malpedia. ID: osx.lador
APT GROUP
Malware family tracked by Malpedia. ID: osx.komplex
APT GROUP
Malware family tracked by Malpedia. ID: osx.kitmos
APT GROUP
According to SentinelOne, KeySteal targets files with the .keychain and keychain-db file extensions in the following locations.
APT GROUP
Malware family tracked by Malpedia. ID: osx.keydnap
APT GROUP
Malware family tracked by Malpedia. ID: osx.kandykorn
APT GROUP
Malware family tracked by Malpedia. ID: osx.jokerspy
APT GROUP
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports Quic.
Variants in C# and GO.
APT GROUPespionageadvanced
The threat was a multi-stage malware displaying a decoy that appeared to the victim as a Chinese language article on the long-running dispute over the Diaoyu Islands; an array of erotic pictures; or images of Tibetan organisations. It consisted of two stages: Revir was the dropper/downloader and Imuler was the backdoor capable of the following operations:
- capture screenshots
- exfiltrate files to a remote computer
- send various information about the infected computer
- extract ZIP archive
- download files from a remote computer and/or the Internet
- run executable files
APT GROUP
Malware family tracked by Malpedia. ID: osx.hloader
APT GROUP
According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising itself as a document - in this case, an Adobe Acrobat file.
APT GROUP
According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading app created for Mac users.
Research shows that there are two variants of this malware, one detected as Trojan.MacOS.GMERA.A and the other as Trojan.MacOS.GMERA.B. Cyber criminals proliferate GMERA to steal various information and upload it to a website under their control. To avoid damage caused by this malware, remove GMERA immediately.
APT GROUP
Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group. Fullhouse is written in C/C++ and includes the capabilities of a tunneler and backdoor commands support such as shell command execution, file transfer, file managment, and process injection. C2 communications occur via HTTP and require configuration through the command line or a configuration file.
APT GROUP
Malware family tracked by Malpedia. ID: osx.fruitfly
APT GROUP
Malware family tracked by Malpedia. ID: osx.frostyferret
APT GROUP
According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.
APT GROUP
Malware family tracked by Malpedia. ID: osx.friendlyferret
APT GROUP
Malware family tracked by Malpedia. ID: osx.flexibleferret
APT GROUP
Malware family tracked by Malpedia. ID: osx.flashback
APT GROUP
Malware family tracked by Malpedia. ID: apk.finfisher
APT GROUP
Malware family tracked by Malpedia. ID: osx.failytale
APT GROUPfinancialhigh
According to PcRisk, EvilQuest (also known as ThiefQuest) is like many other malicious programs of this type - it encrypts files and creates a ransom message. In most cases, this type of malware modifies the names of encrypted files by appending certain extensions, however, this ransomware leaves them unchanged.
It drops the "READ_ME_NOW.txt" in each folder that contains encrypted data and displays another ransom message in a pop-up window. Additionally, this malware is capable of detecting if certain files are stored on the computer, operates as a keylogger, and receives commands from a Command & Control server.