Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUPfinancial
AvosLocker is the ransomware payload of the Avos RaaS group, active from July 2021 to approximately May 2023, targeting education, manufacturing, and healthcare sectors on Windows, Linux, and VMware ESXi environments, with the US accounting for ~72% of victims.
Infra: 🔗 avosqxh72b5ia23dl5fg💬 avosjon4pfh3y7ew3jdw
RSLUpdated: N/A
View profile →
APT GROUP
Information stealer which uses AutoIT for wrapping.
APT GROUP
Malware family tracked by Malpedia. ID: win.aveo
Cyble Research discovered this .Net written malware dubbed "AvD Crypto Stealer". The name of this malware is misleading, because this is a kind of clipper malware. Assumption of Cyble is, that this malware could target other threat actors as scenario.
APT GROUPfinancialhigh
Bleeping Computer notes about discovery of AVCrypt, a malware that tries to uninstall existing security software before it encrypts a computer. Furthermore, as it removes numerous services, including Windows Update, and provides no contact information, this ransomware may be a wiper.
APT GROUP
Malware family tracked by Malpedia. ID: win.avast_disabler
APT GROUPfinancial
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.
Infra: 🔗 avaddongun7rngel.oni💬 avaddonbotrxmuyl.oni
RSLUpdated: N/A
View profile →
First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabilities. The malware targets data from multiple browsers, cryptocurrency wallets, local systems, and act as a loader. During execution, the malware runs several commands through WMIC to collect basic host information, snaps a desktop image, and exfiltrates data to the C2 server within a single base64-encoded JSON file.
APT GROUPfinancialhigh
Ransomware
APT GROUP
Malware family tracked by Malpedia. ID: win.auriga
APT GROUPespionageadvanced
In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription tiers on underground forums. The information stealer targets credentials from over 110 browsers, 70 applications, and 250+ browser extensions, including cryptocurrency wallets and 2FA tools, while using AES-256 encryption for C2 communications. Notable features include seamless Chromium cookie harvesting without process termination, server-side App-Bound data decryption, and a built-in payload loader with custom morphing for detection evasion.
APT GROUPfinancialhigh
According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system.
Malware family tracked by Malpedia. ID: win.august_stealer
APT GROUPespionageadvanced
Adversary group targeting diplomatic missions and governmental organisations.
APT GROUPfinancial
AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access and demanding ransoms up to $1 million, attributed to the Chinese state-linked threat actor BRONZE STARLIGHT.
Infra: 🔗 mhdehvkomeabau7gsetn🔗 l5cjga2ksw6rxumu5l4x🔗 npmh5ahrgakbniuntyc7+1 more
RSLUpdated: N/A
View profile →
APT GROUP
The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either CSCWCNG.dll or MFSXFS.dll. Both libraries are legitimate Windows drivers used to interact with the components of different ATM models.
APT GROUP
Malware family tracked by Malpedia. ID: win.atmosphere
APT GROUP
Malware family tracked by Malpedia. ID: win.atmitch
APT GROUP
Malware family tracked by Malpedia. ID: win.atmii
APT GROUP
Malware family tracked by Malpedia. ID: win.atlas_agent
APT GROUP
Malware family tracked by Malpedia. ID: win.atlantida
APT GROUP
Malware family tracked by Malpedia. ID: win.ati_agent
APT GROUP
Malware family tracked by Malpedia. ID: win.athenago
Updated: 2017-02-13
View profile →
APT GROUP
Part of the Mythic framework, payload in C# (.NET 6), support HTTP, Websockets, Slack, SMB for C2.
APT GROUP
Malware family tracked by Malpedia. ID: win.atharvan
APT GROUP
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victim’s computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques.
APT GROUPfinancial
AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-extortion, smash-and-grab approach: distributed directly via phishing Microsoft Word documents containing embedded OLE objects. Once executed, it kills security and backup processes, deletes shadow copies, and encrypts files using modified HC-128 and Curve25519 algorithms, appending extensions like .Astra or .babyk. A “smash-and-grab” style attack, it’s less methodical than more sophisticated campaigns—deploying ransomware immediately upon user action rather than conducting prolonged network reconnaissance. In mid-2022, the operator ceased ransomware operations, releasing decryptors and announcing a pivot to cryptojacking.
RSLUpdated: 2026-08-05
View profile →
APT GROUPfinancialhigh
Astasia is a banking trojan that spreads through phishing emails that contain an executable attachment. Once the attachment is executed, Astasia downloads and installs a trojan that runs in the background. The trojan can steal personal information, such as passwords and credit card numbers, from victims.
APT GROUPfinancialhigh
First spotted in the wild in 2017, Astaroth is a highly prevalent, information-stealing Latin American banking trojan. It is written in Delphi and has some innovative execution and attack techniques. Originally, this malware variant targeted Brazilian users, but Astaroth now targets users both in North America and Europe.
APT GROUP
According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution, with RSA-encrypted C2 communication disguised as application telemetry.
APT GROUP
Malware family tracked by Malpedia. ID: win.asruex
APT GROUP
Malware family tracked by Malpedia. ID: win.asprox
APT GROUP
Malware family tracked by Malpedia. ID: win.aspc
Updated: 2017-05-19
View profile →
APT GROUP
According to Unit 42, Ashen / AshTag is a modular .NET toolset currently in active development, with extensive features, including file exfiltration, content download and in-memory execution of additional modules.
APT GROUP
Malware family tracked by Malpedia. ID: win.ascentloader
Updated: 2018-07-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.asbit
Malware family tracked by Malpedia. ID: win.artra
APT GROUP
Malware family tracked by Malpedia. ID: win.artfulpie
ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via different available commands, acting as a remote access trojan (RAT). Its code is based on ASPC, another Visual Basic Script malware, which at the same time seems to be based on SafeLoader.
APT GROUP
It is available as a service, purchasable by anyone to use in their own campaigns. It’s features are generally fairly typical of a RAT, with its most notable aspect being the hVNC module which basically gives an attacker full remote access with minimal need for technical knowledge to use it.