Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.alpc_lpe
APT GROUPespionageadvanced
According to Threatray, AlmondRAT is a .NET Remote Access Trojan deployed by the Bitter APT group. It is capable of collecting system information, modifying and exfiltrating data and allows for remote command execution and shares similar functionality with BDarkRAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.alma_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.alma_communicator
APT GROUP
Malware family tracked by Malpedia. ID: win.almanahe
APT GROUP
Allcome is classified as a clipper malware. Clippers are threats designed to access information saved in the clipboard (the temporary buffer space where copied data is stored) and substitute it with another. This attack is targeted at users who are active in the cryptocurrency sector mainly.
APT GROUP
According to HarfangLabs, AllaSenha is specifically aimed at stealing credentials that are required to access Brazilian bank accounts, leverages Azure cloud as command and control (C2) infrastructure, and is another custom variant of AllaKore, an infamous open-source RAT which is frequently leveraged to target users in Latin America.
APT GROUP
Malware family tracked by Malpedia. ID: win.allaple
APT GROUP
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development. It implements the RFB protocol which uses frame buffers and thus is able to send back only the changes of screen frames to the controller, speeding up the transport and visualization control.
APT GROUP
Malware family tracked by Malpedia. ID: win.alina_pos
APT GROUP
Malware family tracked by Malpedia. ID: win.alice_atm
APT GROUP
Malware family tracked by Malpedia. ID: win.alfonso_stealer
APT GROUP
According to Trend Micro Encyclopia:
ALDIBOT first appeared in late August 2012 in relevant forums. Variants can steal passwords from the browser Mozilla Firefox, instant messenger client Pidgin, and the download manager jDownloader. ALDIBOT variants send the gathered information to their command-and-control (C&C) servers.
This malware family can also launch Distributed Denial of Service (DDoS) attacks using different protocols such as HTTP, TCP, UDP, and SYN. It can also perform flood attacks via Slowloris and Layer 7.
This bot can also be set up as a SOCKS proxy to abuse the infected machine as a proxy for any protocols.
This malware family can download and execute arbitrary files, and update itself. Variants can steal information, gathering the infected machine’s hardware identification (HWID), host name, local IP address, and OS version.
This backdoor executes commands from a remote malicious user, effectively compromising the affected system.
APT GROUP
Malware family tracked by Malpedia. ID: win.albaniiutas
APT GROUPfinancial
The Akira ransomware group is said to have emerged in March 2023, and there's much speculation about its ties to the former CONTI ransomware group.<br> <br> It's worth noting that with the end of CONTI's operation, several affiliates migrated to independent campaigns such as Royal, BlackBasta, and others.<br> <br> According to some reports, Akira affiliates also work with other ransomware operations, such as Snatch and BlackByte, as an open directory of tools used by an Akira operator was identified, which also had connections to the Snatch ransomware.<br> <br> The first version of the Akira ransomware was written in C++ and appended files with the '.akira' extension, creating a ransom note named 'akira_readme.txt,' partially based on the Conti V2 source code. However, on June 29, 2023, a decryptor for this version was reportedly released by Avast.<br> <br> Subsequently, a version was released that fixed the decryption flaw on July 2, 2023. Since then, the new version is said to be written in Rust, this time called 'megazord.exe,' and it changes the extension to '.powerranges' for encrypted files.<br> <br> Most of Akira's initial access vectors use brute-force attempts on Cisco VPN devices (which use single-factor authentication only).<br> Additionally, exploitation of CVEs: CVE-2019-6693 and CVE-2022-40684 for initial access has been identified.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 akiral2iz6a7qgd3ayp3…💬 akiralkzxzq2dsrzsrvb…🔗 akiral2iz6a7qgd3ayp3…
T1482T1486T1567.002
RLUpdated: N/A
View profile →APT GROUP
AkdoorTea is a simple TCP RAT.
In August 2025, it was contained in a trojanized Nvidia CUDA toolkit package, delivered probably via the ClickFix technique. The package also contained an obfuscated BeaverTail payload, which suggests its attribution to the Contagious Interview campaigns.
AkdoorTea uses Base64 encryption combined with a single-byte XOR key for network traffic obfuscation.
The RAT supports five commands, one of which is to report its internal version, which is "01.01".
Its name was inspired by the similarity to a TCP RAT, referred to as "Akdoor", that was used in attacks leveraging ActiveX exploits against South Korean targets in April 2018.
APT GROUP
According to Unit 42, this malware steals information from browsers and uses a covert channel through the AirWatch API.
APT GROUP
Malware family tracked by Malpedia. ID: win.ahtapot
APT GROUP
The agfSpy backdoor retrieves configuration and commands from its C&C server. These commands allow the backdoor to execute shell commands and send the execution results back to the server. It also enumerates directories and can list, upload, download, and execute files, among other functions. The capabilities of agfSpy are very similar to dneSpy, except each backdoor uses a different C&C server and various formats in message exchanges.
APT GROUPespionageadvanced
A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
APT GROUP
Agent Racoon is a .NET-based backdoor malware that leverages DNS for covert C2 communication, employing randomized subdomains and Punycode encoding to evade detection. It features encrypted communication using a unique key per sample, supports remote command execution, and facilitates file transfers. Despite lacking an inherent persistence mechanism, it relies on external methods like scheduled tasks for execution. The malware, active since at least 2020, has targeted organizations in the U.S., Middle East, and Africa, including non-profits and government sectors. It disguises itself as legitimate binaries such as Google Update and MS OneDrive Updater, using obfuscation techniques like Base64 encoding and timestamp modifications to avoid detection.
APT GROUP
Malware family tracked by Malpedia. ID: win.agent_btz
APT GROUPfinancialhigh
Ransomware written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.afrodita
APT GROUPfinancialhigh
Ransomware written using .NET.
APT GROUP
Malware family tracked by Malpedia. ID: win.adylkuzz
APT GROUP
AdvisorsBot is a downloader named after early command and control domains that all contained the word "advisors". The malware is written in C and employs a number of anti-analysis features such as junk code, stack strings and Windows API function hashing.
APT GROUP
Malware family tracked by Malpedia. ID: win.adkoob
APT GROUPfinancialhigh
Some Ransomware distributed by TA547 in Australia
APT GROUPespionageadvanced
AdaptixC2 is a open-source post-exploitation and adversarial emulation framework that lets penetration testers control compromised hosts and execute system actions. While being created for red-teaming it is also used by threat actors for attacks.
APT GROUPfinancialhigh
Adam Locker (detected as RANSOM_ADAMLOCK.A) is a ransomware that encrypts targeted files on a victim’s system but offers them a free decryption key which can be accessed through Adf.ly, a URL shortening and advertising service.
APT GROUP
Malware family tracked by Malpedia. ID: win.adamantium_thief
APT GROUP
Malware family tracked by Malpedia. ID: win.action_rat
APT GROUP
First introduced in March 2024, ACR Stealer is an information stealer sold as a Malware-as-a-Service (MaaS) on Russian-speaking cybercrime forums by a threat actor named "SheldIO". Researchers posit that this malware is an evolved version of the GrMsk Stealer, which likely aligns with the private stealer that SheldIO has been selling since July 2023. The malware, written in C++, is compatible with Windows 7 through 10, and the seller manages all command and control (C2) infrastructure. ACR Stealer can harvest system information, stored credentials, web browser cookies, cryptocurrency wallets, and configuration files for various programs. Additionally, it employs the dead drop resolver (DDR) technique to obfuscate the actual C2 infrastructure.
APT GROUP
Malware family tracked by Malpedia. ID: win.acronym
APT GROUP
AcridRain is a password stealer written in C/C++. This malware can steal credentials, cookies, credit cards from multiple browsers. It can also dump Telegram and Steam sessions, rob Filezilla recent connections, and more.
APT GROUP
Unit42 found AcidBox in February 2019 and describes it as a malware family used by an unknown threat actor in 2017 against Russian entities, as stated by Dr.Web. It reused and improved an exploit for VirtualBox previously used by Turla. The malware itself is a modular toolkit, featuring both usermode and kernelmode components and anti-analysis techniques such as stack-based string obfuscation or dynamic XOR-encoded API usage.
APT GROUP
ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload. To execute, a password is necessary (e.g. 9839D7F1A0) and the individual modules are addressed with parameters (-m, -w, -h).
APT GROUP
A Linux backdoor that was apparently ported to Windows. This entry represents the Linux version. This version appears to have been written first and the Windows version was ported later, without full functionality. The Linux version offers persistence as well as some process manipulation techniques, though both versions apparently offer the ability to access the command line and execute programs as well as self-update.
APT GROUP
Malware family tracked by Malpedia. ID: win.absentloader