Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: jar.adzok
APT GROUP
Part of Malware-as-service platform Used as a generic name for Java-based RAT Functionality - collect general system and user information - terminate process -log keystroke -take screenshot and access webcam - steal cache password from local or web forms - download and execute Malware - modify registry - download components - Denial of Service attacks - Acquire VPN certificates Initial infection vector 1. Email to JAR files attached 2. Malspam URL to downlaod the malware Persistence - Runkey - HKCU\Software\Microsoft\Windows\current version\run Hiding Uses attrib.exe Notes on Adwind The malware is not known to be proxy aware
APT GROUP
According to Google, this reconnaissance payload uses a profiling framework drawing canvas to identify the target’s exact iPhone model, a technique used by many other actors. The iPhone model is sent back to the C2 along with screen size, whether or not a touch screen is present, and a unique identifier per initial GET request (e.g., 1lwuzddaxoom5ylli37v90kj). The server replies with either an AES encrypted next stage or 0, indicating that no payload is available for this device. The payload makes another request to the exploit server with gcr=1 as a parameter to get the AES decryption key from the C2.
APT GROUP
Malware family tracked by Malpedia. ID: ios.triangledb
APT GROUP
Malware family tracked by Malpedia. ID: ios.postlo
APT GROUP
Malware family tracked by Malpedia. ID: ios.phenakite
APT GROUP
Malware family tracked by Malpedia. ID: ios.guiinject
APT GROUP
According to Google, this is a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023). The exploit kit, named "Coruna" by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.
APT GROUP
According to Google, this is a cookie stealer
Small downloader composed as a Fast-AutoLoad LISP (FAS) module for AutoCAD.
APT GROUPespionageadvanced
According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets being transmitted over the infected device and perform person-in-the-middle attacks (DNS and HTTPS hijacking based on predefined rules).
APT GROUP
Malware family tracked by Malpedia. ID: elf.zollard
APT GROUP
Malware family tracked by Malpedia. ID: elf.zhtrap
APT GROUP
ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities. It is offered as malware as a service (MaaS) and infrastructure overlaps with DDoS-for-hire services seized by the FBI in December 2022.
APT GROUP
Zergeca is a DDoS-botnet and backdoor written in Golang. It uses modified UPX for packing, with the magic number 0x30219101 instead of "UPX!". It is being distributed via weak telnet passwords and known vulnerabilities.
APT GROUP
Linux DDoS C&C Malware
APT GROUP
According to 360 netlab, this backdoor was derived from the leaked CIA Hive project. It propagates via a vulnerability in F5 and communicates using SSL with a forged Kaspersky certificate.
APT GROUP
Malware family tracked by Malpedia. ID: elf.xbash
APT GROUP
Malware family tracked by Malpedia. ID: elf.xaynnalc
APT GROUP
Malware family tracked by Malpedia. ID: elf.xanthe
APT GROUP
Malware family tracked by Malpedia. ID: elf.wolfsbane
APT GROUP
Malware family tracked by Malpedia. ID: elf.whiterabbit
APT GROUP
Malware family tracked by Malpedia. ID: elf.whirlpool
APT GROUP
Malware family tracked by Malpedia. ID: elf.wellmail
APT GROUP
According to Intezer, this is a spreader module used by WatchBog. It is a dynamically linked ELF executable, compiled with Cython. C&C adresses are fetched from Pastebin. C&C communication references unique identification keys per victim. It contains a BlueKeep scanner, reporting positively scanned hosts to the C&C server (RC4 encrypted within SSL/TLS). It contains 5 exploits targeting Jira, Exim, Solr, Jenkins and Nexus Repository Manager 3.
APT GROUP
Malware family tracked by Malpedia. ID: elf.walkloader
APT GROUP
Malware family tracked by Malpedia. ID: elf.vpnfilter
APT GROUP
VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong operational security through runtime encryption, environment awareness (cloud provider and container detection), and the use of user-mode and kernel-level rootkit techniques to evade detection. VoidLink is not a repurposed legacy tool but a purpose-built framework optimized for cloud infrastructure, indicating a shift in advanced threat development toward Linux-based cloud workloads. Although no confirmed large-scale infections have been observed, its maturity and design suggest potential use by sophisticated threat actors for long-term, stealthy access to cloud environments.
APT GROUP
According to Synacktiv, vGet is an in-memory stager for vShell, written in Rust.
Malware family tracked by Malpedia. ID: elf.vault8_hive
Enables remote execution of scripts on a host, communicates via Tox.
Malware family tracked by Malpedia. ID: elf.unidentified_005
APT GROUPespionageadvanced
Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi surveillance cameras.
According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA: CVE-2019-10149. This attack leverages a week-old vulnerability to gain remote command execution on the target machine, search the Internet for other machines to infect, and initiates a crypto miner.
APT GROUP
Malware family tracked by Malpedia. ID: elf.umbreon
APT GROUP
Malware family tracked by Malpedia. ID: elf.turla_rat
APT GROUP
Malware family tracked by Malpedia. ID: elf.tsh
APT GROUP
Malware family tracked by Malpedia. ID: elf.tscookie
APT GROUP
Malware family tracked by Malpedia. ID: elf.trump_bot
APT GROUP
According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.