Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.abcsync
APT GROUP
Malware family tracked by Malpedia. ID: win.abbath_banker
APT GROUP
Malware family tracked by Malpedia. ID: win.abantes
APT GROUP
MajorGeeks describes this malware as trying to locate credit card data by reading the memory of all processes except itself by first blacklisting its own PID using the GetCurrentProcessId API. Once that data is discovered, it sends this data back to a command and control server using a custom binary protocol instead of HTTP.
APT GROUPfinancialhigh
Uses Discord as C&C, has ransomware feature.
APT GROUPespionageadvanced
9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine. It has been spread over via zero day exploits (e.g. targeting Internet Explorer) as well as via email attachments. The infection chain starts by opening a .LNK (an OLE packager shell object) that executes a Powershell command.
APT GROUP
8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT. According to Proofpoint the attack was developed against a number of government agencies in East Asia overseeing government information technology, domestic affairs, foreign affairs, economic development, and political processes. The dropper was delivered through an RTF document exploiting CVE-2018-0798.
APT GROUPfinancial
The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. This group operates like other ransomware actors, engaging in double extortion. <BR> However, in mid-May and June 2023, the ransomware operation saw a spike in activity against organizations from various sectors, listing 131 organizations in just 3 months.<BR> The 8base data leak site was created and made available in March 2023, claiming honesty and simplicity in its discourse.<BR> VMware published a report on 8base, drawing some similarities with the ransomware group `RansomHouse`, pointing out resemblances such as the website used by 8base and the ransom notes presented in its attacks.<BR> Interestingly, the 8base Ransomware group does not have its own ransomware developed by the group. Instead, the actors took advantage of other leaked ransomware builders to customize the ransom note and present it to the victim organization as 8base's operation.<BR>Source : https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 basemmnnqwxevlymli5b…🔗 xb6q2aggycmlcrjtbjen…🔗 92.118.36.204.…+2 more
RLUpdated: 2026-08-05
View profile →APT GROUPfinancialhigh
The NJCCIC describes 7ev3n as a ransomware "that targets the Windows OS and spreads via spam emails containing malicious attachments, as well as file sharing networks. It installs multiple files in the LocalAppData folder, each of which controls different functions including disabling bootup recovery options, deleting the ransomware installation file, encrypting data, and gaining administrator privileges. This variant also adds registry keys that disables various Windows function keys such as F1, F3, F4, F10, Alt, Num Lock, Ctrl, Enter, Escape, Shift, and Tab. Files encrypted by 7ev3n are labeled with a .R5A extension. It also locks victims out of Windows recovery options making it challenging to repair the damage done by 7ev3n."
APT GROUPespionageadvanced
Downloader used in suspected APT attack against Vietnam.
4h rat
Technical ID: 4h_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.4h_rat
APT GROUP
Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victim’s sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.
APT GROUP
Malware family tracked by Malpedia. ID: osx.3cx_backdoor
APT GROUP
Information stealer, based on strings it seems to target crypto currencies, instant messengers, and browser data.
APT GROUP
Malware family tracked by Malpedia. ID: win.000stealer
APT GROUP
Malware family tracked by Malpedia. ID: vbs.whiteshadow
APT GROUP
Malware family tracked by Malpedia. ID: vbs.wasabiseed
APT GROUP
According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.
Malware family tracked by Malpedia. ID: vbs.unidentified_006
Malware family tracked by Malpedia. ID: vbs.unidentified_005
APT GROUP
Lab52 describes this as a light first-stage RAT used by MuddyWater and observed samples between at least November 2020 and January 2022.
Malware family tracked by Malpedia. ID: vbs.unidentified_003
APT GROUP
Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up via winrar.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.unidentified_001
APT GROUP
TAMECAT is PowerShell-based backdoor with modular components designed to facilitate data exfiltration and remote control
APT GROUP
Malware family tracked by Malpedia. ID: vbs.starwhale
APT GROUP
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on local powershell availability.
APT GROUP
A set of powershell scripts, using services like Google Docs and Dropbox as C2.
APT GROUP
Downloads NodeJS when deployed.
APT GROUP
MOUSEISLAND is a Microsoft Word macro downloader used as the first infection stage and is delivered inside a password-protected zip attached to a phishing email. Based on Fireeye intrusion data from responding to ICEDID related incidents, the secondary payload delivered by MOUSEISLAND has been PHOTOLOADER, which acts as an intermediary downloader to install ICEDID.
APT GROUP
According to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.lockscreen
APT GROUP
Malware family tracked by Malpedia. ID: vbs.litterdrifter
APT GROUP
Malware family tracked by Malpedia. ID: vbs.lcryx
APT GROUPfinancialhigh
Malware is delivered by emails, containing links to ZIP files or ZIP attachments. The ZIP contains a VBscript that, when executed, downloads additional files from AWS S3, Google Drive or other cloud hosting services. The downloaded files are encrypted .exe and .dll files.
The malware targets banking clients in Portugal.
APT GROUP
According to Patrick Wardle, this malware persists a python script as a cron job.
Steps:
1. Python installer first saves any existing cron jobs into a temporary file named '/tmp/dump'.
2. Appends its new job to this file.
3. Once the new cron job has been added 'python (~/.t/runner.pyc)' runs every minute.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.iloveyou
APT GROUP
Malware family tracked by Malpedia. ID: vbs.homesteel
APT GROUP
According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server. Once received, HATVIBE uses a simple XOR algorithm to decrypt each module, contact it between two <script> tags before adding it to the HTML body of the HTA file, leading to the automatic execution of the received module.
APT GROUPfinancialhigh
The HALFBAKED malware family consists of multiple components designed to establish and maintain a foothold in victim networks, with the ultimate goal of gaining access to sensitive financial information.
HALFBAKED listens for the following commands from the C2 server:
info: Sends victim machine information (OS, Processor, BIOS and running processes) using WMI
queries
processList: Send list of process running
screenshot: Takes screen shot of victim machine (using 58d2a83f777688.78384945.ps1)
runvbs: Executes a VB script
runexe: Executes EXE file
runps1: Executes PowerShell script
delete: Delete the specified file
update: Update the specified file