Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.torii
APT GROUP
Malware family tracked by Malpedia. ID: elf.tntbotinger
APT GROUP
Malware family tracked by Malpedia. ID: elf.themoon
APT GROUPespionageadvanced
A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit. It uses three methods for hiding its network activity, by hooking and hijacking 1) fopen/fopen64, 2) eBPF, 3) a set of libpcap functions.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sword2033
APT GROUP
Malware family tracked by Malpedia. ID: elf.suterusu
APT GROUP
Sustes Malware doesn’t infect victims by itself (it’s not a worm) but it is spread over exploitation and brute-force activities with special focus on IoT and Linux servers. The initial infection stage comes from a custom wget directly on the victim machine followed by a simple /bin/bash mr.sh. The script is a simple bash script which drops and executes additional software.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sunless
APT GROUP
According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key material from environment variables.
APT GROUP
Malware family tracked by Malpedia. ID: elf.stantinko
APT GROUP
Malware family tracked by Malpedia. ID: elf.sshdoor
APT GROUP
Malware family tracked by Malpedia. ID: elf.sshdinjector
APT GROUP
Malware family tracked by Malpedia. ID: elf.spry_socks
APT GROUP
Malware family tracked by Malpedia. ID: elf.speculoos
APT GROUP
Malware family tracked by Malpedia. ID: elf.specter
APT GROUP
Malware family tracked by Malpedia. ID: elf.speakup
APT GROUP
According to Mandiant, this is a utility that is written in C and targets Linux. It can be used to extract the uncompressed linux kernel image (vmlinux) into a file and encrypt it using AES without the need for any command line tools.
APT GROUP
Malware family tracked by Malpedia. ID: elf.spamtorte
APT GROUPespionageadvanced
This is an implant used by APT31 on home routers to utilize them as ORBs.
APT GROUP
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
APT GROUP
According to PwC, SnappyTCP is a simple reverse shell for Linux/Unix systems, with variants for plaintext and TLS communication. SeaTurtle has used SnappyTCP at least between 2021 and 2023.
APT GROUP
According to FireEye, SLAPSTICK is a Solaris PAM backdoor that grants a user access to the system with a secret, hard-coded password.
APT GROUP
According to its author, this is a stealthy Linux Kernel Rootkit for modern kernels (6x).
APT GROUP
Malware family tracked by Malpedia. ID: elf.sindoor
APT GROUP
Malware family tracked by Malpedia. ID: elf.silex
APT GROUP
According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.
APT GROUP
Malware family tracked by Malpedia. ID: elf.shishiga
APT GROUP
Malware family tracked by Malpedia. ID: elf.shellbind
APT GROUP
According to Fortinet, this is a Mirai fork propagating through multiple vulnerabilities. ShadowV2 had previously been observed targeting AWS EC2 instances in campaigns disclosed in September 2025.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sedexp
APT GROUP
Malware family tracked by Malpedia. ID: elf.seconddate
APT GROUPespionageadvanced
According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service. The malware is designed to listen to commands received from the Threat Actor’s Command-and-Control through TCP packets. When executed, the malware uses libpcap sniffer to monitor traffic for a magic packet on TCP port 25 (SMTP) and TCP port 587. It checks the network packet captured for a hard-coded string. When the right sequence of packet is captured, it establishes a TCP reverse shell to the C2 server for further exploitation. This allows the TA to execute arbitrary commands on the compromised system.
The malware is based on an open-source backdoor program named "cd00r".
APT GROUP
Malware family tracked by Malpedia. ID: elf.sbidiot
APT GROUP
Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab. It uses exploit to exhibit worm-like behaviour to spread over ports 37215 and 52869 (CVE-2014-8361).
APT GROUP
According to Mandiant, SALTWATER is a module for the Barracuda SMTP daemon (bsmtpd) that has backdoor functionality. SALTWATER can upload or download arbitrary files, execute commands, and has proxy and tunneling capabilities. The backdoor is implemented using hooks on the send, recv, close syscalls via the 3rd party kubo/funchook hooking library, and amounts to five components, most of which are referred to as "Channels" within the binary. In addition to providing backdoor and proxying capabilities, these components exhibit classic backdoor functionality.
APT GROUP
According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid
APT GROUP
Malware family tracked by Malpedia. ID: elf.rude_devil
APT GROUP
Malware family tracked by Malpedia. ID: elf.rshell
APT GROUPespionageadvanced
RotaJakiro is a stealthy Linux backdoor which remained undetected between 2018 and 2021.
The malware uses rotating encryption to encrypt the resource information within the sample, and C2 communication, using a combination of AES, XOR, ROTATE encryption and ZLIB compression.
APT GROUP
P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows attackers to run malicious code with root privileges and take over older Webmin versions. Based on the Netlabs360 analysis, the botnet serves mainly 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs and four DDoS attack methods: ICMP Flood, HTTP Flood, TCP Flood, and UDP Flood.