Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: vbs.grinju
APT GROUP
Malware family tracked by Malpedia. ID: vbs.glowspark
APT GROUP
Malware family tracked by Malpedia. ID: vbs.ggldr
APT GROUP
According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880). They assess with medium confidence a link to Gamaredon.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.forbiks
APT GROUP
CageyChameleon Malware is a VBS-based backdoor which has the capability to enumerate the list of running processes and check for the presence of several antivirus products. CageyChameleon will collect user host information, system current process information, etc. The collected information is sent back to the C2 server, and continue to initiate requests to perform subsequent operations.
APT GROUP
Malware family tracked by Malpedia. ID: vbs.basicstar
APT GROUP
A backdoor brought into version 5.6.0 and 5.6.1 of compression library/tool xz/liblzma, which was intended to enable access via (Open)SSH on affected servers.
APT GROUP
According to its author, PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.
APT GROUP
Malware family tracked by Malpedia. ID: sh.kv
APT GROUP
Malware family tracked by Malpedia. ID: py.wirefire
APT GROUP
A basic info stealer w/ some capability to inject code into legit applications.
APT GROUP
Malware family tracked by Malpedia. ID: py.vilerat
APT GROUP
Venus Stealer is a python based Infostealer observed early 2023.
APT GROUPfinancialhigh
Ransomware written in Python and delivered as compiled executable created using PyInstaller.
APT GROUP
Malware family tracked by Malpedia. ID: py.upstyle
unidentified 002
Technical ID: unidentified_002
APT GROUP
Malware family tracked by Malpedia. ID: py.unidentified_002
APT GROUPfinancial
Stormous is an Arabic-speaking, pro-Russian ransomware and hacktivist group active since at least 2022, known for politically motivated attacks across 15+ countries, collaborating with GhostSec on the GhostLocker 2.0 RaaS platform and inheriting GhostSec's RaaS operations in mid-2024.
On 1st July 2026 the group has annonced the end of their operations & ervices
Infra: 🔗 3slz4povugieoi3tw7sb…🔗 h3reihqb2y7woqdary2g…🔗 h3reihqb2y7woqdary2g…+3 more
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: py.stitch
APT GROUP
Malware family tracked by Malpedia. ID: py.stealler
APT GROUP
Malware family tracked by Malpedia. ID: py.spacecow
APT GROUP
According to Proofpoint, this is a backdoor written in Python, used in attacks against French entities in the construction, real estate, and government industries.
APT GROUP
Malware family tracked by Malpedia. ID: py.saphyra
APT GROUP
Malware family tracked by Malpedia. ID: py.rn_stealer
APT GROUP
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
APT GROUP
Malware family tracked by Malpedia. ID: py.redtiger
APT GROUP
Malware family tracked by Malpedia. ID: py.quietboard
APT GROUP
According to Securonix, this malware exhibits remote access trojan (RAT) behavior, allowing for control of and persistence on the affected host. As with other RATs, PY#RATION possesses a whole host of features and capabilities, including data exfiltration and keylogging. What makes this malware particularly unique is its utilization of websockets for both command and control (C2) communication and exfiltration as well as how it evades detection from antivirus and network security measures.
APT GROUP
According to its author, Pyramid is a post exploitation framework written in Python, capable of executing offensive tooling from a signed binary (e.g. python.exe) by importing their dependencies in memory. It was created to demonstrate a bypass strategy against EDRs based on some blind-spots assumptions.
APT GROUP
Python-version of GolangGhost RAT
APT GROUP
Malware family tracked by Malpedia. ID: py.pyback
APT GROUP
Malware family tracked by Malpedia. ID: py.pyark
APT GROUP
Malware family tracked by Malpedia. ID: py.pyaesloader
APT GROUPfinancialhigh
PXA Stealer is an information-stealing malware written in Python, identified by Cisco Talos in an active campaign attributed to a Vietnamese-speaking threat actor (2024). The stealer targets sensitive data such as credentials for online accounts, VPN and FTP clients, financial information, browser cookies, and gaming-related data. Notably, PXA Stealer is capable of decrypting browser master passwords to exfiltrate stored credentials. The campaign leverages heavily obfuscated batch scripts for delivery and execution. The actor behind this operation is linked to the Telegram channel “Mua Bán Scan MINI,” known to host credential trade and cybercrime activity. While there are connections to the CoralRaider adversary, attribution to this group remains unconfirmed. In q2 2025 PXA stealer was observed to target Italy.
APT GROUP
Malware family tracked by Malpedia. ID: py.powerat
APT GROUP
Cisco Talos has discovered a Python-based RAT they call Poet RAT. It is dropped from a Word document and delivered including a Python interpreter and required libraries. The name originates from references to Shakespeare. Exfiltration happens through FTP.
APT GROUP
According to CERT-UA, this malware establishes a connection to the management server using web sockets and/or MQTT, data is transmitted in JSON format. Based on basic information about the computer (MAC address, BIOS serial number, disk and processor ID), it generates a unique device identifier using the SHA-256 algorithm (the first 16 bytes are used). It ensures the execution of the program code received from the server. Persistence is achieved by creating an entry in the Run branch of the operating system registry.
APT GROUP
Malware family tracked by Malpedia. ID: py.pirat
APT GROUP
Malware family tracked by Malpedia. ID: py.networm