Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.rhombus
APT GROUP
Malware family tracked by Malpedia. ID: elf.rex
APT GROUP
Malware family tracked by Malpedia. ID: elf.reptile
APT GROUP
A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers. The Trojan’s configuration data is stored in a file encrypted with XOR algorithm.
Some versions have there configuration stored within the .data section using RC4 to encrypt the details.
Configuration options include C2 IP and Port, as well as defence evasion details for changing the process name.
APT GROUPfinancialhigh
Ransomware that targets Linux VMware ESXi servers. Encryption procedure uses the NTRUEncrypt public-key encryption algorithm.
APT GROUPespionageadvanced
RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR. Believed to be developed by Chinese nation-state actors, this malware shows similarities to other malware associated with the Winnti umbrella threat group.
RedXOR uses various techniques such as open-source LKM rootkits, Python pty shell, and network data encoding with XOR. It also employs persistence methods and communication with a Command and Control server over HTTP.
The malware can execute various commands including system information collection, updates, shell commands, and network tunneling.
APT GROUP
RedTail is a cryptomining malware, which is based on the open-source XMRIG mining software. It is being spread via known vulnerabilities such as:
- CVE-2024-3400
- CVE-2023-46805
- CVE-2024-21887
- CVE-2023-1389
- CVE-2022-22954
- CVE-2018-20062
rbs srv
Technical ID: rbs_srv
APT GROUP
Malware family tracked by Malpedia. ID: elf.rbs_srv
rat hodin
Technical ID: rat_hodin
APT GROUP
Malware family tracked by Malpedia. ID: elf.rat_hodin
APT GROUP
Malware family tracked by Malpedia. ID: elf.raspberrypibotnet
APT GROUP
A Mirai derivate bruteforcing SSH servers.
APT GROUP
According to IBM Security X-Force, this is a new but functionally very similar version of RansomExx, fully rewritten in Rust and internally referred to as RansomExx2.
APT GROUP
Malware family tracked by Malpedia. ID: elf.rakos
APT GROUP
Malware family tracked by Malpedia. ID: elf.r2r2
APT GROUP
Mandiant observed this backdoor being observed by UNC3524. It is based on the open-source Dropbear SSH source code.
APT GROUP
The malware infects QNAP NAS devices, is persisting via various mechanisms and resists cleaning by preventing firmware updates and interfering with QNAP MalwareRemover. The malware steals passwords and hashes
APT GROUP
Malware family tracked by Malpedia. ID: elf.pwnlnx
APT GROUP
According to Elastic, PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with command-and-control servers.
The rootkit component, referenced by the malware authors as “PUMA", employs an internal Linux function tracer (ftrace) to hook 18 different syscalls and several kernel functions, enabling it to manipulate core system behaviors. Unique methods are used to interact with PUMA, including using the rmdir() syscall for privilege escalation and specialized commands for extracting configuration and runtime information.
Key functionalities of the kernel module include privilege escalation, hiding files and directories, concealing itself from system tools, anti-debugging measures, and establishing communication with command-and-control (C2) servers.
There is also an accompanying userland SO rootkit internally referred to as Kitsune.
APT GROUP
Malware family tracked by Malpedia. ID: elf.pumabot
APT GROUP
Unit 42 describes this as a malware used by Rocke Group that deploys an XMRig miner.
APT GROUP
Black Lotus Labs identified malware for the Windows Subsystem for Linux (WSL). Mostly written in Python but compiled as Linux ELF files.
APT GROUP
According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family, but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB) to facilitate offensive cyber operations.
APT GROUP
According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access.
APT GROUP
According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.
APT GROUP
According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.
APT GROUP
According to Mandiant, this is a SparkGateway plugin that loads LITTLELAMB.WOOLTEA through JNI.
APT GROUP
A botnet with P2P and centralized C&C capabilities.
APT GROUP
Malware family tracked by Malpedia. ID: elf.pingpull
APT GROUP
Malware family tracked by Malpedia. ID: elf.pigmy_goat
PG MEM
Technical ID: PG_MEM
APT GROUP
Malware family tracked by Malpedia. ID: elf.pg_mem
APT GROUP
Malware family tracked by Malpedia. ID: elf.persirai
APT GROUP
Malware family tracked by Malpedia. ID: elf.perlbot
APT GROUP
Malware family tracked by Malpedia. ID: elf.perfctl
APT GROUP
Malware family tracked by Malpedia. ID: elf.penquin_turla
APT GROUP
P2P botnet derived from the Mirai source code.
APT GROUP
P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown. Written in Rust, it is compatible with Windows and Linux, including a MIPS variant for Linux based routers and IoT devices. It is capable of brute forcing SSH logins and exploiting Redis servers in order to propagate itself both to random IPs on the internet and to hosts it can find references to in files present on the infected system.
APT GROUP
According to Yarix digital security, this is a malware that allows to sniff on HTTPS traffic, implemented as Apache module.
APT GROUP
Mirai variant by actor "Anarchy" that used CVE-2017-17215 in July 2018 to compromise 18,000+ devices.
APT GROUP
According to stormshield, Orbit is a two-stage malware that appeared in July 2022, discovered by Intezer lab. Acting as a stealer and backdoor on 64-bit Linux systems, it consists of an executable acting as a dropper and a dynamic library.
APT GROUPespionageadvanced
According to Black Lotus Labs, Nosedive is a custom variation of the Mirai implant that is supported on all major SOHO and IoT architectures (e.g. MIPS, ARM, SuperH, PowerPC, etc.). Nosedive implants are typically deployed from Tier 2 payload servers in the Raptor Train infrastructure through a unique URL encoding scheme and domain injection method. Nosedive droppers use this method to request payloads for specific C2s by encoding the requested C2 domain and joining it with a unique "key" that identifies the bot and the target architecture of the compromised device (e.g. MIPS, ARM, etc.), which is then injected into the Nosedive implant payload that is deployed to the Tier 1 node. Once deployed, Nosedive runs in-memory only and allows the operators to execute commands, upload and download files, and run DDoS attacks on compromised devices.
The malware and its associated droppers are memory-resident only and deleted from disk. This, in addition to anti-forensics techniques employed on these devices including the obfuscation of running process names, compromising devices through a multi-stage infection chain, and killing remote management processes, makes detection and forensics much more difficult.