Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUP
An IRC bot written in (obfuscated) Python code. Distributed in attack campaign FreakOut, written by author Freak/Fl0urite and development potentially dating back as far as 2015.
APT GROUP
Malware family tracked by Malpedia. ID: py.masepie
APT GROUP
Malware family tracked by Malpedia. ID: py.lunagrabber
APT GROUPespionageadvanced
This RAT written in Python is an open-source fork of the Ares RAT. This malware integrates additional modules, like recording, lockscreen, and locate options. It was used in a customized form version by El Machete APT in an ongoing champaign since 2020. The original code can be found at: https://github.com/TheGeekHT/Loki.Rat/
APT GROUP
Malware family tracked by Malpedia. ID: py.lofy
APT GROUP
The author described LaZagne as an open source project used to retrieve lots of passwords stored on a local computer. It has been developed for the purpose of finding these passwords for the most commonly-used software. It is written in Python and provided as compiled standalone binaries for Linux, Mac, and Windows.
APT GROUP
According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.
APT GROUP
Malware family tracked by Malpedia. ID: py.keyplexer
Malware family tracked by Malpedia. ID: py.invisibleferret
APT GROUP
According to Kaspersky Labs, Guard is a malware developed by threat actor WildPressure. It is written in Python and packaged using PyInstaller, both for Windows and macOS operating systems. Its intrinsics resemble parts of how win.milum operates.
APT GROUPfinancialhigh
Ransomware written in Python.
APT GROUP
Discord Stealer written in Python with Javascript-based inject files.
APT GROUP
Malware family tracked by Malpedia. ID: py.dropboxc2c
APT GROUP
Creal is an open-source grabber/credential stealer that was originally made by a GitHub user named Ayhuuu, who even advertised a "premium" version on his now-deleted Telegram channel @Crealstealer. To the day of release, it was already not FUD, but its open-source nature made it attractive for threat actors to modify the base malware and even obfuscate it for less detection ratios. The base project came with a compiler, and the general source code the compiler used was PyInstaller for compilation into native formats like exe. For C2, Discord webhooks were utilized, which in later versions got protected with a service called https://stealer.to to make deletion not possible. It Compromised following Data on Execution: * Discord Information * Browser Data * Crypto Related Data * Steam * Riot Games * Telegram * System Information * Tokens/Secrets
APT GROUP
According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.
APT GROUP
Malware family tracked by Malpedia. ID: py.brickerbot
APT GROUP
According to K7 Security Labs, Braodo Stealer is written in Python and collects all cookies and saved credentials from the browsers and all services and process information of that particular system as a zip file, which is then exfiltrated to a Telegram Channel.
APT GROUP
Stealer written in Python 3, typically distributed bundled via PyInstaller.
APT GROUP
Malware family tracked by Malpedia. ID: py.archivist
According to Prodaft, this is a Python-based backdoor used by the Savage Ladybug (FIN7) group is developed to provide remote access, execute commands, and steal data. It is obfuscated to avoid detection.
APT GROUP
According to Laceworks, this is a SMTP cracker, which is primarily intended to scan for and parse Laravel application secrets from exposed .env files. Note: Laravel is an open source PHP framework and the Laravel .env file is often targeted for its various configuration data including AWS, SendGrid and Twilio. AndroxGh0st has multiple features to enable SMTP abuse including scanning, exploitation of exposed creds and APIs, and even deployment of webshells. For AWS specifically, the malware scans for and parses AWS keys but also has the ability to generate keys for brute force attacks. However, the brute force capability is likely a novelty and is a statistically unlikely attack vector.
APT GROUPfinancialhigh
According to Fortinet, Amnesia RAT is written in Python and designed for broad, multi-category data theft combined with real-time surveillance and system control. Its capabilities include: Browser credentials and session data, Telegram Desktop session hijacking, Seed phrase discovery and clipboard monitoring, Discord and Steam data theft, Cryptocurrency wallets and financial assets, System and hardware intelligence, Screen, audio, and activity surveillance, Process and system control, Persistence, multiple exfiltration channels.
APT GROUP
Malware family tracked by Malpedia. ID: py.akira_stealer
APT GROUP
According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.wmimplant
Malware family tracked by Malpedia. ID: ps1.wannaren_loader
APT GROUP
Malware family tracked by Malpedia. ID: ps1.wannamine
APT GROUP
Malware family tracked by Malpedia. ID: ps1.vipersoftx
Malware family tracked by Malpedia. ID: ps1.unidentified_005
Malware family tracked by Malpedia. ID: ps1.unidentified_004
This malware is a RAT written in PowerShell. It has the following capabilities: Downloading and Uploading files, loading and execution of a PowerShell script, execution of a specific command. It was observed by Malwarebytes LABS Threat Intelligence Team in a newly discovered campaign: this campaigns tries to lure Germans with a promise of updates on the current threat situation in Ukraine according to Malwarebyte LABS.
A Powershell-based RAT capable of pulling further payloads, delivered through Russia-themed phishing mails.
APT GROUPespionageadvanced
Recon and exfiltration script, dropped from a LNK file. Attributed to APT-C-12.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.thundershell
APT GROUP
Malware family tracked by Malpedia. ID: ps1.tater
APT GROUP
Malware family tracked by Malpedia. ID: ps1.swrort
APT GROUP
Malware family tracked by Malpedia. ID: ps1.subtle_paws
APT GROUP
Malware family tracked by Malpedia. ID: ps1.steelhook
APT GROUP
Malware family tracked by Malpedia. ID: ps1.snugy
APT GROUP
sLoad is a PowerShell downloader that most frequently delivers Ramnit banker and includes noteworthy reconnaissance features. The malware gathers information about the infected system including a list of running processes, the presence of Outlook, and the presence of Citrix-related files. sLoad can also take screenshots and check the DNS cache for specific domains (e.g., targeted banks), as well as load external binaries.