Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.noodrat
APT GROUP
Malware family tracked by Malpedia. ID: elf.noabot
APT GROUP
Golang-based RAT that offers execution of shell commands and download+run capability.
APT GROUPfinancialhigh
Ransomware used against Linux servers.
APT GROUP
Malware family tracked by Malpedia. ID: elf.mumblehard
APT GROUP
MrBlack, first identified in May 2014 by Russian security firm Dr. Web, is a botnet that targets Linux OS and is designed to conduct distributed denial-of-service (DDoS) attacks. In May 2015, Incapsula clients suffered a large-scale DDoS attack which the company attributed to network traffic generated by tens of thousands of small office/home office (SOHO) routers infected with MrBlack. This massive botnet spans over 109 countries, especially in Thailand and Brazil.
MrBlack scans for and infects routers that have not had their default login credentials changed and that allow remote access to HTTP and SSH via port 80 and port 22, respectively. One of the most impacted router brands is Ubiquiti, a U.S.-based firm that provides bulk network hub solutions for internet service providers to lease to their customers. Once a vulnerable router is compromised and MrBlack is injected into the system, a remote server is contacted and system information from the device is transmitted. This allows the host server to receive commands in order to perform different types of DDoS attacks, download and execute files, and terminate processes.
APT GROUP
Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.
APT GROUP
Malware family tracked by Malpedia. ID: elf.moose
APT GROUP
Malware family tracked by Malpedia. ID: elf.moobot
APT GROUP
Malware family tracked by Malpedia. ID: elf.momentum
APT GROUP
According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast Reverse Proxy (FRP) client that handles the actual tunneling.
APT GROUP
Malware family tracked by Malpedia. ID: elf.mikey
APT GROUP
A x64 ELF file infector with non-destructive payload.
APT GROUP
MESSAGETAP is a 64-bit ELF data miner initially loaded by an installation script. It is designed to monitor and save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft.
APT GROUP
Malware family tracked by Malpedia. ID: elf.melofee
APT GROUP
Malware family tracked by Malpedia. ID: elf.matryosh
APT GROUP
Masuta is a variant of Mirai that targets IoT devices, primarily routers, using dictionary attacks to target weak credentials. PureMasuta is a variant of Masuta that targets the EDB 38722 D-Link HNAP Bug.
APT GROUP
Malware family tracked by Malpedia. ID: elf.masol
APT GROUP
According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
APT GROUPfinancialhigh
ESXi encrypting ransomware written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: elf.lootwodniw
APT GROUP
Malware family tracked by Malpedia. ID: elf.log_collector
APT GROUP
Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
APT GROUP
According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates. It was observed in both DLL and executable versions, both of them 32-bit PEs. The main purpose of LittleDaemon is to communicate with the hijacking node to obtain the downloader that we call DaemonicLogistics. LittleDaemon does not establish persistence.
APT GROUP
BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has recently incorporated Monero cryptocurrency mining features. Interestingly, LiquorBot is written in Go (also known as Golang), which offers some programming advantages over traditional C-style code, such as memory safety, garbage collection, structural typing, and even CSP-style concurrency.
APT GROUP
Malware family tracked by Malpedia. ID: elf.linodas
APT GROUP
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
APT GROUP
Malware family tracked by Malpedia. ID: elf.lilyofthevalley
APT GROUP
Malware family tracked by Malpedia. ID: elf.lilock
APT GROUP
Malware family tracked by Malpedia. ID: elf.lightning
APT GROUP
Malware family tracked by Malpedia. ID: elf.leethozer
APT GROUP
Malware family tracked by Malpedia. ID: elf.lady
APT GROUP
According to the author if this open source project, this is a library for injecting a shared library into a Linux, Windows and MacOS process.
APT GROUP
ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.
APT GROUP
Malware family tracked by Malpedia. ID: elf.krasue_rat
APT GROUP
Malware family tracked by Malpedia. ID: elf.kobalos
APT GROUP
Malware family tracked by Malpedia. ID: elf.kitty_soks5
APT GROUP
Malware family tracked by Malpedia. ID: elf.kfos
APT GROUP
Malware family tracked by Malpedia. ID: elf.keyplug
APT GROUP
Malware family tracked by Malpedia. ID: elf.kerberods