Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities. The trojan does not create any copies of itself. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
APT GROUP
Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.
APT GROUP
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.
APT GROUP
Kaden is a DDoS botnet that is heavily based on Bashlite/Gafgyt. Next to DDoS capabilities it contains wiper functionality, which currently can not be triggerred (yet).
APT GROUP
According to Lumen, J-Magic is a variant of cd00r and passively scans for five different predefined parameters before activating. If any of these parameters or “magic packets” are received, the agent sends back a secondary challenge. Once that challenge is complete, J-magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or deploy malicious software.
APT GROUP
Malware family tracked by Malpedia. ID: elf.jenx
APT GROUP
ccording to Fortinet, this is a Mirai-based DDoS botnet.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: elf.inc
APT GROUP
Malware family tracked by Malpedia. ID: elf.icnanker
APT GROUP
Malware family tracked by Malpedia. ID: elf.hubnr
APT GROUP
Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a custom MIPS32 ELF implant. HorseShell, the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities:
* Remote shell: Execution of arbitrary shell commands on the infected router
* File transfer: Upload and download files to and from the infected router.
* SOCKS tunneling: Relay communication between different clients.
APT GROUP
Malware family tracked by Malpedia. ID: elf.hipid
APT GROUP
HinataBot is a Go-based DDoS-focused botnet. It was observed in the first quarter of 2023 targeting HTTP and SSH endpoints leveraging old vulnerabilities and weak credentials. Amongst those infection vectors are exploitation of the miniigd SOAP service on Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215), and exposed Hadoop YARN servers.
APT GROUP
Malware family tracked by Malpedia. ID: elf.hideandseek
APT GROUP
HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.
APT GROUP
Lumen discovered this malware used in campaign targeting business-grade routers using a RAT they call HiatusRAT and a variant of tcpdump for traffic interception.
APT GROUP
Malware family tracked by Malpedia. ID: elf.headcrab
APT GROUP
Malware family tracked by Malpedia. ID: elf.hand_of_thief
APT GROUP
Malware family tracked by Malpedia. ID: elf.handymannypot
APT GROUP
Malware family tracked by Malpedia. ID: elf.hakai
APT GROUP
Malware family tracked by Malpedia. ID: elf.hajime
APT GROUP
Malware family tracked by Malpedia. ID: elf.haiduc
APT GROUP
Malware family tracked by Malpedia. ID: elf.hadooken
APT GROUP
According to Mandiant, GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX. It provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload. It's unclear if the threat actor's replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response.
APT GROUP
Malware family tracked by Malpedia. ID: elf.greedyantd
APT GROUP
GoTitan is a DDoS bot under development, which support ten different methods of launching distributed denial-of-service (DDoS) attacks: UDP, UDP HEX, TCP, TLS, RAW, HTTP GET, HTTP POST, HTTP HEAD, and HTTP PUT.
APT GROUP
Malware family tracked by Malpedia. ID: elf.gosh
APT GROUP
GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).
APT GROUP
Malware family tracked by Malpedia. ID: elf.goreshell
APT GROUP
Malware family tracked by Malpedia. ID: elf.gomir
APT GROUPespionageadvanced
According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in Japan. This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
APT GROUP
Malware family tracked by Malpedia. ID: elf.godlua
APT GROUP
Malware family tracked by Malpedia. ID: elf.gobrat
APT GROUP
ARM32 SOCKS proxy, written in Go, used in the Glupteba campaign.
APT GROUP
Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT devices. It uses GitHub and Pastebin as dead drop C2 locations.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ghostpenguin
APT GROUP
Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. It is a worm which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk.
APT GROUP
This family utilizes custom modules allowing for remote access, credential harvesting (e.g. by modifying sshd) and proxy usage.
It comes with a rootkit as well.
APT GROUP
Malware used to run a DDoS botnet.
APT GROUP
Malware family tracked by Malpedia. ID: elf.floodor