Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,713 entities
APT GROUP
From November 2017 to October 2018, we attributed 14 campaigns to the GC threat actors that used a specific MaaS provider (hereinafter “the Provider”) offered by a known individual (hereinafter “the Provider Operator”).
Updated: 2026-08-03
View profile →APT GROUP
Unit 42 threat researchers have recently observed a threat group distributing new, custom developed malware. We have labelled this threat group the Gamaredon Group and our research shows that the Gamaredon Group has been active since at least 2013. In the past, the Gamaredon Group has relied heavily on off-the-shelf tools. Our new research shows the Gamaredon Group have made a shift to custom-developed malware. We believe this shift indicates the Gamaredon Group have improved their technical capabilities.
🇷🇺 RUT1025T1059.005T1497.001
Updated: 2026-08-03
View profile →APT GROUPespionage
Activity: defense and aerospace sectors, also interested in targeting entities in the oil/gas industry.
🇮🇷 IRT1555.003T1105T1056.001
Updated: 2026-08-03
View profile →APT GROUPespionage
Charming Kitten (aka Parastoo, aka Newscaster) is an group with a suspected nexus to Iran that targets organizations involved in government, defense technology, military, and diplomacy sectors.
🇮🇷 IRT1059.005T1046T1685
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
BRONZE HIGHLAND has been observed using spearphishing as an initial infection vector to deploy the MgBot remote access trojan against targets in Hong Kong. Third party reporting suggests the threat group also targets India, Malaysia and Taiwan and leverages Cobalt Strike and KsRemote Android Rat. CTU researchers assess with moderate confidence that BRONZE HIGHLAND operates on behalf of China and has a remit covering espionage against domestic human rights and pro-democracy advocates and nations neighbouring China
🇨🇳 CNT1003.002T1584.004T1204.001
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than half of the organizations we have observed being targeted or breached by APT5 operate in these sectors. Several times, APT5 has targeted organizations and personnel based in Southeast Asia. APT5 has been active since at least 2007. It appears to be a large threat group that consists of several subgroups, often with distinct tactics and infrastructure. APT5 has targeted or breached organizations across multiple industries, but its focus appears to be on telecommunications and technology companies, especially information about satellite communications.
APT5 targeted the network of an electronics firm that sells products for both industrial and military applications. The group subsequently stole communications related to the firm’s business relationship with a national military, including inventories and memoranda about specific products they provided.
In one case in late 2014, APT5 breached the network of an international telecommunications company. The group used malware with keylogging capabilities to monitor the computer of an executive who manages the company’s relationships with other telecommunications companies
🇨🇳 CNT1685T1583.005T1021.001
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
FireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government that conducts long term, resource-intensive operations to collect strategic intelligence. APT35 typically targets U.S. and the Middle Eastern military, diplomatic and government personnel, organizations in the media, energy and defense industrial base (DIB), and engineering, business services and telecommunications sectors.
🇮🇷 IRT1059.005T1046T1685
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
A 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been working for the Russian Federation since at least 2008 to collect intelligence in support of foreign and security policy decision-making. The Dukes show unusual confidence in their ability to continue successfully compromising their targets, as well as in their ability to operate with impunity. The Dukes primarily target Western governments and related organizations, such as government ministries and agencies, political think tanks, and governmental subcontractors. Their targets have also included the governments of members of the Commonwealth of Independent States;Asian, African, and Middle Eastern governments;organizations associated with Chechen extremism;and Russian speakers engaged in the illicit trade of controlled substances and drugs. The Dukes are known to employ a vast arsenal of malware toolsets, which we identify as MiniDuke, CosmicDuke, OnionDuke, CozyDuke, CloudDuke, SeaDuke, HammerDuke, PinchDuke, and GeminiDuke. In recent years, the Dukes have engaged in apparently biannual large - scale spear - phishing campaigns against hundreds or even thousands of recipients associated with governmental institutions and affiliated organizations. These campaigns utilize a smash - and - grab approach involving a fast but noisy breakin followed by the rapid collection and exfiltration of as much data as possible.If the compromised target is discovered to be of value, the Dukes will quickly switch the toolset used and move to using stealthier tactics focused on persistent compromise and long - term intelligence gathering. This threat actor targets government ministries and agencies in the West, Central Asia, East Africa, and the Middle East; Chechen extremist groups; Russian organized crime; and think tanks. It is suspected to be behind the 2015 compromise of unclassified networks at the White House, Department of State, Pentagon, and the Joint Chiefs of Staff. The threat actor includes all of the Dukes tool sets, including MiniDuke, CosmicDuke, OnionDuke, CozyDuke, SeaDuke, CloudDuke (aka MiniDionis), and HammerDuke (aka Hammertoss). '
🇷🇺 RUT1027.002T1098.002T1685.002
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
This threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
🇨🇳 CNT1588.002T1020T1003.003
Updated: 2026-08-03
View profile →APT GROUP
Malware family tracked by Malpedia. ID: osx.uroburos
T1025T1059.005T1685
APT GROUP
SideWinder involved a fake VPN app for Android devices published on Google Play Store along with a custom tool that filters victims for better targeting.
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: apk.konni
APT GROUPespionageadvanced
This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
🇰🇵 KPT1566T1218.010T1587
APT GROUP
According to PcRisk AppleJeus is the name of backdoor malware that was distributed by the Lazarus group. They spread this malicious software through a fake app disguised as a cryptocurrency trading application called Celas Trade Pro.
T1657T1566
APT GROUPespionageadvanced
OilRig is an Iranian threat group operating primarily in the Middle East by targeting organizations in this region that are in a variety of different industries; however, this group has occasionally targeted organizations outside of the Middle East as well. It also appears OilRig carries out supply chain attacks, where the threat group leverages the trust relationship between organizations to attack their primary targets.
OilRig is an active and organized threat group, which is evident based on their systematic targeting of specific organizations that appear to be carefully chosen for strategic purposes. Attacks attributed to this group primarily rely on social engineering to exploit the human rather than software vulnerabilities; however, on occasion this group has used recently patched vulnerabilities in the delivery phase of their attacks. The lack of software vulnerability exploitation does not necessarily suggest a lack of sophistication, as OilRig has shown maturity in other aspects of their operations. Such maturities involve:
-Organized evasion testing used the during development of their tools.
-Use of custom DNS Tunneling protocols for command and control (C2) and data exfiltration.
-Custom web-shells and backdoors used to persistently access servers.
OilRig relies on stolen account credentials for lateral movement. After OilRig gains access to a system, they use credential dumping tools, such as Mimikatz, to steal credentials to accounts logged into the compromised system. The group uses these credentials to access and to move laterally to other systems on the network. After obtaining credentials from a system, operators in this group prefer to use tools other than their backdoors to access the compromised systems, such as remote desktop and putty. OilRig also uses phishing sites to harvest credentials to individuals at targeted organizations to gain access to internet accessible resources, such as Outlook Web Access.
Since at least 2014, an Iranian threat group tracked by FireEye as APT34 has conducted reconnaissance aligned with the strategic interests of Iran. The group conducts operations primarily in the Middle East, targeting financial, government, energy, chemical, telecommunications and other industries. Repeated targeting of Middle Eastern financial, energy and government organizations leads FireEye to assess that those sectors are a primary concern of APT34. The use of infrastructure tied to Iranian operations, timing and alignment with the national interests of Iran also lead FireEye to assess that APT34 acts on behalf of the Iranian government.
🇮🇷 IRT1025T1059.005T1497.001
APT GROUP
Malware family tracked by Malpedia. ID: win.tsunami
APT GROUPespionageadvanced
This threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial of service, and data destruction purposes. Some believe that the threat actor is linked to the 2015 compromise of the Ukrainian electrical grid and a distributed denial of service prior to the Russian invasion of Georgia. Believed to be responsible for the 2008 DDoS attacks in Georgia and the 2015 Ukraine power grid outage
🇷🇺 RUT1059.005T1041T1078.002
Updated: 2026-08-03
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.eternidade_stealer
APT GROUP
UNC6748 targets users in Saudi Arabia through a fake Snapchat website, employing a backdoor known as GHOSTKNIFE for data exfiltration. Their exploitation process initially featured basic obfuscation, which evolved to include anti-debugging measures. The actor primarily leveraged CVE-2025-31277 and CVE-2026-20700 for RCE exploits, but exhibited inconsistencies in exploit support for different iOS versions. Additionally, UNC6748's delivery mechanisms incorporated session storage checks to manage infection attempts.
🇷🇺 RU
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Storm-2561 is a cybercriminal threat actor known for a credential theft campaign that employs SEO poisoning to distribute fake VPN clients. The campaign redirects users to malicious ZIP files containing digitally signed trojans that harvest VPN credentials, leveraging user trust in search engine results. The malicious components are signed by “Taiyuan Lihua Near Information Technology Co., Ltd.” and were hosted on GitHub repositories that have since been taken down. This operation exhibits characteristics consistent with financially motivated cybercrime.
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
SHADOW-EARTH-053 is a China-aligned threat group exploiting unpatched Microsoft Exchange Server vulnerabilities, specifically CVE-2021-26855, to conduct cyberespionage against government and defense-linked targets across Asia and Europe. The group primarily deploys ShadowPad malware, utilizing techniques such as credential dumping, tunneling tools, and lateral movement via WMIC. They have also been observed installing web shells for persistence and leveraging a custom ExchangeExport tool to extract high-value mailbox contents. Additionally, low-confidence associations with Noodle RAT and CVE-2025-55182 have been noted in their operations.
🇨🇳 CN
Updated: 2026-08-03
View profile →APT GROUP
NyxarGroup is a threat actor involved in a coordinated data brokerage ecosystem across Latin America, primarily targeting government infrastructure. They have published high volumes of data, including 110,000 records from Chile's Servicio Civil platform and 250GB from the Ley del Lobby platform, which tracks lobbying activities. The data exfiltrated includes limited fields but provides a directory of Chilean government employees, enhancing the visibility of the public sector workforce. NyxarGroup's activities indicate a focus on exploiting government transparency and training systems for data leaks.
Updated: 2026-08-03
View profile →Mr Rot13
Technical ID: Mr_Rot13
APT GROUP
Mr_Rot13 is a stable hacking group identified through a PHP backdoor and a Downloader domain linked to a C2 infrastructure active since 2020. They utilize the Rot13 algorithm for obfuscation and have demonstrated a low detection rate across security products, indicating advanced operational security. Their activities include exploiting CVE-2026-41940 to deliver malicious payloads and maintaining covert communication via Telegram. The group has shown a particular focus on WordPress as a target, with ongoing operations that suggest a sophisticated threat actor rather than opportunistic attackers.
Updated: 2026-08-03
View profile →APT GROUP
The threat actor lulzintel has claimed responsibility for multiple data breaches, including those of vegehome.pl, Almaex, Smaregi, and Kin Teck Tong, exposing sensitive information of over 400,000 individuals combined. The breaches involved the release of customer and patient records, including personal details and medical histories.Sample data has been provided to demonstrate the validity of the claims.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. They employ the AI-generated PowerShell backdoor Slopoly for persistent command-and-control access, which checks in with attacker infrastructure every 50 seconds and transmits telemetry every 30 seconds. The group leverages AzCopy for bulk data exfiltration to Azure blob storage before executing ransomware, employing a five-stage attack chain. Their operations are characterized by the use of initial access brokers and a variety of custom backdoors for long-term access and data exfiltration.
Updated: 2026-08-03
View profile →APT GROUP
FlowerStorm is a phishing-as-a-service platform that mimics legitimate services to bypass multi-factor authentication structure. The majority of its targets are located in North America and Europe, with a significant focus on organizations in the United States. FlowerStorm's operational mistakes have led to vulnerabilities that can be exploited for disruption and analysis.
Updated: 2026-08-03
View profile →APT GROUP
Keenadu is an Android backdoor that is distributed primarily through pre-infected device firmware, as well as through malicious apps. Its capabilities include full remote control of a victim's device, ad fraud, and browser search hijacking.
APT GROUP
According to Cisco Talos, TernDoor is a Windows backdoor implant delivered as shellcode via a side-loaded DLL-based loader, with the blog not specifying its implementation language. It maintains persistence through scheduled tasks or registry run keys, retrieves an embedded configuration for command-and-control, and provides capabilities such as remote command execution, file manipulation, system information collection, and self-uninstallation. TernDoor also deploys an encrypted kernel-mode driver that can hide malicious components and generically suspend, resume, or terminate chosen processes, supporting evasion and process control. The malware checks that it is injected into a legitimate system process before running, further helping it blend into normal activity.
APT GROUPfinancialhigh
According to Cybereason, "The Gentlemen" ransomware is a cross-platform ransomware family with lockers for Windows, Linux, and ESXi, with the analyzed Windows locker implemented as a 64-bit Golang executable. It is operated as a Ransomware-as-a-Service, supports configurable encryption levels using XChaCha20 and Curve25519, and implements dual-extortion by both encrypting and exfiltrating data. The malware emphasizes persistence and automation (self-restart, run-on-boot, registry and autostart usage), broad system interaction via tools like task schedulers, WMI, and remote PowerShell, and extensive discovery of local, network, and clustered storage to maximize impact. It also includes security evasion and anti-forensics behavior such as disabling security tools, deleting logs and traces, manipulating permissions, and terminating database, backup, remote-access, and virtualization-related services before encryption.
APT GROUP
According to Cisco Talos, Dohdoor is a 64-bit Windows DLL backdoor/loader, written in C/C++, that is delivered via DLL sideloading through legitimate Windows executables launched by batch and PowerShell scripts. It uses DNS-over-HTTPS (DoH) to Cloudflare’s DNS service to resolve its C2 domains, then establishes an HTTPS tunnel to Cloudflare’s edge as a front for the hidden C2, making all traffic look like normal HTTPS to reputable cloud infrastructure. Dohdoor downloads, decrypts (custom XOR-SUB, position-dependent cipher with SIMD), and reflectively executes additional payloads (likely Cobalt Strike) via process hollowing into hardcoded Windows binaries such as OpenWith.exe and ImagingDevices.exe. To stay stealthy, it relies on hash-based API resolution, encrypted C2, EDR bypass via ntdll syscall unhooking, and infrastructure/hostnames that mimic Windows updates and security tools.
APT GROUP
According to Trend Micro, BoryptGrab is a C/C++ Windows stealer that exfiltrates browser credentials (with Chrome App Bound Encryption bypass), desktop and extension-based cryptocurrency wallets, Telegram data, Discord tokens, system information, screenshots, and selected files from common directories. It is delivered via SEO‑poisoned, fake GitHub repositories and multi‑stage loaders (DLL sideloading, VBS/.NET launchers, and a Golang downloader "HeaconLoad") that fetch it and related payloads from attacker servers (notably over HTTP on port 5466). BoryptGrab supports multiple "builds" (tracked via build names like CryptoByte, Shrek, Sonic, etc.), implements anti‑VM/anti‑analysis checks, and can download extra components such as obfuscated Vidar stealer variants and the TunnesshClient backdoor.
APT GROUP
According to Unit 42, AppleChris is a custom Windows backdoor implemented as multiple Portable Executable (PE) binaries (EXEs and DLLs) that support flexible deployment, including DLL hijacking via the Volume Shadow Copy Service. It provides comprehensive remote access capabilities such as drive and directory enumeration, file upload/download/deletion, process listing and creation, and interactive shell execution, all controlled over HTTP using custom verbs and RSA/AES-encrypted C2 traffic. AppleChris uses a dead drop resolver design where C2 IPs are dynamically retrieved and decrypted, initially via a dual Dropbox + Pastebin mechanism (Dropbox variant) and later via a streamlined Pastebin-only approach (Tunneler variant). The newer Tunneler variant additionally introduces a proxy tunneling command that creates reverse TCP tunnels for network pivoting, while employing delayed execution and mutex-based single-instance checks to evade detection.
APT GROUP
According to Cisco Talos, PeerTime is an ELF-based backdoor compiled for multiple architectures including common embedded and server platforms, with one version written in C/C++ and a newer version written in Rust. It is deployed via shell scripts and an auxiliary "instrumentor" component that can detect container runtimes and launch the loader in these environments, with the instrumentor containing debug strings in Simplified Chinese that point to Chinese-speaking developers. PeerTime’s loader decrypts and decompresses the main payload in memory, can rename its process to appear benign, and uses the BitTorrent protocol to discover command-and-control information, exchange data with peers, and download and execute additional payloads. The malware uses standard Unix utilities to copy and place downloaded files, enabling flexible post-compromise tool delivery across diverse Linux and embedded systems.
APT GROUP
According to Google, GRIDTIDE is a sophisticated backdoor written in C and delivered as a Linux ELF binary that provides remote shell command execution, file upload, and file download capabilities. It uses a cloud-based spreadsheet service as its command-and-control channel, interacting via official APIs and encoding all traffic with a URL-safe Base64 scheme to blend into legitimate HTTPS traffic. The malware relies on an external 16-byte key file to decrypt its cloud configuration using AES-128 in CBC mode, then performs detailed host reconnaissance (user, host, OS, network, and locale information) and stores this metadata in designated spreadsheet cells. GRIDTIDE establishes persistence through a system service, uses a cell-based polling mechanism for tasking and responses, and can stage tooling and exfiltrated data in spreadsheet cells to avoid traditional network-based detection.
APT GROUP
According to Cisco Talos, BruteEntry is a Go-based ELF malware family used to convert compromised Linux systems, particularly edge devices, into operational relay boxes that perform large-scale credential brute forcing. It consists of a daemon-like agent and an "instrumentor" written in Go that ensures the agent is running, after which the agent registers with a command-and-control server and receives tasking that includes lists of target hosts and service types. BruteEntry uses embedded credential lists to systematically attempt logins against services such as SSH, PostgreSQL databases, and application servers, reporting back detailed results on success or failure. By distributing scanning and brute-force activity across many infected nodes, BruteEntry provides resilient, outsourced access acquisition capabilities for the operator’s broader intrusion campaigns.
APT GROUP
According to Cisco Talos, LucidRook is a sophisticated stager that embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library (DLL) to download and execute staged Lua bytecode payloads.
APT GROUP
According to Cisco Talos, LucidPawn is a dropper for LucidRook and LucidKnight. It uses region-specific anti-analysis checks and executes only in Traditional Chinese language environments associated with Taiwan.
APT GROUP
According to Cisco Talos, is a companion reconnaissance tool that exfiltrates system information via Gmail. Its presence alongside LucidRook suggests the actor operates a tiered toolkit, potentially using LucidKnight to profile targets before escalating to full stager deployment.
APT GROUP
According to BI.ZONE, Loki is an implant compatible with the Mythic and Havoc post‑exploitation frameworks.
APT GROUPespionageadvanced
According to ANY.RUN, MicroStealer is a rapidly spreading infostealer with low current AV detection that uses a multi stage NSIS, Electron, Node.js, and Java (JAR) delivery chain plus heavy obfuscation and VM checks to evade analysis. It is distributed via compromised or impersonated accounts and malicious download sites, with notable activity in the US and Germany and increased targeting of education and telecom sectors. Once executed, it deploys a bundled JRE, persists via a high privilege ONLOGON scheduled task, and may abuse UAC and LSASS token impersonation. Its core capabilities include stealing browser passwords and session cookies, capturing screenshots, exfiltrating crypto wallets, hijacking and profiling Discord accounts, profiling Steam accounts, and sending archived data over HTTPS to Discord webhooks and attacker controlled servers.