Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUPfinancialhigh
The malware ftcode is a ransomware which encrypts files and changes their extension into .FTCODE. It later asks for a ransom in order to release the decryption key, mandatory to recover your files. It is infamous for attacking Italy pretending to be a notorious telecom provider asking for due payments.
APT GROUP
Loader used to deliver FRat (see family windows.frat)
APT GROUP
Malware family tracked by Malpedia. ID: ps1.flowerpower
APT GROUP
A loader written in Powershell, usually delivered packaged in MSI/MSIX files.
APT GROUP
According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and intelligence gathering. It enables attackers to exfiltrate sensitive data while maintaining persistent control over the compromised system. The malware collects extensive information about the compromised system to create a detailed profile. It determines whether the user has administrative privileges, checks for membership in a corporate domain, and identifies the presence of cryptocurrency wallets or VPN software by scanning specified directories and applications. It also gathers data about the system's operating environment, including public IP address, geographic location, installed antivirus products, firewall status, and system uptime. This information is compiled into a structured format and transmitted to the C&C server.
APT GROUPespionageadvanced
According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets. For each affected computer, a unique identifier is calculated using cryptographic transformations (SHA256/MD5 hash functions) based on a combination of computer name and disk serial number, which is transmitted in the “X-Cookie” header of HTTP requests when interacting with the management server. The persistence of the backdoor is ensured by the corresponding key in the Run branch of the operating system (OS) registry, which is created at the stage of the initial infection by a third-party PowerShell script (including the COOKBOX deployer). As a rule, obfuscation elements are used in the program code: chr-character encoding, character replacement (replace()), base64 conversion, GZIP compression.
APT GROUP
Malware family tracked by Malpedia. ID: ps1.cashy200
APT GROUP
Malware family tracked by Malpedia. ID: ps1.bondupdater
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: pl.silence_ddos
APT GROUP
Malware family tracked by Malpedia. ID: php.wso
Malware family tracked by Malpedia. ID: php.redhat_hacker
APT GROUPespionageadvanced
According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality, including the ability to deliver follow-on modules including an information stealer, keylogger, screen capture collector and more. It also establishes persistence to continue operations following system reboots. The design of this malware framework appears to attempt to minimize artifacts left on infected systems by facilitating the delivery and execution of modules in-memory, without requiring them to be written to disk. Due to similarities in the design and implementation with the malware family AHK Bot, we are referring to this PowerShell-based malware as “PS1Bot.”
Backdoor written in php
APT GROUP
Malware family tracked by Malpedia. ID: php.pas
APT GROUPespionageadvanced
In combination with Parrot TDS the usage of a classical web shell was observed by DECODED Avast.io.
APT GROUP
Malware family tracked by Malpedia. ID: php.p0wnyshell
APT GROUP
According to Xlab, Glutton is a modular PHP fileless attack framework, capable of data exfiltration and running backdoors.
APT GROUP
Malware family tracked by Malpedia. ID: php.ensikology
APT GROUP
PHP/JavaScript malware for WordPress that injects multi-stage scripts, turning compromised sites into distributed TDS/C2 nodes. Delivers signed payloads, maintains persistence via helper files, and redirects traffic to monetized scam networks.
APT GROUP
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.
APT GROUP
C99shell is a PHP backdoor that provides a lot of functionality, for example: * run shell commands; * download/upload files from and to the server (FTP functionality); * full access to all files on the hard disk; * self-delete functionality.
APT GROUP
A webshell for multiple web languages (asp/aspx, jsp/jspx, php), openly distributed through Github.
APT GROUP
ASPXSpy is an open-source web shell written in C# that allows a threat actor to accomplish various post-exploitation tasks, including file access and command execution.
APT GROUP
Antak is a webshell written in ASP.Net which utilizes PowerShell.
APT GROUP
Ani-Shell is a simple PHP shell with some unique features like Mass Mailer, a simple Web-Server Fuzzer, Dosser, Back Connect, Bind Shell, Back Connect, Auto Rooter etc.
APT GROUP
A malware that was observed being embedded alongside legitimate applications (such as iTerm2) offered for download on suspicious websites pushed in search engines. It uses a Python script to perform reconnaissance on the compromised system an pulls additional payload(s).
APT GROUP
Malware family tracked by Malpedia. ID: osx.yort
APT GROUP
Malware family tracked by Malpedia. ID: osx.xslcmd
APT GROUP
Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well. Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent. Not to be confused with apk.xloader or ios.xloader.
APT GROUP
Malware family tracked by Malpedia. ID: osx.xcsset
APT GROUP
Malware family tracked by Malpedia. ID: elf.wirenet
APT GROUP
The iOS malware that is installed over USB by osx.wirelurker
APT GROUP
Malware family tracked by Malpedia. ID: osx.windtail
APT GROUP
According to Mandiant, WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS. The backdoor supports downloading and executing arbitrary payloads retrieved from its command-and-control (C2 or C&C) server, which is provided via the command-line parameters. To communicate with the adversary infrastructure, WAVESHAPER leverages the curl library for either HTTP or HTTPS, depending on the command-line argument provided. WAVESHAPER also runs as a daemon by forking itself into a child process that runs in the background detached from the parent session and collects system information, which is sent to the C&C server in a HTTP POST request.
APT GROUP
Malware family tracked by Malpedia. ID: osx.watchcat
APT GROUP
Malware family tracked by Malpedia. ID: osx.vigram
APT GROUP
Malware family tracked by Malpedia. ID: osx.update_agent
Malware family tracked by Malpedia. ID: osx.unidentified_001
APT GROUP
General purpose backdoor