Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.flodrix
APT GROUP
Malware family tracked by Malpedia. ID: elf.firewood
APT GROUP
Malware family tracked by Malpedia. ID: elf.fbot
APT GROUP
Malware family tracked by Malpedia. ID: elf.facefish
APT GROUP
Malware family tracked by Malpedia. ID: elf.ext4
APT GROUP
Malware family tracked by Malpedia. ID: elf.ewdoor
APT GROUP
According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension. Legitimate extensions help to extend Linux functionality, but instead of a healthy boost in system functionality, EvilGnome begins spying on users with an array of functionalities uncommon for most Linux malware types.
APT GROUP
According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication.
APT GROUPfinancialhigh
Ransomware used to target ESXi servers.
APT GROUP
According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks. This threat, which seems to be disseminated by the Keksec group, expanded its features by adding recent vulnerabilities discovered in 2022. It was designed to attack web servers, Android devices and content management systems (CMS) servers.
APT GROUP
Malware family tracked by Malpedia. ID: elf.elevator
APT GROUP
According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network to a malicious DNS node. This allows the attackers to redirect the traffic from software updates to a hijacking node that serves instructions to the legitimate software to download a malicious update.
APT GROUP
The latest in this long line of Mirai scourges is a new variant named Echobot. Coming to life in mid-May, the malware was first described by Palo Alto Networks in a report published at the start of June, and then again in a report by security researchers from Akamai, in mid-June.
When it was first spotted by Palo Alto Networks researchers in early June, Echobot was using exploits for 18 vulnerabilities. In the Akamai report, a week later, Echobot was at 26.
https://www.zdnet.com/article/new-echobot-malware-is-a-smorgasbord-of-vulnerabilities
APT GROUP
This payload has been used to compromise kernel.org back in August of 2011 and has hit cPanel Support which in turn, has infected quite a few cPanel servers. It is a credential stealing payload which steals SSH keys, passwords, and potentially other credentials.
This family is part of a wider range of tools which are described in detail in the operation windigo whitepaper by ESET.
APT GROUP
According to Cisco Talos, DriveSwitch is a launcher for SilentRaid.
APT GROUP
Malware family tracked by Malpedia. ID: elf.dreambus
APT GROUP
Malware family tracked by Malpedia. ID: elf.doki
APT GROUP
Dofloo (aka AESDDoS) is a popular malware used to create large scale botnets that can launch DDoS attacks and load cryptocurrency miners to the infected machines.
APT GROUP
Malware family tracked by Malpedia. ID: elf.disgomoji
APT GROUP
Cado discovered this malware, written in Go and targeting AWS Lambda environments.
APT GROUP
Malware family tracked by Malpedia. ID: elf.decoy_dog
APT GROUPfinancialhigh
DEADBOLT is a linux ransomware written in Go, targeting QNAP NAS devices worldwide. The files are encrypted with AES128 encryption and will have the .deadbolt extension appended to file names.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ddoor
APT GROUP
First activity observed in October 2017. DDG is a botnet with P2P capability that is targeting crypto currency mining (Monero).
APT GROUP
Malware family tracked by Malpedia. ID: elf.dark_radiation
APT GROUP
Malware family tracked by Malpedia. ID: elf.darknexus
APT GROUP
A sophisticated payload delivery and upgrade framework, discovered in 2024. DarkCracks exploits compromised GLPI and WordPress sites to function as Downloaders and C2 servers.
APT GROUP
Mirai variant exploiting CVE-2021-20090 and CVE2021-35395 for spreading.
APT GROUP
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink deployment also appears indiscriminate and widespread. The actor has so far primarily deployed Cyclops Blink to WatchGuard and ASUS devices, but it is likely that Sandworm would be capable of compiling the malware for other architectures and firmware.
APT GROUP
A malware written in Bash that hides in the Linux calendar system on February 31st. Observed in relation to Magecart attacks.
APT GROUP
Malware family tracked by Malpedia. ID: apk.cpuminer
APT GROUP
ConnectBack malware is a type of malicious software designed to establish unauthorized connections from an infected system to a remote server. Once a victim's device is compromised, ConnectBack creates a covert channel for communication, allowing the attacker to remotely control and gather sensitive information from the compromised system.
APT GROUP
According to CISA, this is an implant found in firmware for the Contec CMS8000, a patient monitor used by the Healthcare and Public Health sector. An embedded backdoor function with a hard-coded IP address and functionality that enables patient data spillage was identified.
APT GROUP
Malware family tracked by Malpedia. ID: elf.cloud_snooper
APT GROUP
Malware family tracked by Malpedia. ID: elf.chapro
APT GROUP
Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua. Variants exist for multiple architectures and it incorporates code from XorDDoS and Mirai.
APT GROUP
Malware family tracked by Malpedia. ID: elf.cetus
APT GROUP
Malware family tracked by Malpedia. ID: elf.cephei
APT GROUP
Malware family tracked by Malpedia. ID: elf.cdrthief
APT GROUP
This is in the same family as eBury, Calfbot, and is also likely related to DarkLeech