Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: osx.sugarloader
APT GROUP
Malware family tracked by Malpedia. ID: elf.spectral_blur
APT GROUP
SimpleTea for Linux is an HTTP(S) RAT. It was discovered in Q1 2023 as an instance of the Lazarus group's Operation DreamJob campaign for Linux. It was a payload downloaded in an execution chain which started with an HSBC-themed job offer lure. It shared the same C&C server as payloads from the 3CX incident around the same time. It’s an object-oriented project, which does not run on Linux distributions without a graphical user interface, and decrypts its configuration from /home/%user%/.config/apdl.cf using 0x7E as the XOR key. It uses AES-GCM for encryption and decryption of its network traffic. It supports basic commands that include operations on the victim’s filesystem, manipulation with its configuration, file exfiltration (via ZIP archives), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 16-bit integers, starting with the value 0x27C3. SimpleTea for Linux seems like an updated version of BadCall for Linux, rewritten from C to C++, as there are similarities in class names and function names between the two.
According to Red Canary, Silver Sparrow is an activity cluster that includes a binary compiled to run on Apple’s new M1 chips but has been distributed without payload so far.
APT GROUP
According to PCrisk, Shlayer is a trojan-type virus designed to proliferate various adware and other unwanted applications, and promote fake search engines. It is typically disguised as a Adobe Flash Player installer and various software cracking tools. In most cases, users encounter this virus when visiting dubious Torrent websites that are full of intrusive advertisements and deceptive downloads.
APT GROUPfinancialhigh
Dok a.k.a. Retefe is the macOS version of the banking trojan Retefe. It consists of a codesigned Mach-O dropper usually malspammed in an app bundle within a DMG disk image, posing as a document. The primary purpose of the dropper is to install a Tor client as well as a malicious CA certificate and proxy pac URL, in order to redirect traffic to targeted sites through their Tor node, effectively carrying out a MITM attack against selected web traffic. It also installs a custom hosts file to prevent access to Apple and VirusTotal. The macOS version shares its MO, many TTPs and infrastructure with the Windows counterpart.
APT GROUP
Cryptocurrency miner that was distributed masquerading as a Counter-Strike: Global Offensive hack.
APT GROUP
According to SentinelOne, this is an infostealer, targeting among other things the encrypted database of Zoom.
APT GROUPespionageadvanced
Proton RAT is a Remote Access Trojan (RAT) specifically designed for macOS systems. It is known for providing attackers with complete remote control over the infected system, allowing the execution of commands, keystroke capturing, access to the camera and microphone, and the ability to steal credentials stored in browsers and other password managers. This malware typically spreads through malicious or modified applications, which, when downloaded and installed by unsuspecting users, trigger its payload. Proton RAT is notorious for its sophistication and evasion capabilities, including techniques to bypass detection by installed security solutions.
macOS infostealer sold by an individual named Rodrigo4, currently consisting of a disk image containing a Mach-O without app bundle, which when executed spawns osascript executing an AppleScript with the actual infostealer payload. The AppleScript payload will steal files by packing them in a ZIP archive and uploading them to a hardcoded C2 via HTTP.
APT GROUP
Part of Mythic C2, written in Golang.
APT GROUP
Malware family tracked by Malpedia. ID: osx.poolrat
APT GROUP
Malware family tracked by Malpedia. ID: osx.pirrit
APT GROUP
Backdoor as a fork of OpenSSH_6.0 with no logging, and “-P” and “-z” hidden command arguments. “PuffySSH_5.8p1” string.
APT GROUP
Malware family tracked by Malpedia. ID: osx.pearl_stealer
APT GROUPfinancialhigh
This crypto-ransomware for macOS was caught spreading via BitTorrent distribution sites in February 2017, masquerading as 'Patcher', an application used for pirating popular software like Adobe Premiere Pro or Microsoft Office for Mac. The downloaded torrent contained an application bundle in the form of a single zip file. After launching the fake application, the main window of the fake cracking tool was displayed. The file encryption process was launched after the misguided victim clicked 'Start'. Once executed, the ransomware generated a random 25-character string and set it as the key for RC4 encryption of all of the user's files. It then demanded ransom in Bitcoin, as instructed in the 'README!' .txt file copied all over the user's directories. Despite the instructions being quite thorough, Patcher lacked the functionality to communicate with any C&C server, and therefore made it impossible for its operators to decrypt affected files. The randomly generated encryption key was also too long to be guessed via a brute-force attack, leaving the encrypted data unrecoverable in a reasonable amount of time.
APT GROUP
Malware family tracked by Malpedia. ID: osx.osaminer
APT GROUP
SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.
APT GROUP
Malware family tracked by Malpedia. ID: osx.olyx
Malware family tracked by Malpedia. ID: osx.odyssey_stealer
APT GROUP
Malware family tracked by Malpedia. ID: osx.netwire
APT GROUP
Malware family tracked by Malpedia. ID: osx.mughthesec
APT GROUP
Malware family tracked by Malpedia. ID: osx.manuscrypt
APT GROUP
Malware family tracked by Malpedia. ID: osx.mami
APT GROUP
Malware family tracked by Malpedia. ID: osx.macvx
APT GROUP
Malware family tracked by Malpedia. ID: osx.macspy
APT GROUP
Malware family tracked by Malpedia. ID: osx.macransom
APT GROUP
Malware family tracked by Malpedia. ID: osx.macinstaller
APT GROUP
Malware family tracked by Malpedia. ID: osx.macdownloader
APT GROUP
Malware family tracked by Malpedia. ID: ios.lightspy
APT GROUP
Malware family tracked by Malpedia. ID: osx.leverage
APT GROUP
Malware family tracked by Malpedia. ID: osx.laoshu
APT GROUP
Malware family tracked by Malpedia. ID: osx.lador
APT GROUP
Malware family tracked by Malpedia. ID: osx.komplex
APT GROUP
Malware family tracked by Malpedia. ID: osx.kitmos
APT GROUP
According to SentinelOne, KeySteal targets files with the .keychain and keychain-db file extensions in the following locations.
APT GROUP
Malware family tracked by Malpedia. ID: osx.keydnap
APT GROUP
Malware family tracked by Malpedia. ID: osx.keranger
APT GROUP
Malware family tracked by Malpedia. ID: osx.kandykorn
APT GROUP
Malware family tracked by Malpedia. ID: osx.jokerspy