Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
RAT. Functionality like ExecShell, GetFileList/SendFile/DownloadFile, Socks5, PortmapManager/GetConn/SendConn. Transport also supports Quic. Variants in C# and GO.
APT GROUPespionageadvanced
The threat was a multi-stage malware displaying a decoy that appeared to the victim as a Chinese language article on the long-running dispute over the Diaoyu Islands; an array of erotic pictures; or images of Tibetan organisations. It consisted of two stages: Revir was the dropper/downloader and Imuler was the backdoor capable of the following operations: - capture screenshots - exfiltrate files to a remote computer - send various information about the infected computer - extract ZIP archive - download files from a remote computer and/or the Internet - run executable files
APT GROUP
Malware family tracked by Malpedia. ID: osx.hloader
APT GROUP
According to Malwarebytes, The HiddenLotus "dropper" is an application named Lê Thu Hà (HAEDC).pdf, using an old trick of disguising itself as a document - in this case, an Adobe Acrobat file.
APT GROUP
According to PCrisk, GMERA (also known as Kassi trojan) is malicious software that disguises itself as Stockfolio, a legitimate trading app created for Mac users. Research shows that there are two variants of this malware, one detected as Trojan.MacOS.GMERA.A and the other as Trojan.MacOS.GMERA.B. Cyber criminals proliferate GMERA to steal various information and upload it to a website under their control. To avoid damage caused by this malware, remove GMERA immediately.
APT GROUP
Fullhouse (AKA FULLHOUSE.DOORED) is a custom backdoor used by subsets of the North Korean Lazarus Group. Fullhouse is written in C/C++ and includes the capabilities of a tunneler and backdoor commands support such as shell command execution, file transfer, file managment, and process injection. C2 communications occur via HTTP and require configuration through the command line or a configuration file.
APT GROUP
Malware family tracked by Malpedia. ID: osx.fruitfly
APT GROUP
Malware family tracked by Malpedia. ID: osx.frostyferret
APT GROUP
According to Proofpoint, FrigidStealer FrigidStealer uses Apple script files and osascript to prompt the user to enter their password, and then to gather data including browser cookies, files with extensions relevant to password material or cryptocurrency from the victim’s Desktop and Documents folders, and any Apple Notes the user has created.
Malware family tracked by Malpedia. ID: osx.friendlyferret
Malware family tracked by Malpedia. ID: osx.flexibleferret
APT GROUP
Malware family tracked by Malpedia. ID: osx.flashback
APT GROUP
Malware family tracked by Malpedia. ID: apk.finfisher
APT GROUP
Malware family tracked by Malpedia. ID: osx.failytale
APT GROUPfinancialhigh
According to PcRisk, EvilQuest (also known as ThiefQuest) is like many other malicious programs of this type - it encrypts files and creates a ransom message. In most cases, this type of malware modifies the names of encrypted files by appending certain extensions, however, this ransomware leaves them unchanged. It drops the "READ_ME_NOW.txt" in each folder that contains encrypted data and displays another ransom message in a pop-up window. Additionally, this malware is capable of detecting if certain files are stored on the computer, operates as a keylogger, and receives commands from a Command & Control server.
APT GROUP
Malware family tracked by Malpedia. ID: osx.evilosx
APT GROUP
According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows, MacOS, and Linux users. Cyber criminals behind ElectroRAT target mainly cryptocurrency users. This RAT is distributed via the trojanized Jamm, eTrader, and DaoPoker applications.
APT GROUPespionageadvanced
Eleanor comes as a drag-and-drop file utility called EasyDoc Converter. This application bundle wraps a shell script that uses Dropbox name as a disguise and installs three components: a hidden Tor service, a Pastebin agent and a web service with a PHP-based graphical interface. The Tor service transforms the victim’s computer into a server that provides attackers with full anonymous access to the infected machine via Tor-generated address. The Pastebin agent uploads the address in encrypted form to the Pastebin website where the attackers can obtain it. The web service is the main malicious component that provides the attackers with the control over the infected machine. After successful authentication, the interface offers several control panels to the attackers, allowing them to do the following actions: - Managing files - Listing processes - Connecting to various database management systems such as MySQL or SQLite - Connecting via bind/reverse shell - Executing shell command - Capturing and browsing images and videos from the victim’s webcam - Sending emails with an attachment
APT GROUP
Malware family tracked by Malpedia. ID: osx.eggshell_rat
APT GROUP
Malware family tracked by Malpedia. ID: osx.dummy
APT GROUP
Malware family tracked by Malpedia. ID: osx.dockster
APT GROUP
Malware family tracked by Malpedia. ID: osx.dazzle_spy
APT GROUP
Malware family tracked by Malpedia. ID: osx.darthminer
Malware family tracked by Malpedia. ID: osx.cthulhu_stealer
APT GROUP
Malware family tracked by Malpedia. ID: osx.crossrider
APT GROUP
Malware family tracked by Malpedia. ID: osx.crisis
Malware family tracked by Malpedia. ID: osx.creative_updater
APT GROUP
Malware family tracked by Malpedia. ID: osx.cpumeaner
APT GROUP
Malware family tracked by Malpedia. ID: osx.convuster
APT GROUP
Malware family tracked by Malpedia. ID: osx.coldroot_rat
APT GROUP
CoinThief was a malware package designed to steal Bitcoins from the victim, consisting of a binary patcher, browser extensions, and a backdoor component. It was spreading in early 2014 from several different sources: - on Github (where the trojanized compiled binary didn’t match the displayed source code), o - on popular and trusted download sites line CNET's Download.com or MacUpdate.com, and - as cracked applications via torrents camouflaged as Bitcoin Ticker TTM, BitVanity, StealthBit, Litecoin Ticker, BBEdit, Pixelmator, Angry Birds and Delicious Library. The patcher‘s role was to locate and modify legitimate versions of the Bitcoin-Qt wallet application. The analyzed malware samples targeted versions of Bitcoin-Qt 0.8.1, 0.8.0 and 0.8.5. The earlier patch modified Bitcoin-Qt adding malicious code that would send nearly all the victim’s Bitcoins to one of the hard-coded addresses belonging to the attacker. The browser extensions targeted Chrome and Firefox and are disguised as a “Pop-up blocker”. The extensions monitored visited websites, download malicious JavaScripts and injected them into various Bitcoin-related websites (mostly Bitcoin exchanges and online wallet sites). The injected JS scripts were able to modify transactions to redirect Bitcoin transfers to an attacker’s address or simply harvest login credentials to the targeted online service. The backdoor enabled the attacker to take full control over the victim’s computer: - collect information about the infected computer - execute arbitrary shell scripts on the target computer - upload an arbitrary file from the victim’s hard drive to a remote server - update itself to a newer version
APT GROUP
Malware family tracked by Malpedia. ID: osx.cloud_mensis
APT GROUP
Google TAG has observed this malware being delivered via watering hole attacks using 0-day exploits, targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political group.
APT GROUP
Malware family tracked by Malpedia. ID: osx.casso
APT GROUP
Malware family tracked by Malpedia. ID: osx.bundlore
APT GROUP
Malware family tracked by Malpedia. ID: osx.bella
APT GROUP
Malware family tracked by Malpedia. ID: osx.banshee
APT GROUP
Malware family tracked by Malpedia. ID: osx.amos
APT GROUP
webshell
Malware family tracked by Malpedia. ID: jsp.godzilla_webshell