Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: apk.switcher
APT GROUPfinancialhigh
Svpeng is a malicious banking trojan targeting Android devices, and it poses a significant threat to both mobile users and the developers of mobile banking apps. Svpeng has been active since around 2013. It primarily targets Android users, and its main objective is to steal sensitive financial information, particularly login credentials and personal data related to banking and financial apps. Svpeng typically spreads through malicious apps, phishing campaigns, or drive-by downloads.
APT GROUPespionageadvanced
According to ThreatFabric, Sturnus is a privately operated Android banking trojan. This malware supports a broad range of fraud-related capabilities, including full device takeover. A key differentiator is its ability to bypass encrypted messaging. By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal. The trojan can harvest banking credentials through convincing fake login screens that replicate legitimate banking apps. In addition, it provides attackers with extensive remote control, enabling them to observe all user activity, inject text without physical interaction, and even black out the device screen while executing fraudulent transactions in the background—without the victim’s knowledge.
APT GROUP
Malware family tracked by Malpedia. ID: apk.stealthmango
APT GROUP
Malware family tracked by Malpedia. ID: apk.stealthagent
APT GROUP
According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.
APT GROUP
SpyMax is a popular Android surveillance tool. Its predecessor, SpyNote, was one of the most widely used spyware frameworks.
APT GROUP
A sophisticated mobile surveillance implant operating as a Remote Control System (RCS). This malware family is characterized by a unique, multi-sided communication architecture that abandons traditional HTTP polling. Instead, it hybridizes Firebase Cloud Messaging (FCM) for asynchronous command signaling with Fast Reverse Proxy (FRP) to establish persistent, NAT-bypassing network tunnels, effectively turning the infected mobile device into a server accessible by the attacker.
APT GROUP
Malware family tracked by Malpedia. ID: apk.spyc23
APT GROUP
Malware family tracked by Malpedia. ID: apk.spybanker
APT GROUP
Malware family tracked by Malpedia. ID: apk.sova
APT GROUP
Malware family tracked by Malpedia. ID: apk.soumnibot
APT GROUP
Malware family tracked by Malpedia. ID: apk.smsspy
Updated: 2017-11-09
View profile →
APT GROUP
SMSAgent appears as a game application, but silently performs malicious routines in the background. It attempts to download other potentially malicious files from a remote server and sends out SMS or MMS messages that places expensive charges on the user's bill.
APT GROUP
Slocker also known as jisut and pigetrl, is a screen locker that is distributed through telegram groups.
APT GROUP
Malware family tracked by Malpedia. ID: apk.slempo
APT GROUP
Malware family tracked by Malpedia. ID: apk.skygofree
APT GROUP
Malware family tracked by Malpedia. ID: apk.silkbean
APT GROUP
Shopper/LeifAccess is a malicious Android app that uses Android's AccessibilityService to secretly control the device. It installs apps, leaves fake reviews, opens ads, and even registers users on various platforms. Disguised as a system app, it collects personal and device information and sends it to remote servers. The malware was most active in late 2019, especially in Russia, Brazil, and India.
APT GROUPfinancialhigh
SharkBot is a piece of malicious software targeting Android Operating Systems (OSes). It is designed to obtain and misuse financial data by redirecting and stealthily initiating money transfers. SharkBot is particularly active in Europe (United Kingdom, Italy, etc.), but its activity has also been detected in the United States.
APT GROUPfinancialhigh
An Android ransomware that locks the device, changes the wallpaper, and demands money in exchange for unlocking the phone.
APT GROUPfinancialhigh
According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number, Aadhaar number, PAN card details, Date of birth, and Net banking user ID and password. It uses Telegram as C2.
APT GROUP
Malware family tracked by Malpedia. ID: apk.rootnik
APT GROUP
Malware family tracked by Malpedia. ID: apk.rogue
APT GROUP
Malware family tracked by Malpedia. ID: apk.riltok
APT GROUPfinancialhigh
According to PCrisk, Revive is the name of a banking Trojan targeting Android users (customers of a specific Spanish bank). It steals sensitive information. Cybercriminals use Revive to take ownership of online accounts using stolen login credentials. This malware abuses Accessibility Services to perform malicious activities.
APT GROUP
Malware family tracked by Malpedia. ID: apk.residentbat
APT GROUP
Malware family tracked by Malpedia. ID: apk.remrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.remo
APT GROUPfinancialhigh
RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps. The malware works by overlaying a login screen with a fake display that sends the credentials to a C2 server. The malware also has the ability to block incoming calls from banks, to prevent the victim of being notified. As a distribution vector RedAlert 2 uses third-party app stores and imitates real Android apps like Viber, Whatsapp or fake Adobe Flash Player updates.
APT GROUP
Malware family tracked by Malpedia. ID: apk.raxir
APT GROUP
According to ThreatFabric, this RAT can perform NFC relay attacks and has Automated Transfer ystem (ATS) capabilities
APT GROUP
RatMilad, a newly discovered Android spyware, has been stealing data from mobile devices in the Middle East. The malware is spread through links on social media and pretends to be applications for services like VPN and phone number spoofing. Unwary users download these trojan applications and grant access to malware.
APT GROUP
Malware family tracked by Malpedia. ID: apk.rana
APT GROUP
Malware family tracked by Malpedia. ID: apk.rambleon
APT GROUP
Malware family tracked by Malpedia. ID: apk.rafelrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.princess
APT GROUP
Malware family tracked by Malpedia. ID: apk.premier_rat
APT GROUP
Malware family tracked by Malpedia. ID: apk.pornhub
Updated: 2017-02-15
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: apk.podec