Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s installed. The code of PlainGnome’s second stage payload evolved significantly from January 2024 through at least October. In particular, PlainGnome’s developers shifted to using Jetpack WorkManager classes to handle data exfiltration, which eases development and maintenance of related code. In addition, WorkManager allows for specifying execution conditions. For example, PlainGnome only exfiltrates data from victim devices when the device enters an idle state. This mechanism is probably intended to reduce the chance of a victim noticing the presence of PlainGnome on their device. As opposed to the minimalist first (installer) stage, the second stage carries out all surveillance functionality and relies on 38 permissions.
APT GROUP
Malware family tracked by Malpedia. ID: apk.pjobrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.pixstealer
APT GROUPfinancialhigh
According to PCrisk, The PixPirate is a dangerous Android banking Trojan that has the capability to carry out ATS (Automatic Transfer System) attacks. This allows threat actors to automatically transfer funds through the Pix Instant Payment platform, which numerous Brazilian banks use. In addition to launching ATS attacks, PixPirate can intercept and delete SMS messages, prevent the uninstallation process, and carry out malvertising attacks.
APT GROUP
According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing system inform information, logging and recording phone calls, initiating audio recordings, reading SMS inboxes and sending SMS messages. The malware also has features to facilitate device location tracking, deleting, downloading, and uploading files, reading connectivity state, speed, and activity, and toggling Bluetooth, Wi-Fi, and mobile data settings.
APT GROUP
According to Zimperium, PhoneSpy is a spyware aimed at South Korean residents with Android devices.
APT GROUP
Malware family tracked by Malpedia. ID: apk.phoenix
APT GROUP
Malware family tracked by Malpedia. ID: apk.phantomlance
APT GROUP
According to TechCrunch, this is a remote surveillance app that allows ordinary consumers to buy software capable of tracking people and their data without their knowledge. Once physically planted on a person’s phone or computer (usually with knowledge of the victim’s passcode or login), the app would continuously upload a copy of the victim’s information, including messages, photos, and location data, to pcTattletale’s servers and make the data accessible to whoever planted the spyware.
APT GROUP
Malware family tracked by Malpedia. ID: apk.packchat
APT GROUP
Malware family tracked by Malpedia. ID: apk.oscorp
APT GROUP
Malware family tracked by Malpedia. ID: apk.omnirat
APT GROUP
Malware family tracked by Malpedia. ID: apk.nexus
APT GROUPfinancialhigh
MysteryBot is an Android banking Trojan with overlay capabilities with support for Android 7/8 but also provides other features such as key logging and ransomware functionality.
APT GROUP
Malware family tracked by Malpedia. ID: apk.mudwater
APT GROUP
Malware family tracked by Malpedia. ID: apk.morder_rat
APT GROUPfinancialhigh
MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based mobile threat that is associated with a financially motivated Chinese group called Roaming Mantis. The malware claims to be the default SMS application and has dropper and banker capabilities.
APT GROUP
Monokle is a sophisticated mobile surveillanceware that possesses remote access trojan (RAT) functionality, advanced data exfiltration techniques as well as the ability to install an attacker-specified certificate to the trusted certificates on an infected device that would allow for man-in-the-middle (MITM) attacks. According to Lookout researchers, It is believed to be developed by Special Technology Center (STC), which is a Russian defense contractor sanctioned by the U.S. Government in connection to alleged interference in the 2016 US presidential elections.
APT GROUP
Check Point has identified samples of this spyware being distributed since 2015. No samples were found on Google Play, meaning they were likely through other channels like social engineering.
APT GROUP
Malware family tracked by Malpedia. ID: apk.mazarbot
APT GROUP
According to heimdal, MasterFred malware, this is designed as an Android trojan that makes use of false login overlays to target not only Netflix, Instagram, and Twitter users, but also bank customers. The hackers’ goal is to steal credit card information.
APT GROUP
Malware family tracked by Malpedia. ID: apk.marcher
APT GROUP
Malware family tracked by Malpedia. ID: apk.mandrake
APT GROUP
Malware family tracked by Malpedia. ID: apk.luna_spy
APT GROUPfinancialhigh
Android banker Trojan with the standard banking capabilities such as overlays, SMS stealing. It also features ransomware functionality. Note, the network traffic is obfuscated the same way as in Android Bankbot.
APT GROUP
Malware family tracked by Malpedia. ID: apk.little_looter
APT GROUP
Malware family tracked by Malpedia. ID: apk.landfall
APT GROUP
Malware family tracked by Malpedia. ID: apk.ksremote
APT GROUP
According to Lookout, this spyware was first observed in March 2022 and remains active with new samples still publicly hosted. It uses a two-stage C2 infrastructure that retrieves initial configurations from a Firebase cloud database. KoSpy can collect extensive data, such as SMS messages, call logs, location, files, audio, and screenshots via dynamically loaded plugins. The spyware has Korean language support with samples distributed across Google Play and third-party app stores such as Apkpure.
APT GROUP
Malware family tracked by Malpedia. ID: apk.koler
APT GROUP
Malware family tracked by Malpedia. ID: apk.knspy
APT GROUP
KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as participating in distributed denial-of-service (DDoS). KIMWOLF primarily infects unofficial Android-TV set-top boxes and digital photo frames. The malware has frequently been noted to achieve infection spread via abusing Android Debug Bridge (ADB) and residential proxies. There are multiple reports suggesting a connection to the Aisuru botnet, with Kimwolf acting as the Android variant.
APT GROUP
Malware family tracked by Malpedia. ID: apk.kevdroid
APT GROUP
Joker is one of the most well-known malware families on Android devices. It manages to take advantage of Google’s official app store with the help of its trail signatures which includes updating the virus’s code, execution process, and payload-retrieval techniques. This malware is capable of stealing users’ personal information including contact details, device data, WAP services, and SMS messages.
APT GROUP
Malware family tracked by Malpedia. ID: apk.jaderat
APT GROUP
Malware family tracked by Malpedia. ID: apk.irrat
APT GROUP
According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application. IRATA can collect sensitive information from your mobile phone including bank details. Since it infects your mobile, it can also gather your SMS messages which then can be used to obtain 2FA tokens.
APT GROUP
According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. It provides WebSocket communication and has RAT capabilities.
APT GROUP
RAT, which can be used to extract sensitive information, e.g. contact lists, txt messages, location information.
APT GROUP
HiddenAd is a malware that shows ads as overlays on the phone.