Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUP
According to SpiderLabs, in May 2015 the "company" Quaverse offered a RAT known as Quaverse RAT or QRAT. At around May 2016, this QRAT evolved into another RAT which became known as Qarallax RAT, because its C2 is at qarallax.com. Quaverse also offers a service to encrypt Java payloads (Qrypter), and thus qrypted payloads are sometimes confused with Quaverse RATs (QRAT / Qarallax RAT).
According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.
Malware family tracked by Malpedia. ID: jar.octopus_scanner
APT GROUP
DDoS for Minecraft servers.
APT GROUP
Malware family tracked by Malpedia. ID: jar.jspy
APT GROUP
jRAT, also known as Jacksbot, is a RAT with history, written in Java. It has support for macOS, Linux, Windows and various BSD. It also has functionality to participate in DDoS-attacks as well as to perform click fraud. Note that the Adwind family often is mistakenly labeled as jRAT, because of of a red hering reference to jrat.io.
APT GROUP
Malware family tracked by Malpedia. ID: jar.javalocker
APT GROUP
JavaDispCash is a piece of malware designed for ATMs. The compromise happens by using the JVM attach-API on the ATM's local application and the goal is to remotely control its operation. The malware's primary feature is the ability to dispense cash. The malware also spawns a local port (65413) listening for commands from the attacker which needs to be located in the same internal network.
APT GROUP
According to Karsten Hahn, this malware is actually written in JPHP, but can be treated similar to .class files produced by Java. IceRat has been observed to carry out information stealing and mining.
APT GROUP
Malware family tracked by Malpedia. ID: jar.feimea_rat
APT GROUP
EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files, manipulating the file system, establishing persistence, taking screenshots, and manipulating keyboard and mouse events. EpicSplit is typically obfuscated with the commercial Allatori Obfuscator software. One unique feature of the malware is that TCP messages sent by EpicSplit RAT to its C2 are terminated with the string "_packet_" as a packet delimiter.
APT GROUP
DynamicRAT is a malware that is spread via email attachments and compromises the security of computer systems. Once running on a device, DynamicRAT establishes a persistent presence and gives attackers complete remote control. Its features include sensitive data exfiltration, hardware control, remote action, and the ability to perform DDoS attacks. In addition, DynamicRAT uses evasion and persistence techniques to evade detection and analysis by security solutions.
APT GROUP
Malware family tracked by Malpedia. ID: jar.crossrat
Malware family tracked by Malpedia. ID: jar.bluebanana
APT GROUP
F-Secure observed Banload variants silently downloading malicious files from a remote server, then installing and executing the files.
APT GROUP
According to VMRay, this malware family uses in interesting obfuscation technique: a trailing slash in its archive to confuse analysis tools. It abuses #GitHub as a #C2 and exfiltrates stolen data, such as browser cookies, via Discord webhooks. The GitHub repositories are quite active and exist since mid to late 2024. The malware also monitors keyboard and mouse input, takes screenshots.
APT GROUP
Malware family tracked by Malpedia. ID: jar.adzok
APT GROUP
Part of Malware-as-service platform Used as a generic name for Java-based RAT Functionality - collect general system and user information - terminate process -log keystroke -take screenshot and access webcam - steal cache password from local or web forms - download and execute Malware - modify registry - download components - Denial of Service attacks - Acquire VPN certificates Initial infection vector 1. Email to JAR files attached 2. Malspam URL to downlaod the malware Persistence - Runkey - HKCU\Software\Microsoft\Windows\current version\run Hiding Uses attrib.exe Notes on Adwind The malware is not known to be proxy aware
APT GROUP
According to Google, this reconnaissance payload uses a profiling framework drawing canvas to identify the target’s exact iPhone model, a technique used by many other actors. The iPhone model is sent back to the C2 along with screen size, whether or not a touch screen is present, and a unique identifier per initial GET request (e.g., 1lwuzddaxoom5ylli37v90kj). The server replies with either an AES encrypted next stage or 0, indicating that no payload is available for this device. The payload makes another request to the exploit server with gcr=1 as a parameter to get the AES decryption key from the C2.
APT GROUP
Malware family tracked by Malpedia. ID: ios.triangledb
APT GROUP
Commercial spyware by Intellexa.
APT GROUP
Malware family tracked by Malpedia. ID: ios.postlo
APT GROUP
Between November 2018 and May 2019, senior members of Tibetan groups received malicious links in individually tailored WhatsApp text exchanges with operators posing as NGO workers, journalists, and other fake personas. The links led to code designed to exploit web browser vulnerabilities to install spyware on iOS and Android devices, and in some cases to OAuth phishing pages. This campaign was carried out by what appears to be a single operator that we call POISON CARP.
Updated: 2026-08-06
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: ios.phenakite
APT GROUP
Malware family tracked by Malpedia. ID: ios.guiinject
APT GROUP
According to Google, this is a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023). The exploit kit, named "Coruna" by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.
APT GROUP
According to Google, this is a cookie stealer
Small downloader composed as a Fast-AutoLoad LISP (FAS) module for AutoCAD.
APT GROUPespionageadvanced
According to Black Lotus Labs, ZuoRAT is a MIPS file compiled for SOHO routers that can enumerate a host and internal LAN, capture packets being transmitted over the infected device and perform person-in-the-middle attacks (DNS and HTTPS hijacking based on predefined rules).
APT GROUP
Malware family tracked by Malpedia. ID: elf.zollard
APT GROUP
Malware family tracked by Malpedia. ID: elf.zhtrap
APT GROUP
ZeroBot is a Go-based botnet that spreads primarily through IoT and web application vulnerabilities. It is offered as malware as a service (MaaS) and infrastructure overlaps with DDoS-for-hire services seized by the FBI in December 2022.
APT GROUP
Zergeca is a DDoS-botnet and backdoor written in Golang. It uses modified UPX for packing, with the magic number 0x30219101 instead of "UPX!". It is being distributed via weak telnet passwords and known vulnerabilities.
APT GROUP
Linux DDoS C&C Malware
APT GROUP
According to 360 netlab, this backdoor was derived from the leaked CIA Hive project. It propagates via a vulnerability in F5 and communicates using SSL with a forged Kaspersky certificate.
APT GROUP
Malware family tracked by Malpedia. ID: elf.xbash
APT GROUP
Malware family tracked by Malpedia. ID: elf.xaynnalc
APT GROUP
Malware family tracked by Malpedia. ID: elf.xanthe
APT GROUP
Malware family tracked by Malpedia. ID: elf.wolfsbane
APT GROUP
Malware family tracked by Malpedia. ID: elf.whiterabbit