Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: apk.hero_rat
APT GROUP
Lookout states that Hermit is an advanced spyware designed to target iOS and Android mobile devices. It is designed to collect extensive amounts of sensitive data on its victims such as their location, contacts, private messages, photos, call logs, phone conversations, ambient audio recordings, and more.
APT GROUP
Malware family tracked by Malpedia. ID: apk.hawkshaw
APT GROUPespionageadvanced
Group-IB describes Gustuff as a mobile Android Trojan, which includes potential targets of customers in leading international banks, users of cryptocurrency services, popular ecommerce websites and marketplaces. Gustuff has previously never been reported. Gustuff is a new generation of malware complete with fully automated features designed to steal both fiat and crypto currency from user accounts en masse. The Trojan uses the Accessibility Service, intended to assist people with disabilities. The analysis of Gustuff sample revealed that the Trojan is equipped with web fakes designed to potentially target users of Android apps of top international banks including Bank of America, Bank of Scotland, J.P.Morgan, Wells Fargo, Capital One, TD Bank, PNC Bank, and crypto services such as Bitcoin Wallet, BitPay, Cryptopay, Coinbase etc. Group-IB specialists discovered that Gustuff could potentially target users of more than 100 banking apps, including 27 in the US, 16 in Poland, 10 in Australia, 9 in Germany, and 8 in India and users of 32 cryptocurrency apps.
APT GROUP
Malware family tracked by Malpedia. ID: apk.guerrilla
APT GROUP
Malware family tracked by Malpedia. ID: apk.grifthorse
APT GROUPespionageadvanced
Cisco Talos identifies GPlayed as a malware written in .NET using the Xamarin environment for mobile applications. It is considered powerful because of its capability to adapt after its deployment. In order to achieve this adaptability, the operator has the capability to remotely load plugins, inject scripts and even compile new .NET code that can be executed.
APT GROUP
Malware family tracked by Malpedia. ID: apk.goontact
APT GROUP
Malware family tracked by Malpedia. ID: apk.gold_digger
APT GROUP
Malware family tracked by Malpedia. ID: apk.goldenrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.goldeneagle
APT GROUPfinancialhigh
According to PCrisk, Godfather is the name of an Android malware targeting online banking pages and cryptocurrency exchanges in 16 countries. It opens fake login windows over legitimate applications. Threat actors use Godfather to steal account credentials. Additionally, Godfather can steal SMSs, device information, and other data.
APT GROUP
Malware family tracked by Malpedia. ID: apk.goat_rat
APT GROUP
Malware family tracked by Malpedia. ID: apk.gnatspy
APT GROUP
Malware family tracked by Malpedia. ID: apk.glancelove
APT GROUPfinancialhigh
Ginp is a mobile banking software targeting Android devices that was discovered by Kaspersky. The malware is able to steal both user credentials and credit cards numbers by implementing overlay attacks. For this, overlay targets are for example the default SMS application. What makes Ginp a remarkable family is how its operators managed to have it remain undetected over time even and it receiving version upgrades over many years. According to ThreatFabric, Ginp has the following features: Overlaying: Dynamic (local overlays obtained from the C2) SMS harvesting: SMS listing SMS harvesting: SMS forwarding Contact list collection Application listing Overlaying: Targets list update SMS: Sending Calls: Call forwarding C2 Resilience: Auxiliary C2 list Self-protection: Hiding the App icon Self-protection: Preventing removal Self-protection: Emulation-detection.
APT GROUPfinancialhigh
Gigabud is the name of an Android Remote Access Trojan (RAT) Android that can record the victim's screen and steal banking credentials by abusing the Accessibility Service. Gigabud masquerades as banking, shopping, and other applications. Threat actors have been observed using deceptive websites to distribute Gigabud RAT.
APT GROUP
According to ESET Research, GhostChat is a malicious Android app (package name com.datingbatch.chatapp) disguised to appear a legitimate chat platform called Dating Apps without payment; this legitimate app is available on Google Play and is unrelated to GhostChat other than through the latter using its icon. Ghostchat’s source and mode of distribution remain unknown.
APT GROUP
Malware family tracked by Malpedia. ID: apk.ghostctrl
APT GROUP
Malware family tracked by Malpedia. ID: apk.ghimob
APT GROUP
Malware family tracked by Malpedia. ID: apk.geost
APT GROUP
According to Check Point, they uncovered an operation dubbed "Domestic Kitten", which uses malicious Android applications to steal sensitive personal information from its victims: screenshots, messages, call logs, surrounding voice recordings, and more. This operation managed to remain under the radar for a long time, as the associated files were not attributed to a known malware family and were only detected by a handful of security vendors.
APT GROUP
Malware family tracked by Malpedia. ID: apk.funkybot
APT GROUP
Zimperium notes that this malware has hit more than 10,000 victims in 140+ countries using social media hijacking, 3rd party app stores and sideloading.
APT GROUP
According to Check Point, this malware features several malicious Android applications that mimic legitimate applications, most of which have more than 1,000,000 installs. These malicious apps steal the victims’ credentials and Two-Factor Authentication (2FA) codes. FluHorse targets different sectors of Eastern Asian markets and is distributed via emails. In some cases, the emails used in the first stage of the attacks belong to high-profile entities. The malware can remain undetected for months making it a persistent, dangerous, and hard-to-spot threat.
APT GROUPfinancialhigh
PRODAFT describes FluBot as a banking malware which originally targeted Spain. Since the first quarter of 2021 it has been targeting many other European countries as well as Japan. It uses a DGA for it's C&C and relies on both DNS and DNS-over-HTTPS for name resolution. Despite arrests of multiple people suspected of involvement with this malware in March of 2021, the campaign has only intensified since.
APT GROUP
Malware family tracked by Malpedia. ID: apk.flexnet
APT GROUP
Malware family tracked by Malpedia. ID: apk.fastspy
APT GROUP
Malware family tracked by Malpedia. ID: apk.fastfire
APT GROUP
Malware family tracked by Malpedia. ID: apk.faketgram
APT GROUP
Malware family tracked by Malpedia. ID: apk.fakespy
APT GROUP
Malware family tracked by Malpedia. ID: apk.fakedefend
APT GROUPfinancialhigh
According to Kaspersky, Fakecalls is a Trojan that masquerades as a banking app and imitates phone conversations with bank employees.
APT GROUP
Malware family tracked by Malpedia. ID: apk.fakeadblocker
APT GROUP
Facebook Credential Stealer.
APT GROUP
Malware family tracked by Malpedia. ID: apk.exodus
APT GROUP
Malware family tracked by Malpedia. ID: apk.exobot
APT GROUPfinancialhigh
According to ThreatFabric, the app overlays 15 financial targets from UK, Italy, and Spain, sniffs 234 apps from banks located in Europe as well as crypto wallets.
APT GROUPfinancialhigh
ErrorFather is an Android banking trojan with a multi-stage dropper. The final payload is derived from the Cerberus source code leak.
APT GROUPfinancialhigh
According to Intel471, ERMAC, an Android banking trojan enables bad actors to determine when certain apps are launched and then overwrites the screen display to steal the user's credentials