Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.whirlpool
APT GROUP
Malware family tracked by Malpedia. ID: elf.wellmail
APT GROUP
According to Intezer, this is a spreader module used by WatchBog. It is a dynamically linked ELF executable, compiled with Cython. C&C adresses are fetched from Pastebin. C&C communication references unique identification keys per victim. It contains a BlueKeep scanner, reporting positively scanned hosts to the C&C server (RC4 encrypted within SSL/TLS). It contains 5 exploits targeting Jira, Exim, Solr, Jenkins and Nexus Repository Manager 3.
APT GROUP
Malware family tracked by Malpedia. ID: elf.walkloader
APT GROUP
Malware family tracked by Malpedia. ID: elf.vpnfilter
APT GROUP
VoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong operational security through runtime encryption, environment awareness (cloud provider and container detection), and the use of user-mode and kernel-level rootkit techniques to evade detection.
VoidLink is not a repurposed legacy tool but a purpose-built framework optimized for cloud infrastructure, indicating a shift in advanced threat development toward Linux-based cloud workloads. Although no confirmed large-scale infections have been observed, its maturity and design suggest potential use by sophisticated threat actors for long-term, stealthy access to cloud environments.
APT GROUP
According to Synacktiv, vGet is an in-memory stager for vShell, written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: elf.vault8_hive
APT GROUP
Enables remote execution of scripts on a host, communicates via Tox.
APT GROUP
Malware family tracked by Malpedia. ID: elf.unidentified_005
APT GROUPespionageadvanced
Implant used by APT31 on compromised SOHO infrastructure, tries to camouflage as a tool ("unifi-video") related to Ubiquiti UniFi surveillance cameras.
APT GROUP
According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA: CVE-2019-10149. This attack leverages a week-old vulnerability to gain remote command execution on the target machine, search the Internet for other machines to infect, and initiates a crypto miner.
APT GROUP
Malware family tracked by Malpedia. ID: elf.umbreon
APT GROUP
Malware family tracked by Malpedia. ID: elf.turla_rat
APT GROUP
Malware family tracked by Malpedia. ID: elf.tsh
APT GROUP
Malware family tracked by Malpedia. ID: elf.tscookie
APT GROUP
Malware family tracked by Malpedia. ID: elf.trump_bot
APT GROUP
According to its author, TripleCross is a Linux eBPF rootkit that demonstrates the offensive capabilities of the eBPF technology.
APT GROUP
Malware family tracked by Malpedia. ID: elf.torii
APT GROUP
Malware family tracked by Malpedia. ID: elf.tntbotinger
APT GROUP
Malware family tracked by Malpedia. ID: elf.themoon
APT GROUP
[TeamTNT](https://attack.mitre.org/groups/G0139) is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud and container resources to deploy cryptocurrency miners in victim environments.(Citation: Palo Alto Black-T October 2020)(Citation: Lacework TeamTNT May 2021)(Citation: Intezer TeamTNT September 2020)(Citation: Cado Security TeamTNT Worm August 2020)(Citation: Unit 42 Hildegard Malware)(Citation: Trend Micro TeamTNT)(Citation: ATT TeamTNT Chimaera September 2020)(Citation: Aqua TeamTNT August 2020)(Citation: Intezer TeamTNT Explosion September 2021)
T1027.002T1046T1685
APT GROUPespionageadvanced
A malware capable of capturing credentials and enabling backdoor access, implemented as a userland rootkit. It uses three methods for hiding its network activity, by hooking and hijacking 1) fopen/fopen64, 2) eBPF, 3) a set of libpcap functions.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sword2033
APT GROUP
Malware family tracked by Malpedia. ID: elf.suterusu
APT GROUP
Sustes Malware doesn’t infect victims by itself (it’s not a worm) but it is spread over exploitation and brute-force activities with special focus on IoT and Linux servers. The initial infection stage comes from a custom wget directly on the victim machine followed by a simple /bin/bash mr.sh. The script is a simple bash script which drops and executes additional software.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sunless
APT GROUP
According to FireEye, STEELCORGI is a packer for Linux ELF files that makes use of execution guardrails by sourcing decryption key material from environment variables.
APT GROUP
Malware family tracked by Malpedia. ID: elf.stantinko
APT GROUP
Malware family tracked by Malpedia. ID: elf.sshdoor
APT GROUP
Malware family tracked by Malpedia. ID: elf.sshdinjector
APT GROUP
Malware family tracked by Malpedia. ID: elf.spry_socks
APT GROUP
Malware family tracked by Malpedia. ID: elf.speculoos
APT GROUP
Malware family tracked by Malpedia. ID: elf.specter
APT GROUP
Malware family tracked by Malpedia. ID: elf.speakup
APT GROUP
According to Mandiant, this is a utility that is written in C and targets Linux. It can be used to extract the uncompressed linux kernel image (vmlinux) into a file and encrypt it using AES without the need for any command line tools.
APT GROUP
Malware family tracked by Malpedia. ID: elf.spamtorte
APT GROUPespionageadvanced
This is an implant used by APT31 on home routers to utilize them as ORBs.
APT GROUP
According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell).
APT GROUP
According to PwC, SnappyTCP is a simple reverse shell for Linux/Unix systems, with variants for plaintext and TLS communication. SeaTurtle has used SnappyTCP at least between 2021 and 2023.