Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: apk.elibomi
APT GROUPespionageadvanced
According to Lookout, EagleMsgSpy is a lawful intercept surveillance tool developed by a Chinese software development company with use by public security bureaus in mainland China. Early samples indicate the surveillance tool has been operational since at least 2017, with development continued into late 2024. EagleMsgSpy collects extensive data from the user: third-party chat messages, screen recording and screenshot capture, audio recordings, call logs, device contacts, SMS messages, location data, network activity.
Through infrastructure overlap and artifacts from open command and control directories, Lookout attributes EagleMsgSpy to Wuhan Chinasoft Token Information Technology Co., Ltd. with high confidence.
APT GROUP
Malware family tracked by Malpedia. ID: apk.dvmap
APT GROUP
Malware family tracked by Malpedia. ID: apk.droidwatcher
APT GROUPespionageadvanced
According to Zimperium, DroidLock has the ability to lock device screens with a ransomware-like overlay and illegally acquire app lock credentials, leading to a total takeover of the compromised device.
It employs deceptive system update screens to trick victims and can stream and remotely control devices via VNC. The malware also exploits device administrator privileges to lock or erase data, capture the victim's image with the front camera, and silence the device. Overall, it utilizes 15 distinct commands to interact with its C2 panel.
APT GROUP
Malware family tracked by Malpedia. ID: apk.droidjack
APT GROUP
According to Cleafy, DroidBot is a modern RAT that combines hidden VNC and overlay attack techniques with spyware-like capabilities, such as keylogging and user interface monitoring. Moreover, it leverages dual-channel communication, transmitting outbound data through MQTT and receiving inbound commands via HTTPS, providing enhanced operation flexibility and resilience.
APT GROUP
Android variant of ios.LightSpy.
APT GROUP
Android malware that impersonates genuine applications such as Signal, Telegram, WhatsApp, YouTube, and other chat applications and distributes through phishing sites.
APT GROUP
Malware family tracked by Malpedia. ID: apk.doublelocker
APT GROUP
Malware family tracked by Malpedia. ID: apk.doubleagent
APT GROUP
Malware family tracked by Malpedia. ID: apk.dmsspy
APT GROUP
Malware family tracked by Malpedia. ID: apk.dendroid
APT GROUP
Malware family tracked by Malpedia. ID: apk.defensor_id
APT GROUPespionageadvanced
According to Lookout, DCHSpy is an Android surveillanceware tool leveraged by Iranian cyber espionage group MuddyWater. DCHSpy collects WhatsApp data, accounts, contacts, SMS, files, location, and call logs, and can record audio and take photos.
APT GROUP
Malware family tracked by Malpedia. ID: apk.dawdropper
APT GROUP
Malware family tracked by Malpedia. ID: apk.darkshades
APT GROUP
According to PCrisk, DAAM is an Android malware utilized to gain unauthorized access to targeted devices since 2021. With the DAAM Android botnet, threat actors can bind harmful code with a genuine application using its APK binding service.
Lookout refers to this malware as BouldSpy and assesses with medium confidence that this Android surveillance tool is used by the Law Enforcement Command of the Islamic Republic of Iran (FARAJA).
APT GROUP
Malware family tracked by Malpedia. ID: apk.cyber_azov
APT GROUP
According to ThreatFabric, this malware offers remote control, black screen overlays, and advanced data harvesting via accessibility logging.
APT GROUP
Malware family tracked by Malpedia. ID: apk.craxs_rat
APT GROUP
Poses as an app that can offer a "corona safety mask" but phone's address book and sends sms to contacts, spreading its own download link.
APT GROUP
Malware family tracked by Malpedia. ID: apk.copybara
APT GROUPfinancialhigh
Coper is an Android banking trojan and RAT descended from ExobotCompact, itself a rewrite of Exobot. It uses a modular architecture, a multi-stage infection chain and (in some variants) a DGA. First observed in Colombia, it has since spread to Europe.
APT GROUP
Malware family tracked by Malpedia. ID: apk.connic
APT GROUP
Malware family tracked by Malpedia. ID: apk.comet_bot
APT GROUP
Malware family tracked by Malpedia. ID: apk.cloudatlas
APT GROUP
Malware family tracked by Malpedia. ID: apk.clipper
APT GROUP
Malware family tracked by Malpedia. ID: apk.clientor
APT GROUP
Malware family tracked by Malpedia. ID: apk.chrysaor
APT GROUP
Malware family tracked by Malpedia. ID: apk.charger
APT GROUP
Malware family tracked by Malpedia. ID: apk.chamois
APT GROUP
The malware chamaleon is an Android trojan that pretends to be legitimate entities to steal data from users in Australia and Poland. It exploits the Accessibility Service to monitor and modify the device screen.
APT GROUPfinancialhigh
According to PCrisk, Cerberus is an Android banking Trojan which can be rented on hacker forums. It was been created in 2019 and is used to steal sensitive, confidential information. Cerberus can also be used to send commands to users' devices and perform dangerous actions.
APT GROUPfinancialhigh
Catelites Bot (identified by Avast and SfyLabs in December 2017) is an Android trojan, with ties to CronBot. Once the malicious app is installed, attackers use social engineering tricks and window overlays to get credit card details from the victim.
The distribution vector seems to be fake apps from third-party app stores (not Google Play) or via malvertisement. After installation and activation, the app creates fake Gmail, Google Play and Chrome icons. Furthermore, the malware sends a fake system notification, telling the victim that they need to re-authenticate with Google Services and ask for their credit card details to be entered.
Currently the malware has overlays for over 2,200 apps of banks and financial institutions.
APT GROUP
Malware family tracked by Malpedia. ID: apk.carbonsteal
APT GROUPespionageadvanced
According to PCrisk, CapraRAT is the name of an Android remote access trojan (RAT), possibly a modified version of another (open-source) RAT called AndroRAT. It is known that CapraRAT is used by an advanced persistent threat group (ATP) called APT36 (also known as Earth Karkaddan). CapraRAT allows attackers to perform certain actions on the infected Android device.
APT GROUP
Malware family tracked by Malpedia. ID: apk.busygasper
APT GROUP
According to Cyble, this is an advanced Android malware evolved from SpySolr that features remote control, credential theft, and data exfiltration. It spreads via phishing sites impersonating streaming services like iNat TV and fake mining platforms. The malware abuses Android’s Accessibility Service to unlock devices, log keystrokes, and automate credential theft through injections. It uses WebSocket-based C&C communication for real-time command execution and data theft. BTMOB RAT supports various malicious actions, including live screen sharing, file management, audio recording, and web injections.
APT GROUP
PRODAFT describes Brunhilda as a "Dropper as a Service" for Google Play, delivering e.g. Alien.