Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,728 entities
APT GROUP
According to FireEye, SLAPSTICK is a Solaris PAM backdoor that grants a user access to the system with a secret, hard-coded password.
APT GROUP
According to its author, this is a stealthy Linux Kernel Rootkit for modern kernels (6x).
APT GROUP
Malware family tracked by Malpedia. ID: elf.sindoor
APT GROUP
Malware family tracked by Malpedia. ID: elf.silex
APT GROUP
According to Cisco Talos, SilentRaid is a primary implant used by UAT-7290 in intrusions meant to establish persistent access to compromised endpoints. It communicates with its command-and-control server (C2) and carries out tasks defined in the malware.
APT GROUP
Malware family tracked by Malpedia. ID: elf.shishiga
APT GROUP
Malware family tracked by Malpedia. ID: elf.shellbind
APT GROUP
According to Fortinet, this is a Mirai fork propagating through multiple vulnerabilities. ShadowV2 had previously been observed targeting AWS EC2 instances in campaigns disclosed in September 2025.
APT GROUPfinancialhigh
SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines and backups, causing significant disruptions to services. The group's name is a play on the word "ESXi," indicating a deliberate focus on these systems. SEXi has been linked to other ransomware variants based on the Babuk source code.
APT GROUP
Malware family tracked by Malpedia. ID: elf.sedexp
APT GROUP
Malware family tracked by Malpedia. ID: elf.seconddate
APT GROUPespionageadvanced
According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service. The malware is designed to listen to commands received from the Threat Actor’s Command-and-Control through TCP packets. When executed, the malware uses libpcap sniffer to monitor traffic for a magic packet on TCP port 25 (SMTP) and TCP port 587. It checks the network packet captured for a hard-coded string. When the right sequence of packet is captured, it establishes a TCP reverse shell to the C2 server for further exploitation. This allows the TA to execute arbitrary commands on the compromised system.
The malware is based on an open-source backdoor program named "cd00r".
APT GROUP
Malware family tracked by Malpedia. ID: elf.sbidiot
APT GROUP
Satori is a variation of elf.mirai which was first detected around 2017-11-27 by 360 Netlab. It uses exploit to exhibit worm-like behaviour to spread over ports 37215 and 52869 (CVE-2014-8361).
APT GROUP
According to Mandiant, SALTWATER is a module for the Barracuda SMTP daemon (bsmtpd) that has backdoor functionality. SALTWATER can upload or download arbitrary files, execute commands, and has proxy and tunneling capabilities. The backdoor is implemented using hooks on the send, recv, close syscalls via the 3rd party kubo/funchook hooking library, and amounts to five components, most of which are referred to as "Channels" within the binary. In addition to providing backdoor and proxying capabilities, these components exhibit classic backdoor functionality.
APT GROUP
According to Cisco Talos, RushDrop is a dropper used by UAT-7290 for deploying SilentRaid
APT GROUP
Malware family tracked by Malpedia. ID: elf.rude_devil
APT GROUP
Malware family tracked by Malpedia. ID: elf.rshell
APT GROUPespionageadvanced
RotaJakiro is a stealthy Linux backdoor which remained undetected between 2018 and 2021.
The malware uses rotating encryption to encrypt the resource information within the sample, and C2 communication, using a combination of AES, XOR, ROTATE encryption and ZLIB compression.
APT GROUP
P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows attackers to run malicious code with root privileges and take over older Webmin versions. Based on the Netlabs360 analysis, the botnet serves mainly 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs and four DDoS attack methods: ICMP Flood, HTTP Flood, TCP Flood, and UDP Flood.
APT GROUP
Malware family tracked by Malpedia. ID: elf.rhombus
APT GROUP
Malware family tracked by Malpedia. ID: elf.rex
APT GROUP
Malware family tracked by Malpedia. ID: elf.reptile
APT GROUP
A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers. The Trojan’s configuration data is stored in a file encrypted with XOR algorithm.
Some versions have there configuration stored within the .data section using RC4 to encrypt the details.
Configuration options include C2 IP and Port, as well as defence evasion details for changing the process name.
APT GROUPfinancialhigh
Ransomware that targets Linux VMware ESXi servers. Encryption procedure uses the NTRUEncrypt public-key encryption algorithm.
APT GROUPespionageadvanced
RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR. Believed to be developed by Chinese nation-state actors, this malware shows similarities to other malware associated with the Winnti umbrella threat group.
RedXOR uses various techniques such as open-source LKM rootkits, Python pty shell, and network data encoding with XOR. It also employs persistence methods and communication with a Command and Control server over HTTP.
The malware can execute various commands including system information collection, updates, shell commands, and network tunneling.
APT GROUP
RedTail is a cryptomining malware, which is based on the open-source XMRIG mining software. It is being spread via known vulnerabilities such as:
- CVE-2024-3400
- CVE-2023-46805
- CVE-2024-21887
- CVE-2023-1389
- CVE-2022-22954
- CVE-2018-20062
rbs srv
Technical ID: rbs_srv
APT GROUP
Malware family tracked by Malpedia. ID: elf.rbs_srv
rat hodin
Technical ID: rat_hodin
APT GROUP
Malware family tracked by Malpedia. ID: elf.rat_hodin
APT GROUP
Malware family tracked by Malpedia. ID: elf.raspberrypibotnet
APT GROUP
A Mirai derivate bruteforcing SSH servers.
APT GROUP
According to IBM Security X-Force, this is a new but functionally very similar version of RansomExx, fully rewritten in Rust and internally referred to as RansomExx2.
APT GROUP
Malware family tracked by Malpedia. ID: elf.rakos
APT GROUP
Malware family tracked by Malpedia. ID: elf.r2r2
APT GROUP
Mandiant observed this backdoor being observed by UNC3524. It is based on the open-source Dropbear SSH source code.
APT GROUP
The malware infects QNAP NAS devices, is persisting via various mechanisms and resists cleaning by preventing firmware updates and interfering with QNAP MalwareRemover. The malware steals passwords and hashes
APT GROUPfinancialhigh
The QNAPCrypt ransomware works similarly to other ransomware, including encrypting all files and delivering a ransom note. However, there are several important differences:
1. The ransom note was included solely as a text file, without any message on the screen—naturally, because it is a server and not an endpoint.
2. Every victim is provided with a different, unique Bitcoin wallet—this could help the attackers avoid being traced.
3. Once a victim is compromised, the malware requests a wallet address and a public RSA key from the command and control server (C&C) before file encryption.
APT GROUPfinancial
Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
Affiliates: Ben
Infra: 💬 ozsxj4hwxub7gio347ac…🔗 24kckepr3tdbcomkimbo…💬 wlh3dpptx2gt7nsxcor3…+637 more
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: elf.pwnlnx
APT GROUP
According to Elastic, PUMAKIT is a sophisticated loadable kernel module (LKM) rootkit that employs advanced stealth mechanisms to hide its presence and maintain communication with command-and-control servers.
The rootkit component, referenced by the malware authors as “PUMA", employs an internal Linux function tracer (ftrace) to hook 18 different syscalls and several kernel functions, enabling it to manipulate core system behaviors. Unique methods are used to interact with PUMA, including using the rmdir() syscall for privilege escalation and specialized commands for extracting configuration and runtime information.
Key functionalities of the kernel module include privilege escalation, hiding files and directories, concealing itself from system tools, anti-debugging measures, and establishing communication with command-and-control (C2) servers.
There is also an accompanying userland SO rootkit internally referred to as Kitsune.