Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
According to Cleafy, the victim's Android device is factory reset after the attackers siphon money from the victim's bank account. This distracts users from the crime, while removing traces or footprints that might be of interest to forensic analysts.
APT GROUPfinancialhigh
According to PCrisk, BraDex is a banking malware targeting Android operating systems. This malicious program aims to gain access to victims' bank accounts and make fraudulent transactions. At the time of writing, BrasDex targets Brazilian banking applications exclusively. In previous BrasDex campaigns, it infiltrated devices under the guise of Android system related apps. Lately, this malware has been installed by a fake Brazilian Banco Santander banking application.
APT GROUP
According to Lookout, BoneSpy is based on the Russian-developed, open-source DroidWatcher surveillanceware, featuring nearly identical code, names, and log messages in multiple classes related to the handling of databases containing collected exfil data such as call logs, location tracking, SMS messages, notifications, and browser bookmarks. Class names for many entry points (receivers, activities, and services) were either the same or very similar to DroidWatcher samples.
APT GROUP
Malware family tracked by Malpedia. ID: apk.blankbot
APT GROUP
Malware family tracked by Malpedia. ID: apk.bingomod
APT GROUP
Malware family tracked by Malpedia. ID: apk.basbanke
APT GROUP
Malware family tracked by Malpedia. ID: apk.badpatch
APT GROUP
According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android electronics with preinstalled malware.
APT GROUP
BadBazaar is a type of malware primarily functioning as a spyware. Designed to compromise Android and iOS devices, it is often distributed through malicious apps downloaded from unofficial app stores, third-party websites, Telegram channels, and social engineering. Once installed, BadBazaar seeks to surveil the victim by intercepting SMS messages, performing screen recordings, and logging keystrokes on the device. Additionally, it can execute remote commands and download and install other malicious applications, further compromising the security of the affected device.
APT GROUPfinancialhigh
According to EnigmaSoft, AxBanker is a banking Trojan targeting Android devices specifically. The threatening tool has been deployed as part of large attack campaigns against users in India. The threat actors use smishing (SMS phishing) techniques to smuggle the malware threat onto the victims' devices. The fake applications carrying AxBanker are designed to visually impersonate the official applications of popular Indian banking organizations. The weaponized applications use fake promises or rewards and discounts as additional lures.
APT GROUPfinancialhigh
According to Lukas Stefanko, this is an open-source crypto-ransomware found on Github in 2018. IT can en/decrypt files (AES, key: 32 random chars, sent to C&C), uses email as contact point but will remove all files after 24 hours or after a reboot.
APT GROUP
Malware family tracked by Malpedia. ID: apk.ashas
APT GROUP
Malware family tracked by Malpedia. ID: apk.asacub
APT GROUP
Malware family tracked by Malpedia. ID: apk.anubisspy
APT GROUP
The malware displays fake Google Play update pages in multiple languages, including German, French, Spanish, Russian, Portuguese, Romanian, and English, indicating potential targets in these regions. Antidot uses overlay attacks and keylogging techniques to efficiently collect sensitive information such as login credentials.
APT GROUP
According to Google, a Chrome cookie stealer.
APT GROUP
Androrat is a remote administration tool developed in Java Android for the client side and in Java/Swing for the Server. The name Androrat is a mix of Android and RAT (Remote Access Tool). It has been developed in a team of 4 for a university project. The goal of the application is to give the control of the android system remotely and retrieve informations from it.
APT GROUP
Malware family tracked by Malpedia. ID: apk.anatsa
APT GROUP
This malware was initially named BlackRock and later renamed to AmpleBot.
APT GROUP
Malware family tracked by Malpedia. ID: apk.amextroll
APT GROUPfinancialhigh
According to ThreatFabric, this is a fork of Cerberus v1 (active January 2020+). Alien is a rented banking trojan that can remotely control a phone and achieves RAT functionality by abusing TeamViewer.
APT GROUPespionageadvanced
According to PCrisk, Ahmyth is a Remote Access Trojan (RAT) targeting Android users. It is distributed via trojanized (fake) applications. Ahmyth RAT steals cryptocurrency and banking credentials, 2FA codes, lock screen passcodes, and captures screenshots.
APT GROUP
Malware family tracked by Malpedia. ID: apk.agentsmith
APT GROUP
Malware family tracked by Malpedia. ID: apk.adultswine
APT GROUP
Malware family tracked by Malpedia. ID: apk.adobot
APT GROUP
Malware family tracked by Malpedia. ID: apk.actionspy
APT GROUP
According to PCrisk, AbstractEmu is the name of rooting malware that can gain privileged access to the Android operating system. Threat actors behind AbstractEmu are using legitimate-looking apps (like password managers, app launchers, data savers) to trick users into downloading and opening/executing this malware.
APT GROUP
Malware family tracked by Malpedia. ID: apk.aberebot
APT GROUP
According to ESET, this is a commercial, multiplatform RAT, originally developed for Windows and extended to Android. In short, it can steal and delete files from a device, take screenshots, get device location, phish Facebook credentials, get a list of installed apps, steal user photos, take photos, record surrounding audio and phone calls, make calls, steal SMS messages, steal the device’s contact list, send text messages, etc.
MALWARE
Wabot is an IRC worm that is written in Delphi.
unidentified 063
Technical ID: win.unidentified_063
MALWARE
Malware family identifying win.unidentified_063. Origin and technical characteristics tracked via Malpedia.
unidentified 059
Technical ID: win.unidentified_059
MALWARE
Malware family identifying win.unidentified_059. Origin and technical characteristics tracked via Malpedia.
sunnyday
Technical ID: win.sunnyday
MALWARE
Malware family identifying win.sunnyday. Origin and technical characteristics tracked via Malpedia.
Py2exe built worm propagating via USB drives, having wiper features embedded in the logic (based on today's date being later than 2016-04-03 and existence of a file C:\txt.txt)
InnifiRAT is coded in .NET and targets personal data on infected devices, with it's top priority appearing to be bitcoin and litecoin wallet data. InffiRAT also includes a backdoor which allows attackers to control the infected host remotely. Possibilities include loggin key stroke, taking pictures with webcam, accessing confidential information, formatting drives, and more. It attempts to steal browser cookies to steal usernames and passwords and monitors the users activities with screenshot functionality.
idat loader
Technical ID: win.idat_loader
MALWARE
Malware family identifying win.idat_loader. Origin and technical characteristics tracked via Malpedia.
IceXLoader is a commercial malware used to download and deploy additional malware on infected machines. The latest version is written in Nim, a relatively new language utilized by threat actors the past two years, most notably by the NimzaLoader variant of BazarLoader used by the TrickBot group. The v1 was written in AutoIT.
Malware family identifying win.ghostengine. Origin and technical characteristics tracked via Malpedia.
Fujinama is a custom VB info stealer capable to execute custom commands and custom exfiltrations, keylogging and screenshot. It was involved in the compromise of Leonardo SpA, a major Italian aerospace and defense company.
beep
Technical ID: win.beep
MALWARE
Malware family identifying win.beep. Origin and technical characteristics tracked via Malpedia.