Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,728 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.pumabot
APT GROUP
Unit 42 describes this as a malware used by Rocke Group that deploys an XMRig miner.
APT GROUP
Black Lotus Labs identified malware for the Windows Subsystem for Linux (WSL). Mostly written in Python but compiled as Linux ELF files.
APT GROUP
Malware family tracked by Malpedia. ID: elf.prism
APT GROUP
According to Sekoia, this is a form of TLS backdoor containing pre-defined commands. Their investigation initially identified Cisco routers as a target but they also uncovered other payloads from the same family, but targeting different devices, notably Asus, QNAP and Synology. A working hypothesis suggests that devices compromised with PolarEdge could be used as Operational Relay Boxes (ORB) to facilitate offensive cyber operations.
APT GROUP
According to Nexttron Systems, this is an implant built as a malicious PAM (Pluggable Authentication Module), enabling attackers to silently bypass system authentication and gain persistent SSH access.
APT GROUP
According to Mandiant, this is backdoor which hooks the accept and setsockopt of the web process by modifying its procedure linkage table (PLT). This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.
APT GROUP
According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.
APT GROUP
According to Mandiant, this is a SparkGateway plugin that loads LITTLELAMB.WOOLTEA through JNI.
APT GROUP
A botnet with P2P and centralized C&C capabilities.
APT GROUP
Malware family tracked by Malpedia. ID: elf.pingpull
APT GROUP
Malware family tracked by Malpedia. ID: elf.pigmy_goat
PG MEM
Technical ID: PG_MEM
APT GROUP
Malware family tracked by Malpedia. ID: elf.pg_mem
APT GROUP
Malware family tracked by Malpedia. ID: elf.persirai
APT GROUP
Malware family tracked by Malpedia. ID: elf.perlbot
APT GROUP
Malware family tracked by Malpedia. ID: elf.perfctl
APT GROUP
Malware family tracked by Malpedia. ID: elf.penquin_turla
APT GROUP
P2P botnet derived from the Mirai source code.
APT GROUP
P2Pinfect is a fast-growing multi platform botnet, the purpose of which is still unknown. Written in Rust, it is compatible with Windows and Linux, including a MIPS variant for Linux based routers and IoT devices. It is capable of brute forcing SSH logins and exploiting Redis servers in order to propagate itself both to random IPs on the internet and to hosts it can find references to in files present on the infected system.
APT GROUP
According to Yarix digital security, this is a malware that allows to sniff on HTTPS traffic, implemented as Apache module.
APT GROUP
Mirai variant by actor "Anarchy" that used CVE-2017-17215 in July 2018 to compromise 18,000+ devices.
APT GROUP
According to stormshield, Orbit is a two-stage malware that appeared in July 2022, discovered by Intezer lab. Acting as a stealer and backdoor on 64-bit Linux systems, it consists of an executable acting as a dropper and a dynamic library.
APT GROUP
Researchers at FireEye report finding a hacking group (dubbed NOTROBIN) that has been bundling mitigation code for NetScaler servers with its exploits. In effect, the hackers exploit the flaw to get access to the server, kill any existing malware, set up their own backdoor, then block off the vulnerable code from future exploit attempts by mitigation.
APT GROUPespionageadvanced
According to Black Lotus Labs, Nosedive is a custom variation of the Mirai implant that is supported on all major SOHO and IoT architectures (e.g. MIPS, ARM, SuperH, PowerPC, etc.). Nosedive implants are typically deployed from Tier 2 payload servers in the Raptor Train infrastructure through a unique URL encoding scheme and domain injection method. Nosedive droppers use this method to request payloads for specific C2s by encoding the requested C2 domain and joining it with a unique "key" that identifies the bot and the target architecture of the compromised device (e.g. MIPS, ARM, etc.), which is then injected into the Nosedive implant payload that is deployed to the Tier 1 node. Once deployed, Nosedive runs in-memory only and allows the operators to execute commands, upload and download files, and run DDoS attacks on compromised devices.
The malware and its associated droppers are memory-resident only and deleted from disk. This, in addition to anti-forensics techniques employed on these devices including the obfuscation of running process names, compromising devices through a multi-stage infection chain, and killing remote management processes, makes detection and forensics much more difficult.
APT GROUP
Malware family tracked by Malpedia. ID: elf.noodrat
APT GROUP
Malware family tracked by Malpedia. ID: elf.noabot
APT GROUP
Golang-based RAT that offers execution of shell commands and download+run capability.
APT GROUPfinancialhigh
Ransomware used against Linux servers.
APT GROUP
Malware family tracked by Malpedia. ID: elf.mumblehard
APT GROUP
MrBlack, first identified in May 2014 by Russian security firm Dr. Web, is a botnet that targets Linux OS and is designed to conduct distributed denial-of-service (DDoS) attacks. In May 2015, Incapsula clients suffered a large-scale DDoS attack which the company attributed to network traffic generated by tens of thousands of small office/home office (SOHO) routers infected with MrBlack. This massive botnet spans over 109 countries, especially in Thailand and Brazil.
MrBlack scans for and infects routers that have not had their default login credentials changed and that allow remote access to HTTP and SSH via port 80 and port 22, respectively. One of the most impacted router brands is Ubiquiti, a U.S.-based firm that provides bulk network hub solutions for internet service providers to lease to their customers. Once a vulnerable router is compromised and MrBlack is injected into the system, a remote server is contacted and system information from the device is transmitted. This allows the host server to receive commands in order to perform different types of DDoS attacks, download and execute files, and terminate processes.
APT GROUP
Mozi is a IoT botnet, that makes use of P2P for communication and reuses source code of other well-known malware families, including Gafgyt, Mirai, and IoT Reaper.
APT GROUP
Malware family tracked by Malpedia. ID: elf.moose
APT GROUP
Malware family tracked by Malpedia. ID: elf.moobot
APT GROUPfinancial
Monti is a ransomware group first observed in June 2022 that initially copied nearly all of Conti's leaked source code, pivoting to target government, legal, and healthcare entities, later releasing a new Linux variant in 2023 with significantly less Conti code similarity, and experimenting with an affiliate model.
Affiliates: Wazawaka
Infra: 🔗 4s4lnfeujzo67fy2jebz…🔗 mblogci3rudehaagbryj…📁 fzuaswymt34cbkneudij…+18 more
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: elf.momentum
APT GROUP
According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast Reverse Proxy (FRP) client that handles the actual tunneling.
APT GROUP
Malware family tracked by Malpedia. ID: elf.mikey
APT GROUP
A x64 ELF file infector with non-destructive payload.
APT GROUP
MESSAGETAP is a 64-bit ELF data miner initially loaded by an installation script. It is designed to monitor and save SMS traffic from specific phone numbers, IMSI numbers and keywords for subsequent theft.
APT GROUP
Malware family tracked by Malpedia. ID: elf.melofee