Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
MALWAREfinancialhigh
Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.
Also known as: blacklockbit
A PHP webshell that allows file system management, data exfiltration and command execution.
APT GROUP
The threat actor of this family compromised Chrome extension developer accounts and attached malicious code to the extensions. Web Developer 0.4.9, Chrometana 1.1.3, Infinity New Tab 3.12.3, CopyFish 2.8.5, Web Paint 1.2.1, and Social Fixer 20.1.1 were affected by this. TouchVPN and BetterVPN were assumed to be targets as well. This lead to the execution of another Javascript that substitutes ad banners for their own, effectively hijacking ad traffic. It is also reported that fake pop-up alerts were used to lure victims to download possibly other malware.
MALWARE
Malware family identifying elf.wellmess. Origin and technical characteristics tracked via Malpedia.
elf.iocontrol
Cyber Av3ngers
MALWARE
IOControl is a Linux backdoor which targets ARM-based IoT and OT systems, which a particular focus on Fuel and Industrial Control Systems.
Also known as: OrpraCab • QueueCat
corona
Technical ID: elf.corona
MALWARE
Malware family identifying elf.corona. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to Microsoft Threat Intelligence, ChocoShell is a PowerShell-based information stealer delivered and executed entirely in memory, with the primary objective of harvesting browser session cookies, saved passwords, Microsoft 365 SSO tokens, and Wi-Fi credentials from compromised systems. It was authored with developer comments suggesting AI-assisted code generation and performs defense evasion by disabling AMSI via .NET reflection and exiting silently when virtual machine or sandbox conditions are detected. To enable its most impactful capabilities it implements several ordered silent UAC bypass techniques with fallback to a visible prompt, and impersonates a SYSTEM process token to access browser encryption keys, while also using the Chrome DevTools Protocol to extract plaintext cookies and collecting cloud tokens and Wi-Fi profiles. Collected data is aggregated into a JSON structure, GZip-compressed and Base64-encoded, then exfiltrated over an encrypted HTTPS channel to the actor's C2 server before the script cleans up artifacts and removes its temporary elevation registry keys.
APT GROUP
Malware family tracked by Malpedia. ID: win.pureminer
According to Check Point Research, AnimateClipper is a cryptocurrency clipper that is delivered through a ClickFix-style phishing chain in which a built-in Windows utility runs a remote scripted page, leading to a bundled Python environment that executes embedded shellcode in memory to load the final payload without writing the unpacked binary to disk. The malware continuously monitors the clipboard for cryptocurrency wallet addresses, identifies the wallet format locally, and silently replaces the copied address with one of many embedded attacker-controlled wallets, enabling transaction hijacking across more than 20 blockchain ecosystems. It resolves its command-and-control server dynamically by querying a smart contract over a public blockchain JSON-RPC endpoint, then communicates over HTTPS for periodic check-ins and to report address-replacement activity. The embedded replacement wallets themselves are stored directly in the binary, and on-chain data indicates the operation has been active since at least mid-2025.
APT GROUPespionageadvanced
Gunra is a highly aggressive ransomware family that first emerged in April 2025, operating as a Ransomware-as-a-Service (RaaS). It is built upon the leaked source code of the notorious Conti ransomware. As a double-extortion threat, Gunra not only encrypts the victim's data but also exfiltrates sensitive business information. The threat actors then threaten to publish this stolen data on their Tor-hosted leak sites if the ransom is not paid within a strict 5-day deadline. Gunra has a global footprint, heavily targeting critical infrastructure, healthcare, pharmaceuticals, manufacturing and real estate across both Windows and Linux environments. The name of the ransomware is derived from the malicious executable process it spawns upon infection, typically named gunraransome.exe. It systematically deletes all Volume Shadow Copies via Windows Management Instrumentation (WMI) to prevent victims from easily restoring their files. Once Gunra has secured its foothold and terminated interfering processes, it encrypts the victim's files using a combination of ChaCha20 and RSA-4096 encryption, notably featuring "step-skip" partial encryption to maximize speed. The encrypted files are easily identifiable because the malware appends the .ENCRT extension to their original filenames. In every directory where files have been encrypted, the malware drops a ransom note named R3ADM3.txt. This note informs the victim of the double extortion and provides instructions on how to contact the attackers. Victims are directed to a negotiation portal hosted on the Tor network to initiate communication, utilizing .onion addresses such as [http://gunrabxbig445sjqa535uaymzerj6fp4nwc6ngc2xughf2pedjdhk4ad.onion/]
APT GROUPespionageadvanced
CornFlake is a Go-based Windows RAT attributed to Storm-2945, a subcluster of Midnight Blizzard. The implant communicates over TLS-wrapped TCP; inside the tunnel it performs a length-prefixed JSON hello/ack exchange (0xAB/0xAC), derives a per-session AES-256-GCM key from ephemeral P-256 ECDH and a built-in secret, and exchanges opcode-driven JSON/binary messages. Startup traffic includes system-information (0x5A) and persistence (0x9E) reports. An encrypted heartbeat (0xE7) with an empty payload is sent at a randomized 18–41-second interval, while commands and results are handled asynchronously. Collection and exfiltration use a resumable upload state machine with optional gzip-compressed 64-KiB chunks, acknowledgements carrying resume offsets, and explicit completion messages. Runtime configuration supports server and collection-policy changes, hot reload, and DNS-based fallback. CornFlake maintains a machine identifier across reconnects and supports persistence, security-posture discovery, credential-hint collection, remote shell execution, keylogging, clipboard and USB monitoring, screenshots, audio/webcam capture, selective file collection, and encrypted uploads.
← PreviousPage 88 / 88Next →