Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,728 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.matryosh
APT GROUP
Masuta is a variant of Mirai that targets IoT devices, primarily routers, using dictionary attacks to target weak credentials. PureMasuta is a variant of Masuta that targets the EDB 38722 D-Link HNAP Bug.
APT GROUP
Malware family tracked by Malpedia. ID: elf.masol
APT GROUP
According to Akamai, a Mirai variant exploiting GeoVision IoT devices, (possibly CVE-2024-6047 and/or CVE-2024-11120).
APT GROUPfinancialhigh
ESXi encrypting ransomware written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: elf.lootwodniw
APT GROUP
Malware family tracked by Malpedia. ID: elf.log_collector
APT GROUP
Loader and Cleaner components used in attacks against high-performance computing centers in Europe.
APT GROUP
According to ESET Research, LittleDaemon is the first stage deployed on the victim’s machine through hijacked updates. It was observed in both DLL and executable versions, both of them 32-bit PEs. The main purpose of LittleDaemon is to communicate with the hijacking node to obtain the downloader that we call DaemonicLogistics. LittleDaemon does not establish persistence.
APT GROUP
BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has recently incorporated Monero cryptocurrency mining features. Interestingly, LiquorBot is written in Go (also known as Golang), which offers some programming advantages over traditional C-style code, such as memory safety, garbage collection, structural typing, and even CSP-style concurrency.
APT GROUP
Malware family tracked by Malpedia. ID: elf.linodas
APT GROUP
According to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
APT GROUP
Malware family tracked by Malpedia. ID: elf.lilyofthevalley
APT GROUP
Malware family tracked by Malpedia. ID: elf.lilock
APT GROUP
Malware family tracked by Malpedia. ID: elf.lightning
APT GROUP
Malware family tracked by Malpedia. ID: elf.leethozer
APT GROUP
Malware family tracked by Malpedia. ID: elf.lady
APT GROUP
According to the author if this open source project, this is a library for injecting a shared library into a Linux, Windows and MacOS process.
APT GROUP
ELF x64 Rust downloader first discovered on Ivanti Connect Secure VPN after the exploitation of CVE-2024-21887 and CVE-2023-46805. Downloads Sliver backdoor and deletes itself.
APT GROUP
Malware family tracked by Malpedia. ID: elf.krasue_rat
APT GROUP
Malware family tracked by Malpedia. ID: elf.kobalos
APT GROUP
Malware family tracked by Malpedia. ID: elf.kitty_soks5
APT GROUP
This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear if they conducted the attacks themselves, or if they bought leaked databases from third parties.
APT GROUP
Malware family tracked by Malpedia. ID: elf.kfos
APT GROUP
Malware family tracked by Malpedia. ID: elf.keyplug
APT GROUP
Malware family tracked by Malpedia. ID: elf.kerberods
APT GROUP
According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities. The trojan does not create any copies of itself. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
APT GROUP
Surfaced in late April 2020, Intezer describes Kaiji as a DDoS malware written in Go that spreads through SSH brute force attacks. Recovered function names are an English representation of Chinese words, hinting about the origin. The name Kaiji was given by MalwareMustDie based on strings found in samples.
APT GROUP
According to Black Lotus Labs, KadNap primarily targets Asus routers, conscripting them into a botnet that proxies malicious traffic. It employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring.
APT GROUP
Kaden is a DDoS botnet that is heavily based on Bashlite/Gafgyt. Next to DDoS capabilities it contains wiper functionality, which currently can not be triggerred (yet).
APT GROUP
According to Lumen, J-Magic is a variant of cd00r and passively scans for five different predefined parameters before activating. If any of these parameters or “magic packets” are received, the agent sends back a secondary challenge. Once that challenge is complete, J-magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or deploy malicious software.
APT GROUP
Malware family tracked by Malpedia. ID: elf.jenx
APT GROUP
ccording to Fortinet, this is a Mirai-based DDoS botnet.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: elf.inc
APT GROUP
Malware family tracked by Malpedia. ID: elf.icnanker
APT GROUPfinancial
IceFire is a ransomware group first observed in 2022 that expanded to Linux in early 2023 by exploiting a vulnerability in IBM Aspera Faspex (CVE-2022-47986), targeting media and entertainment organizations in Turkey, Iran, Pakistan, and the UAE using double-extortion tactics.
Infra: 🔗 kf6x3mjeqljqxjznaw65…🔗 7kstc545azxeahkduxme…💬 nxx3cy6aee2s53v7v5px…
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: elf.hubnr
APT GROUP
Checkpoint Research describes this as part of a custom firmware image affiliated with the Chinese state-sponsored actor “Camaro Dragon”, a custom MIPS32 ELF implant. HorseShell, the main implant inserted into the modified firmware by the attackers, provides the attacker with 3 main functionalities:
* Remote shell: Execution of arbitrary shell commands on the infected router
* File transfer: Upload and download files to and from the infected router.
* SOCKS tunneling: Relay communication between different clients.
APT GROUP
Malware family tracked by Malpedia. ID: elf.hipid
APT GROUP
HinataBot is a Go-based DDoS-focused botnet. It was observed in the first quarter of 2023 targeting HTTP and SSH endpoints leveraging old vulnerabilities and weak credentials. Amongst those infection vectors are exploitation of the miniigd SOAP service on Realtek SDK devices (CVE-2014-8361), Huawei HG532 routers (CVE-2017-17215), and exposed Hadoop YARN servers.