Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,728 entities
APT GROUP
Malware family tracked by Malpedia. ID: elf.hideandseek
APT GROUP
HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.
APT GROUP
Lumen discovered this malware used in campaign targeting business-grade routers using a RAT they call HiatusRAT and a variant of tcpdump for traffic interception.
APT GROUPfinancial
Helldown is an aggressive ransomware group first documented in August 2024, known for exploiting Zyxel firewall vulnerabilities to gain initial access and conducting large-scale data exfiltration averaging 70 GB per victim, targeting IT services, telecommunications, manufacturing, and healthcare primarily in the US.
Infra: 🔗 onyxcgfg4pjevvp5h34z…🔗 onyxcym4mjilrsptk5uo…🔗 www.helldown.org…+1 more
RLUpdated: 2026-08-06
View profile →APT GROUP
Malware family tracked by Malpedia. ID: elf.headcrab
APT GROUP
Malware family tracked by Malpedia. ID: elf.hand_of_thief
APT GROUP
Malware family tracked by Malpedia. ID: elf.handymannypot
APT GROUP
Malware family tracked by Malpedia. ID: elf.hakai
APT GROUP
Malware family tracked by Malpedia. ID: elf.hajime
APT GROUP
Malware family tracked by Malpedia. ID: elf.haiduc
APT GROUP
Malware family tracked by Malpedia. ID: elf.hadooken
APT GROUP
According to Mandiant, GRIMBOLT is a C#-written foothold backdoor compiled using native ahead-of-time (AOT) compilation and packed with UPX. It provides a remote shell capability and uses the same command and control as previously deployed BRICKSTORM payload. It's unclear if the threat actor's replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response.
APT GROUP
Malware family tracked by Malpedia. ID: elf.greedyantd
APT GROUP
GoTitan is a DDoS bot under development, which support ten different methods of launching distributed denial-of-service (DDoS) attacks: UDP, UDP HEX, TCP, TLS, RAW, HTTP GET, HTTP POST, HTTP HEAD, and HTTP PUT.
APT GROUP
Malware family tracked by Malpedia. ID: elf.gosh
APT GROUP
Gorilla is a threat-actor operating a DoS-as-a-service service controlled on Telegram.
APT GROUP
GOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).
APT GROUP
Malware family tracked by Malpedia. ID: elf.goreshell
APT GROUP
Malware family tracked by Malpedia. ID: elf.gomir
APT GROUPespionageadvanced
According to LAC, this malware is written in Go and was observed in 2022 used by an unknown China-based APT across several incidents in Japan. This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
APT GROUP
Malware family tracked by Malpedia. ID: elf.godlua
APT GROUP
Malware family tracked by Malpedia. ID: elf.gobrat
APT GROUP
ARM32 SOCKS proxy, written in Go, used in the Glupteba campaign.
APT GROUP
Gitpaste-12 is a modular malware first observed in October 2020 targeting Linux based x86 servers, as well as Linux ARM and MIPS based IoT devices. It uses GitHub and Pastebin as dead drop C2 locations.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ghostpenguin
APT GROUP
Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. It is a worm which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk.
APT GROUP
This family utilizes custom modules allowing for remote access, credential harvesting (e.g. by modifying sshd) and proxy usage.
It comes with a rootkit as well.
APT GROUP
Malware used to run a DDoS botnet.
APT GROUP
Malware family tracked by Malpedia. ID: elf.floodor
APT GROUP
Malware family tracked by Malpedia. ID: elf.flodrix
APT GROUP
Malware family tracked by Malpedia. ID: elf.firewood
APT GROUP
Malware family tracked by Malpedia. ID: elf.fbot
APT GROUP
Malware family tracked by Malpedia. ID: elf.facefish
APT GROUP
Malware family tracked by Malpedia. ID: elf.ext4
APT GROUP
Malware family tracked by Malpedia. ID: elf.ewdoor
APT GROUP
According to Infosec Institute, EvilGnome presents itself to unwitting Linux users as a legitimate GNOME extension. Legitimate extensions help to extend Linux functionality, but instead of a healthy boost in system functionality, EvilGnome begins spying on users with an array of functionalities uncommon for most Linux malware types.
APT GROUP
According to the author, Evilginx is a standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication.
APT GROUPfinancialhigh
Ransomware used to target ESXi servers.
APT GROUP
According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks. This threat, which seems to be disseminated by the Keksec group, expanded its features by adding recent vulnerabilities discovered in 2022. It was designed to attack web servers, Android devices and content management systems (CMS) servers.
APT GROUP
Malware family tracked by Malpedia. ID: elf.elevator