Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,728 entities
APT GROUP
According to ESET Research, EdgeStepper is an adversary-in-the-middle tool, which forwards DNS traffic from machines in a targeted network to a malicious DNS node. This allows the attackers to redirect the traffic from software updates to a hijacking node that serves instructions to the legitimate software to download a malicious update.
APT GROUP
The latest in this long line of Mirai scourges is a new variant named Echobot. Coming to life in mid-May, the malware was first described by Palo Alto Networks in a report published at the start of June, and then again in a report by security researchers from Akamai, in mid-June. When it was first spotted by Palo Alto Networks researchers in early June, Echobot was using exploits for 18 vulnerabilities. In the Akamai report, a week later, Echobot was at 26. https://www.zdnet.com/article/new-echobot-malware-is-a-smorgasbord-of-vulnerabilities
APT GROUP
This payload has been used to compromise kernel.org back in August of 2011 and has hit cPanel Support which in turn, has infected quite a few cPanel servers. It is a credential stealing payload which steals SSH keys, passwords, and potentially other credentials. This family is part of a wider range of tools which are described in detail in the operation windigo whitepaper by ESET.
APT GROUP
According to Cisco Talos, DriveSwitch is a launcher for SilentRaid.
APT GROUP
Malware family tracked by Malpedia. ID: elf.dreambus
APT GROUP
Malware family tracked by Malpedia. ID: elf.doki
APT GROUP
Dofloo (aka AESDDoS) is a popular malware used to create large scale botnets that can launch DDoS attacks and load cryptocurrency miners to the infected machines.
APT GROUP
Malware family tracked by Malpedia. ID: elf.disgomoji
APT GROUP
Cado discovered this malware, written in Go and targeting AWS Lambda environments.
APT GROUP
Malware family tracked by Malpedia. ID: elf.decoy_dog
APT GROUPfinancialhigh
DEADBOLT is a linux ransomware written in Go, targeting QNAP NAS devices worldwide. The files are encrypted with AES128 encryption and will have the .deadbolt extension appended to file names.
APT GROUP
Malware family tracked by Malpedia. ID: elf.ddoor
APT GROUP
First activity observed in October 2017. DDG is a botnet with P2P capability that is targeting crypto currency mining (Monero).
APT GROUP
Malware family tracked by Malpedia. ID: elf.dark_radiation
APT GROUP
Malware family tracked by Malpedia. ID: elf.darknexus
APT GROUP
A sophisticated payload delivery and upgrade framework, discovered in 2024. DarkCracks exploits compromised GLPI and WordPress sites to function as Downloaders and C2 servers.
APT GROUP
Mirai variant exploiting CVE-2021-20090 and CVE2021-35395 for spreading.
APT GROUP
According to CISA, Cyclops Blink appears to be a replacement framework for the VPNFilter malware exposed in 2018, and which exploited network devices, primarily small office/home office (SOHO) routers and network attached storage (NAS) devices. Cyclops Blink has been deployed since at least June 2019, fourteen months after VPNFilter was disrupted. In common with VPNFilter, Cyclops Blink deployment also appears indiscriminate and widespread. The actor has so far primarily deployed Cyclops Blink to WatchGuard and ASUS devices, but it is likely that Sandworm would be capable of compiling the malware for other architectures and firmware.
APT GROUP
A malware written in Bash that hides in the Linux calendar system on February 31st. Observed in relation to Magecart attacks.
APT GROUP
Malware family tracked by Malpedia. ID: elf.cr1ptt0r
APT GROUP
Malware family tracked by Malpedia. ID: apk.cpuminer
APT GROUP
ConnectBack malware is a type of malicious software designed to establish unauthorized connections from an infected system to a remote server. Once a victim's device is compromised, ConnectBack creates a covert channel for communication, allowing the attacker to remotely control and gather sensitive information from the compromised system.
According to CISA, this is an implant found in firmware for the Contec CMS8000, a patient monitor used by the Healthcare and Public Health sector. An embedded backdoor function with a hard-coded IP address and functionality that enables patient data spillage was identified.
APT GROUP
Malware family tracked by Malpedia. ID: elf.cloud_snooper
APT GROUP
Malware family tracked by Malpedia. ID: elf.chapro
APT GROUP
Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua. Variants exist for multiple architectures and it incorporates code from XorDDoS and Mirai.
APT GROUP
Malware family tracked by Malpedia. ID: elf.cetus
APT GROUP
Malware family tracked by Malpedia. ID: elf.cephei
APT GROUP
Malware family tracked by Malpedia. ID: elf.cdrthief
APT GROUP
This is in the same family as eBury, Calfbot, and is also likely related to DarkLeech
APT GROUP
A backdoor for UNIX operating systems that implements knocking as authentication method.
APT GROUP
XMRig-based mining malware written in Go.
APT GROUP
According to Avast Decoded, Caligula is an IRC multiplatform bot that allows to perform DDoS attacks. It is written in Go and distributed in ELF files targeting Intel 32/64bit code, as well as ARM 32bit and PowerPC 64bit. It is based on the Hellabot open source project.
APT GROUP
Linux malware cross-compiled for x86, MIPS, ARM. XOR encoded strings, 13 commands supported for its C&C, including downloading, file modification and execution and ability to run shell commands.
APT GROUP
Pangu Lab discovered this backdoor during a forensic investigation in 2013. They refer to related incidents as "Operation Telescreen".
APT GROUP
According to Mandiant, this is a webshell, written in Perl.
brute ratel
Technical ID: brute_ratel
APT GROUP
Malware family tracked by Malpedia. ID: elf.brute_ratel
APT GROUP
According to Google, BRICKSTORM is used to consistently target appliances, among them primarily VMware vCenter and ESXi hosts.
APT GROUP
BPFDoor is a passive backdoor used by a China-based threat actor. This backdoor supports multiple protocols for communicating with a C2 including TCP, UDP, and ICMP allowing the threat actor a variety of mechanisms to interact with the implant.
APT GROUP
According to Alien Labs, this malware targets embedded devices including routers with more than 30 exploits. SourceCode: https://github.com/Egida/kek/blob/19991ef983f838287aa9362b78b4ed8da0929184/loader_multi.go (2021-10-16)