Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,728 entities
APT GROUP
Malware family tracked by Malpedia. ID: apk.xbot
APT GROUP
Malware family tracked by Malpedia. ID: apk.wyrmspy
APT GROUPfinancialhigh
According to Avira, this is a banking trojan targeting Japan.
APT GROUP
Malware family tracked by Malpedia. ID: apk.wolf_rat
APT GROUP
Malware family tracked by Malpedia. ID: apk.wirex
APT GROUP
Malware family tracked by Malpedia. ID: apk.vultur
APT GROUP
According to Xlab, this malware is used to compromise Android TVs and set-top boxes, and its corresponding botnet had more than 1 million nodes observed via sinkholing (Jan 2025).
APT GROUP
Malware family tracked by Malpedia. ID: apk.viper_rat
APT GROUP
According to Mandiant, VINETHORN is an Android malware family capable of a wide range of backdoor functionality. It can steal system information, read SMS inboxes, send SMS messages, access contact lists and call histories, record audio and video, and track device location via GPS.
APT GROUP
Related to the micropsia windows malware and also sometimes named micropsia.
APT GROUP
Malware family tracked by Malpedia. ID: apk.vajraspy
According to Google, a Chrome reconnaissance payload
APT GROUPfinancialhigh
Android malware distributed through fake shopping websites targeting Malaysian users, targeting banking information.
According to Cyble, this is an Android application that pretends to be the legitimate application for the Army Mobile Aadhaar App Network (ARMAAN), intended to be used by Indian army personnel. The application was customized to include RAT functionality.
APT GROUPfinancialhigh
Information stealer posing as a fake banking app, targeting Korean users.
Malware family tracked by Malpedia. ID: apk.unidentified_005
Updated: 2023-07-24
View profile →
According to Check Point Research, this is a RAT that is disguised as a set of dating apps like "GrixyApp", "ZatuApp", "Catch&See", including dedicated websites to conceal their malicious purpose.
Malware family tracked by Malpedia. ID: apk.unidentified_002
Updated: 2017-08-31
View profile →
Malware family tracked by Malpedia. ID: apk.unidentified_001
APT GROUP
Malware family tracked by Malpedia. ID: apk.ultima_sms
APT GROUPespionageadvanced
According to Cyble, this is a banking trojan that targets over 750 applications globally, including banking, finance, cryptocurrency, and e-commerce apps. The malware spreads via phishing sites masquerading as legitimate financial platforms and is installed through a dropper disguised as Google Play Services. It uses overlay attacks to steal banking credentials, credit card details, and login credentials by displaying fake login pages over legitimate apps. TsarBot can record and remotely control the screen, executing fraud by simulating user actions such as swiping, tapping, and entering credentials while hiding malicious activities using a black overlay screen. It captures device lock credentials using a fake lock screen to gain full control. TsarBot communicates with its C&C server using WebSocket across multiple ports to receive commands, send stolen data, and dynamically execute on-device fraud.
APT GROUP
Bitdefender described Triout as a Android spyware, which appears to act as a framework for building extensive surveillance capabilities into seemingly benign applications. Found bundled with a repackaged app, the spyware’s surveillance capabilities involve hiding its presence on the device, recording phone calls, logging incoming text messages, recoding videos, taking pictures and collecting GPS coordinates, then broadcasting all of that to an attacker-controlled C&C (command and control) server.
Updated: 2018-10-23
View profile →
APT GROUPfinancialhigh
TrickMo is an advanced banking trojan for Android. Starting out as a companion malware to TrickBot in 2020, it first became a standalone banking trojan by addition of overlay attacks in 2021 and was later (2024) upgraded with remote control capabilities for on-device fraud. The continued development and progressively improved obfuscation suggests an active Threat Actor.
APT GROUP
Triada is a remote access trojan (RAT) malware that is used to compromise Android devices in order to steal confidential and sensitive information such as credit card numbers, passwords, bank account information, etc. It also provides a backdoor for attackers to include the device as part of a botnet and perform other malicious activities.
APT GROUP
A group targeting dissident groups in China and at the boundaries.
🇨🇳 CN
Updated: 2026-08-06
View profile →
APT GROUPfinancial
Founded 4 April 2026
Infra: 🔗 x4bccxlsmjsxlnnf3ocv🔗 titanblog.org🔗 x4bccxlsmjsxlnnf3ocv
RLUpdated: 2026-08-06
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: apk.tinyz
APT GROUP
According to Trend Micro, this malware appears to have been designed to steal credentials associated with membership websites of major Japanese telecommunication services.
APT GROUP
Malware family tracked by Malpedia. ID: apk.thiefbot
APT GROUPfinancialhigh
According to Trend Micro, TgToxic has been used in an ongoing campaign that has been targeting Android users in Southeast Asia since July 2022. Goal of the campaign is to steal victims’ assets from finance and banking applications (such as cryptocurrency wallets, credentials for official bank apps on mobile, and money in deposit), via a banking trojan they named TgToxic (based on its special encrypted filename) embedded in multiple fake apps. While previously targeting users in Taiwan, Trend Micro observed the fraudulent activities and phishing lures targeting users from Thailand and Indonesia as of this writing. Users are advised to be wary of opening embedded links from unknown email and message senders, and to avoid downloading apps from third party platforms.
Tempting cedar spyware is an Android spyware campaign, active since at least 2015, that used social engineering via fake, attractive Facebook profiles to trick victims into downloading malware. The spyware was designed to steal a wide range of sensitive personal data.
APT GROUP
Malware family tracked by Malpedia. ID: apk.telerat
APT GROUP
Malware family tracked by Malpedia. ID: apk.tangle_bot
APT GROUP
Malware family tracked by Malpedia. ID: apk.talent_rat
APT GROUP
Malware family tracked by Malpedia. ID: apk.switcher
APT GROUPfinancialhigh
Svpeng is a malicious banking trojan targeting Android devices, and it poses a significant threat to both mobile users and the developers of mobile banking apps. Svpeng has been active since around 2013. It primarily targets Android users, and its main objective is to steal sensitive financial information, particularly login credentials and personal data related to banking and financial apps. Svpeng typically spreads through malicious apps, phishing campaigns, or drive-by downloads.
APT GROUPespionageadvanced
According to ThreatFabric, Sturnus is a privately operated Android banking trojan. This malware supports a broad range of fraud-related capabilities, including full device takeover. A key differentiator is its ability to bypass encrypted messaging. By capturing content directly from the device screen after decryption, Sturnus can monitor communications via WhatsApp, Telegram, and Signal. The trojan can harvest banking credentials through convincing fake login screens that replicate legitimate banking apps. In addition, it provides attackers with extensive remote control, enabling them to observe all user activity, inject text without physical interaction, and even black out the device screen while executing fraudulent transactions in the background—without the victim’s knowledge.
APT GROUP
Malware family tracked by Malpedia. ID: apk.stealthmango
APT GROUP
Malware family tracked by Malpedia. ID: apk.stealthagent
APT GROUP
According to Cleafy, SpyNote abuses Accessibility services and other Android permissions in order to: Collect SMS messages and contacts list; Record audio and screen; Perform keylogging activities; Bypass 2FA; Track GPS locations.