Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,728 entities
APT GROUP
SpyMax is a popular Android surveillance tool. Its predecessor, SpyNote, was one of the most widely used spyware frameworks.
APT GROUP
A sophisticated mobile surveillance implant operating as a Remote Control System (RCS). This malware family is characterized by a unique, multi-sided communication architecture that abandons traditional HTTP polling. Instead, it hybridizes Firebase Cloud Messaging (FCM) for asynchronous command signaling with Fast Reverse Proxy (FRP) to establish persistent, NAT-bypassing network tunnels, effectively turning the infected mobile device into a server accessible by the attacker.
APT GROUP
Malware family tracked by Malpedia. ID: apk.spyc23
APT GROUP
Malware family tracked by Malpedia. ID: apk.spybanker
APT GROUP
Malware family tracked by Malpedia. ID: apk.sova
APT GROUP
Malware family tracked by Malpedia. ID: apk.soumnibot
APT GROUP
Malware family tracked by Malpedia. ID: apk.smsspy
Updated: 2017-11-09
View profile →
APT GROUP
SMSAgent appears as a game application, but silently performs malicious routines in the background. It attempts to download other potentially malicious files from a remote server and sends out SMS or MMS messages that places expensive charges on the user's bill.
APT GROUP
Slocker also known as jisut and pigetrl, is a screen locker that is distributed through telegram groups.
APT GROUP
Malware family tracked by Malpedia. ID: apk.slempo
APT GROUP
Malware family tracked by Malpedia. ID: apk.skygofree
APT GROUP
Malware family tracked by Malpedia. ID: apk.silkbean
APT GROUP
Shopper/LeifAccess is a malicious Android app that uses Android's AccessibilityService to secretly control the device. It installs apps, leaves fake reviews, opens ads, and even registers users on various platforms. Disguised as a system app, it collects personal and device information and sends it to remote servers. The malware was most active in late 2019, especially in Russia, Brazil, and India.
APT GROUPfinancialhigh
SharkBot is a piece of malicious software targeting Android Operating Systems (OSes). It is designed to obtain and misuse financial data by redirecting and stealthily initiating money transfers. SharkBot is particularly active in Europe (United Kingdom, Italy, etc.), but its activity has also been detected in the United States.
APT GROUPfinancialhigh
An Android ransomware that locks the device, changes the wallpaper, and demands money in exchange for unlocking the phone.
APT GROUPfinancialhigh
According to ANY.RUN, this is a banking trojan that this collection sensitive user information, including: Registered mobile number, Aadhaar number, PAN card details, Date of birth, and Net banking user ID and password. It uses Telegram as C2.
APT GROUP
Malware family tracked by Malpedia. ID: apk.rootnik
APT GROUP
Malware family tracked by Malpedia. ID: apk.rogue
According to new research by Kaspersky's GReAT team, the online criminal activities of the Roaming Mantis Group have continued to evolve since they were first discovered in April 2018. As part of their activities, this group hacks into exploitable routers and changes their DNS configuration. This allows the attackers to redirect the router user's traffic to malicious Android apps disguised as Facebook and Chrome or to Apple phishing pages that were used to steal Apple ID credentials. Recently, Kaspersky has discovered that this group is testing a new monetization scheme by redirecting iOS users to pages that contain the Coinhive in-browser mining script rather than the normal Apple phishing page. When users are redirected to these pages, they will be shown a blank page in the browser, but their CPU utilization will jump to 90% or higher.
APT GROUP
Malware family tracked by Malpedia. ID: apk.riltok
APT GROUPfinancialhigh
According to PCrisk, Revive is the name of a banking Trojan targeting Android users (customers of a specific Spanish bank). It steals sensitive information. Cybercriminals use Revive to take ownership of online accounts using stolen login credentials. This malware abuses Accessibility Services to perform malicious activities.
APT GROUP
Malware family tracked by Malpedia. ID: apk.residentbat
APT GROUP
Malware family tracked by Malpedia. ID: apk.remrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.remo
APT GROUPfinancialhigh
RedAlert 2 is an new Android malware used by an attacker to gain access to login credentials of various e-banking apps. The malware works by overlaying a login screen with a fake display that sends the credentials to a C2 server. The malware also has the ability to block incoming calls from banks, to prevent the victim of being notified. As a distribution vector RedAlert 2 uses third-party app stores and imitates real Android apps like Viber, Whatsapp or fake Adobe Flash Player updates.
APT GROUP
Malware family tracked by Malpedia. ID: apk.raxir
APT GROUP
According to ThreatFabric, this RAT can perform NFC relay attacks and has Automated Transfer ystem (ATS) capabilities
APT GROUP
RatMilad, a newly discovered Android spyware, has been stealing data from mobile devices in the Middle East. The malware is spread through links on social media and pretends to be applications for services like VPN and phone number spoofing. Unwary users download these trojan applications and grant access to malware.
APT GROUP
Malware family tracked by Malpedia. ID: apk.rana
APT GROUP
Malware family tracked by Malpedia. ID: apk.rambleon
APT GROUP
Malware family tracked by Malpedia. ID: apk.rafelrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.princess
APT GROUP
Malware family tracked by Malpedia. ID: apk.premier_rat
APT GROUP
Malware family tracked by Malpedia. ID: apk.pornhub
Updated: 2017-02-15
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: apk.podec
APT GROUP
According to Lookout, PlainGnome consists of a two-stage deployment in which a very minimal first stage drops a malicious APK once it’s installed. The code of PlainGnome’s second stage payload evolved significantly from January 2024 through at least October. In particular, PlainGnome’s developers shifted to using Jetpack WorkManager classes to handle data exfiltration, which eases development and maintenance of related code. In addition, WorkManager allows for specifying execution conditions. For example, PlainGnome only exfiltrates data from victim devices when the device enters an idle state. This mechanism is probably intended to reduce the chance of a victim noticing the presence of PlainGnome on their device. As opposed to the minimalist first (installer) stage, the second stage carries out all surveillance functionality and relies on 38 permissions.
APT GROUP
Malware family tracked by Malpedia. ID: apk.pjobrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.pixstealer
APT GROUPfinancialhigh
According to PCrisk, The PixPirate is a dangerous Android banking Trojan that has the capability to carry out ATS (Automatic Transfer System) attacks. This allows threat actors to automatically transfer funds through the Pix Instant Payment platform, which numerous Brazilian banks use. In addition to launching ATS attacks, PixPirate can intercept and delete SMS messages, prevent the uninstallation process, and carry out malvertising attacks.
APT GROUP
According to Mandiant, PINEFLOWER is an Android malware family capable of a wide range of backdoor functionality, including stealing system inform information, logging and recording phone calls, initiating audio recordings, reading SMS inboxes and sending SMS messages. The malware also has features to facilitate device location tracking, deleting, downloading, and uploading files, reading connectivity state, speed, and activity, and toggling Bluetooth, Wi-Fi, and mobile data settings.