Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,728 entities
APT GROUP
According to Zimperium, PhoneSpy is a spyware aimed at South Korean residents with Android devices.
APT GROUP
Malware family tracked by Malpedia. ID: apk.phoenix
APT GROUP
Malware family tracked by Malpedia. ID: apk.phantomlance
APT GROUP
According to TechCrunch, this is a remote surveillance app that allows ordinary consumers to buy software capable of tracking people and their data without their knowledge. Once physically planted on a person’s phone or computer (usually with knowledge of the victim’s passcode or login), the app would continuously upload a copy of the victim’s information, including messages, photos, and location data, to pcTattletale’s servers and make the data accessible to whoever planted the spyware.
APT GROUP
Malware family tracked by Malpedia. ID: apk.packchat
APT GROUP
Malware family tracked by Malpedia. ID: apk.oscorp
APT GROUP
Malware family tracked by Malpedia. ID: apk.omnirat
APT GROUP
Malware family tracked by Malpedia. ID: apk.nexus
APT GROUPfinancialhigh
MysteryBot is an Android banking Trojan with overlay capabilities with support for Android 7/8 but also provides other features such as key logging and ransomware functionality.
APT GROUP
Malware family tracked by Malpedia. ID: apk.mudwater
APT GROUP
Malware family tracked by Malpedia. ID: apk.morder_rat
APT GROUPfinancialhigh
MoqHao, also called Wroba and XLoader (not to be confused with the malware of the same name for Windows and macOS), is an Android-based mobile threat that is associated with a financially motivated Chinese group called Roaming Mantis. The malware claims to be the default SMS application and has dropper and banker capabilities.
APT GROUP
Monokle is a sophisticated mobile surveillanceware that possesses remote access trojan (RAT) functionality, advanced data exfiltration techniques as well as the ability to install an attacker-specified certificate to the trusted certificates on an infected device that would allow for man-in-the-middle (MITM) attacks.
According to Lookout researchers, It is believed to be developed by Special Technology Center (STC), which is a Russian defense contractor sanctioned by the U.S. Government in connection to alleged interference in the 2016 US presidential elections.
APT GROUP
Check Point has identified samples of this spyware being distributed since 2015. No samples were found on Google Play, meaning they were likely through other channels like social engineering.
APT GROUP
Malware family tracked by Malpedia. ID: apk.mazarbot
APT GROUP
According to heimdal, MasterFred malware, this is designed as an Android trojan that makes use of false login overlays to target not only Netflix, Instagram, and Twitter users, but also bank customers. The hackers’ goal is to steal credit card information.
APT GROUP
Malware family tracked by Malpedia. ID: apk.marcher
APT GROUP
Malware family tracked by Malpedia. ID: apk.mandrake
APT GROUP
Malware family tracked by Malpedia. ID: apk.luna_spy
APT GROUP
A series of attacks, targeting both Indian military research and south Asian shipping organizations, demonstrate the minimum level of effort required to successfully compromise a target and steal sensitive information. The attackers use very simple malware, which required little development time or skills, in conjunction with freely available Web hosting, to implement a highly effective attack. It is a case of the attackers obtaining a maximum return on their investment. The attack shows how an intelligent attacker does not need to be particularly technically skilled in order to steal the information they are after. The attack begins, as is often the case, with an email sent to the victim. A malicious document is attached to the email, which, when loaded, activates the malware. The attackers use tailored emails to encourage the victim to open the email. For example, one email sent to an academic claimed to be a call for papers for a conference (CFP).
The vast majority of the victims were based in India, with some in Malaysia. The victim industry was mostly military research and also shipping based in the Arabian and South China seas. In some instances the attackers appeared to have a clear goal, whereby specific files were retrieved from certain compromised computers. In other cases, the attackers used more of a ‘shotgun’ like approach, copying every file from a computer. Military technologies were obviously the focus of one particular attack with what appeared to be source code stolen. 45 different attacker IP addresses were observed. Out of those, 43 were within the same IP address range based in Sichuan province, China. The remaining two were based in South Korea. The pattern of attacker connections implies that the IP addresses are being used as a VPN, probably in an attempt to render the attackers anonymous.ænThe attacks have been active from at least April 2011 up to February 2012. The attackers are intelligent and focused, employing the minimum amount of work necessary for the maximum gain. They do not use zero day exploits or complicated threats, instead they rely on effective social engineering and lax security measures on the part of the victims.
Updated: 2026-08-06
View profile →APT GROUPfinancialhigh
Android banker Trojan with the standard banking capabilities such as overlays, SMS stealing. It also features ransomware functionality. Note, the network traffic is obfuscated the same way as in Android Bankbot.
APT GROUP
Malware family tracked by Malpedia. ID: apk.loki
APT GROUP
Malware family tracked by Malpedia. ID: apk.little_looter
APT GROUP
Malware family tracked by Malpedia. ID: apk.landfall
APT GROUP
Malware family tracked by Malpedia. ID: apk.ksremote
APT GROUP
According to Lookout, this spyware was first observed in March 2022 and remains active with new samples still publicly hosted. It uses a two-stage C2 infrastructure that retrieves initial configurations from a Firebase cloud database. KoSpy can collect extensive data, such as SMS messages, call logs, location, files, audio, and screenshots via dynamically loaded plugins. The spyware has Korean language support with samples distributed across Google Play and third-party app stores such as Apkpure.
APT GROUP
Malware family tracked by Malpedia. ID: apk.koler
APT GROUP
Malware family tracked by Malpedia. ID: apk.knspy
APT GROUP
KIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as participating in distributed denial-of-service (DDoS). KIMWOLF primarily infects unofficial Android-TV set-top boxes and digital photo frames. The malware has frequently been noted to achieve infection spread via abusing Android Debug Bridge (ADB) and residential proxies. There are multiple reports suggesting a connection to the Aisuru botnet, with Kimwolf acting as the Android variant.
APT GROUP
Malware family tracked by Malpedia. ID: apk.kevdroid
APT GROUP
Joker is one of the most well-known malware families on Android devices. It manages to take advantage of Google’s official app store with the help of its trail signatures which includes updating the virus’s code, execution process, and payload-retrieval techniques. This malware is capable of stealing users’ personal information including contact details, device data, WAP services, and SMS messages.
APT GROUP
Malware family tracked by Malpedia. ID: apk.jaderat
APT GROUP
Malware family tracked by Malpedia. ID: apk.irrat
APT GROUP
According to redpiranha, IRATA (Iranian Remote Access Trojan) Android Malware is a new malware detected in the wild. It originates from a phishing attack through SMS. The theme of the message resembles information coming from the government that will ask you to download this malicious application. IRATA can collect sensitive information from your mobile phone including bank details. Since it infects your mobile, it can also gather your SMS messages which then can be used to obtain 2FA tokens.
APT GROUPfinancialhigh
Avira states that Hydra is an Android BankBot variant, a type of malware designed to steal banking credentials. The way it does this is by requesting the user enables dangerous permissions such as accessibility and every time the banking app is opened, the malware is hijacking the user by overwriting the legit banking application login page with a malicious one. The goal is the same, to trick the user to enter his login credentials so that it will go straight to the malware authors.
APT GROUP
According to ThreatFabric, this is a malware family based on apk.ermac. The name hook is the self-advertised named by its vendor DukeEugene. It provides WebSocket communication and has RAT capabilities.
APT GROUP
RAT, which can be used to extract sensitive information, e.g. contact lists, txt messages, location information.
APT GROUP
HiddenAd is a malware that shows ads as overlays on the phone.
APT GROUP
Malware family tracked by Malpedia. ID: apk.hero_rat
APT GROUP
Lookout states that Hermit is an advanced spyware designed to target iOS and Android mobile devices. It is designed to collect extensive amounts of sensitive data on its victims such as their location, contacts, private messages, photos, call logs, phone conversations, ambient audio recordings, and more.