Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,486 entities
1337 GTWK
Technical ID: 1337_GTWK
APT GROUP
This is a Linux malware program consisting of several modules, parts of which were likely programmed using AI. It consists of a rootkit and an agent capable of executing malicious code.
APT GROUP
Malware family tracked by Malpedia. ID: win.potemkin
APT GROUPespionageadvanced
According to Gen Threat Labs, VoidStealer is a Malware-as-a-Service infostealer that targets browser credentials and is the first observed malware in the wild to employ a novel debugger-based Application-Bound Encryption bypass technique. It attaches to the browser process as a debugger and sets hardware breakpoints at specific code locations to extract the v20_master_key directly from browser memory during startup, without requiring privilege escalation or code injection. The technique is adapted from the open-source ElevationKatz project and specifically targets Chromium-based browsers such as Chrome and Edge. As a fallback, VoidStealer also implements a traditional process injection method to invoke the browser's internal decryption interface when the debugger approach is unavailable.
According to Group-IB, TriBack Loader is a custom shellcode loader used to deliver and execute secondary payloads in memory on targeted Windows systems. It operates through DLL sideloading, where a signed legitimate binary loads a malicious DLL that decrypts an encrypted companion file using a two-stage decryption routine consisting of byte reversal and rolling XOR with an offset. The decrypted shellcode is then executed via Win32 callback APIs such as InitOnceExecuteOnce, TimerQueue callbacks, or the undocumented EtwpCreateEtwThread, each chosen to evade detection by endpoint security products. Four observed variants indicate it is produced by a custom builder, with each variant rotating the callback API used for execution while maintaining the same decryption scheme and reflective loader mechanism for deploying final payloads.
APT GROUP
According to Proofpoint, ZimReaper is a JavaScript-based malware family delivered via a half-click cross-site scripting exploit (CVE-2025-66376) targeting Zimbra Collaboration Suite webmail servers, requiring only that the victim open or preview a malicious email in the webmail client. The exploit uses a tag-splitting technique where CSS "@import" directives fragment HTML tags to bypass Zimbra's client-side HTML sanitizer, allowing arbitrary JavaScript execution in the context of the authenticated webmail session. Once executed, ZimReaper steals the CSRF token, auto-filled credentials, and two-factor authentication codes from the browser, creates an app-specific password named "ZimbraWeb" for persistent IMAP/POP3/SMTP access, and exfiltrates stolen data via DNS queries and HTTP POST. The malware also enumerates the Global Address List and exfiltrates the last 90 days of the victim's emails in a TGZ archive, using obfuscation layers including XOR-encrypted payloads that evolved over the course of the campaign.
APT GROUP
According to its author, this is a C-based malware research framework designed to demonstrate advanced multi-stage system compromise techniques on Windows.
APT GROUP
According to Rapid7, ModeloRAT is a Python-based remote access trojan framework previously tied to the KongTuke group's browser extension campaigns, which in this incident was delivered through Microsoft Teams social engineering using a portable WinPython environment to bypass traditional detections. Its capabilities center on a long-running HTTP C2 beacon that can load DLLs via rundll32, launch additional Python modules, execute PowerShell commands, install MSI packages, handle persistence, and self-update or remove, while supporting supplementary modules for reverse shells, SOCKS proxying, and HTTP tunneling. The Python modules are obfuscated and run through pythonw.exe to avoid visible console windows, with all communication blended into normal-looking web traffic over port 80.
APT GROUP
According to Zscaler, MacSync (also tracked as MacSync Stealer) is a macOS information stealer likely developed by a Russian-speaking threat actor, as evidenced by Russian-language comments found in its third-stage AppleScript payload. It is distributed through a multi-stage ClickFix campaign that abuses shared Claude chats, ultimately delivering the core stealer via osascript, which leaves no file trace on disk. Its capabilities include stealing keychain data, browser credentials, cookies, and autofill information from Chromium- and Gecko-based browsers, harvesting cryptocurrency wallet data (both browser extensions and desktop applications), and collecting sensitive files such as cloud keys, shell history, and high-value documents, all of which are compressed and exfiltrated in 10MB HTTP PUT chunks. The malware also implements persistence by appending a curl command to ~/.zshrc, prompts the user for full disk access, and may drop additional trojanized payloads targeting hardware-wallet users.
APT GROUP
Jackskid is a Mirai-derived Linux/IoT DDoS botnet, first publicly documented by Foresiet in November 2025 and tracked by CNCERT/SecrSS as RCtea. It encrypts its configuration with a custom RC4 cipher post-processed by an LCG (key DEADBEEF CAFEBABE E0A4CBD6 BADC0DE5) and negotiates per-session ChaCha20 keys via XXTEA (passphrase FrshPckBnnnSplit). The same RC4+LCG modification appears in Aisuru, indicating a shared code lineage, and the family sits within the CatDDoS-derivative ecosystem. Later builds add ENS-based C2 resolution, an anti-competition module (0clKiller) backed by a NETLINK process monitor, and a pivot toward Android/ADB-exposed TV boxes. Jackskid and several related botnets were disrupted by law enforcement in March 2026.
APT GROUP
According to Kaspersky, this malware sticks out as performing a large set of operations in memory with the help of the malloc, memmove and memcmp function calls.
APT GROUP
According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling". In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.
APT GROUP
Malware family tracked by Malpedia. ID: win.warlock
Malware family tracked by Malpedia. ID: win.unidentified_003
Updated: 2016-12-29
View profile →
APT GROUPfinancialhigh
According to PCrisk, Trigona is ransomware that encrypts files and appends the "._locked" extension to filenames. Also, it drops the "how_to_decrypt.hta" file that opens a ransom note. An example of how Trigona renames files: it renames "1.jpg" to "1.jpg._locked", "2.png" to "2.png._locked", and so forth. It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.
APT GROUP
Malware family tracked by Malpedia. ID: win.termite
APT GROUPespionageadvanced
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company> A decryptor was released on 2022-02-07 by AVAST
APT GROUP
Malware family tracked by Malpedia. ID: win.taidoor
APT GROUPfinancialhigh
Ransomware, written in Delphi.
APT GROUPfinancialhigh
Ransomware, written in .NET.
APT GROUP
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.sarcoma
APT GROUP
Malware family tracked by Malpedia. ID: win.safepay
APT GROUP
Malware family tracked by Malpedia. ID: win.rtm_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.reynolds
APT GROUPfinancialhigh
Ransomware.
APT GROUPfinancialhigh
A ransomware written in Rust.
APT GROUPfinancialhigh
According to ESET Research, PromptLock is first known AI-powered ransomware. PromptLock leverages Lua scripts generated from hard-coded prompts to enumerate the local filesystem, inspect target files, exfiltrate selected data, and perform encryption. These Lua scripts are cross-platform compatible, functioning on Windows, Linux, and macOS. For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.
APT GROUP
Malware family tracked by Malpedia. ID: win.polyvice
APT GROUPfinancialhigh
According to PCrisk, PLAY is the name of a ransomware-type program. Malware categorized as such operates by encrypting data and demanding ransoms for the decryption. After we executed a sample of this ransomware on our test machine, it encrypted files and appended their filenames with a ".PLAY" extension. For example, a file titled "1.jpg" appeared as "1.jpg.PLAY", "2.png" as "2.png.PLAY", etc. Once the encryption process was completed, PLAY created a text file named "ReadMe.txt" on the desktop.
APT GROUP
Malware family tracked by Malpedia. ID: win.payloadbin
APT GROUPfinancialhigh
According to EG-FinCIRT, Payload is a cross-platform ransomware family with native compiled binaries for Windows and Linux/ESXi, exposing rich command-line options that let operators tune targeting, performance, and anti-forensic behavior. The Windows variant aggressively prepares the system by deleting recovery points, stopping key services and processes, wiping or bypassing logging mechanisms, and optionally hiding and self-deleting its executable while running encryption in the background. Its core uses an offline hybrid cryptosystem combining Curve25519 key exchange with optimized ChaCha20 (using CPU feature detection and multithreading, plus partial encryption for large files) and appends an obfuscated metadata footer needed for decryption. The Linux/ESXi variant is a small stripped ELF binary that parses virtual machine inventory data to locate and encrypt VM disk files, focusing on efficient disruption of virtualized workloads with fewer ancillary features than the Windows version.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.nightsky
APT GROUP
Malware family tracked by Malpedia. ID: win.mortalkombat
APT GROUPfinancialhigh
Ransomware. Identical samples (apart from note) operated by Morpheus and HellCat ransomware groups.
APT GROUPfinancialhigh
A new ransomware gang hitting companies in worldwide firstly spotted by Zscaler.
APT GROUPfinancialhigh
Ransomware, potential rebranding of win.sfile.
APT GROUP
Malware family tracked by Malpedia. ID: win.metaencryptor
APT GROUPfinancialhigh
According to PCrisk, MEOW is ransomware based on other ransomware called CONTI. MEOW encrypts files and appends the ".MEOW" extension to their filenames. It also drops the "readme.txt" file (a ransom note). An example of how MEOW ransomware modifies filenames: it renames "1.jpg" to "1.jpg.MEOW", "2.png" to "2.png.MEOW", and so forth.
← PreviousPage 1 / 88Next →