Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.w32times
APT GROUP
Vyveva is a remote access trojan that uses the Tor library for communication with C&C. Its use of fake TLS for camouflaging the network traffic is one of the typical Lazarus traits.
It uses a simple XOR for encryption of its configuration and network traffic.
It sends detailed information about the victim's environment, like computer name, user name, IP, code page, Windows version, architecture, and time zone.
It supports more than 20 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, and the download and memory execution of an additional DLL from the C&C (by calling the expected export SamIPromote). As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. The lowest index is 0x3, followed by 0x10, which goes incrementally up to 0x26. Also, it can monitor newly connected drives and the number of logged-on users.
It has MPRD.dll as the internal DLL name, and a single export SamIInitialize.
Vyveva RAT was used in an attack against a freight logistics company in South Africa in June 2020.
APT GROUP
Malware family tracked by Malpedia. ID: win.vx_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.vskimmer
APT GROUP
Malware family tracked by Malpedia. ID: win.vsingle
APT GROUP
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
APT GROUP
Malware family tracked by Malpedia. ID: win.vreikstadi
APT GROUP
Malware family tracked by Malpedia. ID: win.volgmer
APT GROUPespionageadvanced
Voldemort is a backdoor discovered by Proofpoint in August 2024. It is being distributed via phishing E-Mails and makes use of creative techniques such as using saved search files during the infection chain for obfuscation and Google Sheets for C2. While its broad targeting looks like it is related to ecrime, Proofpoint notes that the capabilities of the malware point towards espionage/APT activity.
APT GROUP
Malware family tracked by Malpedia. ID: win.void_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.voidoor
APT GROUP
Malware family tracked by Malpedia. ID: win.vohuk
APT GROUP
Malware of this family searches for computers on a network and creates copies of itself in folders with open access. For the program to be activated, the user must first run it on the computer. The code of this malware is written in the Visual Basic programming language and uses obfuscation, which is a distinguishing feature of this family. Code obfuscation complicates attempts by anti-virus software to analyze suspected malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.vmzeus
APT GROUP
VJW0rm (aka Vengeance Justice Worm) is a publicly available, modular JavaScript RAT. Vjw0rm was first released in November 2016 by its primary author, v_B01 (aka Sliemerez), within the prominent DevPoint Arabic-language malware development community. VJW0rm appears to be the JavaScript variant of a series of RATs with identical functionality released by the author throughout late 2016. Other variants include a Visual Basic Script (VBS) based worm titled vw0rm (Vengeance Worm), an AutoHotkey-based tool called vrw0rm (Vengeance Rise Worm), and a PowerShell-based variant called vdw0rm (Vengeance Depth Worm).
APT GROUP
Malware family tracked by Malpedia. ID: win.vizom
APT GROUP
Malware family tracked by Malpedia. ID: win.virut
APT GROUP
Malware family tracked by Malpedia. ID: win.virtualgate
APT GROUPfinancialhigh
Polymorphic parasitic file infecting virus which transforms files into copies of itself. Additionally it uses screen-locking as a ransomware technique.
APT GROUP
Malware family tracked by Malpedia. ID: win.virdetdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.vipkeylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.vilsastealer
APT GROUP
Wiper malware discovered by Japanese security firm Mitsui Bussan Secure Directions (MBSD), which is assumed to target Japan, the host country of the 2021 Summer Olympics. In addition to targeting common file Office-related files, it specifically targets file types associated with the Japanese word processor Ichitaro.
APT GROUP
Vidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser.
APT GROUP
VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020. The used malware itself was also referred to as VictoryGate. It was spotted in May 2019 and targeted mainly Latin American users, specifically, Peru (Criptonizando states 90% of the botnet publication residing there). Both public and private sectors were targeted.
This cryptojacking malware was specialized in Monero (XRM) cryptocurrency. VictoryGate shows very strong code overlap with win.orchard.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.vhd_ransomware
APT GROUP
Vflooder floods VirusTotal by infinitely submitting a copy of itself. Some variants apparently also try to flood Twitter. The impact on these services are negligible, but for researchers it can be a nuisance. Most versions are protected by VMProtect.
APT GROUP
Vetta Loader is a persistent Loader spreading with infected USB drives. It downloads other components leveraging legit hosting services.
https://yoroi.company/wp-content/uploads/2023/12/202311-Vetta-Loader_Def-min.pdf
APT GROUP
Malware family tracked by Malpedia. ID: win.vermin
APT GROUP
Malware family tracked by Malpedia. ID: elf.vermilion_strike
APT GROUP
Malware family tracked by Malpedia. ID: win.venus_locker
APT GROUP
According to Cisco Talos, this is a reverse proxy socks5 server-client tool originally developed for penetration testers.
APT GROUP
VenomLNK is the initial phase of the more_eggs malware-as-a-service. It is a poisoned .lnk file that depends on User Execution and points to LOLBINs (often cmd.exe) with additional obfuscated scripting options. This typically initiates WMI abuse and TerraLoader, which can load additional functionality through various plugins.
APT GROUP
Malware family tracked by Malpedia. ID: win.venomloader
APT GROUP
Malware family tracked by Malpedia. ID: win.venom
APT GROUP
According to Seqrite, VELETRIX as been observed as a loader for VShell.
APT GROUP
Malware family tracked by Malpedia. ID: win.veiledsignal
APT GROUP
Credential Stealer, written in .NET.