Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.veaty
APT GROUP
Malware family tracked by Malpedia. ID: win.vawtrak
APT GROUP
In May 2019, ESET researchers observed a spike in ESET telemetry data regarding malware targeting France. After further investigations, they identified malware that distributes various types of spam. One of them is leading to a survey that redirects to a dodgy smartphone promotion while the other is a sextortion campaign. The spam targets the users of Orange S.A., a French ISP.
APT GROUP
According to Mandiant, VaporRage or BOOMMIC, is a shellcode downloader written in C that communicates over HTTPS. Shellcode Payloads are retrieved from a hardcoded C2 that uses an encoded host_id generated from the targets domain and account name. BOOMMIC XOR decodes the downloaded shellcode payload in memory and executes it.
APT GROUP
Description:
VanillaRat is an advanced remote administration tool coded in C#. VanillaRat uses the Telepathy TCP networking library, dnlib module reading and writing library, and Costura.Fody dll embedding library.
Features:
Remote Desktop Viewer (With remote click)
File Browser (Including downloading, drag and drop uploading, and file opening)
Process Manager
Computer Information
Hardware Usage Information (CPU usage, disk usage, available ram)
Message Box Sender
Text To Speech
Screen Locker
Live Keylogger (Also shows current window)
Website Opener
Application Permission Raiser (Normal -> Admin)
Clipboard Text (Copied text)
Chat (Does not allow for client to close form)
Audio Recorder (Microphone)
Process Killer (Task manager, etc.)
Remote Shell
Startup
Security Blacklist (Drag client into list if you don't want connection. Press del. key on client to remove from list)
APT GROUP
Malware family tracked by Malpedia. ID: win.vampire_bot
APT GROUP
Malware family tracked by Malpedia. ID: win.valuevault
APT GROUP
Malware family tracked by Malpedia. ID: win.valley_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.valkyrie_stealer
APT GROUPfinancialhigh
ESET reports that Vadokrist is a Latin American banking trojan that they have been tracking since 2018 and that is active almost exclusively in Brazil.
APT GROUP
Malware family tracked by Malpedia. ID: win.usbferry
APT GROUP
According to Kaspersky, USBCulprit is a malware that is capable of scanning various paths in victim machines, collecting documents with particular extensions and passing them on to USB drives when they are connected to the system. It can also selectively copy itself to a removable drive in the presence of a particular file, suggesting it can be spread laterally by having designated drives infected and the executable in them opened manually.
APT GROUP
Malware family tracked by Malpedia. ID: win.urlzone
APT GROUP
Malware family tracked by Malpedia. ID: win.urausy
APT GROUP
Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for delivering further malware to the victims, in specific upatre was a prolific delivery mechanism for Gameover P2P in 2013-2014 and then for Dyre in 2015.
APT GROUP
Malware family tracked by Malpedia. ID: win.upas
APT GROUP
This malware uses Azure Functions as its C2.
APT GROUP
An infostealer written in Go.
APT GROUP
According to Datadog, this malware functions primarily as a credential and infostealer. It enumerates LevelDB files within application data directories for Discord, Chromium-based browsers, cryptocurrency wallets, and Electron applications.
APT GROUP
unidentified_121 acts as a downloader and reflective PE loader, employing a dual-mode execution strategy based on its privilege level. When executed without administrative rights, it uniquely attempts to bypass User Account Control (UAC) by first patching its own Process Environment Block (PEB) in memory to masquerade as explorer.exe, and then leveraging a specific COM object ({3E5FC7F9-9A51-4367-9063-A120244FBEC7} with the Elevation:Administrator!new: moniker) to relaunch itself with elevated privileges. This initial stage focuses purely on achieving elevation and does not perform C2 communication or direct payload execution itself in the non-elevated state.
Once running with administrative privileges (either initially or after successful elevation), the malware establishes persistence by creating a Scheduled Task named "BlaBlaAgu" using COM, configuring it to run with the highest privileges and repeat every five minutes indefinitely. It actively evades defenses by using PowerShell commands (Add-MpPreference) to add Windows Defender exclusions for its own process and the user's profile directory, reinforcing these exclusions every 60 seconds via a separate thread. Its primary function in this elevated state is to act as a downloader, connecting to its Command and Control (C2) server over TCP port 33334 using a custom protocol encrypted with an RC4-like cipher and the hardcoded key "ALB9SxZBzCqwPFnD"; after a distinct 20-byte client handshake (RC4 Key + integer 444, followed by a 16-byte server response (RC4 Key) for validation), it downloads further encrypted PE payloads and executes them reflectively in its own memory space.
APT GROUP
According to Deutsche Telekom CERT, this malware unpacks an obfuscated, multi-stage shellcode payload. After unpacking, a password prompt is displayed to the user. The password is provided to the victim and used to decrypt the final stage payload.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_118
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_117
APT GROUP
This malware family delivers its artifacts packed with free and generic packers. It writes files to windows temporary folders, downloads additional malware (generally cryptominers) and deletes itself.
APT GROUP
According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that will download/decrypt a payload via AES CFB and inject it into a hardcoded process target (e.g. explorer.exe).
APT GROUP
According to Trend Micro, this is a small information stealer written in .NET, that pushes its loot to a benign file sharing service and does not have a direct C&C callback.
APT GROUPespionageadvanced
According to Phylum, this is a RAT with these characteristics:
* Registers as a scheduled task.
* Receives commands from a remote server using web sockets.
* Installs Chrome extensions to Secure Preferences.
* Configures AnyDesk, hides the screen, and disables shutting down Windows.
* Captures keyboard and mouse events.
* Collects information about files, browser extensions, and browser history.
APT GROUPespionageadvanced
A Rust-based stealer, observed by Seqrite, along TTPs overlapping with Pakistan-linked APT groups.
APT GROUP
According to Deep Instinct, this information stealer is written in Rust and was observed in Operation Rusty Flag.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_109
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_108
APT GROUPespionageadvanced
Small shellcode downloader, likely used by APT29.
APT GROUP
This is possibly related to the MATA framework / Dacls.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_105
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_104
APT GROUPfinancialhigh
A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to in coverage on WHITERABBIT ransomware attacks.
APT GROUP
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
APT GROUP
Potential Lazarus sample.
APT GROUP
Malware family tracked by Malpedia. ID: win.unidentified_100
APT GROUPespionageadvanced
This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations. It is different from win.boombox, which is another APT29 attributed malware using DropBox (written in .NET).