Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.xxmm
APT GROUPfinancialhigh
Malware with wide range of capabilities ranging from RAT to ransomware.
APT GROUP
In March 2019, AT&T Alien Labs identified a new malware family that is actively scanning for exposed web services and default passwords. Based on our findings we are calling it “Xwo” - taken from its primary module name. It is likely related to the previously reported malware families Xbash and MongoLock.
APT GROUP
This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.
APT GROUP
X-Tunnel is a network proxy tool that implements a custom network protocol encapsulated in the TLS protocol.
APT GROUP
Simple Loader used to download and install stealers, clippers and other malwares.
APT GROUP
Malware family tracked by Malpedia. ID: win.xsplus
APT GROUP
Malware family tracked by Malpedia. ID: win.xserver
APT GROUPespionageadvanced
According to eSentire, XRed, also known as Synaptics worm, is a backdoor that has been circulating since at least 2019. This malware was initially spread through drivers bundled with USB-C hub adapters, which served as its primary distribution vector. Once executed, the backdoor self-replicates and to maintain persistence, it creates a Windows Registry Run key. Additionally, it uses a mutex named Synaptics2X to ensure that only one instance of the malware runs at a time. XRed includes several advanced features that enable remote control and data exfiltration. It can download additional payloads from hardcoded URLs embedded within its binary. The malware exfiltrates sensitive system information—such as the MAC address, username, and computer name—which is sent via SMTP to hardcoded email addresses. It also incorporates keylogging functionality through keyboard hooking techniques. Furthermore, XRed supports a variety of remote commands that allow the attacker to gain command prompt access, capture screenshots, list available disks and directories, download files from remote sources, and delete files from the infected system. XRed also exhibits worm-like behavior: It spreads through USB drives by creating an autorun.inf file. Additionally, the malware infects Excel files with macros (.xlsm) by injecting a malicious VBA macro into them. The malware uses a hardcoded dynamic DNS domain (xred.mooo.com) to communicate with its command and control server. This domain serves as an identifying feature of the malware. According to researchers at eSentire, linguistic evidence found in the malware's code suggests that the developer is a native Turkish speaker.
APT GROUP
Malware family tracked by Malpedia. ID: win.xp_privesc
APT GROUP
According to PCrisk, XpertRAT is a Remote Administration Trojan, a malicious program that allows cyber criminals to remotely access and control infected computers. Typically, users download and install this software inadvertently because they are tricked. By having computers infected with malware such as XpertRAT, users can experience serious problems.
APT GROUP
Malware family tracked by Malpedia. ID: win.xpan
APT GROUP
Symantec describes this as a decryptor/loader used by Chinese threat actor Antlion in campaigns targeting Taiwan.
APT GROUP
Malware family tracked by Malpedia. ID: win.xoriumstealer
APT GROUPfinancialhigh
According to PCrisk, Xorist is a family of ransomware-type malware. After stealth system infiltration, ransomware from this family encrypts various files stored on the computer. After encrypting the files, this ransomware creates a 'How to Decrypt Files.txt text file on the victim's desktop. The file contains a message stating that the files can only be restored by paying a ransom.
APT GROUP
Malware family tracked by Malpedia. ID: elf.xmrig
APT GROUP
Malware family tracked by Malpedia. ID: win.xillen_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.xiebroc2
APT GROUP
Malware family tracked by Malpedia. ID: win.xiangoop
APT GROUP
Malware family tracked by Malpedia. ID: win.xfscashncr
APT GROUP
Malware family tracked by Malpedia. ID: win.xfsadm
APT GROUP
Malware family tracked by Malpedia. ID: win.xfilesstealer
APT GROUP
XenoRAT is an open source remote access trojan written in C#. It can monitor user activity including keystrokes, and provide remote control over the compromised system.
APT GROUP
Malware family tracked by Malpedia. ID: win.xenon
APT GROUP
XenArmor is a suite of password recovery tools for various applications that have been observed to be abused in attacks alongside malware.
APT GROUP
Xehook is a .NET-based malware targeting Windows systems. It collects data from Chromium and Gecko browsers, supporting over 110 cryptocurrencies and 2FA extensions. CRIL found a potential link between Xehook Stealer, Agniane, and the Cinoshi project, suggesting a progression from a free MaaS model to the development of Xehook Stealer. SmokeLoader binaries were identified as a common vector for distributing Xehook Stealer. Xehook Stealer shares code overlaps with Agniane Stealer, indicating an evolutionary relationship.
APT GROUPespionageadvanced
Rare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since 2011. It has attracted very little public attention, with the exception of an advisory from the Belarusian CERT in February 2020. In the interim, the group has compromised many government agencies and private companies in Eastern Europe and the Balkans.
APT GROUP
Malware family tracked by Malpedia. ID: win.xdata
APT GROUP
Checkpoint Research found this backdoor, attributed to IndigoZebra, used to target Afghan and other Central-Asia countries, including Kyrgyzstan and Uzbekistan, since at least 2014.
APT GROUP
Malware family tracked by Malpedia. ID: win.xbtl
APT GROUP
Malware family tracked by Malpedia. ID: win.xbot_pos
APT GROUP
Malware family tracked by Malpedia. ID: apk.popr-d30
APT GROUP
Malware family tracked by Malpedia. ID: win.x4
APT GROUP
Malware family tracked by Malpedia. ID: win.wslink
APT GROUP
Malware family tracked by Malpedia. ID: win.wscspl
APT GROUP
Malware family tracked by Malpedia. ID: win.wpbrutebot
APT GROUP
Malware family tracked by Malpedia. ID: win.wormlocker