Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Zeus
Technical ID: win.zeus
MALWAREfinancialhigh
According to CrowdStrike, The two primary goals of the Zeus trojan horse virus are stealing people's financial information and adding machines to a botnet. Unlike many types of malware, most Zeus variants try to avoid doing long-term damage to the devices they infect. Their aim is to avoid detection from antivirus software.
Also known as: Zbot
ZeroT
Technical ID: win.zerot
MALWARE
Malware family identifying win.zerot. Origin and technical characteristics tracked via Malpedia.
Zeropadypt
Technical ID: win.zeropadypt
MALWARE
Malware family identifying win.zeropadypt. Origin and technical characteristics tracked via Malpedia.
Also known as: Ouroboros
ZeroLocker
Technical ID: win.zerolocker
MALWARE
Malware family identifying win.zerolocker. Origin and technical characteristics tracked via Malpedia.
ZeroEvil
Technical ID: win.zeroevil
MALWARE
ZeroEvil is a malware that seems to be distributed by an ARSguarded VBS loader.
It first connects to a gate.php (version=). Upon success, an embedded VBS gets started connecting to logs_gate.php (plugin=, report=).
So far, only one embedded VBS was observed: it creates and starts a PowerShell script to retrieve all password from the Windows.Security.Credentials.PasswordVault. Apart from that, a screenshot is taken and a list of running processes generated.
The ZeroEvil executable contains multiple DLLs, sqlite3.dll, ze_core.DLL (Mutex) and ze_autorun.DLL (Run-Key).
MALWARE
ZeroCleare is a destructive malware. It has been developed in order to wipe the master boot record section in order to damage a disk's partitioning. Attackers use the EldoS RawDisk driver to perform the malicious action, which is not a signed driver and would therefore not runnable by default. The attackers managed to install it by using a vulnerable version of VBoxDrv driver, which the DSE accepts and runs. Used to attack middle-east energy and industrial sectors.
ZeroAccess
Technical ID: win.zeroaccess
MALWARE
ZeroAccess is a modular botnet that was primarily active around 2012. It has been observed selling fake antivirus software to infected users, performing click fraud and deploying bitcoin miners.
It utilizes both peer-to-peer networking and a centralized C&C, spoofing the HTTP Host header with fake DGA-generated domains to confuse researchers.
While there is no evidence that the DGA-generated domains were ever intentonally contacted by the malware, faulty middleboxes still caused some requests to be sent to the DGA domains.
Also known as: Max++ • Sirefef • Smiscer • ZAccess
MALWAREfinancialhigh
Zeppelin is a ransomware written in Delphi and sold a as-a-service. The Cylance research team notes that it is a clear evolution of the known VegaLocker, but they assessed it as a new family becaue of additionally developed modules that makes Zeppelin much more configurable than Vegalocker. There are executable variants of type DLL and EXE.
Zeoticus
Technical ID: win.zeoticus
MALWARE
Malware family identifying win.zeoticus. Origin and technical characteristics tracked via Malpedia.
zenar
Technical ID: win.zenar
MALWARE
Malware family identifying win.zenar. Origin and technical characteristics tracked via Malpedia.
Zedhou
Technical ID: win.zedhou
MALWARE
Malware family identifying win.zedhou. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →MALWARE
Malware family identifying win.zebrocy_au3. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
According to brandefense, Zebrocy is malware that falls into the Trojan category, which the threat actor group APT28/Sofacy has used since 2015. Zebrocy malware consists of 3 main components; Backdoor, Downloader, and Dropper. The Downloader and Dropper take responsibility for discovery processes and downloading the main malware on the systems. At the same time, Backdoor undertakes the duties such as persistence in the system, espionage, and data extraction.
This malware, which is not considered new, has variants in many languages from the past to the present. These include programming languages such as Delphi, C#, Visual C++, VB.net, and Golang. Furthermore, we know advanced threat actors and groups revise their malicious software among their toolkits at certain time intervals using different languages and technologies.
Also known as: Zekapab
ZarDoor
Technical ID: win.zardoor
MALWARE
Malware family identifying win.zardoor. Origin and technical characteristics tracked via Malpedia.
Zacinlo
Technical ID: win.zacinlo
MALWARE
Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its other components, presence of man-in-the-browser capabilities that intercepts and decrypts SSL communications, and presence of an adware cleanup routine used to remove potential competition in the adware space. It also communicates with its C&C server, sending environment information such as installed AV and other applications. The malware also takes screenshots and does browser redirects, potentially manipulating the DOM tree. It also creates traffic in hidden windows, likely causing adfraud. The malware is generally very configurable and internally makes use of Lua scripts.
Also known as: s5mark
Yunsip
Technical ID: win.yunsip
MALWARE
W32/Yunsip!tr.pws is classified as a password stealing trojan.
Password Stealing Trojan searches the infected system for passwords and send them to the hacker.
MALWARE
Malware family identifying win.yty. Origin and technical characteristics tracked via Malpedia.
YTStealer
Technical ID: win.ytstealer
MALWARE
According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analyzed in a sandbox.
YourCyanide
Technical ID: win.your_cyanide
MALWAREfinancialhigh
According to Trend Micro, this is a ransomware written as a Windows commandline script, with obfuscation applied.
Also known as: GonnaCope • Kekpop • Kekware
YoungLotus
Technical ID: win.younglotus
MALWARE
Simple malware with proxy/RDP and download capabilities. It often comes bundled with installers, in particular in the Chinese realm.
PE timestamps suggest that it came into existence in the second half of 2014.
Some versions perform checks of the status of the internet connection (InternetGetConnectedState: MODEM, LAN, PROXY), some versions perform simple AV process-checks (CreateToolhelp32Snapshot).
Also known as: DarkShare
MALWARE
Malware family identifying win.yorekey. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.yokai. Origin and technical characteristics tracked via Malpedia.
Yoddos
Technical ID: win.yoddos
MALWARE
Malware family identifying win.yoddos. Origin and technical characteristics tracked via Malpedia.
Ymir
Technical ID: win.ymir
MALWARE
According to Kaspersky, this malware sticks out as performing a large set of operations in memory with the help of the malloc, memmove and memcmp function calls.
YiBackdoor
Technical ID: win.yibackdoor
MALWARE
Malware family identifying win.yibackdoor. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.yesrobot. Origin and technical characteristics tracked via Malpedia.
Yellow Cockatoo RAT
Technical ID: win.yellow_cockatoo
MALWARE
Malware family identifying win.yellow_cockatoo. Origin and technical characteristics tracked via Malpedia.
Also known as: Polazer
yayih
Technical ID: win.yayih
MALWARE
Malware family identifying win.yayih. Origin and technical characteristics tracked via Malpedia.
Also known as: bbsinfo • aumlib
Yatron
Technical ID: win.yatron
MALWARE
Malware family identifying win.yatron. Origin and technical characteristics tracked via Malpedia.
Yasso
Technical ID: win.yasso
MALWARE
According to Palo Alto Networks, Yasso is an open source multi-platform intranet-assisted penetration toolset that brings together a number of features such as scanning, brute forcing, remote interactive shell, and running arbitrary commands. It is authored by a Mandarin-speaking pentester nicknamed Sairson.
Yarraq
Technical ID: win.yarraq
MALWAREfinancialhigh
Yarraq is a ransomware that encrypts files by using asymmetric keys and adding '.yarraq' as extension to the end of filenames. At the time of writing the attacker asks for $2000 ransom in order to provide a decryptor, to enable victims to restore their original files back. To communicate with the attacker the email: cyborgyarraq@protonmail.ch is provided.
MALWARE
According to PTSecurity, this RAT uses Yandex Disk as a C2.
Yanluowang
Technical ID: win.yanluowang
MALWAREfinancialhigh
According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the "README.txt" file containing a ransom note. It appends the ".yanluowang" extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector.
Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).
Also known as: Dryxiphia
MALWARE
Malware family identifying win.yamabot. Origin and technical characteristics tracked via Malpedia.
Also known as: Kaos
Yakuza
Technical ID: win.yakuza_ransomware
MALWAREfinancialhigh
Ransomware.
Also known as: Teslarvng Ransomware
MALWARE
Malware family identifying win.yahoyah. Origin and technical characteristics tracked via Malpedia.
Also known as: KeyBoy
X-ZIGZAG
Technical ID: win.x_zigzag
MALWARE
The author of X-ZIGZAG claims that it is a lightweight and stealthy Windows Remote Access Trojan (RAT) designed for educational purposes.
MALWARE
Malware family identifying win.xxmm. Origin and technical characteristics tracked via Malpedia.
Also known as: ShadowWalker
MALWAREfinancialhigh
Malware with wide range of capabilities ranging from RAT to ransomware.