Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Zeus
Technical ID: win.zeus
MALWAREfinancialhigh
According to CrowdStrike, The two primary goals of the Zeus trojan horse virus are stealing people's financial information and adding machines to a botnet. Unlike many types of malware, most Zeus variants try to avoid doing long-term damage to the devices they infect. Their aim is to avoid detection from antivirus software.
Also known as: Zbot
Updated: 2024-03-12
View profile →
ZeroT
Technical ID: win.zerot
MALWARE
Malware family identifying win.zerot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-04
View profile →
Zeropadypt
Technical ID: win.zeropadypt
MALWARE
Malware family identifying win.zeropadypt. Origin and technical characteristics tracked via Malpedia.
Also known as: Ouroboros
Updated: 2023-05-10
View profile →
ZeroLocker
Technical ID: win.zerolocker
MALWARE
Malware family identifying win.zerolocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-31
View profile →
ZeroEvil
Technical ID: win.zeroevil
MALWARE
ZeroEvil is a malware that seems to be distributed by an ARSguarded VBS loader. It first connects to a gate.php (version=). Upon success, an embedded VBS gets started connecting to logs_gate.php (plugin=, report=). So far, only one embedded VBS was observed: it creates and starts a PowerShell script to retrieve all password from the Windows.Security.Credentials.PasswordVault. Apart from that, a screenshot is taken and a list of running processes generated. The ZeroEvil executable contains multiple DLLs, sqlite3.dll, ze_core.DLL (Mutex) and ze_autorun.DLL (Run-Key).
Updated: 2018-10-06
View profile →
ZeroCleare
Technical ID: win.zerocleare
OilRig
MALWARE
ZeroCleare is a destructive malware. It has been developed in order to wipe the master boot record section in order to damage a disk's partitioning. Attackers use the EldoS RawDisk driver to perform the malicious action, which is not a signed driver and would therefore not runnable by default. The attackers managed to install it by using a vulnerable version of VBoxDrv driver, which the DSE accepts and runs. Used to attack middle-east energy and industrial sectors.
Updated: 2023-01-19
View profile →
ZeroAccess
Technical ID: win.zeroaccess
MALWARE
ZeroAccess is a modular botnet that was primarily active around 2012. It has been observed selling fake antivirus software to infected users, performing click fraud and deploying bitcoin miners. It utilizes both peer-to-peer networking and a centralized C&C, spoofing the HTTP Host header with fake DGA-generated domains to confuse researchers. While there is no evidence that the DGA-generated domains were ever intentonally contacted by the malware, faulty middleboxes still caused some requests to be sent to the DGA domains.
Also known as: Max++ • Sirefef • Smiscer • ZAccess
Updated: 2025-07-24
View profile →
Zeppelin
Technical ID: win.zeppelin
Vanilla Tempest
MALWAREfinancialhigh
Zeppelin is a ransomware written in Delphi and sold a as-a-service. The Cylance research team notes that it is a clear evolution of the known VegaLocker, but they assessed it as a new family becaue of additionally developed modules that makes Zeppelin much more configurable than Vegalocker. There are executable variants of type DLL and EXE.
Updated: 2025-05-09
View profile →
Zeoticus
Technical ID: win.zeoticus
MALWARE
Malware family identifying win.zeoticus. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-04
View profile →
zenar
Technical ID: win.zenar
MALWARE
Malware family identifying win.zenar. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-11
View profile →
Zedhou
Technical ID: win.zedhou
MALWARE
Malware family identifying win.zedhou. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
Zebrocy (AutoIT)
Technical ID: win.zebrocy_au3
APT28
MALWARE
Malware family identifying win.zebrocy_au3. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-07-10
View profile →
Zebrocy
Technical ID: win.zebrocy
APT28
MALWAREespionageadvanced
According to brandefense, Zebrocy is malware that falls into the Trojan category, which the threat actor group APT28/Sofacy has used since 2015. Zebrocy malware consists of 3 main components; Backdoor, Downloader, and Dropper. The Downloader and Dropper take responsibility for discovery processes and downloading the main malware on the systems. At the same time, Backdoor undertakes the duties such as persistence in the system, espionage, and data extraction. This malware, which is not considered new, has variants in many languages from the past to the present. These include programming languages such as Delphi, C#, Visual C++, VB.net, and Golang. Furthermore, we know advanced threat actors and groups revise their malicious software among their toolkits at certain time intervals using different languages and technologies.
Also known as: Zekapab
Updated: 2024-07-10
View profile →
ZarDoor
Technical ID: win.zardoor
MALWARE
Malware family identifying win.zardoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-04
View profile →
Zacinlo
Technical ID: win.zacinlo
MALWARE
Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its other components, presence of man-in-the-browser capabilities that intercepts and decrypts SSL communications, and presence of an adware cleanup routine used to remove potential competition in the adware space. It also communicates with its C&C server, sending environment information such as installed AV and other applications. The malware also takes screenshots and does browser redirects, potentially manipulating the DOM tree. It also creates traffic in hidden windows, likely causing adfraud. The malware is generally very configurable and internally makes use of Lua scripts.
Also known as: s5mark
Updated: 2020-07-08
View profile →
Z3
Technical ID: win.z3
MALWAREfinancialhigh
Ransomware.
Also known as: Z3enc Ransomware
Updated: 2020-09-15
View profile →
Yunsip
Technical ID: win.yunsip
MALWARE
W32/Yunsip!tr.pws is classified as a password stealing trojan. Password Stealing Trojan searches the infected system for passwords and send them to the hacker.
Updated: 2022-07-01
View profile →
yty
Technical ID: win.yty
APT-C-35Donot TeamViceroy Tiger
MALWARE
Malware family identifying win.yty. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-18
View profile →
YTStealer
Technical ID: win.ytstealer
MALWARE
According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analyzed in a sandbox.
Updated: 2023-06-09
View profile →
YourCyanide
Technical ID: win.your_cyanide
MALWAREfinancialhigh
According to Trend Micro, this is a ransomware written as a Windows commandline script, with obfuscation applied.
Also known as: GonnaCope • Kekpop • Kekware
Updated: 2022-06-08
View profile →
YoungLotus
Technical ID: win.younglotus
MALWARE
Simple malware with proxy/RDP and download capabilities. It often comes bundled with installers, in particular in the Chinese realm. PE timestamps suggest that it came into existence in the second half of 2014. Some versions perform checks of the status of the internet connection (InternetGetConnectedState: MODEM, LAN, PROXY), some versions perform simple AV process-checks (CreateToolhelp32Snapshot).
Also known as: DarkShare
Updated: 2018-05-28
View profile →
YoreKey
Technical ID: win.yorekey
Kimsuky
MALWARE
Malware family identifying win.yorekey. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-15
View profile →
Yokai
Technical ID: win.yokai
MUSTANG PANDA
MALWARE
Malware family identifying win.yokai. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-23
View profile →
Yoddos
Technical ID: win.yoddos
MALWARE
Malware family identifying win.yoddos. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-12
View profile →
Ymir
Technical ID: win.ymir
MALWARE
According to Kaspersky, this malware sticks out as performing a large set of operations in memory with the help of the malloc, memmove and memcmp function calls.
Updated: 2025-03-21
View profile →
YiBackdoor
Technical ID: win.yibackdoor
MALWARE
Malware family identifying win.yibackdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-24
View profile →
YESROBOT
Technical ID: win.yesrobot
Callisto
MALWARE
Malware family identifying win.yesrobot. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-22
View profile →
Yellow Cockatoo RAT
Technical ID: win.yellow_cockatoo
MALWARE
Malware family identifying win.yellow_cockatoo. Origin and technical characteristics tracked via Malpedia.
Also known as: Polazer
Updated: 2022-03-23
View profile →
yayih
Technical ID: win.yayih
MALWARE
Malware family identifying win.yayih. Origin and technical characteristics tracked via Malpedia.
Also known as: bbsinfo • aumlib
Updated: 2018-09-19
View profile →
Yatron
Technical ID: win.yatron
MALWARE
Malware family identifying win.yatron. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-11
View profile →
Yasso
Technical ID: win.yasso
MALWARE
According to Palo Alto Networks, Yasso is an open source multi-platform intranet-assisted penetration toolset that brings together a number of features such as scanning, brute forcing, remote interactive shell, and running arbitrary commands. It is authored by a Mandarin-speaking pentester nicknamed Sairson.
Updated: 2025-01-15
View profile →
Yarraq
Technical ID: win.yarraq
MALWAREfinancialhigh
Yarraq is a ransomware that encrypts files by using asymmetric keys and adding '.yarraq' as extension to the end of filenames. At the time of writing the attacker asks for $2000 ransom in order to provide a decryptor, to enable victims to restore their original files back. To communicate with the attacker the email: cyborgyarraq@protonmail.ch is provided.
Updated: 2020-01-15
View profile →
YaRAT
Technical ID: win.yarat
APT31
MALWARE
According to PTSecurity, this RAT uses Yandex Disk as a C2.
Updated: 2022-08-15
View profile →
Yanluowang
Technical ID: win.yanluowang
MALWAREfinancialhigh
According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the "README.txt" file containing a ransom note. It appends the ".yanluowang" extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector. Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).
Also known as: Dryxiphia
Updated: 2023-06-09
View profile →
YamaBot
Technical ID: win.yamabot
Silent Chollima
MALWARE
Malware family identifying win.yamabot. Origin and technical characteristics tracked via Malpedia.
Also known as: Kaos
Updated: 2023-08-28
View profile →
Yakuza
Technical ID: win.yakuza_ransomware
MALWAREfinancialhigh
Ransomware.
Also known as: Teslarvng Ransomware
Updated: 2020-03-27
View profile →
Yahoyah
Technical ID: win.yahoyah
Pirate Panda
MALWARE
Malware family identifying win.yahoyah. Origin and technical characteristics tracked via Malpedia.
Also known as: KeyBoy
Updated: 2017-02-15
View profile →
X-ZIGZAG
Technical ID: win.x_zigzag
MALWARE
The author of X-ZIGZAG claims that it is a lightweight and stealthy Windows Remote Access Trojan (RAT) designed for educational purposes.
Updated: 2024-10-17
View profile →
xxmm
Technical ID: win.xxmm
Tick
MALWARE
Malware family identifying win.xxmm. Origin and technical characteristics tracked via Malpedia.
Also known as: ShadowWalker
Updated: 2021-03-02
View profile →
XWorm
Technical ID: win.xworm
Hive0137
MALWAREfinancialhigh
Malware with wide range of capabilities ranging from RAT to ransomware.
Updated: 2026-02-03
View profile →
← PreviousPage 122 / 269Next →