Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Xwo
Technical ID: win.xwo
MALWARE
In March 2019, AT&T Alien Labs identified a new malware family that is actively scanning for exposed web services and default passwords. Based on our findings we are calling it “Xwo” - taken from its primary module name. It is likely related to the previously reported malware families Xbash and MongoLock.
MALWARE
This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.
MALWARE
X-Tunnel is a network proxy tool that implements a custom network protocol encapsulated in the TLS protocol.
Also known as: Shunnael • X-Tunnel • xaps
XTinyLoader
Technical ID: win.xtinyloader
MALWARE
Simple Loader used to download and install stealers, clippers and other malwares.
MALWARE
Malware family identifying win.xsplus. Origin and technical characteristics tracked via Malpedia.
Also known as: nokian
MALWARE
Malware family identifying win.xserver. Origin and technical characteristics tracked via Malpedia.
Also known as: Filesnfer
XRed
Technical ID: win.xred
MALWAREespionageadvanced
According to eSentire, XRed, also known as Synaptics worm, is a backdoor that has been circulating since at least 2019. This malware was initially spread through drivers bundled with USB-C hub adapters, which served as its primary distribution vector. Once executed, the backdoor self-replicates and to maintain persistence, it creates a Windows Registry Run key. Additionally, it uses a mutex named Synaptics2X to ensure that only one instance of the malware runs at a time. XRed includes several advanced features that enable remote control and data exfiltration. It can download additional payloads from hardcoded URLs embedded within its binary. The malware exfiltrates sensitive system information—such as the MAC address, username, and computer name—which is sent via SMTP to hardcoded email addresses. It also incorporates keylogging functionality through keyboard hooking techniques. Furthermore, XRed supports a variety of remote commands that allow the attacker to gain command prompt access, capture screenshots, list available disks and directories, download files from remote sources, and delete files from the infected system. XRed also exhibits worm-like behavior: It spreads through USB drives by creating an autorun.inf file. Additionally, the malware infects Excel files with macros (.xlsm) by injecting a malicious VBA macro into them. The malware uses a hardcoded dynamic DNS domain (xred.mooo.com) to communicate with its command and control server. This domain serves as an identifying feature of the malware. According to researchers at eSentire, linguistic evidence found in the malware's code suggests that the developer is a native Turkish speaker.
MALWARE
Malware family identifying win.xp_privesc. Origin and technical characteristics tracked via Malpedia.
XpertRAT
Technical ID: win.xpertrat
MALWARE
According to PCrisk, XpertRAT is a Remote Administration Trojan, a malicious program that allows cyber criminals to remotely access and control infected computers. Typically, users download and install this software inadvertently because they are tricked. By having computers infected with malware such as XpertRAT, users can experience serious problems.
MALWARE
Malware family identifying win.xpan. Origin and technical characteristics tracked via Malpedia.
MALWARE
Symantec describes this as a decryptor/loader used by Chinese threat actor Antlion in campaigns targeting Taiwan.
Also known as: NERAPACK
XoriumStealer
Technical ID: win.xoriumstealer
MALWARE
Malware family identifying win.xoriumstealer. Origin and technical characteristics tracked via Malpedia.
Xorist
Technical ID: win.xorist
MALWAREfinancialhigh
According to PCrisk, Xorist is a family of ransomware-type malware. After stealth system infiltration, ransomware from this family encrypts various files stored on the computer. After encrypting the files, this ransomware creates a 'How to Decrypt Files.txt text file on the victim's desktop. The file contains a message stating that the files can only be restored by paying a ransom.
xmrig
Technical ID: win.xmrig
MALWARE
According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling".
In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.
Xillen Stealer
Technical ID: win.xillen_stealer
MALWARE
Malware family identifying win.xillen_stealer. Origin and technical characteristics tracked via Malpedia.
XiebroC2
Technical ID: win.xiebroc2
MALWARE
Malware family identifying win.xiebroc2. Origin and technical characteristics tracked via Malpedia.
XiaoBa
Technical ID: win.xiaoba
MALWAREfinancialhigh
Ransomware.
Xiangoop
Technical ID: win.xiangoop
MALWARE
Malware family identifying win.xiangoop. Origin and technical characteristics tracked via Malpedia.
XFSCashNCR
Technical ID: win.xfscashncr
MALWARE
Malware family identifying win.xfscashncr. Origin and technical characteristics tracked via Malpedia.
XFSADM
Technical ID: win.xfsadm
MALWARE
Malware family identifying win.xfsadm. Origin and technical characteristics tracked via Malpedia.
X-Files Stealer
Technical ID: win.xfilesstealer
MALWARE
Malware family identifying win.xfilesstealer. Origin and technical characteristics tracked via Malpedia.
XenoRAT
Technical ID: win.xenorat
MALWARE
XenoRAT is an open source remote access trojan written in C#. It can monitor user activity including keystrokes, and provide remote control over the compromised system.
Xenon Stealer
Technical ID: win.xenon
MALWARE
Malware family identifying win.xenon. Origin and technical characteristics tracked via Malpedia.
XenArmor
Technical ID: win.xenarmor
MALWARE
XenArmor is a suite of password recovery tools for various applications that have been observed to be abused in attacks alongside malware.
Also known as: XenArmor Suite
XehookStealer
Technical ID: win.xehook
MALWARE
Xehook is a .NET-based malware targeting Windows systems. It collects data from Chromium and Gecko browsers, supporting over 110 cryptocurrencies and 2FA extensions. CRIL found a potential link between Xehook Stealer, Agniane, and the Cinoshi project, suggesting a progression from a free MaaS model to the development of Xehook Stealer. SmokeLoader binaries were identified as a common vector for distributing Xehook Stealer. Xehook Stealer shares code overlaps with Agniane Stealer, indicating an evolutionary relationship.
XDSpy
Technical ID: win.xdspy
MALWARE
According to ESET Research, XDDown is a primary malware component and is strictly a downloader. It persists on the system using the traditional Run key. It downloads additional plugins from the hardcoded C&C server using the HTTP protocol. The HTTP replies contain PE binaries encrypted with a hardcoded two-byte XOR key. Plugins include a module for reconnaissance on the affected system, crawling drives, file exfiltration, SSID gathering, and grabbing saved passwords.
XData
Technical ID: win.xdata
MALWARE
Malware family identifying win.xdata. Origin and technical characteristics tracked via Malpedia.
Also known as: AESNI
xCaon
Technical ID: win.xcaon
MALWARE
Checkpoint Research found this backdoor, attributed to IndigoZebra, used to target Afghan and other Central-Asia countries, including Kyrgyzstan and Uzbekistan, since at least 2014.
XBTL
Technical ID: win.xbtl
MALWARE
Malware family identifying win.xbtl. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →XBot POS
Technical ID: win.xbot_pos
MALWARE
Malware family identifying win.xbot_pos. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.xagent. Origin and technical characteristics tracked via Malpedia.
Also known as: splm • chopstick
x4
Technical ID: win.x4
MALWARE
Malware family identifying win.x4. Origin and technical characteristics tracked via Malpedia.
Wslink
Technical ID: win.wslink
MALWARE
Malware family identifying win.wslink. Origin and technical characteristics tracked via Malpedia.
Also known as: FinickyFrogfish
MALWARE
Malware family identifying win.wscspl. Origin and technical characteristics tracked via Malpedia.
WpBruteBot
Technical ID: win.wpbrutebot
MALWARE
Malware family identifying win.wpbrutebot. Origin and technical characteristics tracked via Malpedia.
WormLocker
Technical ID: win.wormlocker
MALWARE
Malware family identifying win.wormlocker. Origin and technical characteristics tracked via Malpedia.
Also known as: WormLckr
MALWARE
WORMHOLE is a TCP tunneler that is dynamically configurable from a C&C server and can communicate with an additional remote machine endpoint for a relay.
WorldWind
Technical ID: win.worldwind
MALWARE
Information Stealer.