Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Xwo
Technical ID: win.xwo
MALWARE
In March 2019, AT&T Alien Labs identified a new malware family that is actively scanning for exposed web services and default passwords. Based on our findings we are calling it “Xwo” - taken from its primary module name. It is likely related to the previously reported malware families Xbash and MongoLock.
Updated: 2019-04-03
View profile →
X-Tunnel (.NET)
Technical ID: win.xtunnel_net
APT28
MALWARE
This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.
Updated: 2018-10-24
View profile →
XTunnel
Technical ID: win.xtunnel
APT28
MALWARE
X-Tunnel is a network proxy tool that implements a custom network protocol encapsulated in the TLS protocol.
Also known as: Shunnael • X-Tunnel • xaps
Updated: 2022-03-14
View profile →
XTinyLoader
Technical ID: win.xtinyloader
MALWARE
Simple Loader used to download and install stealers, clippers and other malwares.
Updated: 2025-09-09
View profile →
xsPlus
Technical ID: win.xsplus
Naikon
MALWARE
Malware family identifying win.xsplus. Origin and technical characteristics tracked via Malpedia.
Also known as: nokian
XServer
Technical ID: win.xserver
UPSViolin Panda
MALWARE
Malware family identifying win.xserver. Origin and technical characteristics tracked via Malpedia.
Also known as: Filesnfer
Updated: 2020-05-19
View profile →
XRed
Technical ID: win.xred
MALWAREespionageadvanced
According to eSentire, XRed, also known as Synaptics worm, is a backdoor that has been circulating since at least 2019. This malware was initially spread through drivers bundled with USB-C hub adapters, which served as its primary distribution vector. Once executed, the backdoor self-replicates and to maintain persistence, it creates a Windows Registry Run key. Additionally, it uses a mutex named Synaptics2X to ensure that only one instance of the malware runs at a time. XRed includes several advanced features that enable remote control and data exfiltration. It can download additional payloads from hardcoded URLs embedded within its binary. The malware exfiltrates sensitive system information—such as the MAC address, username, and computer name—which is sent via SMTP to hardcoded email addresses. It also incorporates keylogging functionality through keyboard hooking techniques. Furthermore, XRed supports a variety of remote commands that allow the attacker to gain command prompt access, capture screenshots, list available disks and directories, download files from remote sources, and delete files from the infected system. XRed also exhibits worm-like behavior: It spreads through USB drives by creating an autorun.inf file. Additionally, the malware infects Excel files with macros (.xlsm) by injecting a malicious VBA macro into them. The malware uses a hardcoded dynamic DNS domain (xred.mooo.com) to communicate with its command and control server. This domain serves as an identifying feature of the malware. According to researchers at eSentire, linguistic evidence found in the malware's code suggests that the developer is a native Turkish speaker.
Updated: 2025-06-23
View profile →
XP PrivEsc (CVE-2014-4076)
Technical ID: win.xp_privesc
APT28
MALWARE
Malware family identifying win.xp_privesc. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
XpertRAT
Technical ID: win.xpertrat
MALWARE
According to PCrisk, XpertRAT is a Remote Administration Trojan, a malicious program that allows cyber criminals to remotely access and control infected computers. Typically, users download and install this software inadvertently because they are tricked. By having computers infected with malware such as XpertRAT, users can experience serious problems.
Updated: 2023-06-09
View profile →
XPCTRA
Technical ID: win.xpctra
MALWARE
Incorporates code of Quasar RAT.
Also known as: Expectra
Updated: 2020-12-10
View profile →
Xpan
Technical ID: win.xpan
TeamXRat
MALWARE
Malware family identifying win.xpan. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
xPack
Technical ID: win.xpack
AntlionPirate Panda
MALWARE
Symantec describes this as a decryptor/loader used by Chinese threat actor Antlion in campaigns targeting Taiwan.
Also known as: NERAPACK
Updated: 2022-03-30
View profile →
XP10
Technical ID: win.xp10
MALWAREfinancialhigh
Ransomware.
Also known as: FakeChrome Ransomware
Updated: 2020-09-15
View profile →
XoriumStealer
Technical ID: win.xoriumstealer
MALWARE
Malware family identifying win.xoriumstealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-05
View profile →
Xorist
Technical ID: win.xorist
MALWAREfinancialhigh
According to PCrisk, Xorist is a family of ransomware-type malware. After stealth system infiltration, ransomware from this family encrypts various files stored on the computer. After encrypting the files, this ransomware creates a 'How to Decrypt Files.txt text file on the victim's desktop. The file contains a message stating that the files can only be restored by paying a ransom.
Updated: 2023-06-09
View profile →
xmrig
Technical ID: win.xmrig
MALWARE
According to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling". In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.
Updated: 2025-02-28
View profile →
Xillen Stealer
Technical ID: win.xillen_stealer
MALWARE
Malware family identifying win.xillen_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-31
View profile →
XiebroC2
Technical ID: win.xiebroc2
MALWARE
Malware family identifying win.xiebroc2. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-25
View profile →
XiaoBa
Technical ID: win.xiaoba
MALWAREfinancialhigh
Ransomware.
Updated: 2020-03-19
View profile →
Xiangoop
Technical ID: win.xiangoop
MALWARE
Malware family identifying win.xiangoop. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-23
View profile →
XFSCashNCR
Technical ID: win.xfscashncr
MALWARE
Malware family identifying win.xfscashncr. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-04
View profile →
XFSADM
Technical ID: win.xfsadm
MALWARE
Malware family identifying win.xfsadm. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-12
View profile →
X-Files Stealer
Technical ID: win.xfilesstealer
MALWARE
Malware family identifying win.xfilesstealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
XenoRAT
Technical ID: win.xenorat
MALWARE
XenoRAT is an open source remote access trojan written in C#. It can monitor user activity including keystrokes, and provide remote control over the compromised system.
Updated: 2025-08-20
View profile →
Xenon Stealer
Technical ID: win.xenon
MALWARE
Malware family identifying win.xenon. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-03
View profile →
XenArmor
Technical ID: win.xenarmor
MALWARE
XenArmor is a suite of password recovery tools for various applications that have been observed to be abused in attacks alongside malware.
Also known as: XenArmor Suite
Updated: 2023-05-10
View profile →
XehookStealer
Technical ID: win.xehook
MALWARE
Xehook is a .NET-based malware targeting Windows systems. It collects data from Chromium and Gecko browsers, supporting over 110 cryptocurrencies and 2FA extensions. CRIL found a potential link between Xehook Stealer, Agniane, and the Cinoshi project, suggesting a progression from a free MaaS model to the development of Xehook Stealer. SmokeLoader binaries were identified as a common vector for distributing Xehook Stealer. Xehook Stealer shares code overlaps with Agniane Stealer, indicating an evolutionary relationship.
Updated: 2024-05-17
View profile →
XDSpy
Technical ID: win.xdspy
MALWARE
According to ESET Research, XDDown is a primary malware component and is strictly a downloader. It persists on the system using the traditional Run key. It downloads additional plugins from the hardcoded C&C server using the HTTP protocol. The HTTP replies contain PE binaries encrypted with a hardcoded two-byte XOR key. Plugins include a module for reconnaissance on the affected system, crawling drives, file exfiltration, SSID gathering, and grabbing saved passwords.
Updated: 2025-06-23
View profile →
XData
Technical ID: win.xdata
MALWARE
Malware family identifying win.xdata. Origin and technical characteristics tracked via Malpedia.
Also known as: AESNI
Updated: 2022-08-25
View profile →
xCaon
Technical ID: win.xcaon
MALWARE
Checkpoint Research found this backdoor, attributed to IndigoZebra, used to target Afghan and other Central-Asia countries, including Kyrgyzstan and Uzbekistan, since at least 2014.
Updated: 2021-08-03
View profile →
XBTL
Technical ID: win.xbtl
MALWARE
Malware family identifying win.xbtl. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-10
View profile →
XBot POS
Technical ID: win.xbot_pos
MALWARE
Malware family identifying win.xbot_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-14
View profile →
X-Agent
Technical ID: win.xagent
APT28
MALWARE
Malware family identifying win.xagent. Origin and technical characteristics tracked via Malpedia.
Also known as: splm • chopstick
Updated: 2024-07-10
View profile →
x4
Technical ID: win.x4
MALWARE
Malware family identifying win.x4. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-15
View profile →
Wslink
Technical ID: win.wslink
MALWARE
Malware family identifying win.wslink. Origin and technical characteristics tracked via Malpedia.
Also known as: FinickyFrogfish
Updated: 2022-03-30
View profile →
WSCSPL
Technical ID: win.wscspl
Dropping Elephant
MALWARE
Malware family identifying win.wscspl. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-03
View profile →
WpBruteBot
Technical ID: win.wpbrutebot
MALWARE
Malware family identifying win.wpbrutebot. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-23
View profile →
WormLocker
Technical ID: win.wormlocker
MALWARE
Malware family identifying win.wormlocker. Origin and technical characteristics tracked via Malpedia.
Also known as: WormLckr
Updated: 2021-01-29
View profile →
WORMHOLE
Technical ID: win.wormhole
Lazarus Group
MALWARE
WORMHOLE is a TCP tunneler that is dynamically configurable from a C&C server and can communicate with an additional remote machine endpoint for a relay.
Updated: 2023-08-14
View profile →
WorldWind
Technical ID: win.worldwind
MALWARE
Information Stealer.
Updated: 2023-04-08
View profile →
← PreviousPage 123 / 269Next →