Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Woolger
Technical ID: win.woolger
Rocket Kitten
MALWARE
Malware family identifying win.woolger. Origin and technical characteristics tracked via Malpedia.
Also known as: WoolenLogger
Updated: 2022-04-29
View profile →
Woody RAT
Technical ID: win.woodyrat
MALWARE
Malware family identifying win.woodyrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-05
View profile →
woody
Technical ID: win.woody
MALWARE
Malware family identifying win.woody. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
Wonknu
Technical ID: win.wonknu
MALWARE
Malware family identifying win.wonknu. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
WndTest
Technical ID: win.wndtest
Cleaver
MALWARE
Malware family identifying win.wndtest. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
WmRAT
Technical ID: win.wm_rat
HAZY TIGER
MALWARE
According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. The RAT can gather basic host information, upload or download files, take screenshots, get geolocation data of the target machine, enumerate directories and files, and run arbitrary commands via cmd or PowerShell. The malware also generates a number of junk threads, potentially to mislead researchers or responders investigating the samples.
Updated: 2025-06-05
View profile →
WMI Ghost
Technical ID: win.wmighost
Thrip
MALWARE
Malware family identifying win.wmighost. Origin and technical characteristics tracked via Malpedia.
Also known as: Wimmie • Syndicasec
Updated: 2018-06-22
View profile →
Wipbot
Technical ID: win.wipbot
Turla
MALWARE
Malware family identifying win.wipbot. Origin and technical characteristics tracked via Malpedia.
Also known as: Epic • Tavdig
Updated: 2024-12-11
View profile →
Winsloader
Technical ID: win.winsloader
Pirate Panda
MALWARE
Malware family identifying win.winsloader. Origin and technical characteristics tracked via Malpedia.
WinScreeny
Technical ID: win.winscreeny
MALWARE
Backdoor used in the EvilPlayout campaign against Iran's State Broadcaster.
Updated: 2022-03-02
View profile →
WinPot
Technical ID: win.winpot
MALWARE
WinPot is created to make ATMs by a popular ATM vendor to automatically dispense all cash from their most valuable cassettes.
Also known as: ATMPot
Updated: 2020-04-26
View profile →
Winos
Technical ID: win.winos
Void Arachne
MALWARE
Malware family identifying win.winos. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-19
View profile →
WinorDLL64
Technical ID: win.winordll64
Lazarus Group
MALWARE
According to ESET Research, this is a payload downloaded by win.wslink. They attribute it with low confidence to Lazarus.
Updated: 2023-02-27
View profile →
Winnti
Technical ID: win.winnti
APT17
MALWARE
Malware family identifying win.winnti. Origin and technical characteristics tracked via Malpedia.
Also known as: BleDoor • JUMPALL • RbDoor • Pasteboy
Updated: 2025-02-28
View profile →
WinMM
Technical ID: win.winmm
Naikon
MALWARE
Malware family identifying win.winmm. Origin and technical characteristics tracked via Malpedia.
winlog
Technical ID: win.winlog
MALWARE
Malware family identifying win.winlog. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-12
View profile →
WinInetLoader
Technical ID: win.wininetloader
Lazarus Group
MALWARE
Malware family identifying win.wininetloader. Origin and technical characteristics tracked via Malpedia.
Also known as: LIDSHOT
Updated: 2025-09-15
View profile →
WINELOADER
Technical ID: win.wineloader
APT29
MALWARE
Malware family identifying win.wineloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-16
View profile →
WinDealer
Technical ID: win.windealer
MALWARE
Information stealer used by threat actor LuoYu.
Updated: 2023-12-27
View profile →
WildFire
Technical ID: win.wildfire
MALWARE
Malware family identifying win.wildfire. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →
WikiLoader
Technical ID: win.wikiloader
MALWARE
Malware family identifying win.wikiloader. Origin and technical characteristics tracked via Malpedia.
Also known as: WailingCrab
Updated: 2024-03-04
View profile →
WhiteSnake Stealer
Technical ID: win.whitesnake
MALWARE
WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and crypto wallets. The builder can build payloads in different file formats such as EXE, SCR, COM, CMD, BAT, VBS, PIF, WSF, .hta, MSI, PY, DOC, DOCM, XLS, XLL, XLSM. Some of these (python, bash) allow the malware to run on Linux systems. The stealer has two execution methods: * Non-resident - the stealer auto-deletes itself after successful execution * Resident - the stealer beacons out to the C2 (possibly in the TOR network) WhiteSnake Stealer can gather system information, execute remote commands, spread through USB drives, and perform tasks like keylogging, file management, and webcam access.
Updated: 2025-04-14
View profile →
WhiteBlackCrypt
Technical ID: win.whiteblackcrypt
MALWARE
Malware family identifying win.whiteblackcrypt. Origin and technical characteristics tracked via Malpedia.
Also known as: WARYLOOK
Updated: 2022-03-07
View profile →
WhiteBird
Technical ID: win.whitebird
MALWARE
According to Dr.Web, WhiteBird is a backdoor written in C++ and designed to operate in both 32-bit and 64-bit Microsoft Windows operating systems. The configuration is encrypted with a single byte XOR key. An interesting feature is that the malware can be restricted to operate only within certain "working_hours" with a granularity of one minute.
Updated: 2020-10-02
View profile →
WhisperGate
Technical ID: win.whispergate
MALWARE
Destructive malware deployed against targets in Ukraine in January 2022.
Also known as: PAYWIPE
Updated: 2026-01-05
View profile →
WhiskerSpy
Technical ID: win.whiskerspy
MALWARE
Malware family identifying win.whiskerspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-24
View profile →
WeSteal
Technical ID: win.westeal
MALWARE
Malware family identifying win.westeal. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-19
View profile →
WellMess
Technical ID: win.wellmess
MALWARE
WellMess is A Remote Access Trojan written in GoLang and .NET. It has hard-coded User-Agents. Attackers deploy WellMess using separate tools which also allow lateral movement, for example "gost". Command and Control traffic is handled via HTTP using the Set-Cookie field and message body.
Updated: 2023-12-04
View profile →
WeControl
Technical ID: win.wecontrol
MALWARE
Malware family identifying win.wecontrol. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-19
View profile →
WebMonitor RAT
Technical ID: win.webmonitor
MALWARE
On its website, Webmonitor RAT is described as 'a very powerful, user-friendly, easy-to-setup and state-of-the-art monitoring tool. Webmonitor is a fully native RAT, meaning it will run on all Windows versions and languages starting from Windows XP and up, and perfectly compatible with all crypters and protectors.' Unit42 notes in their analysis that it is offered as C2-as-a-service and raises the controversial aspect that the builder allows to create client binaries that will not show any popup or dialogue during installation or while running on a target system.
Also known as: RevCode
Updated: 2020-11-19
View profile →
WebC2-Yahoo
Technical ID: win.webc2_yahoo
Comment Crew
MALWARE
Malware family identifying win.webc2_yahoo. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-UGX
Technical ID: win.webc2_ugx
Comment Crew
MALWARE
Malware family identifying win.webc2_ugx. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-Table
Technical ID: win.webc2_table
Comment Crew
MALWARE
Malware family identifying win.webc2_table. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
WebC2-Rave
Technical ID: win.webc2_rave
Comment Crew
MALWARE
Malware family identifying win.webc2_rave. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
WebC2-Qbp
Technical ID: win.webc2_qbp
Comment Crew
MALWARE
Malware family identifying win.webc2_qbp. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-Kt3
Technical ID: win.webc2_kt3
Comment Crew
MALWARE
Malware family identifying win.webc2_kt3. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-Head
Technical ID: win.webc2_head
Comment Crew
MALWARE
Malware family identifying win.webc2_head. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-GreenCat
Technical ID: win.webc2_greencat
Comment Crew
MALWARE
Malware family identifying win.webc2_greencat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-DIV
Technical ID: win.webc2_div
Comment Crew
MALWARE
Malware family identifying win.webc2_div. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebC2-Cson
Technical ID: win.webc2_cson
Comment Crew
MALWARE
Malware family identifying win.webc2_cson. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
← PreviousPage 124 / 269Next →