Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.woolger. Origin and technical characteristics tracked via Malpedia.
Also known as: WoolenLogger
Woody RAT
Technical ID: win.woodyrat
MALWARE
Malware family identifying win.woodyrat. Origin and technical characteristics tracked via Malpedia.
woody
Technical ID: win.woody
MALWARE
Malware family identifying win.woody. Origin and technical characteristics tracked via Malpedia.
Wonknu
Technical ID: win.wonknu
MALWARE
Malware family identifying win.wonknu. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.wndtest. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. The RAT can gather basic host information, upload or download files, take screenshots, get geolocation data of the target machine, enumerate directories and files, and run arbitrary commands via cmd or PowerShell. The malware also generates a number of junk threads, potentially to mislead researchers or responders investigating the samples.
MALWARE
Malware family identifying win.wmighost. Origin and technical characteristics tracked via Malpedia.
Also known as: Wimmie • Syndicasec
MALWARE
Malware family identifying win.wipbot. Origin and technical characteristics tracked via Malpedia.
Also known as: Epic • Tavdig
MALWARE
Malware family identifying win.winsloader. Origin and technical characteristics tracked via Malpedia.
WinScreeny
Technical ID: win.winscreeny
MALWARE
Backdoor used in the EvilPlayout campaign against Iran's State Broadcaster.
WinPot
Technical ID: win.winpot
MALWARE
WinPot is created to make ATMs by a popular ATM vendor to automatically dispense all cash from their most valuable cassettes.
Also known as: ATMPot
MALWARE
Malware family identifying win.winos. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to ESET Research, this is a payload downloaded by win.wslink. They attribute it with low confidence to Lazarus.
MALWARE
Malware family identifying win.winnti. Origin and technical characteristics tracked via Malpedia.
Also known as: BleDoor • JUMPALL • RbDoor • Pasteboy
MALWARE
Malware family identifying win.winmm. Origin and technical characteristics tracked via Malpedia.
winlog
Technical ID: win.winlog
MALWARE
Malware family identifying win.winlog. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.wininetloader. Origin and technical characteristics tracked via Malpedia.
Also known as: LIDSHOT
MALWARE
Malware family identifying win.wineloader. Origin and technical characteristics tracked via Malpedia.
WinDealer
Technical ID: win.windealer
MALWARE
Information stealer used by threat actor LuoYu.
WildFire
Technical ID: win.wildfire
MALWARE
Malware family identifying win.wildfire. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →WikiLoader
Technical ID: win.wikiloader
MALWARE
Malware family identifying win.wikiloader. Origin and technical characteristics tracked via Malpedia.
Also known as: WailingCrab
WhiteSnake Stealer
Technical ID: win.whitesnake
MALWARE
WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and crypto wallets.
The builder can build payloads in different file formats such as EXE, SCR, COM, CMD, BAT, VBS, PIF, WSF, .hta, MSI, PY, DOC, DOCM, XLS, XLL, XLSM. Some of these (python, bash) allow the malware to run on Linux systems.
The stealer has two execution methods:
* Non-resident - the stealer auto-deletes itself after successful execution
* Resident - the stealer beacons out to the C2 (possibly in the TOR network)
WhiteSnake Stealer can gather system information, execute remote commands, spread through USB drives, and perform tasks like keylogging, file management, and webcam access.
WhiteBlackCrypt
Technical ID: win.whiteblackcrypt
MALWARE
Malware family identifying win.whiteblackcrypt. Origin and technical characteristics tracked via Malpedia.
Also known as: WARYLOOK
WhiteBird
Technical ID: win.whitebird
MALWARE
According to Dr.Web, WhiteBird is a backdoor written in C++ and designed to operate in both 32-bit and 64-bit Microsoft Windows operating systems. The configuration is encrypted with a single byte XOR key. An interesting feature is that the malware can be restricted to operate only within certain "working_hours" with a granularity of one minute.
WhisperGate
Technical ID: win.whispergate
MALWARE
Destructive malware deployed against targets in Ukraine in January 2022.
Also known as: PAYWIPE
WhiskerSpy
Technical ID: win.whiskerspy
MALWARE
Malware family identifying win.whiskerspy. Origin and technical characteristics tracked via Malpedia.
WeSteal
Technical ID: win.westeal
MALWARE
Malware family identifying win.westeal. Origin and technical characteristics tracked via Malpedia.
WellMess
Technical ID: win.wellmess
MALWARE
WellMess is A Remote Access Trojan written in GoLang and .NET. It has hard-coded User-Agents. Attackers deploy WellMess using separate tools which also allow lateral movement, for example "gost". Command and Control traffic is handled via HTTP using the Set-Cookie field and message body.
WeControl
Technical ID: win.wecontrol
MALWARE
Malware family identifying win.wecontrol. Origin and technical characteristics tracked via Malpedia.
WebMonitor RAT
Technical ID: win.webmonitor
MALWARE
On its website, Webmonitor RAT is described as 'a very powerful, user-friendly, easy-to-setup and state-of-the-art monitoring tool. Webmonitor is a fully native RAT, meaning it will run on all Windows versions and languages starting from Windows XP and up, and perfectly compatible with all crypters and protectors.'
Unit42 notes in their analysis that it is offered as C2-as-a-service and raises the controversial aspect that the builder allows to create client binaries that will not show any popup or dialogue during installation or while running on a target system.
Also known as: RevCode
MALWARE
Malware family identifying win.webc2_yahoo. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_ugx. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_table. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_rave. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_qbp. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_kt3. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_head. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_greencat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_div. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_cson. Origin and technical characteristics tracked via Malpedia.