Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
WebC2-Bolid
Technical ID: win.webc2_bolid
Comment Crew
MALWARE
Malware family identifying win.webc2_bolid. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
WebC2-Ausov
Technical ID: win.webc2_ausov
Comment Crew
MALWARE
Malware family identifying win.webc2_ausov. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-13
View profile →
WebC2-AdSpace
Technical ID: win.webc2_adspace
Comment Crew
MALWARE
Malware family identifying win.webc2_adspace. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
WebbyTea
Technical ID: win.webbytea
Lazarus Group
MALWARE
WebbyTea is an HTTP(S) downloader that uses AES for C&C trafic encryption. It sends detailed information about the victim's environment, like proxy settings, system instalation date, Windows product name and version, manufacturer, product name, system boot time, time zone, computer name, user name, current time and a list of currently running processes. Data sent to the C&C server consists of the prefix "ci", a 16-characters long hexadecimal string representing the victim ID and an encrypted data about the victim's system. After the payload is acquired from the server and successfully injected in a newly created explorer.exe process, the malware responds back with the same victim ID having the prefix changed to "cs". The internal DLL name of the native WebbyTea is usually pe64.dll or webT64.dll (from which its name is derived). The usual payload associated with WebbyTea is SnatchCrypto.
Updated: 2025-09-15
View profile →
WavyExfiller
Technical ID: win.wavy_exfiller
CeranaKeeper
MALWARE
Malware family identifying win.wavy_exfiller. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
Wave Stealer
Technical ID: win.wavestealer
MALWARE
Wave Stealer is an infostealer offered as Malware-as-a-Service by a French-speaking actor called "Wave". The threat actor has strong relationships with Nova Stealer's and Epsilon Stealer's groups. It's capabilities include passwords and crypto-wallet stealing, discord and telegram injection, and backup codes finder.
Updated: 2024-06-28
View profile →
WaterSpout
Technical ID: win.waterspout
IXESHE
MALWARE
Malware family identifying win.waterspout. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
WaterMiner
Technical ID: win.waterminer
MALWARE
Malware family identifying win.waterminer. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-08-01
View profile →
Waterbear
Technical ID: win.waterbear
BlackTech
MALWAREespionageadvanced
Waterbear, also known as DbgPrint in its earlier export function, has been active since 2009. The malware is presumably developed by the BlackTech APT group and adopts advanced anti-analysis and forward-thinking design. These designs include a sophisticated shellcode stager, the ability to load plugins on-the-fly, and overall evasiveness should the C2 server fail to respond with a valid session key.
Also known as: DbgPrint • EYEWELL
Updated: 2023-07-19
View profile →
WastedLocker
Technical ID: win.wastedlocker
MALWAREfinancialhigh
WastedLocker is a ransomware detected to be in use since May 2020 by EvilCorp. The ransomware name is derived from the filename that it creates which includes an abbreviation of the victim’s name and the string ‘wasted’. WastedLocker is protected with a custom crypter, referred to as CryptOne by Fox-IT InTELL. On examination, this crypter turned out to be very basic and was used also by other malware families such as: Netwalker, Gozi ISFB v3, ZLoader and Smokeloader. The crypter mainly contains junk code to increase entropy of the sample and hide the actual code.
Updated: 2022-08-02
View profile →
WastedLoader
Technical ID: win.wastedloader
MALWAREfinancialhigh
This malware looks similar to WastedLocker, but the ransomware component is missing.
Updated: 2022-07-01
View profile →
Warsaw
Technical ID: win.warsaw
MALWAREfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
Updated: 2021-08-06
View profile →
Warp Stealer
Technical ID: win.warp_stealer
MALWARE
According to Seqrite, this is a fork of Stealerium that has high overlap with its originating codebase. Main changes include removal of Discord web hooks (for the sake of using Telegram) and rebranding away from Stealerium (string removal).
Updated: 2025-11-19
View profile →
WarmCookie
Technical ID: win.warmcookie
MALWAREespionageadvanced
WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots. It communicates with a command and control (C&C) server via HTTP to receive further instructions and exfiltrate stolen data. It is commonly distributed through phishing campaigns and malicious downloads, targeting unsuspecting users to infiltrate systems undetected.
Also known as: Badspace • Carrotstick • QUICKBIND
Updated: 2025-11-25
View profile →
WarLock
Technical ID: win.warlock
MALWARE
Malware family identifying win.warlock. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-20
View profile →
WarHawk
Technical ID: win.warhawk
MALWARE
Malware family identifying win.warhawk. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-08-29
View profile →
Warezov
Technical ID: win.warezov
MALWARE
Malware family identifying win.warezov. Origin and technical characteristics tracked via Malpedia.
Also known as: Stration • Opnis
Updated: 2024-04-29
View profile →
WannaRen
Technical ID: win.wannaren
MALWAREfinancialhigh
Ransomware.
Updated: 2020-04-20
View profile →
WannaHusky
Technical ID: win.wannahusky
MALWAREfinancialhigh
According to Mars, WannaHusky is a Nim-compiled ransomware malware sample, created for demonstration purposes and provided as part of the Practical Malware Analysis & Triage course provided by HuskyHacks.
Updated: 2022-04-08
View profile →
WannaCryptor
Technical ID: win.wannacryptor
Lazarus Group
MALWAREfinancialhigh
WannaCry is ransomware that contains a worm component enabled by the EternalBlue exploit. It attempts to use vulnerabilities in the Windows SMBv1 server to remotely compromise systems, encrypt files, and spread to other hosts. Systems that have installed the MS17-010 patch are not vulnerable to the exploits used. The spreading was stopped about 8 hours after initial outbreak due to triggering a kill switch domain.
Also known as: Wana Decrypt0r • WannaCry • WannaCrypt • Wcry
Updated: 2025-09-30
View profile →
WallyShack
Technical ID: win.wallyshack
MALWARE
Malware family identifying win.wallyshack. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-07
View profile →
Wainscot
Technical ID: win.wainscot
MALWARE
Malware family identifying win.wainscot. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-12-09
View profile →
wAgentTea
Technical ID: win.wagenttea
Lazarus Group
MALWARE
wAgentTea is an HTTP(S) downloader. It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or semiconductor industry (Q2 2023). In several cases, the initial access was obtained via exploitation of South Korean software like Initech's INISAFE CrossWeb EX or Dream Security’s MagicLine4NX. It uses AES-128 for encryption and decryption of its network traffic, and for decryption of its binary configuration. There is a hard-coded list of parameter names used in its HTTP POST request: identy;tname;blogdata;content;thesis;method;bbs;level;maincode;tab;idx;tb;isbn;entry;doc; category;articles;portal It contains a specific RTTI symbol ".?AVCHttp_socket@@".
Also known as: wAgent
Updated: 2025-10-31
View profile →
MALWARE
Wabot is an IRC worm that is written in Delphi.
w32times
Technical ID: win.w32times
UPS
MALWARE
Malware family identifying win.w32times. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-13
View profile →
Vyveva RAT
Technical ID: win.vyveva
Lazarus Group
MALWARE
Vyveva is a remote access trojan that uses the Tor library for communication with C&C. Its use of fake TLS for camouflaging the network traffic is one of the typical Lazarus traits. It uses a simple XOR for encryption of its configuration and network traffic. It sends detailed information about the victim's environment, like computer name, user name, IP, code page, Windows version, architecture, and time zone. It supports more than 20 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, and the download and memory execution of an additional DLL from the C&C (by calling the expected export SamIPromote). As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. The lowest index is 0x3, followed by 0x10, which goes incrementally up to 0x26. Also, it can monitor newly connected drives and the number of logged-on users. It has MPRD.dll as the internal DLL name, and a single export SamIInitialize. Vyveva RAT was used in an attack against a freight logistics company in South Africa in June 2020.
Updated: 2023-09-18
View profile →
vxRat
Technical ID: win.vx_rat
MALWARE
Malware family identifying win.vx_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-20
View profile →
Vulturi
Technical ID: win.vulturi
MALWARE
Information stealer.
Updated: 2021-08-31
View profile →
vSkimmer
Technical ID: win.vskimmer
MALWARE
Malware family identifying win.vskimmer. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
VSingle
Technical ID: win.vsingle
Lazarus GroupSilent Chollima
MALWARE
Malware family identifying win.vsingle. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-28
View profile →
VShell
Technical ID: win.vshell
MALWARE
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
Updated: 2025-11-05
View profile →
Vreikstadi
Technical ID: win.vreikstadi
MALWARE
Malware family identifying win.vreikstadi. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-16
View profile →
Vovalex
Technical ID: win.vovalex
MALWAREfinancialhigh
Ransomware written in D.
Updated: 2021-02-06
View profile →
Volgmer
Technical ID: win.volgmer
Lazarus Group
MALWARE
Malware family identifying win.volgmer. Origin and technical characteristics tracked via Malpedia.
Also known as: FALLCHILL • Manuscrypt
Updated: 2025-07-29
View profile →
Voldemort
Technical ID: win.voldemort
MALWAREespionageadvanced
Voldemort is a backdoor discovered by Proofpoint in August 2024. It is being distributed via phishing E-Mails and makes use of creative techniques such as using saved search files during the infection chain for obfuscation and Google Sheets for C2. While its broad targeting looks like it is related to ecrime, Proofpoint notes that the capabilities of the malware point towards espionage/APT activity.
Updated: 2025-07-17
View profile →
VoidRAT
Technical ID: win.void_rat
MALWARE
Malware family identifying win.void_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-20
View profile →
Voidoor
Technical ID: win.voidoor
MALWARE
Malware family identifying win.voidoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-19
View profile →
Void
Technical ID: win.void
MALWAREfinancialhigh
Ransomware.
Also known as: VoidCrypt
Updated: 2021-10-11
View profile →
Vohuk
Technical ID: win.vohuk
MALWARE
Malware family identifying win.vohuk. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-19
View profile →
Vobfus
Technical ID: win.vobfus
MALWARE
Malware of this family searches for computers on a network and creates copies of itself in folders with open access. For the program to be activated, the user must first run it on the computer. The code of this malware is written in the Visual Basic programming language and uses obfuscation, which is a distinguishing feature of this family. Code obfuscation complicates attempts by anti-virus software to analyze suspected malware.
Also known as: Beebone
Updated: 2022-11-12
View profile →
← PreviousPage 125 / 269Next →