Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.webc2_bolid. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_ausov. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.webc2_adspace. Origin and technical characteristics tracked via Malpedia.
MALWARE
WebbyTea is an HTTP(S) downloader that uses AES for C&C trafic encryption.
It sends detailed information about the victim's environment, like proxy settings, system instalation date, Windows product name and version, manufacturer, product name, system boot time, time zone, computer name, user name, current time and a list of currently running processes. Data sent to the C&C server consists of the prefix "ci", a 16-characters long hexadecimal string representing the victim ID and an encrypted data about the victim's system. After the payload is acquired from the server and successfully injected in a newly created explorer.exe process, the malware responds back with the same victim ID having the prefix changed to "cs".
The internal DLL name of the native WebbyTea is usually pe64.dll or webT64.dll (from which its name is derived).
The usual payload associated with WebbyTea is SnatchCrypto.
MALWARE
Malware family identifying win.wavy_exfiller. Origin and technical characteristics tracked via Malpedia.
Wave Stealer
Technical ID: win.wavestealer
MALWARE
Wave Stealer is an infostealer offered as Malware-as-a-Service by a French-speaking actor called "Wave". The threat actor has strong relationships with Nova Stealer's and Epsilon Stealer's groups. It's capabilities include passwords and crypto-wallet stealing, discord and telegram injection, and backup codes finder.
MALWARE
Malware family identifying win.waterspout. Origin and technical characteristics tracked via Malpedia.
WaterMiner
Technical ID: win.waterminer
MALWARE
Malware family identifying win.waterminer. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Waterbear, also known as DbgPrint in its earlier export function, has been active since 2009. The malware is presumably developed by the BlackTech APT group and adopts advanced anti-analysis and forward-thinking design. These designs include a sophisticated shellcode stager, the ability to load plugins on-the-fly, and overall evasiveness should the C2 server fail to respond with a valid session key.
Also known as: DbgPrint • EYEWELL
WastedLocker
Technical ID: win.wastedlocker
MALWAREfinancialhigh
WastedLocker is a ransomware detected to be in use since May 2020 by EvilCorp. The ransomware name is derived from the filename that it creates which includes an abbreviation of the victim’s name and the string ‘wasted’. WastedLocker is protected with a custom crypter, referred to as CryptOne by Fox-IT InTELL. On examination, this crypter turned out to be very basic and was used also by other malware families such as: Netwalker, Gozi ISFB v3, ZLoader and Smokeloader. The crypter mainly contains junk code to increase entropy of the sample and hide the actual code.
WastedLoader
Technical ID: win.wastedloader
MALWAREfinancialhigh
This malware looks similar to WastedLocker, but the ransomware component is missing.
Warsaw
Technical ID: win.warsaw
MALWAREfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
Warp Stealer
Technical ID: win.warp_stealer
MALWARE
According to Seqrite, this is a fork of Stealerium that has high overlap with its originating codebase. Main changes include removal of Discord web hooks (for the sake of using Telegram) and rebranding away from Stealerium (string removal).
WarmCookie
Technical ID: win.warmcookie
MALWAREespionageadvanced
WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots. It communicates with a command and control (C&C) server via HTTP to receive further instructions and exfiltrate stolen data. It is commonly distributed through phishing campaigns and malicious downloads, targeting unsuspecting users to infiltrate systems undetected.
Also known as: Badspace • Carrotstick • QUICKBIND
WarLock
Technical ID: win.warlock
MALWARE
Malware family identifying win.warlock. Origin and technical characteristics tracked via Malpedia.
WarHawk
Technical ID: win.warhawk
MALWARE
Malware family identifying win.warhawk. Origin and technical characteristics tracked via Malpedia.
Warezov
Technical ID: win.warezov
MALWARE
Malware family identifying win.warezov. Origin and technical characteristics tracked via Malpedia.
Also known as: Stration • Opnis
WannaRen
Technical ID: win.wannaren
MALWAREfinancialhigh
Ransomware.
WannaHusky
Technical ID: win.wannahusky
MALWAREfinancialhigh
According to Mars, WannaHusky is a Nim-compiled ransomware malware sample, created for demonstration purposes and provided as part of the Practical Malware Analysis & Triage course provided by HuskyHacks.
MALWAREfinancialhigh
WannaCry is ransomware that contains a worm component enabled by the EternalBlue exploit. It attempts to use vulnerabilities in the Windows SMBv1 server to remotely compromise systems, encrypt files, and spread to other hosts. Systems that have installed the MS17-010 patch are not vulnerable to the exploits used. The spreading was stopped about 8 hours after initial outbreak due to triggering a kill switch domain.
Also known as: Wana Decrypt0r • WannaCry • WannaCrypt • Wcry
WallyShack
Technical ID: win.wallyshack
MALWARE
Malware family identifying win.wallyshack. Origin and technical characteristics tracked via Malpedia.
Wainscot
Technical ID: win.wainscot
MALWARE
Malware family identifying win.wainscot. Origin and technical characteristics tracked via Malpedia.
MALWARE
wAgentTea is an HTTP(S) downloader.
It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or semiconductor industry (Q2 2023). In several cases, the initial access was obtained via exploitation of South Korean software like Initech's INISAFE CrossWeb EX or Dream Security’s MagicLine4NX.
It uses AES-128 for encryption and decryption of its network traffic, and for decryption of its binary configuration.
There is a hard-coded list of parameter names used in its HTTP POST request:
identy;tname;blogdata;content;thesis;method;bbs;level;maincode;tab;idx;tb;isbn;entry;doc;
category;articles;portal
It contains a specific RTTI symbol ".?AVCHttp_socket@@".
Also known as: wAgent
MALWARE
Wabot is an IRC worm that is written in Delphi.
MALWARE
Malware family identifying win.w32times. Origin and technical characteristics tracked via Malpedia.
MALWARE
Vyveva is a remote access trojan that uses the Tor library for communication with C&C. Its use of fake TLS for camouflaging the network traffic is one of the typical Lazarus traits.
It uses a simple XOR for encryption of its configuration and network traffic.
It sends detailed information about the victim's environment, like computer name, user name, IP, code page, Windows version, architecture, and time zone.
It supports more than 20 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, and the download and memory execution of an additional DLL from the C&C (by calling the expected export SamIPromote). As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. The lowest index is 0x3, followed by 0x10, which goes incrementally up to 0x26. Also, it can monitor newly connected drives and the number of logged-on users.
It has MPRD.dll as the internal DLL name, and a single export SamIInitialize.
Vyveva RAT was used in an attack against a freight logistics company in South Africa in June 2020.
vxRat
Technical ID: win.vx_rat
MALWARE
Malware family identifying win.vx_rat. Origin and technical characteristics tracked via Malpedia.
Vulturi
Technical ID: win.vulturi
MALWARE
Information stealer.
vSkimmer
Technical ID: win.vskimmer
MALWARE
Malware family identifying win.vskimmer. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.vsingle. Origin and technical characteristics tracked via Malpedia.
VShell
Technical ID: win.vshell
MALWARE
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
Vreikstadi
Technical ID: win.vreikstadi
MALWARE
Malware family identifying win.vreikstadi. Origin and technical characteristics tracked via Malpedia.
Vovalex
Technical ID: win.vovalex
MALWAREfinancialhigh
Ransomware written in D.
MALWARE
Malware family identifying win.volgmer. Origin and technical characteristics tracked via Malpedia.
Also known as: FALLCHILL • Manuscrypt
Voldemort
Technical ID: win.voldemort
MALWAREespionageadvanced
Voldemort is a backdoor discovered by Proofpoint in August 2024. It is being distributed via phishing E-Mails and makes use of creative techniques such as using saved search files during the infection chain for obfuscation and Google Sheets for C2. While its broad targeting looks like it is related to ecrime, Proofpoint notes that the capabilities of the malware point towards espionage/APT activity.
VoidRAT
Technical ID: win.void_rat
MALWARE
Malware family identifying win.void_rat. Origin and technical characteristics tracked via Malpedia.
Voidoor
Technical ID: win.voidoor
MALWARE
Malware family identifying win.voidoor. Origin and technical characteristics tracked via Malpedia.
Vohuk
Technical ID: win.vohuk
MALWARE
Malware family identifying win.vohuk. Origin and technical characteristics tracked via Malpedia.
Vobfus
Technical ID: win.vobfus
MALWARE
Malware of this family searches for computers on a network and creates copies of itself in folders with open access. For the program to be activated, the user must first run it on the computer. The code of this malware is written in the Visual Basic programming language and uses obfuscation, which is a distinguishing feature of this family. Code obfuscation complicates attempts by anti-virus software to analyze suspected malware.
Also known as: Beebone