Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
VM Zeus
Technical ID: win.vmzeus
MALWARE
Malware family identifying win.vmzeus. Origin and technical characteristics tracked via Malpedia.
Also known as: VMzeus • ZeusVM • Zberp
Vjw0rm
Technical ID: win.vjw0rm
MALWARE
VJW0rm (aka Vengeance Justice Worm) is a publicly available, modular JavaScript RAT. Vjw0rm was first released in November 2016 by its primary author, v_B01 (aka Sliemerez), within the prominent DevPoint Arabic-language malware development community. VJW0rm appears to be the JavaScript variant of a series of RATs with identical functionality released by the author throughout late 2016. Other variants include a Visual Basic Script (VBS) based worm titled vw0rm (Vengeance Worm), an AutoHotkey-based tool called vrw0rm (Vengeance Rise Worm), and a PowerShell-based variant called vdw0rm (Vengeance Depth Worm).
Vizom
Technical ID: win.vizom
MALWARE
Malware family identifying win.vizom. Origin and technical characteristics tracked via Malpedia.
Virut
Technical ID: win.virut
MALWARE
Malware family identifying win.virut. Origin and technical characteristics tracked via Malpedia.
VIRTUALGATE
Technical ID: win.virtualgate
MALWARE
Malware family identifying win.virtualgate. Origin and technical characteristics tracked via Malpedia.
VirLock
Technical ID: win.virlock
MALWAREfinancialhigh
Polymorphic parasitic file infecting virus which transforms files into copies of itself. Additionally it uses screen-locking as a ransomware technique.
virdetdoor
Technical ID: win.virdetdoor
MALWARE
Malware family identifying win.virdetdoor. Origin and technical characteristics tracked via Malpedia.
VIP Keylogger
Technical ID: win.vipkeylogger
MALWARE
Malware family identifying win.vipkeylogger. Origin and technical characteristics tracked via Malpedia.
Vilsa Stealer
Technical ID: win.vilsastealer
MALWARE
Malware family identifying win.vilsastealer. Origin and technical characteristics tracked via Malpedia.
VIGILANT CLEANER
Technical ID: win.vigilant_cleaner
MALWARE
Wiper malware discovered by Japanese security firm Mitsui Bussan Secure Directions (MBSD), which is assumed to target Japan, the host country of the 2021 Summer Olympics. In addition to targeting common file Office-related files, it specifically targets file types associated with the Japanese word processor Ichitaro.
Also known as: VIGILANT CHECKER
Vidar
Technical ID: win.vidar
MALWARE
Vidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser.
VictoryGate
Technical ID: win.victorygate
MALWARE
VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020. The used malware itself was also referred to as VictoryGate. It was spotted in May 2019 and targeted mainly Latin American users, specifically, Peru (Criptonizando states 90% of the botnet publication residing there). Both public and private sectors were targeted.
This cryptojacking malware was specialized in Monero (XRM) cryptocurrency. VictoryGate shows very strong code overlap with win.orchard.
VHD Ransomware
Technical ID: win.vhd_ransomware
MALWAREfinancialhigh
Malware family identifying win.vhd_ransomware. Origin and technical characteristics tracked via Malpedia.
Vflooder
Technical ID: win.vflooder
MALWARE
Vflooder floods VirusTotal by infinitely submitting a copy of itself. Some variants apparently also try to flood Twitter. The impact on these services are negligible, but for researchers it can be a nuisance. Most versions are protected by VMProtect.
Vetta Loader
Technical ID: win.vetta_loader
MALWARE
Vetta Loader is a persistent Loader spreading with infected USB drives. It downloads other components leveraging legit hosting services.
https://yoroi.company/wp-content/uploads/2023/12/202311-Vetta-Loader_Def-min.pdf
Also known as: BrokerLoader • EMPTYSPACE
Vermin
Technical ID: win.vermin
MALWARE
Malware family identifying win.vermin. Origin and technical characteristics tracked via Malpedia.
Vermilion Strike
Technical ID: win.vermilion_strike
MALWARE
Malware family identifying win.vermilion_strike. Origin and technical characteristics tracked via Malpedia.
Venus Locker
Technical ID: win.venus_locker
MALWARE
Malware family identifying win.venus_locker. Origin and technical characteristics tracked via Malpedia.
Venom Proxy
Technical ID: win.venom_proxy
MALWARE
According to Cisco Talos, this is a reverse proxy socks5 server-client tool originally developed for penetration testers.
VenomLNK
Technical ID: win.venom_lnk
MALWARE
VenomLNK is the initial phase of the more_eggs malware-as-a-service. It is a poisoned .lnk file that depends on User Execution and points to LOLBINs (often cmd.exe) with additional obfuscated scripting options. This typically initiates WMI abuse and TerraLoader, which can load additional functionality through various plugins.
VenomLoader
Technical ID: win.venomloader
MALWARE
Malware family identifying win.venomloader. Origin and technical characteristics tracked via Malpedia.
Venom RAT
Technical ID: win.venom
MALWARE
Malware family identifying win.venom. Origin and technical characteristics tracked via Malpedia.
Vendetta
Technical ID: win.vendetta
MALWAREfinancialhigh
Ransomware, which appears to be a rebranding of win.cuba.
Velso
Technical ID: win.velso
MALWAREfinancialhigh
Ransomware that appears to require manually installation (believed to be via RDP). Encrypts files with .velso extension.
VELETRIX
Technical ID: win.veletrix
MALWARE
According to Seqrite, VELETRIX as been observed as a loader for VShell.
MALWARE
Malware family identifying win.veiledsignal. Origin and technical characteristics tracked via Malpedia.
VegaLocker
Technical ID: win.vegalocker
MALWAREfinancialhigh
Delphi-based ransomware.
Also known as: Buran • Vega
Veaty
Technical ID: win.veaty
MALWARE
Malware family identifying win.veaty. Origin and technical characteristics tracked via Malpedia.
Also known as: Whisper
MALWARE
Malware family identifying win.vawtrak. Origin and technical characteristics tracked via Malpedia.
Also known as: Catch • grabnew • NeverQuest
Varenyky
Technical ID: win.varenyky
MALWARE
In May 2019, ESET researchers observed a spike in ESET telemetry data regarding malware targeting France. After further investigations, they identified malware that distributes various types of spam. One of them is leading to a survey that redirects to a dodgy smartphone promotion while the other is a sextortion campaign. The spam targets the users of Orange S.A., a French ISP.
MALWARE
According to Mandiant, VaporRage or BOOMMIC, is a shellcode downloader written in C that communicates over HTTPS. Shellcode Payloads are retrieved from a hardcoded C2 that uses an encoded host_id generated from the targets domain and account name. BOOMMIC XOR decodes the downloaded shellcode payload in memory and executes it.
Also known as: BOOMMIC
vanillarat
Technical ID: win.vanillarat
MALWARE
Description:
VanillaRat is an advanced remote administration tool coded in C#. VanillaRat uses the Telepathy TCP networking library, dnlib module reading and writing library, and Costura.Fody dll embedding library.
Features:
Remote Desktop Viewer (With remote click)
File Browser (Including downloading, drag and drop uploading, and file opening)
Process Manager
Computer Information
Hardware Usage Information (CPU usage, disk usage, available ram)
Message Box Sender
Text To Speech
Screen Locker
Live Keylogger (Also shows current window)
Website Opener
Application Permission Raiser (Normal -> Admin)
Clipboard Text (Copied text)
Chat (Does not allow for client to close form)
Audio Recorder (Microphone)
Process Killer (Task manager, etc.)
Remote Shell
Startup
Security Blacklist (Drag client into list if you don't want connection. Press del. key on client to remove from list)
VanHelsing
Technical ID: win.vanhelsing
MALWARE
Malware family identifying win.vanhelsing. Origin and technical characteristics tracked via Malpedia.
Vampire Bot
Technical ID: win.vampire_bot
MALWARE
Malware family identifying win.vampire_bot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.valuevault. Origin and technical characteristics tracked via Malpedia.
ValleyRAT
Technical ID: win.valley_rat
MALWARE
Malware family identifying win.valley_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: Winos
Valkyrie Stealer
Technical ID: win.valkyrie_stealer
MALWARE
Malware family identifying win.valkyrie_stealer. Origin and technical characteristics tracked via Malpedia.
Vaggen
Technical ID: win.vaggen
MALWARE
Malware family identifying win.vaggen. Origin and technical characteristics tracked via Malpedia.
Vadokrist
Technical ID: win.vadokrist
MALWAREfinancialhigh
ESET reports that Vadokrist is a Latin American banking trojan that they have been tracking since 2018 and that is active almost exclusively in Brazil.