Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
USBferry
Technical ID: win.usbferry
Pirate Panda
MALWARE
Malware family identifying win.usbferry. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-17
View profile →
USBCulprit
Technical ID: win.usbculprit
Hellsing
MALWARE
According to Kaspersky, USBCulprit is a malware that is capable of scanning various paths in victim machines, collecting documents with particular extensions and passing them on to USB drives when they are connected to the system. It can also selectively copy itself to a removable drive in the presence of a particular file, suggesting it can be spread laterally by having designated drives infected and the executable in them opened manually.
Updated: 2021-12-17
View profile →
Uroburos
Technical ID: win.uroburos
Turla
MALWARE
Uroburos is a driver for Windows, including a bypass of PatchGuard. According to Andrzej Dereszowski and Matthieu Kaczmarek, "the techniques used demonstrate [their] excellent knowledge of Windows kernel internals."
Also known as: Snake
Updated: 2023-08-11
View profile →
UrlZone
Technical ID: win.urlzone
MALWARE
Malware family identifying win.urlzone. Origin and technical characteristics tracked via Malpedia.
Also known as: Bebloh • Shiotob
Updated: 2021-05-31
View profile →
Urausy
Technical ID: win.urausy
MALWARE
Malware family identifying win.urausy. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-24
View profile →
Upatre
Technical ID: win.upatre
MALWARE
Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for delivering further malware to the victims, in specific upatre was a prolific delivery mechanism for Gameover P2P in 2013-2014 and then for Dyre in 2015.
Updated: 2023-04-18
View profile →
UPAS
Technical ID: win.upas
MALWARE
Malware family identifying win.upas. Origin and technical characteristics tracked via Malpedia.
Also known as: Rombrast
Updated: 2025-07-24
View profile →
Unlock92
Technical ID: win.unlock92
MALWARE
Malware family identifying win.unlock92. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-20
View profile →
Unidentified 124 (Azure Functions)
Technical ID: win.unidentified_124
MALWARE
This malware uses Azure Functions as its C2.
Updated: 2026-01-05
View profile →
Unidentified 123 (Go Infostealer)
Technical ID: win.unidentified_123
MALWARE
An infostealer written in Go.
Also known as: Go Infostealer
Updated: 2025-07-25
View profile →
Unidentified 122 (Stealer)
Technical ID: win.unidentified_122
MALWARE
According to Datadog, this malware functions primarily as a credential and infostealer. It enumerates LevelDB files within application data directories for Discord, Chromium-based browsers, cryptocurrency wallets, and Electron applications.
Updated: 2025-05-22
View profile →
Unidentified 121
Technical ID: win.unidentified_121
MALWARE
unidentified_121 acts as a downloader and reflective PE loader, employing a dual-mode execution strategy based on its privilege level. When executed without administrative rights, it uniquely attempts to bypass User Account Control (UAC) by first patching its own Process Environment Block (PEB) in memory to masquerade as explorer.exe, and then leveraging a specific COM object ({3E5FC7F9-9A51-4367-9063-A120244FBEC7} with the Elevation:Administrator!new: moniker) to relaunch itself with elevated privileges. This initial stage focuses purely on achieving elevation and does not perform C2 communication or direct payload execution itself in the non-elevated state. Once running with administrative privileges (either initially or after successful elevation), the malware establishes persistence by creating a Scheduled Task named "BlaBlaAgu" using COM, configuring it to run with the highest privileges and repeat every five minutes indefinitely. It actively evades defenses by using PowerShell commands (Add-MpPreference) to add Windows Defender exclusions for its own process and the user's profile directory, reinforcing these exclusions every 60 seconds via a separate thread. Its primary function in this elevated state is to act as a downloader, connecting to its Command and Control (C2) server over TCP port 33334 using a custom protocol encrypted with an RC4-like cipher and the hardcoded key "ALB9SxZBzCqwPFnD"; after a distinct 20-byte client handshake (RC4 Key + integer 444, followed by a 16-byte server response (RC4 Key) for validation), it downloads further encrypted PE payloads and executes them reflectively in its own memory space.
Updated: 2025-04-28
View profile →
Unidentified 120
Technical ID: win.unidentified_120
MALWARE
According to Deutsche Telekom CERT, this malware unpacks an obfuscated, multi-stage shellcode payload. After unpacking, a password prompt is displayed to the user. The password is provided to the victim and used to decrypt the final stage payload.
Updated: 2025-02-19
View profile →
Unidentified 118
Technical ID: win.unidentified_118
MALWARE
Malware family identifying win.unidentified_118. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-03-05
View profile →
Unidentified 117 (Donot Loader)
Technical ID: win.unidentified_117
VICEROY TIGER
MALWARE
Malware family identifying win.unidentified_117. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
Unidentified 116 (Miner)
Technical ID: win.unidentified_116
MALWARE
This malware family delivers its artifacts packed with free and generic packers. It writes files to windows temporary folders, downloads additional malware (generally cryptominers) and deletes itself.
Updated: 2024-08-29
View profile →
Unidentified 115 (Nim Loader)
Technical ID: win.unidentified_115
MALWARE
According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that will download/decrypt a payload via AES CFB and inject it into a hardcoded process target (e.g. explorer.exe).
Updated: 2024-03-06
View profile →
Unidentified 114 (APT28 InfoStealer)
Technical ID: win.unidentified_114
APT28
MALWARE
According to Trend Micro, this is a small information stealer written in .NET, that pushes its loot to a benign file sharing service and does not have a direct C&C callback.
Updated: 2024-02-02
View profile →
Unidentified 113 (RAT)
Technical ID: win.unidentified_113
MALWAREespionageadvanced
According to Phylum, this is a RAT with these characteristics: * Registers as a scheduled task. * Receives commands from a remote server using web sockets. * Installs Chrome extensions to Secure Preferences. * Configures AnyDesk, hides the screen, and disables shutting down Windows. * Captures keyboard and mouse events. * Collects information about files, browser extensions, and browser history.
Updated: 2024-01-22
View profile →
Unidentified 112 (Rust-based Stealer)
Technical ID: win.unidentified_112
MALWAREespionageadvanced
A Rust-based stealer, observed by Seqrite, along TTPs overlapping with Pakistan-linked APT groups.
Updated: 2023-12-27
View profile →
Unidentified 110 (RustyFlag)
Technical ID: win.unidentified_110
MALWARE
According to Deep Instinct, this information stealer is written in Rust and was observed in Operation Rusty Flag.
Updated: 2023-09-20
View profile →
Unidentified 109 (Lazarus?)
Technical ID: win.unidentified_109
MALWARE
Malware family identifying win.unidentified_109. Origin and technical characteristics tracked via Malpedia.
Also known as: IMEEX
Updated: 2024-10-20
View profile →
Unidentified 108
Technical ID: win.unidentified_108
MALWARE
Malware family identifying win.unidentified_108. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-31
View profile →
Unidentified 107 (APT29)
Technical ID: win.unidentified_107
MALWAREespionageadvanced
Small shellcode downloader, likely used by APT29.
Also known as: ICEBEAT
Updated: 2023-10-18
View profile →
Unidentified 106
Technical ID: win.unidentified_106
MALWARE
This is possibly related to the MATA framework / Dacls.
Updated: 2023-10-18
View profile →
Unidentified 105
Technical ID: win.unidentified_105
Silent Chollima
MALWARE
Malware family identifying win.unidentified_105. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-07-24
View profile →
Unidentified 104
Technical ID: win.unidentified_104
MALWARE
Malware family identifying win.unidentified_104. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-01
View profile →
Unidentified 103 (FIN8)
Technical ID: win.unidentified_103
MALWAREfinancialhigh
A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to in coverage on WHITERABBIT ransomware attacks.
Also known as: Ragnar Loader • Sardonic
Updated: 2025-03-06
View profile →
Unidentified 102 (Donot)
Technical ID: win.unidentified_102
VICEROY TIGER
MALWARE
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
Updated: 2023-07-24
View profile →
Unidentified 101 (Lazarus?)
Technical ID: win.unidentified_101
Lazarus Group
MALWARE
Potential Lazarus sample.
Updated: 2023-06-29
View profile →
Unidentified 100 (APT-Q-12)
Technical ID: win.unidentified_100
APT-Q-12
MALWARE
Malware family identifying win.unidentified_100. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-15
View profile →
Unidentified 099 (APT29 Dropbox Loader)
Technical ID: win.unidentified_099
APT29
MALWAREespionageadvanced
This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations. It is different from win.boombox, which is another APT29 attributed malware using DropBox (written in .NET).
Updated: 2024-02-02
View profile →
Unidentified 098 (APT29 Slack Downloader)
Technical ID: win.unidentified_098
APT29
MALWARE
Malware family identifying win.unidentified_098. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-20
View profile →
Unidentified 097 (Polonium Keylogger)
Technical ID: win.unidentified_097
POLONIUM
MALWARE
Malware family identifying win.unidentified_097. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-10-12
View profile →
Unidentified 096 (Keylogger)
Technical ID: win.unidentified_096
TA410
MALWARE
Keylogger.
Updated: 2025-10-15
View profile →
Unidentified 095 (Iranian Wiper)
Technical ID: win.unidentified_095
MALWARE
Wiper, using EldoS RawDisk for low level access to disks.
Updated: 2022-09-26
View profile →
Unidentified 093 (Sidewinder)
Technical ID: win.unidentified_093
RAZOR TIGER
MALWARE
Check Point Research observed this malware being used by Sidewinder.
Updated: 2025-11-13
View profile →
Unidentified 092 (Confucius Backdoor)
Technical ID: win.unidentified_092
MALWAREespionageadvanced
According to Antiy CERT, this is a C++ backdoor that was first discovered in an attack by Confucius in September 2020. Its main functions include creating scheduled tasks, retrieving process information, retrieving network adapter information, retrieving disk drive information, uploading files, downloading files, executing files, and providing shell access.
Updated: 2022-07-15
View profile →
Unidentified 091
Technical ID: win.unidentified_091
MALWARE
Avast found this unidentified RAT, which abuses a code-signing certificate by the Philippine Navy. It is statically linked against OpenSSL 1.1.1g.
Updated: 2022-04-07
View profile →
Unidentified 090 (Lazarus)
Technical ID: win.unidentified_090
Lazarus Group
MALWARE
Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
Updated: 2023-07-24
View profile →
← PreviousPage 127 / 269Next →