Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.usbferry. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Kaspersky, USBCulprit is a malware that is capable of scanning various paths in victim machines, collecting documents with particular extensions and passing them on to USB drives when they are connected to the system. It can also selectively copy itself to a removable drive in the presence of a particular file, suggesting it can be spread laterally by having designated drives infected and the executable in them opened manually.
MALWARE
Uroburos is a driver for Windows, including a bypass of PatchGuard. According to Andrzej Dereszowski and Matthieu Kaczmarek, "the techniques used demonstrate [their] excellent knowledge of Windows kernel internals."
Also known as: Snake
UrlZone
Technical ID: win.urlzone
MALWARE
Malware family identifying win.urlzone. Origin and technical characteristics tracked via Malpedia.
Also known as: Bebloh • Shiotob
Urausy
Technical ID: win.urausy
MALWARE
Malware family identifying win.urausy. Origin and technical characteristics tracked via Malpedia.
Upatre
Technical ID: win.upatre
MALWARE
Upatre is primarly a downloader. It has been discovered in 2013 and since that time it has been widely updated. Upatre is responsible for delivering further malware to the victims, in specific upatre was a prolific delivery mechanism for Gameover P2P in 2013-2014 and then for Dyre in 2015.
UPAS
Technical ID: win.upas
MALWARE
Malware family identifying win.upas. Origin and technical characteristics tracked via Malpedia.
Also known as: Rombrast
Unlock92
Technical ID: win.unlock92
MALWARE
Malware family identifying win.unlock92. Origin and technical characteristics tracked via Malpedia.
Unidentified 124 (Azure Functions)
Technical ID: win.unidentified_124
MALWARE
This malware uses Azure Functions as its C2.
Unidentified 123 (Go Infostealer)
Technical ID: win.unidentified_123
MALWARE
An infostealer written in Go.
Also known as: Go Infostealer
Unidentified 122 (Stealer)
Technical ID: win.unidentified_122
MALWARE
According to Datadog, this malware functions primarily as a credential and infostealer. It enumerates LevelDB files within application data directories for Discord, Chromium-based browsers, cryptocurrency wallets, and Electron applications.
Unidentified 121
Technical ID: win.unidentified_121
MALWARE
unidentified_121 acts as a downloader and reflective PE loader, employing a dual-mode execution strategy based on its privilege level. When executed without administrative rights, it uniquely attempts to bypass User Account Control (UAC) by first patching its own Process Environment Block (PEB) in memory to masquerade as explorer.exe, and then leveraging a specific COM object ({3E5FC7F9-9A51-4367-9063-A120244FBEC7} with the Elevation:Administrator!new: moniker) to relaunch itself with elevated privileges. This initial stage focuses purely on achieving elevation and does not perform C2 communication or direct payload execution itself in the non-elevated state.
Once running with administrative privileges (either initially or after successful elevation), the malware establishes persistence by creating a Scheduled Task named "BlaBlaAgu" using COM, configuring it to run with the highest privileges and repeat every five minutes indefinitely. It actively evades defenses by using PowerShell commands (Add-MpPreference) to add Windows Defender exclusions for its own process and the user's profile directory, reinforcing these exclusions every 60 seconds via a separate thread. Its primary function in this elevated state is to act as a downloader, connecting to its Command and Control (C2) server over TCP port 33334 using a custom protocol encrypted with an RC4-like cipher and the hardcoded key "ALB9SxZBzCqwPFnD"; after a distinct 20-byte client handshake (RC4 Key + integer 444, followed by a 16-byte server response (RC4 Key) for validation), it downloads further encrypted PE payloads and executes them reflectively in its own memory space.
Unidentified 120
Technical ID: win.unidentified_120
MALWARE
According to Deutsche Telekom CERT, this malware unpacks an obfuscated, multi-stage shellcode payload. After unpacking, a password prompt is displayed to the user. The password is provided to the victim and used to decrypt the final stage payload.
Unidentified 118
Technical ID: win.unidentified_118
MALWARE
Malware family identifying win.unidentified_118. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.unidentified_117. Origin and technical characteristics tracked via Malpedia.
Unidentified 116 (Miner)
Technical ID: win.unidentified_116
MALWARE
This malware family delivers its artifacts packed with free and generic packers. It writes files to windows temporary folders, downloads additional malware (generally cryptominers) and deletes itself.
Updated: 2024-08-29
View profile →Unidentified 115 (Nim Loader)
Technical ID: win.unidentified_115
MALWARE
According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that will download/decrypt a payload via AES CFB and inject it into a hardcoded process target (e.g. explorer.exe).
MALWARE
According to Trend Micro, this is a small information stealer written in .NET, that pushes its loot to a benign file sharing service and does not have a direct C&C callback.
Unidentified 113 (RAT)
Technical ID: win.unidentified_113
MALWAREespionageadvanced
According to Phylum, this is a RAT with these characteristics:
* Registers as a scheduled task.
* Receives commands from a remote server using web sockets.
* Installs Chrome extensions to Secure Preferences.
* Configures AnyDesk, hides the screen, and disables shutting down Windows.
* Captures keyboard and mouse events.
* Collects information about files, browser extensions, and browser history.
Unidentified 112 (Rust-based Stealer)
Technical ID: win.unidentified_112
MALWAREespionageadvanced
A Rust-based stealer, observed by Seqrite, along TTPs overlapping with Pakistan-linked APT groups.
Unidentified 110 (RustyFlag)
Technical ID: win.unidentified_110
MALWARE
According to Deep Instinct, this information stealer is written in Rust and was observed in Operation Rusty Flag.
Unidentified 109 (Lazarus?)
Technical ID: win.unidentified_109
MALWARE
Malware family identifying win.unidentified_109. Origin and technical characteristics tracked via Malpedia.
Also known as: IMEEX
Unidentified 108
Technical ID: win.unidentified_108
MALWARE
Malware family identifying win.unidentified_108. Origin and technical characteristics tracked via Malpedia.
Unidentified 107 (APT29)
Technical ID: win.unidentified_107
MALWAREespionageadvanced
Small shellcode downloader, likely used by APT29.
Also known as: ICEBEAT
Unidentified 106
Technical ID: win.unidentified_106
MALWARE
This is possibly related to the MATA framework / Dacls.
MALWARE
Malware family identifying win.unidentified_105. Origin and technical characteristics tracked via Malpedia.
Unidentified 104
Technical ID: win.unidentified_104
MALWARE
Malware family identifying win.unidentified_104. Origin and technical characteristics tracked via Malpedia.
Unidentified 103 (FIN8)
Technical ID: win.unidentified_103
MALWAREfinancialhigh
A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to in coverage on WHITERABBIT ransomware attacks.
Also known as: Ragnar Loader • Sardonic
MALWARE
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
Updated: 2023-07-24
View profile →MALWARE
Potential Lazarus sample.
MALWARE
Malware family identifying win.unidentified_100. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations. It is different from win.boombox, which is another APT29 attributed malware using DropBox (written in .NET).
MALWARE
Malware family identifying win.unidentified_098. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.unidentified_097. Origin and technical characteristics tracked via Malpedia.
Unidentified 095 (Iranian Wiper)
Technical ID: win.unidentified_095
MALWARE
Wiper, using EldoS RawDisk for low level access to disks.
MALWARE
Check Point Research observed this malware being used by Sidewinder.
Unidentified 092 (Confucius Backdoor)
Technical ID: win.unidentified_092
MALWAREespionageadvanced
According to Antiy CERT, this is a C++ backdoor that was first discovered in an attack by Confucius in September 2020. Its main functions include creating scheduled tasks, retrieving process information, retrieving network adapter information, retrieving disk drive information, uploading files, downloading files, executing files, and providing shell access.
Unidentified 091
Technical ID: win.unidentified_091
MALWARE
Avast found this unidentified RAT, which abuses a code-signing certificate by the Philippine Navy. It is statically linked against OpenSSL 1.1.1g.
MALWARE
Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
Updated: 2023-07-24
View profile →