Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUP
WORMHOLE is a TCP tunneler that is dynamically configurable from a C&C server and can communicate with an additional remote machine endpoint for a relay.
APT GROUP
Malware family tracked by Malpedia. ID: win.woolger
APT GROUP
Malware family tracked by Malpedia. ID: win.woodyrat
APT GROUP
Malware family tracked by Malpedia. ID: win.woody
APT GROUP
Malware family tracked by Malpedia. ID: win.wonknu
APT GROUP
Malware family tracked by Malpedia. ID: win.wndtest
APT GROUP
According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. The RAT can gather basic host information, upload or download files, take screenshots, get geolocation data of the target machine, enumerate directories and files, and run arbitrary commands via cmd or PowerShell. The malware also generates a number of junk threads, potentially to mislead researchers or responders investigating the samples.
APT GROUP
Malware family tracked by Malpedia. ID: win.wmighost
APT GROUP
Malware family tracked by Malpedia. ID: win.wipbot
APT GROUP
Malware family tracked by Malpedia. ID: win.winsloader
APT GROUP
Backdoor used in the EvilPlayout campaign against Iran's State Broadcaster.
APT GROUP
WinPot is created to make ATMs by a popular ATM vendor to automatically dispense all cash from their most valuable cassettes.
APT GROUP
Malware family tracked by Malpedia. ID: win.winos
APT GROUP
According to ESET Research, this is a payload downloaded by win.wslink. They attribute it with low confidence to Lazarus.
APT GROUP
Malware family tracked by Malpedia. ID: elf.winnti
APT GROUP
Malware family tracked by Malpedia. ID: win.winmm
APT GROUP
Malware family tracked by Malpedia. ID: win.winlog
APT GROUP
Malware family tracked by Malpedia. ID: win.wininetloader
APT GROUP
Malware family tracked by Malpedia. ID: win.wineloader
APT GROUP
Information stealer used by threat actor LuoYu.
APT GROUP
Malware family tracked by Malpedia. ID: win.wildfire
APT GROUP
Malware family tracked by Malpedia. ID: win.wikiloader
APT GROUP
WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and crypto wallets.
The builder can build payloads in different file formats such as EXE, SCR, COM, CMD, BAT, VBS, PIF, WSF, .hta, MSI, PY, DOC, DOCM, XLS, XLL, XLSM. Some of these (python, bash) allow the malware to run on Linux systems.
The stealer has two execution methods:
* Non-resident - the stealer auto-deletes itself after successful execution
* Resident - the stealer beacons out to the C2 (possibly in the TOR network)
WhiteSnake Stealer can gather system information, execute remote commands, spread through USB drives, and perform tasks like keylogging, file management, and webcam access.
APT GROUP
Malware family tracked by Malpedia. ID: win.whiteblackcrypt
APT GROUP
According to Dr.Web, WhiteBird is a backdoor written in C++ and designed to operate in both 32-bit and 64-bit Microsoft Windows operating systems. The configuration is encrypted with a single byte XOR key. An interesting feature is that the malware can be restricted to operate only within certain "working_hours" with a granularity of one minute.
APT GROUP
Destructive malware deployed against targets in Ukraine in January 2022.
APT GROUP
Malware family tracked by Malpedia. ID: win.whiskerspy
APT GROUP
Malware family tracked by Malpedia. ID: win.westeal
APT GROUP
WellMess is A Remote Access Trojan written in GoLang and .NET. It has hard-coded User-Agents. Attackers deploy WellMess using separate tools which also allow lateral movement, for example "gost". Command and Control traffic is handled via HTTP using the Set-Cookie field and message body.
APT GROUP
Malware family tracked by Malpedia. ID: win.wecontrol
APT GROUP
On its website, Webmonitor RAT is described as 'a very powerful, user-friendly, easy-to-setup and state-of-the-art monitoring tool. Webmonitor is a fully native RAT, meaning it will run on all Windows versions and languages starting from Windows XP and up, and perfectly compatible with all crypters and protectors.'
Unit42 notes in their analysis that it is offered as C2-as-a-service and raises the controversial aspect that the builder allows to create client binaries that will not show any popup or dialogue during installation or while running on a target system.
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_yahoo
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_ugx
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_table
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_rave
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_qbp
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_kt3
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_head
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_greencat