Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
ThumbThief
Technical ID: win.thumbthief
MALWARE
Malware family identifying win.thumbthief. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.threebyte. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.thinmon. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.theme_forest_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: TALLSHIP
Thanatos Ransomware
Technical ID: win.thanatos_ransom
MALWARE
Malware family identifying win.thanatos_ransom. Origin and technical characteristics tracked via Malpedia.
Thanatos
Technical ID: win.thanatos
MALWARE
Malware family identifying win.thanatos. Origin and technical characteristics tracked via Malpedia.
Also known as: Alphabot
TFlower
Technical ID: win.tflower
MALWAREfinancialhigh
TFlower is a new ransomware targeting mostly corporate networks discovered in August, 2019. It is reportedly installed on networks by attackers after they gain access via RDP. TFlower displays a console showing activity being performed by the ransomware when it encrypts a machine, further indicating that this ransomware is triggered by the attacker post compromise, similar to Samsam/Samas in terms of TTP. Once encryption is started, the ransomware will conduct a status report to an apparently hard-coded C2. Shadow copies are deleted and the Windows 10 repair environment is disabled by this ransomware. This malware also will terminate any running Outlook.exe process so that the mail files can be encrypted. This ransomware does not add an extention to encrypted files, but prepends the marker "*tflower" and what may be the encrypted encryption key for the file to each affected file. Once encryption is completed, another status report is sent to the C2 server.
Tetra Loader
Technical ID: win.tetra_loader
MALWARE
According to Cisco Talos, this is loader is written in Rust and was observed to stage Cobalt Strike Beacons and VShell.
TeslaCrypt
Technical ID: win.teslacrypt
MALWAREfinancialhigh
According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers. Amongst other types of target files, it tries to infect typical gaming files: game saves, user profiles, recoded replays etc. That said, TeslaCrypt does not encrypt files that are larger than 268 MB. Recently,
Also known as: cryptesla
MALWARE
TerraTV is a custom DLL designed to hijack legit TeamViewer applications. It was discovered and documented by QuoINT. It has been attributed to Golden Chickens malware as a service group.
Also known as: Taurus Loader TeamViewer Module
MALWARE
According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email clients, web browsers, and file transfer utilities. Attributed to Golden Chickens.
Also known as: StealerOne • SONE • Taurus Loader Stealer Module
MALWARE
According to QuoINT TerraRecon is a reconnaissance tool, looking for a specific piece of hardware and software targeting retail and payment services sectors. Attributed to Golden Chickens.
Also known as: Taurus Loader Reconnaissance Module
TerraLoader
Technical ID: win.terra_loader
MALWARE
Malware family identifying win.terra_loader. Origin and technical characteristics tracked via Malpedia.
TerraPreter
Technical ID: win.terrapreter
MALWARE
Malware family identifying win.terrapreter. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
TerraLogger is a standalone keylogger malware developed by Golden Chickens, a financially motivated threat actor. It uses a common low-level keyboard hook to record keystrokes and writes the logs to local files. The malware is typically delivered as an OCX file and employs initial execution checks before proceeding. Upon execution, it opens a file handle to log keystrokes and implements its keylogger using a SetWindowsHookExA hook. Keystrokes are written to the open log file, with special characters handled accordingly. Five distinct TerraLogger samples were identified, reflecting minor updates and active development.
Termite
Technical ID: win.termite
MALWARE
Malware family identifying win.termite. Origin and technical characteristics tracked via Malpedia.
Terminator RAT
Technical ID: win.terminator_rat
MALWARE
Malware family identifying win.terminator_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: Fakem RAT
MALWARE
Malware family identifying win.tendyron_dropper. Origin and technical characteristics tracked via Malpedia.
TempStealer
Technical ID: win.temp_stealer
MALWARE
According to Cyble, this is a stealer targeting several crypto currency wallets along browser data.
MALWARE
Malware family identifying win.templedoor. Origin and technical characteristics tracked via Malpedia.
Tempedreve
Technical ID: win.tempedreve
MALWARE
Malware family identifying win.tempedreve. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-20
View profile →TellYouThePass
Technical ID: win.tellyouthepass
MALWAREfinancialhigh
According to PCrisk, Tellyouthepass is one of many ransomware-type programs used to block access to files by encryption and keep them in this state unless a ransom is paid.
The program renames all encrypted files by adding the ".locked" extension and creates a ransom message in a text file called "README.html". For example, "1.jpg" is renamed by Tellyouthepass to "1.jpg.locked".
According to cyber criminals, this ransomware encrypts data using RSA-1024 and AES-256 cryptography algorithms.
TelePowerBot
Technical ID: win.telepowerbot
MALWARE
Malware family identifying win.telepowerbot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Cisco Talos reports that this is a data exfiltration tool used by TA505.
Telemiris
Technical ID: win.telemiris
MALWARE
Malware family identifying win.telemiris. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.telegram_grabber. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.teledoor. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.telebot. Origin and technical characteristics tracked via Malpedia.
TelB
Technical ID: win.telb
MALWARE
According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
TelAndExt
Technical ID: win.telandext
MALWARE
According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
TefoSteal
Technical ID: win.tefosteal
MALWARE
Malware family identifying win.tefosteal. Origin and technical characteristics tracked via Malpedia.
MALWARE
TEARDROP is a memory only dropper that runs as a service, spawns a thread and reads from the file “gracious_truth.jpg”, which likely has a fake JPG header. Next it checks that HKU\SOFTWARE\Microsoft\CTF exists, decodes an embedded payload using a custom rolling XOR algorithm and manually loads into memory an embedded payload using a custom PE-like file format. TEARDROP does not have code overlap with any previously seen malware. FireEye believe that this was used to execute a customized Cobalt Strike BEACON.
TeamSpy
Technical ID: win.teamspy
MALWARE
Malware family identifying win.teamspy. Origin and technical characteristics tracked via Malpedia.
Also known as: TVSPY • TeamViewerENT • TVRAT
TeamBot
Technical ID: win.teambot
MALWARE
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer.
This is achieved by sideloading another DLL among the legit TeamViewer.
Also known as: FINTEAM
Updated: 2023-07-24
View profile →MALWARE
Malware family identifying win.tdtess. Origin and technical characteristics tracked via Malpedia.
MALWARE
F-Secure described tDiscoverer (also known as HammerDuke) as interesting because it is written in .NET, and even more so because of its occasional use of Twitter as a C&C communication channel. Some HammerDuke variants only contain a hardcoded C&C server address from which they will retrieve commands, but other HammerDuke variants will first use a custom algorithm to generate a Twitter account name based on the current date. If the account exists, HammerDuke will then search for tweets from that account with links to image files that contain embedded commands for the toolset to execute.
Also known as: HAMMERTOSS • HammerDuke
MALWARE
Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
Also known as: FIRESHADOW
Taurus Stealer
Technical ID: win.taurus_stealer
MALWARE
According to Zscaler, Taurus is a stealer that surfaced in June 2020. It is being developed by the author(s) that previously created Predator the Thief. The name overlaps partly with the StealerOne / Terra* family (also aliased Taurus Loader) but appears to be a completely disjunct project.
MALWARE
Malware family identifying win.tarsip. Origin and technical characteristics tracked via Malpedia.
TargetCompany
Technical ID: win.targetcompany
MALWAREfinancialhigh
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company>
A decryptor was released on 2022-02-07 by AVAST
Also known as: Fargo • Mallox • Tohnichi