Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Sorano
Technical ID: win.sorano
MALWARE
Malware family identifying win.sorano. Origin and technical characteristics tracked via Malpedia.
Somnia
Technical ID: win.somnia
MALWARE
Malware family identifying win.somnia. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.sombrat. Origin and technical characteristics tracked via Malpedia.
SolidBit
Technical ID: win.solidbit
MALWAREfinancialhigh
Ransomware, written in .NET.
solarmarker
Technical ID: win.solarmarker
MALWARE
Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities, mainly delivered through search engine optimization (SEO) manipulation to convince users to download malicious documents.
Some of SolarMarker’s capabilities include the exfiltration of auto-fill data, saved passwords and saved credit card information from victims’ web browsers. Besides capabilities typical for infostealers, SolarMarker has additional capabilities such as file transfer and execution of commands received from a C2 server.
The malware invests significant effort into defense evasion, which consists of techniques like signed files, huge files, impersonation of legitimate software installations and obfuscated PowerShell scripts.
Also known as: Jupyter • Polazert • Yellow Cockatoo
Solarbot
Technical ID: win.solarbot
MALWARE
Malware family identifying win.solarbot. Origin and technical characteristics tracked via Malpedia.
Also known as: Napolar
MALWARE
Malware family identifying win.solar. Origin and technical characteristics tracked via Malpedia.
MALWARE
This is a RAT that is usually loaded with one or more shellcode and/or reflective DLL injection techniques. The RAT uses RC4 or a hardcoded RSA key for traffic encryption/decryption. Its communication can either happen via a raw TCP socket or a HTTP POST request. Depending on the version, the RAT may remotely execute DLLs or shellcode.
Also known as: dfls • HEAVYPOT • DelfsCake
MALWARE
Malware family identifying win.socksbot. Origin and technical characteristics tracked via Malpedia.
Also known as: BIRDDOG • Nadrac
Socks5 Systemz
Technical ID: win.socks5_systemz
MALWARE
The Socks5 Systemz malware is a proxy botnet distributed via the PrivateLoader and Amadey loaders. Active since at least 2016, this botnet infects devices to use them as proxies for malicious activities, offering access for prices ranging from $1 to $140 per day in cryptocurrency. It employs a domain generation algorithm (DGA) to evade detection and enhance its resilience. Persistence is maintained through a Windows service named ContentDWSvc, with the malware injected into memory via a file called previewer.exe. To date, it has compromised approximately 10,000 devices globally, excluding Russia.
Sockbot
Technical ID: win.sockbot
MALWARE
Sockbot is a customized and in Go written fork of the Ligolo reverse tunneling open-source
tool. Several modification were performed by the threat actors who rewrote that code, e.g. execution checks, hardcoded values.
Ligolo: https://github.com/sysdream/ligolo
Socelars
Technical ID: win.socelars
MALWARE
Socelars is an infostealer with main focus on:
* Facebook Stealer (ads/manager)
* Cookie Stealer | AdsCreditCard {Amazon}
Sobig
Technical ID: win.sobig
MALWARE
Malware family identifying win.sobig. Origin and technical characteristics tracked via Malpedia.
Also known as: Palyh
Sobaken
Technical ID: win.sobaken
MALWARE
According to ESET, this RAT was derived from (the open-source) Quasar RAT.
SNS Locker
Technical ID: win.snslocker
MALWARE
Malware family identifying win.snslocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-06-02
View profile →SnowFlake Stealer
Technical ID: win.snowflake_stealer
MALWARE
Information stealer, written in Rust.
Snojan
Technical ID: win.snojan
MALWARE
Malware family identifying win.snojan. Origin and technical characteristics tracked via Malpedia.
SnipVex
Technical ID: win.snipvex
MALWARE
SnipVex is a virus that infects files with .exe extension via prepending itself to the host. It is written in .NET. It has a clipbanker as payload.
Snifula
Technical ID: win.snifula
MALWARE
Malware family identifying win.snifula. Origin and technical characteristics tracked via Malpedia.
Also known as: Ursnif
SNEEPY
Technical ID: win.sneepy
MALWARE
Malware family identifying win.sneepy. Origin and technical characteristics tracked via Malpedia.
Also known as: ByeByeShell
SnatchLoader
Technical ID: win.snatch_loader
MALWARE
A downloader trojan with some infostealer capabilities focused on the browser. Previously observed as part of RigEK campaigns.
MALWARE
Malware observed in the SnatchCrypto campaign, attributed by Kaspersky Labs to BlueNoroff with high confidence.
Also known as: BackbitingTea • msoRAT
Snatch
Technical ID: win.snatch
MALWAREfinancialhigh
Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.
MALWARE
Malware family identifying win.snappybee. Origin and technical characteristics tracked via Malpedia.
Also known as: Deed RAT • POISONPLUG.DEED
MALWARE
According to X-Force, SnakeDisk is a USB worm, dropping further payloads
Snake
Technical ID: win.snake
MALWAREfinancialhigh
Snake Ransomware is a Golang ransomware reportedly containing obfuscation not typically seen in Golang ransomware. This malware will remove shadow copies and kill processes related to SCADA/ICS devices, virtual machines, remote management tools, network management software, and others. After this, encryption of files on the device commences, while skipping Windows system folders and various system files. A random 5 character string is appended to encrypted files. According to Bleeping Computer, this ransomware takes an especially long time to encrypt files on a targeted machine. This ransomware is reported to target an entire network, rather than individual workstations.
Also known as: EKANS • SNAKEHOSE
Sn0wsLogger
Technical ID: win.sn0wslogger
MALWARE
Malware family identifying win.sn0wslogger. Origin and technical characteristics tracked via Malpedia.
Smrss32
Technical ID: win.smrss32
MALWAREfinancialhigh
Ransomware.
Smominru
Technical ID: win.smominru
MALWARE
Malware family identifying win.smominru. Origin and technical characteristics tracked via Malpedia.
Also known as: Ismo
MALWARE
The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.
Also known as: Dofoil • Sharik • Smoke • Smoke Loader
SMOKEDHAM
Technical ID: win.smokedham
MALWARE
According to Mandiant, SMOKEDHAM is dropped through a powershell script that contains the (C#) source code for this backdoor, which is stored in an encrypted variable. The dropper dynamically defines a cmdlet and .NET class for the backdoor, meaning the compiled code is only found in memory.
SMAUG
Technical ID: win.smaug
MALWAREfinancialhigh
According to PCrisk, Smaug ransomware is available for download on the dark web: it is for sale as Ransomware as a Service (RaaS). Therefore, cyber criminals who purchase it can perform ransomware attacks without having to develop malware of this type. Smaug is designed to encrypt files, rename them and create a ransom message.
SmartLoader
Technical ID: win.smartloader
MALWARE
Malware family identifying win.smartloader. Origin and technical characteristics tracked via Malpedia.
SmartEyes
Technical ID: win.smarteyes
MALWARE
Malware family identifying win.smarteyes. Origin and technical characteristics tracked via Malpedia.
SManager
Technical ID: win.smanager
MALWARE
Malware family identifying win.smanager. Origin and technical characteristics tracked via Malpedia.
Also known as: PhantomNet
Smackdown
Technical ID: win.smackdown
MALWARE
Malware family identifying win.smackdown. Origin and technical characteristics tracked via Malpedia.
smac
Technical ID: win.smac
MALWARE
Malware family identifying win.smac. Origin and technical characteristics tracked via Malpedia.
Also known as: speccom
SLUB
Technical ID: win.slub
MALWARE
Malware family identifying win.slub. Origin and technical characteristics tracked via Malpedia.
SlowStepper
Technical ID: win.slowstepper
MALWARE
According to ESET, SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components, programmed in C++, Python, and Go.
MALWARE
According to MITRE, SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.
Also known as: QueenOfClubs