Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.salgorea. Origin and technical characteristics tracked via Malpedia.
Also known as: BadCake
SalatStealer
Technical ID: win.salatstealer
MALWAREespionageadvanced
Crypto Stealer written in GO. Targets browsers, crypto wallets and telegram clients (Telegram Desktop, Kotatogram). Can capture webcam and microphone and stream it on to c2 server.
MALWARE
Sakula / Sakurel is a trojan horse that opens a back door and downloads potentially malicious files onto the compromised computer.
Also known as: Sakurel
MALWARE
This in .Net witten backdoor abuses the DNS protocoll for its C2 communication. Also other techniques (e.g. long random sleeps, compression) are used to become more stealthy.
Also known as: AMATIAS • Saitama
Saint Bot
Technical ID: win.saint_bot
MALWARE
Malware family identifying win.saint_bot. Origin and technical characteristics tracked via Malpedia.
SaiGon
Technical ID: win.saigon
MALWAREfinancialhigh
FireEye reports SaiGon as a variant of ISFB v3 (versions documented are tagged 3.50.132) that is more a generic backdoor than being focused on enabling banking fraud.
SAGE
Technical ID: win.sage_ransom
MALWARE
Malware family identifying win.sage_ransom. Origin and technical characteristics tracked via Malpedia.
Also known as: Saga
MALWARE
According to Symantec, Sagerunex is a backdoor that is fairly resilient and implements multiple forms of communication with its command-and-control (C&C) server. Its logs are encrypted and the encryption algorithm used is AES256-CBC with 8192 rounds of SHA256 for key derivation based on a hardcoded key. It supports multiple modes methods for communicating via HTTP (proxy-aware).
SafePay
Technical ID: win.safepay
MALWARE
Malware family identifying win.safepay. Origin and technical characteristics tracked via Malpedia.
SafeNet
Technical ID: win.safenet
MALWARE
Malware family identifying win.safenet. Origin and technical characteristics tracked via Malpedia.
Saefko
Technical ID: win.saefko
MALWARE
Malware family identifying win.saefko. Origin and technical characteristics tracked via Malpedia.
Sadogo
Technical ID: win.sadogo
MALWAREfinancialhigh
Ransomware.
SADBRIDGE
Technical ID: win.sadbridge
MALWARE
According to Elastic, SADBRIDGE is a malware loader packaged as an MSI executable for delivery and it uses DLL side-loading with various injection techniques to execute malicious payloads. SADBRIDGE abuses legitimate applications such as x64dbg.exe and MonitoringHost.exe to load malicious DLLs like x64bridge.dll and HealthServiceRuntime.dll, which leads to subsequent stages and shellcodes.
Ryuk Stealer
Technical ID: win.ryuk_stealer
MALWARE
Information Stealer that searches for sensitive documents and uploads its results to an FTP server. Skips files with known Ryuk extensions.
Also known as: Sidoh
MALWAREfinancialhigh
Ryuk is a ransomware which encrypts its victim's files and asks for a ransom via bitcoin to release the original files. It is has been observed being used to attack companies or professional environments. Cybersecurity experts figured out that Ryuk and Hermes ransomware shares pieces of codes. Hermes is commodity ransomware that has been observed for sale on dark-net forums and used by multiple threat actors.
MALWARE
According to Proofpoint, RustyClaw is a downloader written in Rust
RustyRocket
Technical ID: win.rustyrocket
MALWARE
Written in Rust and
designed for both Windows and Linux environments, RustyRocket enables WorldLeaks affiliates to steal data
through heavily obfuscated, multi-layered encrypted tunnels that can be exceptionally difficult to detect using
traditional network monitoring.
MALWAREespionageadvanced
Rustonotto, active since June 2025, is a Rust-compiled malware, representing the first known instance of APT37 leveraging Rust-based malware to target Windows systems.
Also known as: CHILLYCHINO
Rustock
Technical ID: win.rustock
MALWARE
Malware family identifying win.rustock. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.rustbucket. Origin and technical characteristics tracked via Malpedia.
Rurktar
Technical ID: win.rurktar
MALWARE
Malware family identifying win.rurktar. Origin and technical characteristics tracked via Malpedia.
Also known as: RCSU
RURansom
Technical ID: win.ruransom
MALWAREfinancialhigh
RURansom shows characteristics of typical ransomware, but despite its name, TrendMicro's assumptions after analysis showed that this malware is more a wiper than ransomware, because the irreversible destruction of encrypted files.
Running RAT
Technical ID: win.runningrat
MALWARE
NJCCIC characterizes RunningRAT as a remote access trojan (RAT) that operates using two DLL files. When the trojan is loaded onto a system, it executes the first DLL. This is used to disable anti-malware solutions, unpack and execute the main RAT DLL, and gain persistence. The trojan installs a Windows batch file dx.bat that attempts to kill the daumcleaner.exe task, a Korean security program. The file then attempts to remove itself. Once the second DLL is loaded into memory, the first DLL overwrites the IP address for the control server to change the address the trojan communicates with. The second DLL gathers information about the victim's system, including its operating system and driver and processor information. The RAT can log user keystrokes, copy the clipboard, delete files, compress files, clear event logs, shut down the machine, and more. The second DLL also uses several anti-bugging techniques.
Also known as: running_rat
Rumish
Technical ID: win.rumish
MALWARE
Malware family identifying win.rumish. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →Rugmi
Technical ID: win.rugmi
MALWARE
Malware family identifying win.rugmi. Origin and technical characteristics tracked via Malpedia.
Also known as: Penguish
Ruckguv
Technical ID: win.ruckguv
MALWARE
Malware family identifying win.ruckguv. Origin and technical characteristics tracked via Malpedia.
Rubeus
Technical ID: win.rubeus
MALWARE
Rubeus is a C# toolset for raw Kerberos interaction and abuses.
rtpos
Technical ID: win.rtpos
MALWARE
Malware family identifying win.rtpos. Origin and technical characteristics tracked via Malpedia.
RTM Locker
Technical ID: win.rtm_locker
MALWARE
Malware family identifying win.rtm_locker. Origin and technical characteristics tracked via Malpedia.
Also known as: Read The Manual Locker
RTM
Technical ID: win.rtm
MALWARE
RTM Banker also known as Redaman was first blogged about in February 2017 by ESET. The malware is written in Delphi and shows some similarities (like process list) with Buhtrap. It uses a slightly modified version of RC4 to encrypt its strings, network data, configuration and modules, according to ESET.
Also known as: Redaman
Rozena
Technical ID: win.rozena
MALWARE
Malware family identifying win.rozena. Origin and technical characteristics tracked via Malpedia.
Royal Ransom
Technical ID: win.royal_ransom
MALWAREfinancialhigh
Ransomware
MALWAREespionageadvanced
RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
MALWARE
RoyalCli is a backdoor which appears to be an evolution of BS2005 and uses familiar encryption and encoding routines. The name RoyalCli was chosen by us due to a debugging path left in the binary. RoyalCli and BS2005 both communicate with the attacker's command and control (C2) through Internet Explorer (IE) by using the COM interface IWebBrowser2.
Rovnix
Technical ID: win.rovnix
MALWARE
Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves. It is part of the Carberp source code leak (https://github.com/nyx0/Rovnix). Rovnix has been used to protect Gozi ISFB, ReactorBot and Rerdom (at least).
Also known as: Mayachok • Cidox • BkLoader
Rover
Technical ID: win.rover
MALWARE
Malware family identifying win.rover. Origin and technical characteristics tracked via Malpedia.
RotorCrypt
Technical ID: win.rotorcrypt
MALWAREfinancialhigh
Ransomware that was discovered over the last months of 2016 and likely based on Gomasom, another ransomware family.
Also known as: Rotor • RotoCrypt
Roshtyak
Technical ID: win.roshtyak
MALWARE
A DLL backdoor distributed by Raspberry Robin. According to Avast Decoded, Roshtyak belongs to one of the best-protected malware strains they have ever seen.
MALWARE
Malware family identifying win.roseam. Origin and technical characteristics tracked via Malpedia.
Also known as: PisLoader
Rorschach Ransomware
Technical ID: win.rorschach
MALWARE
Malware family identifying win.rorschach. Origin and technical characteristics tracked via Malpedia.
Also known as: BabLock