Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,718 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_div
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_cson
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_bolid
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_ausov
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_adspace
APT GROUP
WebbyTea is an HTTP(S) downloader that uses AES for C&C trafic encryption.
It sends detailed information about the victim's environment, like proxy settings, system instalation date, Windows product name and version, manufacturer, product name, system boot time, time zone, computer name, user name, current time and a list of currently running processes. Data sent to the C&C server consists of the prefix "ci", a 16-characters long hexadecimal string representing the victim ID and an encrypted data about the victim's system. After the payload is acquired from the server and successfully injected in a newly created explorer.exe process, the malware responds back with the same victim ID having the prefix changed to "cs".
The internal DLL name of the native WebbyTea is usually pe64.dll or webT64.dll (from which its name is derived).
The usual payload associated with WebbyTea is SnatchCrypto.
APT GROUP
Malware family tracked by Malpedia. ID: win.wavy_exfiller
APT GROUP
Wave Stealer is an infostealer offered as Malware-as-a-Service by a French-speaking actor called "Wave". The threat actor has strong relationships with Nova Stealer's and Epsilon Stealer's groups. It's capabilities include passwords and crypto-wallet stealing, discord and telegram injection, and backup codes finder.
APT GROUP
Malware family tracked by Malpedia. ID: win.waterspout
APT GROUP
Malware family tracked by Malpedia. ID: win.waterminer
APT GROUPespionageadvanced
Waterbear, also known as DbgPrint in its earlier export function, has been active since 2009. The malware is presumably developed by the BlackTech APT group and adopts advanced anti-analysis and forward-thinking design. These designs include a sophisticated shellcode stager, the ability to load plugins on-the-fly, and overall evasiveness should the C2 server fail to respond with a valid session key.
APT GROUPespionageadvanced
WastedLocker is a ransomware detected to be in use since May 2020 by EvilCorp. The ransomware name is derived from the filename that it creates which includes an abbreviation of the victim’s name and the string ‘wasted’. WastedLocker is protected with a custom crypter, referred to as CryptOne by Fox-IT InTELL. On examination, this crypter turned out to be very basic and was used also by other malware families such as: Netwalker, Gozi ISFB v3, ZLoader and Smokeloader. The crypter mainly contains junk code to increase entropy of the sample and hide the actual code.
APT GROUPfinancialhigh
This malware looks similar to WastedLocker, but the ransomware component is missing.
APT GROUPfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
APT GROUP
According to Seqrite, this is a fork of Stealerium that has high overlap with its originating codebase. Main changes include removal of Discord web hooks (for the sake of using Telegram) and rebranding away from Stealerium (string removal).
APT GROUPespionageadvanced
WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots. It communicates with a command and control (C&C) server via HTTP to receive further instructions and exfiltrate stolen data. It is commonly distributed through phishing campaigns and malicious downloads, targeting unsuspecting users to infiltrate systems undetected.
APT GROUPfinancial
The Warlock ransomware and operator(s) are believed to be attributed to Storm-2603, a China-based threat actor who is also known to have deployed LockBit ransomware. There's also a crossover between victims with Black Basta. Both are RaaS and have a long list of known and unknown affiliates. Having said that, this is possibly an affiliate (likely a cybergroup) of both of those groups. The Alliance & Association would technically be Encryptor Sharing, but this is realistically more of an "Old Affiliate" that created their own ransomware encryptor and operation.
Infra: 🔗 elqfbcx5nofwtqfookqm…🔗 zfytizegsze6uiswodhb…📁 ocwjy4ynmpbbzhumh2am…+7 more
RLUpdated: 2026-08-04
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.warhawk
APT GROUP
Malware family tracked by Malpedia. ID: win.warezov
APT GROUPfinancialhigh
According to Mars, WannaHusky is a Nim-compiled ransomware malware sample, created for demonstration purposes and provided as part of the Practical Malware Analysis & Triage course provided by HuskyHacks.
APT GROUPfinancialhigh
WannaCry is ransomware that contains a worm component enabled by the EternalBlue exploit. It attempts to use vulnerabilities in the Windows SMBv1 server to remotely compromise systems, encrypt files, and spread to other hosts. Systems that have installed the MS17-010 patch are not vulnerable to the exploits used. The spreading was stopped about 8 hours after initial outbreak due to triggering a kill switch domain.
APT GROUP
Malware family tracked by Malpedia. ID: win.wallyshack
APT GROUP
Malware family tracked by Malpedia. ID: win.wainscot
APT GROUP
wAgentTea is an HTTP(S) downloader.
It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or semiconductor industry (Q2 2023). In several cases, the initial access was obtained via exploitation of South Korean software like Initech's INISAFE CrossWeb EX or Dream Security’s MagicLine4NX.
It uses AES-128 for encryption and decryption of its network traffic, and for decryption of its binary configuration.
There is a hard-coded list of parameter names used in its HTTP POST request:
identy;tname;blogdata;content;thesis;method;bbs;level;maincode;tab;idx;tb;isbn;entry;doc;
category;articles;portal
It contains a specific RTTI symbol ".?AVCHttp_socket@@".
APT GROUP
Malware family tracked by Malpedia. ID: win.w32times
APT GROUP
Vyveva is a remote access trojan that uses the Tor library for communication with C&C. Its use of fake TLS for camouflaging the network traffic is one of the typical Lazarus traits.
It uses a simple XOR for encryption of its configuration and network traffic.
It sends detailed information about the victim's environment, like computer name, user name, IP, code page, Windows version, architecture, and time zone.
It supports more than 20 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, and the download and memory execution of an additional DLL from the C&C (by calling the expected export SamIPromote). As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. The lowest index is 0x3, followed by 0x10, which goes incrementally up to 0x26. Also, it can monitor newly connected drives and the number of logged-on users.
It has MPRD.dll as the internal DLL name, and a single export SamIInitialize.
Vyveva RAT was used in an attack against a freight logistics company in South Africa in June 2020.
APT GROUP
Malware family tracked by Malpedia. ID: win.vx_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.vskimmer
APT GROUP
Malware family tracked by Malpedia. ID: win.vsingle
APT GROUP
VShell is an OST framework written in Go, enabling availability of implants for multiple platforms (Windows, Linux, macOS).
APT GROUP
Malware family tracked by Malpedia. ID: win.vreikstadi
APT GROUPfinancialhigh
Ransomware written in D.
APT GROUP
Malware family tracked by Malpedia. ID: win.volgmer
APT GROUPespionageadvanced
Voldemort is a backdoor discovered by Proofpoint in August 2024. It is being distributed via phishing E-Mails and makes use of creative techniques such as using saved search files during the infection chain for obfuscation and Google Sheets for C2. While its broad targeting looks like it is related to ecrime, Proofpoint notes that the capabilities of the malware point towards espionage/APT activity.
APT GROUP
Malware family tracked by Malpedia. ID: win.void_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.voidoor
APT GROUP
Malware family tracked by Malpedia. ID: win.vohuk