Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Roopy
Technical ID: win.roopy
MALWARE
Malware family identifying win.roopy. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-26
View profile →
Roopirs
Technical ID: win.roopirs
MALWARE
Malware family identifying win.roopirs. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
Rook
Technical ID: win.rook
MALWAREfinancialhigh
According to PCrisk, Rook is ransomware (an updated variant of Babuk) that prevents victims from accessing/opening files by encrypting them. It also modifies filenames and creates a text file/ransom note ("HowToRestoreYourFiles.txt"). Rook renames files by appending the ".Rook" extension. For example, it renames "1.jpg" to "1.jpg.Rook", "2.jpg" to "2.jpg.Rook".
Updated: 2023-05-25
View profile →
RONINGLOADER
Technical ID: win.roningloader
MALWARE
Malware family identifying win.roningloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-18
View profile →
Romeo(Alfa,Bravo, ...)
Technical ID: win.romeos
Lazarus Group
MALWARE
Malware family identifying win.romeos. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-17
View profile →
ROMCOM RAT
Technical ID: win.romcom_rat
MALWAREfinancialhigh
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.
Also known as: PEAPOD • SingleCamper • SnipBot
Updated: 2025-12-12
View profile →
Rombertik
Technical ID: win.rombertik
MALWARE
Malware family identifying win.rombertik. Origin and technical characteristics tracked via Malpedia.
Also known as: CarbonGrabber
Updated: 2017-05-21
View profile →
RollSling
Technical ID: win.roll_sling
Lazarus Group
MALWARE
Malware family identifying win.roll_sling. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-20
View profile →
ROLLCOAST
Technical ID: win.rollcoast
MALWAREespionageadvanced
ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system. ROLLCOAST is a Dynamic Linked Library (DLL) with no named exports. When observed by Mandiant it uniquely had only one ordinal export 0x01. This suggested the sample was designed to avoid detection and be invoked within memory, possibly through BEACON provided to affiliates. Incident responders working on similar intrusions should capture memory for analysis.
Also known as: Sabbath • S4bb47h • Arcane
Updated: 2023-01-19
View profile →
RokRAT
Technical ID: win.rokrat
APT37
MALWAREespionageadvanced
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. DOGCALL is capable of capturing screenshots, logging keystrokes, evading analysis with anti-virtual machine detections, and leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex.
Also known as: DOGCALL
Updated: 2025-12-23
View profile →
Rokku
Technical ID: win.rokku
MALWARE
Malware family identifying win.rokku. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-12-20
View profile →
RogueRobinNET
Technical ID: win.roguerobin
DarkHydrus
MALWARE
A .NET variant of ps1.roguerobin
Updated: 2021-07-20
View profile →
Rofin
Technical ID: win.rofin
MALWARE
Malware family identifying win.rofin. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-20
View profile →
Rockloader
Technical ID: win.rockloader
MALWARE
Malware family identifying win.rockloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
rock
Technical ID: win.rock
MALWARE
Malware family identifying win.rock. Origin and technical characteristics tracked via Malpedia.
Also known as: yellowalbatross
Updated: 2018-09-19
View profile →
RobinHood
Technical ID: win.robinhood
MALWARE
Malware family identifying win.robinhood. Origin and technical characteristics tracked via Malpedia.
Also known as: RobbinHood
Updated: 2022-06-15
View profile →
RoarBAT
Technical ID: win.roar_bat
Sandworm
MALWARE
According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.
Updated: 2024-04-23
View profile →
ROADSWEEP
Technical ID: win.roadsweep
MALWARE
Malware family identifying win.roadsweep. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
RMS
Technical ID: win.rms
TA505
MALWARE
CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices.
Also known as: Gussdoor • Remote Manipulator System • RuRAT
Updated: 2026-01-19
View profile →
RM3
Technical ID: win.rm3
MALWARE
Created from the codebase of Gozi/ISFB.
Updated: 2022-12-29
View profile →
Rising Sun
Technical ID: win.rising_sun
Operation Sharpshooter
MALWARE
Malware family identifying win.rising_sun. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-05
View profile →
RisePro
Technical ID: win.risepro
MALWARE
RisePro is a stealer that is spread through downloaders like win.privateloader. Once executed on a system, the malware can steal credit card information, passwords, and personal data.
Updated: 2024-12-11
View profile →
RiseLoader
Technical ID: win.riseloader
MALWARE
RiseLoader is a new malware loader family first observed in October 2024. It uses a custom TCP-based binary network protocol similar to, but distinct from, that used by the PrivateLoader and RisePro malware families. RiseLoader often drops other malware families, such as Vidar, Lumma Stealer, and XMRig, as secondary payloads. It collects information about installed applications and browser extensions, likely related to cryptocurrency. Key technical characteristics of RiseLoader include: Anti-analysis Techniques: Samples are often packed with VMProtect and obfuscate strings related to malware analysis and debugging tools. Behavioural Analysis: Creates a mutex with a hardcoded prefix and randomly generated suffixes. Communicates with a C2 server over TCP using a custom protocol involving specific message types for tasks such as transferring system information, receiving payloads, and confirming execution. Downloads and executes payloads from URLs provided by the C2 server. Creates registry keys as infection markers. Network Communication: Uses a custom TCP-based protocol with message types like SEND_VICTIM_INFO, SYS_INFO, PAYLOADS, KEEPALIVE, and others. Data is XOR encoded using keys exchanged via a SET_XORKEYS message. The protocol includes a three-way handshake and mechanisms for re-establishing connections. Similarities to RisePro/PrivateLoader: Shares similar network communication protocols and message structures with RisePro and PrivateLoader suggesting a potential link between their developers, though RiseLoader's protocol appears simplified. It currently lacks RisePro/PrivateLoader's information-stealing features but may be under development.
Updated: 2025-01-02
View profile →
Ripper ATM
Technical ID: win.ripper_atm
MALWARE
Malware family identifying win.ripper_atm. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-27
View profile →
Rincux
Technical ID: win.rincux
MALWARE
Malware family identifying win.rincux. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-26
View profile →
Rikamanu
Technical ID: win.rikamanu
Thrip
MALWARE
Malware family identifying win.rikamanu. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-25
View profile →
Rifdoor
Technical ID: win.rifdoor
Lazarus GroupSilent Chollima
MALWARE
Malware family identifying win.rifdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-28
View profile →
Rietspoof
Technical ID: win.rietspoof
MALWARE
Rietspoof is malware that mainly acts as a dropper and downloader, however, it also sports bot capabilities and appears to be in active development.
Updated: 2020-01-27
View profile →
Rhysida
Technical ID: win.rhysida
Vanilla Tempest
MALWARE
Malware family identifying win.rhysida. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-09
View profile →
RHttpCtrl
Technical ID: win.rhttpctrl
APT 30
MALWARE
Malware family identifying win.rhttpctrl. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-20
View profile →
Rhino
Technical ID: win.rhino
MALWAREfinancialhigh
Ransomware.
Updated: 2020-05-18
View profile →
Rhadamanthys
Technical ID: win.rhadamanthys
Sandworm
MALWARE
According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines. At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.
Updated: 2026-01-14
View profile →
RGDoor
Technical ID: win.rgdoor
MALWARE
Malware family identifying win.rgdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-08-09
View profile →
REvil
Technical ID: win.revil
Pinchy Spider
MALWARE
REvil Beta MD5: bed6fc04aeb785815744706239a1f243 SHA1: 3d0649b5f76dbbff9f86b926afbd18ae028946bf SHA256: 3641b09bf6eae22579d4fd5aae420476a134f5948966944189a70afd8032cb45 * Privilege escalation via CVE-2018-8453 (64-bit only) * Rerun with RunAs to elevate privileges * Implements a requirement that if "exp" is set, privilege escalation must be successful for full execution to occur * Implements target whitelisting using GetKetboardLayoutList * Contains debug console logging functionality * Defines the REvil registry root key as SOFTWARE\!test * Includes two variable placeholders in the ransom note: UID & KEY * Terminates processes specified in the "prc" configuration key prior to encryption * Deletes shadow copies and disables recovery * Wipes contents of folders specified in the "wfld" configuration key prior to encryption * Encrypts all non-whitelisted files on fixed drives * Encrypts all non-whitelisted files on network mapped drives if it is running with System-level privileges or can impersonate the security context of explorer.exe * Partially implements a background image setting to display a basic "Image text" message * Sends encrypted system data to a C2 domain via an HTTPS POST request (URI path building is not implemented.) ------------------------------------ REvil 1.00 MD5: 65aa793c000762174b2f86077bdafaea SHA1: 95a21e764ad0c98ea3d034d293aee5511e7c8457 SHA256: f0c60f62ef9ffc044d0b4aeb8cc26b971236f24a2611cb1be09ff4845c3841bc * Adds 32-bit implementation of CVE-2018-8453 exploit * Removes console debug logging * Changes the REvil registry root key to SOFTWARE\recfg * Removes the System/Impersonation success requirement for encrypting network mapped drives * Adds a "wipe" key to the configuration for optional folder wiping * Fully implements the background image setting and leverages values defined in the "img" configuration key * Adds an EXT variable placeholder to the ransom note to support UID, KEY, and EXT * Implements URI path building so encrypted system data is sent to a C2 pseudo-random URL * Fixes the function that returns the victim's username so the correct value is placed in the stats JSON data ------------------------------------ REvil 1.01 MD5: 2abff29b4d87f30f011874b6e98959e9 SHA1: 9d1b61b1cba411ee6d4664ba2561fa59cdb0732c SHA256: a88e2857a2f3922b44247316642f08ba8665185297e3cd958bbd22a83f380feb * Removes the exp/privilege escalation requirement for full execution and encrypts data regardless of privilege level * Makes encryption of network mapped drives optional by adding the "-nolan" argument ------------------------------------ REvil 1.02 MD5: 4af953b20f3a1f165e7cf31d6156c035 SHA1: b859de5ffcb90e4ca8e304d81a4f81e8785bb299 SHA256: 89d80016ff4c6600e8dd8cfad1fa6912af4d21c5457b4e9866d1796939b48dc4 * Enhances whitelisting validation by adding inspection of GetUserDefaultUILanguage and GetSystemDefaultUILanguage * Partially implements "lock file" logic by generating a lock filename based on the first four bytes of the Base64-decoded pk key, appending a .lock file extension, and adding the filename to the list of whitelisted files in the REvil configuration (It does not appear that this value is referenced after it is created and stored in memory. There is no evidence that a lock file is dropped to disk.) * Enhances folder whitelisting logic that take special considerations if the folder is associated with "program files" directories * Hard-codes whitelisting of all direct content within the Program Files or Program Files x86 directories * Hard-codes whitelisting of "sql" subfolders within program files * Encrypts program files sub-folders that does not contain "sql" in the path * Compares other folders to the list of whitelisted folders specified in the REvil configuration to determine if they are whitelisted * Encodes stored strings used for URI building within the binary and decodes them in memory right before use * Introduces a REvil registry root key "sub_key" registry value containing the attacker's public key ------------------------------------ REvil 1.03 MD5: 3cae02306a95564b1fff4ea45a7dfc00 SHA1: 0ce2cae5287a64138d273007b34933362901783d SHA256: 78fa32f179224c46ae81252c841e75ee4e80b57e6b026d0a05bb07d34ec37bbf * Removes lock file logic that was partially implemented in 1.02 * Leverages WMI to continuously monitor for and kill newly launched processes whose names are listed in the prc configuration key (Previous versions performed this action once.) * Encodes stored shellcode * Adds the -path argument: * Does not wipe folders (even if wipe == true) * Does not set desktop background * Does not contact the C2 server (even if net == true) * Encrypts files in the specified folder and drops the ransom note * Changes the REvil registry root key to SOFTWARE\QtProject\OrganizationDefaults * Changes registry key values from --> to: * sub_key --> pvg * pk_key --> sxsP * sk_key --> BDDC8 * 0_key --> f7gVD7 * rnd_ext --> Xu7Nnkd * stat --> sMMnxpgk ------------------------------------ REvil 1.04 MD5: 6e3efb83299d800edf1624ecbc0665e7 SHA1: 0bd22f204c5373f1a22d9a02c59f69f354a2cc0d SHA256: 2ca64feaaf5ab6cf96677fbc2bc0e1995b3bc93472d7af884139aa757240e3f6 * Leverages PowerShell and WMI to delete shadow copies if the victim's operating system is newer than Windows XP (For Windows XP or older, it uses the original command that was executed in all previous REvil versions.) * Removes the folder wipe capability * Changes the REvil registry root key to SOFTWARE\GitForWindows * Changes registry key values from --> to: * pvg --> QPM * sxsP --> cMtS * BDDC8 --> WGg7j * f7gVD7 --> zbhs8h * Xu7Nnkd --> H85TP10 * sMMnxpgk --> GCZg2PXD ------------------------------------ REvil v1.05 MD5: cfefcc2edc5c54c74b76e7d1d29e69b2 SHA1: 7423c57db390def08154b77e2b5e043d92d320c7 SHA256: e430479d1ca03a1bc5414e28f6cdbb301939c4c95547492cdbe27b0a123344ea * Add new 'arn' configuration key that contains a boolean true/false value that controls whether or not to implement persistence. * Implements persistence functionality via registry Run key. Data for value is set to the full path and filename of the currently running executable. The executable is never moved into any 'working directory' such as %AppData% or %TEMP% as part of the persistence setup. The Reg Value used is the hardcoded value of 'lNOWZyAWVv' : * SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lNOWZyAWVv * Before exiting, REvil sets up its malicious executable to be deleted upon reboot by issuing a call to MoveFileExW and setting the destination to NULL and the flags to 4 (MOVEFILE_DELAY_UNTIL_REBOOT). This breaks persistence however as the target executable specified in the Run key will no longer exist once this is done. * Changes registry key values from --> to: * QPM --> tgE * cMtS --> 8K09 * WGg7j --> xMtNc * zbhs8h --> CTgE4a * H85TP10 --> oE5bZg0 * GCZg2PXD --> DC408Qp4 ------------------------------------ REvil v1.06 MD5: 65ff37973426c09b9ff95f354e62959e SHA1: b53bc09cfbd292af7b3609734a99d101bd24d77e SHA256: 0e37d9d0a7441a98119eb1361a0605042c4db0e8369b54ba26e6ba08d9b62f1e * Updated string decoding function to break existing yara rules. Likely the result of the blog posted by us. * Modified handling of network file encryption. Now explicitly passes every possible "Scope" constant to the WNetOpenEnum function when looking for files to encrypt. It also changed the 'Resource Type" from RESOURCETYPE_DISK to RESOURCETYPE_ANY which will now include things like mapped printers. * Persistence registry value changed from 'lNOWZyAWVv' to 'sNpEShi30R' * Changes registry key values from --> to: * tgE --> 73g * 8K09 --> vTGj * xMtNc --> Q7PZe * CTgE4a --> BuCrIp * oE5bZg0 --> lcZd7OY * DC408Qp4 --> sLF86MWC ------------------------------------ REvil v1.07 MD5: ea4cae3d6d8150215a4d90593a4c30f2 SHA1: 8dcbcbefaedf5675b170af3fd44db93ad864894e SHA256: 6a2bd52a5d68a7250d1de481dcce91a32f54824c1c540f0a040d05f757220cd3 TBD
Also known as: Sodinokibi • Sodin
Updated: 2024-06-12
View profile →
Reveton
Technical ID: win.reveton
MALWAREfinancialhigh
Ransomware.
Updated: 2025-07-24
View profile →
ReverseRAT
Technical ID: win.reverse_rat
MALWARE
Malware family identifying win.reverse_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-21
View profile →
Revenge RAT
Technical ID: win.revenge_rat
The Gorgon Group
MALWARE
According to Cofense, Revenge RAT is a simple and freely available Remote Access Trojan that automatically gathers system information before allowing threat actors to remotely access system components such as webcams, microphones, and various other utilities.
Also known as: Revetrat
Updated: 2025-03-07
View profile →
Revenant
Technical ID: win.revenant
MALWARE
According to its author, Revenant is a 3rd party agent for Havoc written in C, and based on Talon. This implant is meant to expand on the Talon implant by implementing covert methods of execution, robust capabilities, and more customization.
Updated: 2023-04-03
View profile →
RevC2
Technical ID: win.revc2
MALWARE
Malware family identifying win.revc2. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-07
View profile →
Retro
Technical ID: win.retro
DarkHotel
MALWARE
Malware family identifying win.retro. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-17
View profile →
← PreviousPage 140 / 269Next →