Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Retefe
Technical ID: win.retefe
MALWAREfinancialhigh
Retefe is a Windows Banking Trojan that can also download and install additional malware onto the system using Windows PowerShell. It's primary functionality is to assist the attacker with stealing credentials for online banking websites. It is typically targeted against Swiss banks. The malware binary itself is primarily a dropper component for a Javascript file which builds a VBA file which in turn loads multiple tools onto the host including: 7zip and TOR. The VBA installs a new root certificate and then forwards all traffic via TOR to the attacker controlled host in order to effectively MITM TLS traffic.
Also known as: Tsukuba • Werdlod
Retadup
Technical ID: win.retadup
MALWARE
Malware family identifying win.retadup. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Cisco Talos, Resident is a backdoor likely developed by the same author as win.warmcookie, and it was observed being delivered in intrusions they attribute to TA866.
MALWARE
Malware family identifying win.reshell. Origin and technical characteristics tracked via Malpedia.
Rerdom
Technical ID: win.rerdom
MALWARE
Malware family identifying win.rerdom. Origin and technical characteristics tracked via Malpedia.
Remy
Technical ID: win.remy
MALWARE
Malware family identifying win.remy. Origin and technical characteristics tracked via Malpedia.
Also known as: WINDSHIELD
MALWARE
Malware family identifying win.remsec_strider. Origin and technical characteristics tracked via Malpedia.
RemoteControl
Technical ID: win.remotecontrolclient
MALWARE
Malware family identifying win.remotecontrolclient. Origin and technical characteristics tracked via Malpedia.
Also known as: remotecontrolclient
RemoteAdmin
Technical ID: win.remoteadmin
MALWARE
Malware family identifying win.remoteadmin. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Remexi is a highly advanced and stealthy malware discovered in recent times. It employs sophisticated evasion techniques to infiltrate target systems and networks undetected. This malware utilizes various propagation vectors, including exploit kits, social engineering tactics, and compromised websites. Once inside a system, Remexi establishes persistence through rootkit capabilities and leverages coAmmand-and-control infrastructure to receive and execute malicious commands. It possesses keylogging and data exfiltration capabilities, enabling it to steal sensitive information such as login credentials and financial data. Additionally, Remexi can download and execute additional payloads, making it adaptable and capable of evolving its malicious activities over time.
Also known as: CACHEMONEY
MALWARE
Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.
Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.
Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.
Remcos is developed by the cybersecurity company BreakingSecurity.
Also known as: RemcosRAT • Remvio • Socmer
RemCom
Technical ID: win.remcom
MALWARE
Malware family identifying win.remcom. Origin and technical characteristics tracked via Malpedia.
Also known as: RemoteCommandExecution
RelicRace
Technical ID: win.relic_race
MALWARE
Malware family identifying win.relic_race. Origin and technical characteristics tracked via Malpedia.
Rektware
Technical ID: win.rektware
MALWARE
Malware family identifying win.rektware. Origin and technical characteristics tracked via Malpedia.
Also known as: PRZT Ransomware
Rekt Loader
Technical ID: win.rektloader
MALWARE
Malware family identifying win.rektloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
A Trojan for Winows with the same code structure and functionalities of elf.rekoobe, for Linux environment instead.
Also known as: tinyshell.win • tshd.win
RegretLocker
Technical ID: win.regretlocker
MALWAREfinancialhigh
According to PCrisk, RegretLocker is malicious software classified as ransomware. Systems infected with this malware have their data encrypted and users receive ransom demands for decryption. During the encryption process, all affected files are appended with the ".mouse" extension.
Regin
Technical ID: win.regin
MALWAREfinancialhigh
Regin is a sophisticated malware and hacking toolkit attributed to United States' National Security Agency (NSA) for government spying operations. It was first publicly revealed by Kaspersky Lab, Symantec, and The Intercept in November 2014. Regin malware targeted victims in a range of industries, telecom, government, and financial institutions. It was engineered to be modular and over time dozens of modules have been found and attributed to this family. Symantec observed around 100 infections in 10 different countries across a variety of organisations including private companies, government entities, and research institutes.
reGeorg
Technical ID: win.regeorg
MALWARE
Malware family identifying win.regeorg. Origin and technical characteristics tracked via Malpedia.
MALWARE
ReedBed, identified as a malware proxy backdoor, is suspected to be developed by QAKBOT devs, and was deployed by the threat actor Storm-1811 in campaigns observed during late October and early November 2024. These campaigns are typically initiated with email bombing, a tactic involving mass email distribution, followed by social engineering strategies where the actor impersonates help desk personnel to gain access to victim systems.
Upon execution, ReedBed ensures single-instance operation via the mutex "JhishdiI2Uhsvoc94keiojn7ns19m0do" and hooks critical system APIs (NtCreateUserProcess, RtlExitUserProcess) for defense evasion, process interference, and anti-termination. It reads its Command and Control (C2) configuration, typically from the "Software\TitanPlus" registry key, establishes a persistent SSL/TLS encrypted connection, and transmits an initial system information beacon. Subsequently, ReedBed enters its main operational loop, acting as a versatile network proxy based on C2 commands; this includes initiating outgoing TCP connections, relaying data bi-directionally, and establishing reverse SOCKS5 (with authentication) or direct TCP port mapping services via locally opened listening ports. If commanded or upon connection failure, it transitions into a restart/wait cycle guided by registry values, leveraging its hooked exit function to hinder termination before attempting to reconnect to the C2.
Red Gambler
Technical ID: win.red_gambler
MALWARE
Malware family identifying win.red_gambler. Origin and technical characteristics tracked via Malpedia.
Red Alert
Technical ID: win.red_alert
MALWARE
Malware family identifying win.red_alert. Origin and technical characteristics tracked via Malpedia.
Redyms
Technical ID: win.redyms
MALWARE
Malware family identifying win.redyms. Origin and technical characteristics tracked via Malpedia.
MALWARE
REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.
MALWARE
Malware family identifying win.redsalt. Origin and technical characteristics tracked via Malpedia.
Also known as: Dipsind
RedRum
Technical ID: win.redrum
MALWAREfinancialhigh
Ransomware.
Also known as: Grinch • Tycoon • Thanos
MALWARE
Malware family identifying win.redpepper. Origin and technical characteristics tracked via Malpedia.
Also known as: Adupib
Redosdru
Technical ID: win.redosdru
MALWARE
Redosdru is a malware family that primarily acts as a downloader. Upon execution, it may drop downloaded DLLs in the "%ProgramFiles%\AppPatch" directory. The malware modifies the Windows registry to ensure its persistence, adding entries to run automatically at system startup.
RedLine Stealer
Technical ID: win.redline_stealer
MALWARE
RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer.
Also known as: RECORDSTEALER
MALWARE
Malware family identifying win.redleaves. Origin and technical characteristics tracked via Malpedia.
Also known as: BUGJUICE
RedEnergy Stealer
Technical ID: win.redenergy_stealer
MALWAREfinancialhigh
According to Zscaler ThreatLabz, RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for carrying out ransomware activities.The name of the malware was kept due to the common method names observed during the analysis.
RedCurl
Technical ID: win.redcurl
MALWARE
Malware family identifying win.redcurl. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Trend Micro, this backdoor receives valid domain credentials as an argument and uses it to log on to the Exchange Server and use it for data exfiltration purposes. The main function of this stage is to take the stolen password from the argument and send it to the attackers as an attachment in an email. We also observed that the threat actors relay these emails via government Exchange Servers using vaild accounts with stolen passwords.
RedAlpha
Technical ID: win.redalpha
MALWARE
Malware family identifying win.redalpha. Origin and technical characteristics tracked via Malpedia.
RecordBreaker
Technical ID: win.recordbreaker
MALWARE
This malware is a successor to Raccoon Stealer (also referred to as Raccoon Stealer 2.0), which is however a full rewrite in C/C++.
Reaver
Technical ID: win.reaver
MALWARE
Reaver is a type of malware discovered by researchers at Palo Alto Networks in November 2017, but its activity dates back to at least late 2016. Researchers identified only ten unique samples of the malware, indicating limited use, and three different variants, noted as versions 1, 2, and 3. The malware is unique as its final payload masquerades as a control panel link (CPL) file. The intended targets of this activity are unknown as of this writing; however, it was used concurrently with the SunOrcal malware and the same C2 infrastructure used by threat actors who primarily target based on the "Five Poisons" - five perceived threats deemed dangerous to, and working against the interests of, the Chinese government.
ReactorBot
Technical ID: win.reactorbot
MALWARE
Please note: ReactorBot in its naming is often mistakenly labeled as Rovnix. ReactorBot is a full blown bot with modules, whereas Rovnix is just a bootkit / driver component (originating from Carberp), occasionally delivered alongside ReactorBot.
MALWARE
Malware family identifying win.rdat. Origin and technical characteristics tracked via Malpedia.
Also known as: GREYSTUFF
rdasrv
Technical ID: win.rdasrv
MALWARE
Malware family identifying win.rdasrv. Origin and technical characteristics tracked via Malpedia.