Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,743 entities
Retefe
Technical ID: win.retefe
MALWAREfinancialhigh
Retefe is a Windows Banking Trojan that can also download and install additional malware onto the system using Windows PowerShell. It's primary functionality is to assist the attacker with stealing credentials for online banking websites. It is typically targeted against Swiss banks. The malware binary itself is primarily a dropper component for a Javascript file which builds a VBA file which in turn loads multiple tools onto the host including: 7zip and TOR. The VBA installs a new root certificate and then forwards all traffic via TOR to the attacker controlled host in order to effectively MITM TLS traffic.
Also known as: Tsukuba • Werdlod
Updated: 2019-05-23
View profile →
Retadup
Technical ID: win.retadup
MALWARE
Malware family identifying win.retadup. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-28
View profile →
Resident
Technical ID: win.resident
TA866
MALWARE
According to Cisco Talos, Resident is a backdoor likely developed by the same author as win.warmcookie, and it was observed being delivered in intrusions they attribute to TA866.
Updated: 2024-11-11
View profile →
Reshell
Technical ID: win.reshell
GALLIUM
MALWARE
Malware family identifying win.reshell. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-11
View profile →
Rerdom
Technical ID: win.rerdom
MALWARE
Malware family identifying win.rerdom. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-08-10
View profile →
Remy
Technical ID: win.remy
MALWARE
Malware family identifying win.remy. Origin and technical characteristics tracked via Malpedia.
Also known as: WINDSHIELD
Updated: 2020-05-23
View profile →
Remsec
Technical ID: win.remsec_strider
ProjectSauron
MALWARE
Malware family identifying win.remsec_strider. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-21
View profile →
RemoteControl
Technical ID: win.remotecontrolclient
MALWARE
Malware family identifying win.remotecontrolclient. Origin and technical characteristics tracked via Malpedia.
Also known as: remotecontrolclient
Updated: 2020-02-13
View profile →
RemoteAdmin
Technical ID: win.remoteadmin
MALWARE
Malware family identifying win.remoteadmin. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-18
View profile →
Remexi
Technical ID: win.remexi
APT39Chafer
MALWAREespionageadvanced
Remexi is a highly advanced and stealthy malware discovered in recent times. It employs sophisticated evasion techniques to infiltrate target systems and networks undetected. This malware utilizes various propagation vectors, including exploit kits, social engineering tactics, and compromised websites. Once inside a system, Remexi establishes persistence through rootkit capabilities and leverages coAmmand-and-control infrastructure to receive and execute malicious commands. It possesses keylogging and data exfiltration capabilities, enabling it to steal sensitive information such as login credentials and financial data. Additionally, Remexi can download and execute additional payloads, making it adaptable and capable of evolving its malicious activities over time.
Also known as: CACHEMONEY
Updated: 2023-05-25
View profile →
Remcos
Technical ID: win.remcos
APT33The Gorgon GroupUAC-0050
MALWARE
Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers. Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns. Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user. Remcos is developed by the cybersecurity company BreakingSecurity.
Also known as: RemcosRAT • Remvio • Socmer
Updated: 2026-01-15
View profile →
RemCom
Technical ID: win.remcom
MALWARE
Malware family identifying win.remcom. Origin and technical characteristics tracked via Malpedia.
Also known as: RemoteCommandExecution
Updated: 2024-04-11
View profile →
RelicRace
Technical ID: win.relic_race
MALWARE
Malware family identifying win.relic_race. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
Rektware
Technical ID: win.rektware
MALWARE
Malware family identifying win.rektware. Origin and technical characteristics tracked via Malpedia.
Also known as: PRZT Ransomware
Updated: 2020-03-22
View profile →
Rekt Loader
Technical ID: win.rektloader
MALWARE
Malware family identifying win.rektloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
win.rekoobe
Technical ID: win.rekoobew
FIN7
MALWARE
A Trojan for Winows with the same code structure and functionalities of elf.rekoobe, for Linux environment instead.
Also known as: tinyshell.win • tshd.win
Updated: 2021-12-08
View profile →
RekenSom
Technical ID: win.rekensom
MALWAREfinancialhigh
Ransomware.
Also known as: GHack Ransomware
Updated: 2020-03-22
View profile →
RegretLocker
Technical ID: win.regretlocker
MALWAREfinancialhigh
According to PCrisk, RegretLocker is malicious software classified as ransomware. Systems infected with this malware have their data encrypted and users receive ransom demands for decryption. During the encryption process, all affected files are appended with the ".mouse" extension.
Updated: 2023-05-25
View profile →
Regin
Technical ID: win.regin
MALWAREfinancialhigh
Regin is a sophisticated malware and hacking toolkit attributed to United States' National Security Agency (NSA) for government spying operations. It was first publicly revealed by Kaspersky Lab, Symantec, and The Intercept in November 2014. Regin malware targeted victims in a range of industries, telecom, government, and financial institutions. It was engineered to be modular and over time dozens of modules have been found and attributed to this family. Symantec observed around 100 infections in 10 different countries across a variety of organisations including private companies, government entities, and research institutes.
Updated: 2022-03-22
View profile →
reGeorg
Technical ID: win.regeorg
MALWARE
Malware family identifying win.regeorg. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-08
View profile →
ReedBed
Technical ID: win.reedbed
MALLARD SPIDERUNC4393
MALWARE
ReedBed, identified as a malware proxy backdoor, is suspected to be developed by QAKBOT devs, and was deployed by the threat actor Storm-1811 in campaigns observed during late October and early November 2024. These campaigns are typically initiated with email bombing, a tactic involving mass email distribution, followed by social engineering strategies where the actor impersonates help desk personnel to gain access to victim systems. Upon execution, ReedBed ensures single-instance operation via the mutex "JhishdiI2Uhsvoc94keiojn7ns19m0do" and hooks critical system APIs (NtCreateUserProcess, RtlExitUserProcess) for defense evasion, process interference, and anti-termination. It reads its Command and Control (C2) configuration, typically from the "Software\TitanPlus" registry key, establishes a persistent SSL/TLS encrypted connection, and transmits an initial system information beacon. Subsequently, ReedBed enters its main operational loop, acting as a versatile network proxy based on C2 commands; this includes initiating outgoing TCP connections, relaying data bi-directionally, and establishing reverse SOCKS5 (with authentication) or direct TCP port mapping services via locally opened listening ports. If commanded or upon connection failure, it transitions into a restart/wait cycle guided by registry values, leveraging its hooked exit function to hinder termination before attempting to reconnect to the C2.
Updated: 2025-03-28
View profile →
Red Gambler
Technical ID: win.red_gambler
MALWARE
Malware family identifying win.red_gambler. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-11
View profile →
Red Alert
Technical ID: win.red_alert
MALWARE
Malware family identifying win.red_alert. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
Redyms
Technical ID: win.redyms
MALWARE
Malware family identifying win.redyms. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-18
View profile →
REDSHAWL
Technical ID: win.redshawl
Lazarus Group
MALWARE
REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.
Updated: 2023-08-31
View profile →
REDSALT
Technical ID: win.redsalt
PLATINUM
MALWARE
Malware family identifying win.redsalt. Origin and technical characteristics tracked via Malpedia.
Also known as: Dipsind
Updated: 2020-01-20
View profile →
RedRum
Technical ID: win.redrum
MALWAREfinancialhigh
Ransomware.
Also known as: Grinch • Tycoon • Thanos
Updated: 2020-12-23
View profile →
REDPEPPER
Technical ID: win.redpepper
PLATINUM
MALWARE
Malware family identifying win.redpepper. Origin and technical characteristics tracked via Malpedia.
Also known as: Adupib
Updated: 2020-01-01
View profile →
Redosdru
Technical ID: win.redosdru
MALWARE
Redosdru is a malware family that primarily acts as a downloader. Upon execution, it may drop downloaded DLLs in the "%ProgramFiles%\AppPatch" directory. The malware modifies the Windows registry to ensure its persistence, adding entries to run automatically at system startup.
Updated: 2024-12-09
View profile →
RedLine Stealer
Technical ID: win.redline_stealer
MALWARE
RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer.
Also known as: RECORDSTEALER
Updated: 2025-11-25
View profile →
RedLeaves
Technical ID: win.redleaves
Stone Panda
MALWARE
Malware family identifying win.redleaves. Origin and technical characteristics tracked via Malpedia.
Also known as: BUGJUICE
Updated: 2022-06-22
View profile →
RedEnergy Stealer
Technical ID: win.redenergy_stealer
MALWAREfinancialhigh
According to Zscaler ThreatLabz, RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for carrying out ransomware activities.The name of the malware was kept due to the common method names observed during the analysis.
Updated: 2023-07-11
View profile →
RedCurl
Technical ID: win.redcurl
MALWARE
Malware family identifying win.redcurl. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-16
View profile →
RedCap
Technical ID: win.redcap
OilRig
MALWARE
According to Trend Micro, this backdoor receives valid domain credentials as an argument and uses it to log on to the Exchange Server and use it for data exfiltration purposes. The main function of this stage is to take the stolen password from the argument and send it to the attackers as an attachment in an email. We also observed that the threat actors relay these emails via government Exchange Servers using vaild accounts with stolen passwords.
Updated: 2023-08-10
View profile →
RedAlpha
Technical ID: win.redalpha
MALWARE
Malware family identifying win.redalpha. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-06
View profile →
RecordBreaker
Technical ID: win.recordbreaker
MALWARE
This malware is a successor to Raccoon Stealer (also referred to as Raccoon Stealer 2.0), which is however a full rewrite in C/C++.
Updated: 2025-02-28
View profile →
Reaver
Technical ID: win.reaver
MALWARE
Reaver is a type of malware discovered by researchers at Palo Alto Networks in November 2017, but its activity dates back to at least late 2016. Researchers identified only ten unique samples of the malware, indicating limited use, and three different variants, noted as versions 1, 2, and 3. The malware is unique as its final payload masquerades as a control panel link (CPL) file. The intended targets of this activity are unknown as of this writing; however, it was used concurrently with the SunOrcal malware and the same C2 infrastructure used by threat actors who primarily target based on the "Five Poisons" - five perceived threats deemed dangerous to, and working against the interests of, the Chinese government.
Updated: 2019-05-17
View profile →
ReactorBot
Technical ID: win.reactorbot
MALWARE
Please note: ReactorBot in its naming is often mistakenly labeled as Rovnix. ReactorBot is a full blown bot with modules, whereas Rovnix is just a bootkit / driver component (originating from Carberp), occasionally delivered alongside ReactorBot.
Updated: 2017-06-07
View profile →
RDAT
Technical ID: win.rdat
OilRig
MALWARE
Malware family identifying win.rdat. Origin and technical characteristics tracked via Malpedia.
Also known as: GREYSTUFF
Updated: 2025-06-16
View profile →
rdasrv
Technical ID: win.rdasrv
MALWARE
Malware family identifying win.rdasrv. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
← PreviousPage 141 / 269Next →