Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.rctrl. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.rcs. Origin and technical characteristics tracked via Malpedia.
Also known as: Remote Control System • Crisis
RC2FM
Technical ID: win.rc2fm
MALWARE
A family identified by ESET Research in the InvisiMole campaign.
Razy
Technical ID: win.razy
MALWARE
Razy is a malware family which uses a malicious browser extension in order to steal cryptocurrency.
Razr ransomware
Technical ID: win.razr
MALWARE
Malware family identifying win.razr. Origin and technical characteristics tracked via Malpedia.
RawPOS
Technical ID: win.rawpos
MALWARE
Malware family identifying win.rawpos. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.rawdoor. Origin and technical characteristics tracked via Malpedia.
Raven Stealer
Technical ID: win.ravenstealer
MALWARE
Malware family identifying win.ravenstealer. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ratsnif. Origin and technical characteristics tracked via Malpedia.
RatonRAT
Technical ID: win.raton_rat
MALWARE
Malware family identifying win.raton_rat. Origin and technical characteristics tracked via Malpedia.
RATel
Technical ID: win.ratel
MALWARE
Malware family identifying win.ratel. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ratankbapos. Origin and technical characteristics tracked via Malpedia.
Also known as: RATANKBAPOS
MALWARE
This is a backdoor that establishes persistence using the Startup folder.
It communicates to its C&C server using HTTPS and a static HTTP User-Agent
string. QUICKRIDE is capable of gathering information about the system,
downloading and loading executables, and uninstalling itself. It was leveraged
against banks in Poland.
Also known as: QUICKRIDE
Raspberry Robin
Technical ID: win.raspberry_robin
MALWARE
Worm spread by external drives that leverages Windows Installer to reach out to QNAP-associated domains and download a malicious DLL.
Also known as: RaspberryRobin • QNAP-Worm • LINK_MSIEXEC
MALWAREfinancialhigh
This ransomware encrypts all user’s data on the PC (photos, documents, excel tables, music, videos, etc), adds its specific extension to every file, and creates the HOW_TO_DECYPHER_FILES.txt files in every folder which contains encrypted files.
Rarog
Technical ID: win.rarog
MALWARE
Malware family identifying win.rarog. Origin and technical characteristics tracked via Malpedia.
MALWARE
A spy trojan is a type of malware that has the capability to gather information from the infected system without consent from the user. This information is then sent to a remote attacker.
Rapid Ransom
Technical ID: win.rapid_ransom
MALWAREfinancialhigh
InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems and also encrypts any new files that are created. It does this by creating auto-runs that are designed to launch the ransomware and display the ransom note every time the infected system is started.
SNC
Technical ID: win.ransomware_snc
MALWAREfinancialhigh
Ransomware SNC is a ransomware who encrypts files and asks for a variable amount of Bitcoin before releasing the decryption key to your files. The threat actor asks to be contacted for negotiating the right ransom fee.
Ransomlock
Technical ID: win.ransomlock
MALWARE
Malware family identifying win.ransomlock. Origin and technical characteristics tracked via Malpedia.
Also known as: WinLock
MALWAREfinancialhigh
Ransomware written in Golang and obfuscated with Gobfuscate, with significant code overlap to Knight ransomware.
MALWAREfinancialhigh
RansomExx is a ransomware family that targeted multiple companies starting in mid-2020. It shares commonalities with Defray777.
Also known as: Ransom X • Defray777
Ransoc
Technical ID: win.ransoc
MALWARE
Malware family identifying win.ransoc. Origin and technical characteristics tracked via Malpedia.
Ranscam
Technical ID: win.ranscam
MALWARE
Malware family identifying win.ranscam. Origin and technical characteristics tracked via Malpedia.
Ranion
Technical ID: win.ranion
MALWAREfinancialhigh
Ransomware.
Ranbyus
Technical ID: win.ranbyus
MALWARE
Malware family identifying win.ranbyus. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ramsay. Origin and technical characteristics tracked via Malpedia.
Ramnit
Technical ID: win.ramnit
MALWAREfinancialhigh
According to Check Point, Ramnit is primarily a banking trojan, meaning that its purpose is to steal login credentials for online banking, which cybercriminals can sell or use in future attacks. For this reason, Ramnit primarily targets individuals rather than focusing on particular industries.
Ramnit campaigns have been observed to target organizations in particular industries. For example, a 2019 campaign targeted financial organizations in the United Kingdom, Italy, and Canada.
Also known as: Nimnul
Ramdo
Technical ID: win.ramdo
MALWARE
Malware family identifying win.ramdo. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-20
View profile →MALWARE
Malware family identifying win.rambo. Origin and technical characteristics tracked via Malpedia.
Also known as: brebsd
RALord
Technical ID: win.ralord
MALWAREfinancialhigh
A ransomware written in Rust.
Rakhni
Technical ID: win.rakhni
MALWARE
Malware family identifying win.rakhni. Origin and technical characteristics tracked via Malpedia.
MALWARE
Raindrop is a loader for Cobalt Strike that was observed in the SolarWinds attack.
RAILSETTER
Technical ID: win.railsetter
MALWARE
According to Trend Micro, RAILSETTER is a persistence installer component designed to work with RAILLOAD. Its main functions include: Copying and renaming RAILLOAD’s intended host from System32 to the intended target directory; Timestomping RAILLOAD and its host’s create, access, and modify time; Creating a scheduled task for persistence.
Ragnarok
Technical ID: win.ragnarok
MALWAREfinancialhigh
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.
RagnarLocker
Technical ID: win.ragnarlocker
MALWARE
Malware family identifying win.ragnarlocker. Origin and technical characteristics tracked via Malpedia.
RadRAT
Technical ID: win.radrat
MALWARE
Malware family identifying win.radrat. Origin and technical characteristics tracked via Malpedia.
Radamant
Technical ID: win.radamant
MALWARE
Malware family identifying win.radamant. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →Rad
Technical ID: win.rad
MALWARE
Malware family identifying win.rad. Origin and technical characteristics tracked via Malpedia.
MALWARE
Racket Downloader is an HTTP(S) downloader.
It uses a custom substitution cipher for decryption of its character strings, and RC5 with a 256-bit key for encryption and decryption of network traffic.
It sends an HTTP POST request containing a particular value that inspired its name, like "?product_field=racket" or "prd_fld=racket".
Racket Downloader was deployed against South Korean targets running the Initech INISAFE CrossWeb EX software in Q2 2021 and Q1 2022.