Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
Passlock
Technical ID: win.passlock
MALWAREfinancialhigh
Ransomware.
PartyTicket
Technical ID: win.partyticket
MALWAREfinancialhigh
PartyTicket is a Go-written ransomware, which was described as a poorly designed one by Zscaler. According to Brett Stone-Gross this malware is likely intended to be a diversion from the Hermetic wiper (aka. KillDisk.NCV, DriveSlayer) attack.
Also known as: Elections GoRansom • HermeticRansom • SonicVote
Parite
Technical ID: win.parite
MALWARE
According to Microsoft, Parite is a family of polymorphic file infectors that targets computers running Microsoft Windows. The virus infects .exe and .scr executable files on the local file system and on writeable network shares. In turn, the infected executable files perform operations that cause other .exe and .scr files to become infected.
parasite_http
Technical ID: win.parasite_http
MALWARE
Malware family identifying win.parasite_http. Origin and technical characteristics tracked via Malpedia.
Parallax RAT
Technical ID: win.parallax
MALWARE
Parallax is a Remote Access Trojan used by attackers to gain access to a victim's machine. It was involved in one of the many infamous "coronamalware" campaigns. Basically, the attackers abused the COVID-19 pandemic news to lure victims into opening themed emails spreading parallax.
Also known as: ParallaxRAT
Paradise
Technical ID: win.paradise
MALWAREfinancialhigh
Ransomware.
Paradies Clipper
Technical ID: win.paradies_clipper
MALWARE
Malware family identifying win.paradies_clipper. Origin and technical characteristics tracked via Malpedia.
Pantegana
Technical ID: win.pantegana
MALWARE
A multi-platform RAT written in Go.
Pandora RAT
Technical ID: win.pandora_rat
MALWARE
Malware family identifying win.pandora_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: Pandora hVNC RAT
Pandora
Technical ID: win.pandora
MALWAREfinancialhigh
Pandora ransomware was obtained by vx-underground at 2022-03-14.
Panda Stealer
Technical ID: win.panda_stealer
MALWARE
According to PCrisk, Panda is the name of a malicious program, which is classified as a stealer. It is a new variant of CollectorStealer.
The aim of this malware is to extract and exfiltrate sensitive and personal information from infected devices. Panda primarily targets data relating to cryptocurrency wallets.
This piece of malicious software has been observed being actively distributed via spam campaigns - large-scale operations during which thousands of scam emails are sent. The spam mail proliferating Panda stealer heavily targeted users from the United States, Germany, Japan, and Australia.
The deceptive email letters concerned business-related topics (e.g., fake product quote requests, etc.). Panda stealer is a dangerous program, and as such - its infections must be removed immediately upon detection.
PandaBanker
Technical ID: win.pandabanker
MALWAREfinancialhigh
According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*). Fox IT discovered it in February 2016.
This banking trojan uses the infamous ATS (Automatic Transfer System/Scripts) to automate online bank portal actions.
The baseconfig (c2, crypto material, botnet name, version) is embedded in the malware itself. It then obtains a dynamic config from the c2, with further information about how to grab the webinjects and additional modules, such as vnc, backsocks and grabber.
Panda does have some DGA implemented, but according to Arbor, a bug prevents it from using it.
Also known as: ZeusPanda
MALWARE
Paladin RAT is a variant of Gh0st RAT used by PittyPanda active since at least 2011.
PadCrypt
Technical ID: win.padcrypt
MALWARE
Malware family identifying win.padcrypt. Origin and technical characteristics tracked via Malpedia.
Ozone RAT
Technical ID: win.ozone
MALWARE
Malware family identifying win.ozone. Origin and technical characteristics tracked via Malpedia.
OZH RAT
Technical ID: win.ozh_rat
MALWARE
Malware family identifying win.ozh_rat. Origin and technical characteristics tracked via Malpedia.
OxtaRAT
Technical ID: win.oxtarat
MALWARE
Malware family identifying win.oxtarat. Origin and technical characteristics tracked via Malpedia.
Owowa
Technical ID: win.owowa
MALWARE
Kaspersky describes this as a OWA add-on that has credential stealing capabilities.
Owlproxy
Technical ID: win.owlproxy
MALWARE
Malware family identifying win.owlproxy. Origin and technical characteristics tracked via Malpedia.
owaauth
Technical ID: win.owaauth
MALWARE
Malware family identifying win.owaauth. Origin and technical characteristics tracked via Malpedia.
Also known as: luckyowa
OvidiyStealer
Technical ID: win.ovidiystealer
MALWARE
Malware family identifying win.ovidiystealer. Origin and technical characteristics tracked via Malpedia.
Overlay RAT
Technical ID: win.overlay_rat
MALWARE
Malware family identifying win.overlay_rat. Origin and technical characteristics tracked via Malpedia.
OutSteel
Technical ID: win.outsteel
MALWARE
According to MITRE, OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Ember Bear since at least March 2021.
MALWARE
Malware family identifying win.outlook_backdoor. Origin and technical characteristics tracked via Malpedia.
Also known as: FACADE
OutCrypt
Technical ID: win.outcrypt
MALWAREfinancialhigh
Ransomware.
Ousaban
Technical ID: win.ousaban
MALWARE
Malware family identifying win.ousaban. Origin and technical characteristics tracked via Malpedia.
Osno
Technical ID: win.osno
MALWARE
Malware family identifying win.osno. Origin and technical characteristics tracked via Malpedia.
Also known as: Babax
Oski Stealer
Technical ID: win.oski
MALWARE
Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums. It collects different types of data (cryptocurrency wallets, saved passwords, files matching an attacker-defined pattern etc) and it exfiltrates it in a zip file uploaded to the attacker's panel.
ORPCBackdoor
Technical ID: win.orpcbackdoor
MALWARE
Malware family identifying win.orpcbackdoor. Origin and technical characteristics tracked via Malpedia.
OriginLogger
Technical ID: win.originlogger
MALWARE
Malware family identifying win.originlogger. Origin and technical characteristics tracked via Malpedia.
OriginBot
Technical ID: win.originbot
MALWARE
OriginBot is a modular information stealer which can also download and execute other malicious payloads.
Also known as: OriginBotnet • OriginLoader
Ordinypt
Technical ID: win.ordinypt
MALWAREfinancialhigh
This malware claims to be a ransomware, but it's actually a wiper. After execution, this malware terminates a number of processes such as database processes, likely to allow access to any files that these programs may have held open. Ordinypt will avoid wiping certain files and folders in order to prevent the infected machine from becoming unusable. Affected files are overwritten with null character and receive a random 5 character file extension. Finally, shadow copies are removed and Windows startup repair is disabled to complicate recovery of data from the affected system. The desktop background is changed and a ransom note is dropped for the victim. A C2 check-in occurs to keep track of the file extension used on that specific machine, as well as which BitCoin address was randomly provided for payment to the victim (drawn from a long list stored in the ransomware configuration).
Also known as: GermanWiper • HSDFSDCrypt
Orcus RAT
Technical ID: win.orcus_rat
MALWARE
Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016. It has all the features that would be expected from a RAT and probably more. The long list of the commands is documented on their website. But what separates Orcus from the others is its capability to load custom plugins developed by users, as well as plugins that are readily available from the Orcus repository. In addition to that, users can also execute C# and VB.net code on the remote machine in real-time.
Also known as: Schnorchel
Orchard
Technical ID: win.orchard
MALWARE
A malware generating DGA domains seeded by the Bitcoin Genesis Block. This family has strong code overlap with win.victorygate.
Also known as: Antavmu
OrcaRAT
Technical ID: win.orcarat
MALWARE
OrcaRAT is a Backdoor that targets the Windows platform. It has been reported that a variant of this malware has been used in a targeted attack. It contacts a remote server, sending system information. Moreover, it receives control commands to execute shell commands, and download/upload a file, among other actions.
MALWARE
FireEye details ORANGEADE as a dropper for the CREAMSICLE malware.
MALWARE
Malware family identifying win.op_blockbuster. Origin and technical characteristics tracked via Malpedia.
OpGhoul
Technical ID: win.opghoul
MALWARE
This entry serves as a placeholder of malware observed during Operation Ghoul. The samples will likely be assigned to their respective families. Some families involved and identified were Alina POS (Katrina variant) and TreasureHunter POS.
MALWARE
Malware family identifying win.open_carrot. Origin and technical characteristics tracked via Malpedia.
OpenSUpdater
Technical ID: win.opensupdater
MALWARE
Malware family identifying win.opensupdater. Origin and technical characteristics tracked via Malpedia.