Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,718 entities
APT GROUP
Malware of this family searches for computers on a network and creates copies of itself in folders with open access. For the program to be activated, the user must first run it on the computer. The code of this malware is written in the Visual Basic programming language and uses obfuscation, which is a distinguishing feature of this family. Code obfuscation complicates attempts by anti-virus software to analyze suspected malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.vmzeus
APT GROUP
VJW0rm (aka Vengeance Justice Worm) is a publicly available, modular JavaScript RAT. Vjw0rm was first released in November 2016 by its primary author, v_B01 (aka Sliemerez), within the prominent DevPoint Arabic-language malware development community. VJW0rm appears to be the JavaScript variant of a series of RATs with identical functionality released by the author throughout late 2016. Other variants include a Visual Basic Script (VBS) based worm titled vw0rm (Vengeance Worm), an AutoHotkey-based tool called vrw0rm (Vengeance Rise Worm), and a PowerShell-based variant called vdw0rm (Vengeance Depth Worm).
APT GROUP
Malware family tracked by Malpedia. ID: win.vizom
APT GROUP
Malware family tracked by Malpedia. ID: win.virut
APT GROUP
Malware family tracked by Malpedia. ID: win.virtualgate
APT GROUPfinancialhigh
Polymorphic parasitic file infecting virus which transforms files into copies of itself. Additionally it uses screen-locking as a ransomware technique.
APT GROUP
Malware family tracked by Malpedia. ID: win.virdetdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.vipkeylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.vilsastealer
Wiper malware discovered by Japanese security firm Mitsui Bussan Secure Directions (MBSD), which is assumed to target Japan, the host country of the 2021 Summer Olympics. In addition to targeting common file Office-related files, it specifically targets file types associated with the Japanese word processor Ichitaro.
APT GROUP
Vidar is a forked malware based on Arkei. It seems this stealer is one of the first that is grabbing information on 2FA Software and Tor Browser.
APT GROUP
VictoryGate was the name of a cryptomining botnet, which was disrupted by ESET researchers in April 2020. The used malware itself was also referred to as VictoryGate. It was spotted in May 2019 and targeted mainly Latin American users, specifically, Peru (Criptonizando states 90% of the botnet publication residing there). Both public and private sectors were targeted. This cryptojacking malware was specialized in Monero (XRM) cryptocurrency. VictoryGate shows very strong code overlap with win.orchard.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.vhd_ransomware
APT GROUP
Vflooder floods VirusTotal by infinitely submitting a copy of itself. Some variants apparently also try to flood Twitter. The impact on these services are negligible, but for researchers it can be a nuisance. Most versions are protected by VMProtect.
APT GROUP
Vetta Loader is a persistent Loader spreading with infected USB drives. It downloads other components leveraging legit hosting services. https://yoroi.company/wp-content/uploads/2023/12/202311-Vetta-Loader_Def-min.pdf
APT GROUP
Malware family tracked by Malpedia. ID: win.vermin
Malware family tracked by Malpedia. ID: elf.vermilion_strike
APT GROUP
Malware family tracked by Malpedia. ID: win.venus_locker
APT GROUP
According to Cisco Talos, this is a reverse proxy socks5 server-client tool originally developed for penetration testers.
APT GROUP
VenomLNK is the initial phase of the more_eggs malware-as-a-service. It is a poisoned .lnk file that depends on User Execution and points to LOLBINs (often cmd.exe) with additional obfuscated scripting options. This typically initiates WMI abuse and TerraLoader, which can load additional functionality through various plugins.
APT GROUP
Malware family tracked by Malpedia. ID: win.venomloader
APT GROUP
Malware family tracked by Malpedia. ID: win.venom
APT GROUPfinancial
Ransomware, which appears to be a rebranding of win.cuba.
RLUpdated: N/A
View profile →
APT GROUPfinancialhigh
Ransomware that appears to require manually installation (believed to be via RDP). Encrypts files with .velso extension.
APT GROUP
According to Seqrite, VELETRIX as been observed as a loader for VShell.
APT GROUP
Malware family tracked by Malpedia. ID: win.veiledsignal
APT GROUPfinancialhigh
Delphi-based ransomware.
APT GROUP
Credential Stealer, written in .NET.
APT GROUP
Malware family tracked by Malpedia. ID: win.veaty
APT GROUP
Malware family tracked by Malpedia. ID: win.vawtrak
APT GROUP
In May 2019, ESET researchers observed a spike in ESET telemetry data regarding malware targeting France. After further investigations, they identified malware that distributes various types of spam. One of them is leading to a survey that redirects to a dodgy smartphone promotion while the other is a sextortion campaign. The spam targets the users of Orange S.A., a French ISP.
APT GROUP
According to Mandiant, VaporRage or BOOMMIC, is a shellcode downloader written in C that communicates over HTTPS. Shellcode Payloads are retrieved from a hardcoded C2 that uses an encoded host_id generated from the targets domain and account name. BOOMMIC XOR decodes the downloaded shellcode payload in memory and executes it.
APT GROUP
Description: VanillaRat is an advanced remote administration tool coded in C#. VanillaRat uses the Telepathy TCP networking library, dnlib module reading and writing library, and Costura.Fody dll embedding library. Features: Remote Desktop Viewer (With remote click) File Browser (Including downloading, drag and drop uploading, and file opening) Process Manager Computer Information Hardware Usage Information (CPU usage, disk usage, available ram) Message Box Sender Text To Speech Screen Locker Live Keylogger (Also shows current window) Website Opener Application Permission Raiser (Normal -> Admin) Clipboard Text (Copied text) Chat (Does not allow for client to close form) Audio Recorder (Microphone) Process Killer (Task manager, etc.) Remote Shell Startup Security Blacklist (Drag client into list if you don't want connection. Press del. key on client to remove from list)
APT GROUPfinancial
VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.
APT GROUP
Malware family tracked by Malpedia. ID: win.vampire_bot
APT GROUP
Malware family tracked by Malpedia. ID: win.valuevault
APT GROUP
Malware family tracked by Malpedia. ID: win.valley_rat
Malware family tracked by Malpedia. ID: win.valkyrie_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.vaggen