Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
TigerLite is a TCP downloader.
It creates mutexes like "qtrgads32" or "Microsoft32".
It uses RC4 with the key "MicrosoftCorporationValidation@#$%^&*()!US" for decryption of its character strings, and a custom algorithm for encryption and decryption of network traffic.
It supports from 5 up to 8 commands with the following identifiers: 1111, 1234, 2099/3333, 4444, 8877, 8888, 9876, 9999. The commands mostly perform various types of execution - either of code received from the server, or native Windows commands, with their output collected and sent back to the server.
TigerLite is an intermediate step of a multi-stage attack, in which Tiger RAT is usually the next step. This malware was observed in attacks against South Korean entities in H1 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.tidepool
APT GROUP
Malware family tracked by Malpedia. ID: win.thunker
APT GROUP
Malware family tracked by Malpedia. ID: win.thumbthief
APT GROUP
Malware family tracked by Malpedia. ID: win.threebyte
APT GROUP
Malware family tracked by Malpedia. ID: win.thinmon
APT GROUP
Malware family tracked by Malpedia. ID: win.theme_forest_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.thanatos_ransom
APT GROUP
According to Cisco Talos, this is loader is written in Rust and was observed to stage Cobalt Strike Beacons and VShell.
APT GROUPfinancialhigh
According to Kaspersky, detected in February 2015, the new ransomware Trojan gained immediate notoriety as a menace to computer gamers. Amongst other types of target files, it tries to infect typical gaming files: game saves, user profiles, recoded replays etc. That said, TeslaCrypt does not encrypt files that are larger than 268 MB. Recently,
APT GROUP
TerraTV is a custom DLL designed to hijack legit TeamViewer applications. It was discovered and documented by QuoINT. It has been attributed to Golden Chickens malware as a service group.
APT GROUP
According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a generic reconnaissance tool, targeting for example email clients, web browsers, and file transfer utilities. Attributed to Golden Chickens.
APT GROUP
According to QuoINT TerraRecon is a reconnaissance tool, looking for a specific piece of hardware and software targeting retail and payment services sectors. Attributed to Golden Chickens.
APT GROUP
Malware family tracked by Malpedia. ID: win.terra_loader
APT GROUP
Malware family tracked by Malpedia. ID: win.terrapreter
APT GROUPfinancialhigh
TerraLogger is a standalone keylogger malware developed by Golden Chickens, a financially motivated threat actor. It uses a common low-level keyboard hook to record keystrokes and writes the logs to local files. The malware is typically delivered as an OCX file and employs initial execution checks before proceeding. Upon execution, it opens a file handle to log keystrokes and implements its keylogger using a SetWindowsHookExA hook. Keystrokes are written to the open log file, with special characters handled accordingly. Five distinct TerraLogger samples were identified, reflecting minor updates and active development.
APT GROUP
Malware family tracked by Malpedia. ID: win.terminator_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.tendyron_dropper
APT GROUP
According to Cyble, this is a stealer targeting several crypto currency wallets along browser data.
APT GROUP
Malware family tracked by Malpedia. ID: win.templedoor
APT GROUP
Malware family tracked by Malpedia. ID: win.tempedreve
APT GROUPfinancialhigh
According to PCrisk, Tellyouthepass is one of many ransomware-type programs used to block access to files by encryption and keep them in this state unless a ransom is paid.
The program renames all encrypted files by adding the ".locked" extension and creates a ransom message in a text file called "README.html". For example, "1.jpg" is renamed by Tellyouthepass to "1.jpg.locked".
According to cyber criminals, this ransomware encrypts data using RSA-1024 and AES-256 cryptography algorithms.
APT GROUP
Malware family tracked by Malpedia. ID: win.telepowerbot
APT GROUP
Cisco Talos reports that this is a data exfiltration tool used by TA505.
APT GROUP
Malware family tracked by Malpedia. ID: win.telemiris
APT GROUP
Malware family tracked by Malpedia. ID: win.telegram_grabber
APT GROUP
Malware family tracked by Malpedia. ID: win.teledoor
APT GROUP
Malware family tracked by Malpedia. ID: win.telebot
APT GROUP
According to Check Point, this is a Telegram-focused infostealer (SOAP / Delphi) used to target Iranian expats and dissidents.
APT GROUP
According to Check Point, this is a Telegram-focused infostealer (FTP / Delphi) used to target Iranian expats and dissidents.
APT GROUP
Malware family tracked by Malpedia. ID: win.tefosteal
APT GROUP
TEARDROP is a memory only dropper that runs as a service, spawns a thread and reads from the file “gracious_truth.jpg”, which likely has a fake JPG header. Next it checks that HKU\SOFTWARE\Microsoft\CTF exists, decodes an embedded payload using a custom rolling XOR algorithm and manually loads into memory an embedded payload using a custom PE-like file format. TEARDROP does not have code overlap with any previously seen malware. FireEye believe that this was used to execute a customized Cobalt Strike BEACON.
APT GROUP
Malware family tracked by Malpedia. ID: win.teamspy
APT GROUP
Recently, Check Point researchers spotted a targeted attack against officials within government finance authorities and representatives in several embassies in Europe. The attack, which starts with a malicious attachment disguised as a top secret US document, weaponizes TeamViewer, the popular remote access and desktop sharing software, to gain full control of the infected computer.
This is achieved by sideloading another DLL among the legit TeamViewer.
APT GROUP
Malware family tracked by Malpedia. ID: win.tdtess
APT GROUP
F-Secure described tDiscoverer (also known as HammerDuke) as interesting because it is written in .NET, and even more so because of its occasional use of Twitter as a C&C communication channel. Some HammerDuke variants only contain a hardcoded C&C server address from which they will retrieve commands, but other HammerDuke variants will first use a custom algorithm to generate a Twitter account name based on the current date. If the account exists, HammerDuke will then search for tweets from that account with links to image files that contain embedded commands for the toolset to execute.
APT GROUP
Steve Miller pointed out that it is proxy-aware (Tencent) for C&C communication and uses wolfSSL, which makes it stick out.
APT GROUP
According to Zscaler, Taurus is a stealer that surfaced in June 2020. It is being developed by the author(s) that previously created Predator the Thief. The name overlaps partly with the StealerOne / Terra* family (also aliased Taurus Loader) but appears to be a completely disjunct project.
APT GROUP
Malware family tracked by Malpedia. ID: win.tarsip
APT GROUP
Malware family tracked by Malpedia. ID: win.tapaoux