Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,743 entities
MALWARE
Malware family identifying win.newsreels. Origin and technical characteristics tracked via Malpedia.
NewPosThings
Technical ID: win.newposthings
MALWARE
Malware family identifying win.newposthings. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.newpass. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.newcore_rat. Origin and technical characteristics tracked via Malpedia.
NewBounce
Technical ID: win.newbounce
MALWARE
Malware family identifying win.newbounce. Origin and technical characteristics tracked via Malpedia.
NewBot Loader
Technical ID: win.newbot_loader
MALWARE
Malware family identifying win.newbot_loader. Origin and technical characteristics tracked via Malpedia.
Nevada
Technical ID: win.nevada
MALWARE
Malware family identifying win.nevada. Origin and technical characteristics tracked via Malpedia.
Neutrino POS
Technical ID: win.neutrino_pos
MALWARE
Malware family identifying win.neutrino_pos. Origin and technical characteristics tracked via Malpedia.
Neutrino
Technical ID: win.neutrino
MALWARE
Malware family identifying win.neutrino. Origin and technical characteristics tracked via Malpedia.
Also known as: Kasidet
MALWARE
Malware family identifying win.neuron. Origin and technical characteristics tracked via Malpedia.
NET-STAR
Technical ID: win.net_star
MALWARE
According to Unit 42, NET-STAR is a .NET malware suite designed to target Internet Information Services (IIS) web servers. It was named based on the use of the string in the malware’s program database (PDB) paths. The suite consists of three distinct web-based backdoors, each serving a specific role in the attack chain while maintaining persistence within the target’s IIS environment: A fileless modular backdoor that supports in-memory execution of command-line arguments, arbitrary commands and payloads, a loader for additional Assemblies, and improved version of the Assembly loader that is also equipped with Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) bypass capabilities.
MALWARE
Netwire is a RAT, its functionality seems focused on password stealing and keylogging, but includes remote control capabilities as well.
Keylog files are stored on the infected machine in an obfuscated form. The algorithm is:
for i in range(0,num_read):
buffer[i] = ((buffer[i]-0x24)^0x9D)&0xFF
Also known as: NetWeird • NetWire • Recam
MALWARE
Malware family identifying win.nettraveler. Origin and technical characteristics tracked via Malpedia.
Also known as: TravNet
NetSupportManager RAT
Technical ID: win.netsupportmanager_rat
MALWARE
Enigma Software notes that NetSupport Manager is a genuine application, which was first released about twenty years ago. The purpose of the NetSupport Manager tool is to enable users to receive remote technical support or provide remote computer assistance. However, cyber crooks have hijacked this useful application and misappropriated it to use it in their harmful campaigns. The name of the modified version of the NetSupport Manager has been labeled the NetSupport Manager RAT.
Also known as: NetSupport
NetSpy
Technical ID: win.netspy
MALWARE
Freely available network reconnaissance tool.
Netrepser
Technical ID: win.netrepser_keylogger
MALWARE
Malware family identifying win.netrepser_keylogger. Origin and technical characteristics tracked via Malpedia.
NetKey
Technical ID: win.netkey
MALWARE
Malware family identifying win.netkey. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.netflash. Origin and technical characteristics tracked via Malpedia.
NetfilterRootkit
Technical ID: win.netfilter
MALWARE
NetfilterRootkit is a WFP application layer enforcement callout driver which is signed by Microsoft via the Windows Hardware Compatibility program. It was first discovered by Karsten Hahn. His team submitted the malware to Microsoft, which allowed Microsoft to start an investigation.
After Karsten Hahn published tweets and an article about the rootkit, Microsoft quickly responded with their own article. Their investigation revealed Chinese gamers as targets of the malware. The rootkit redirects traffic to the threat actor's IP. The threat actor can use the driver to spoof their geo-location to cheat, but it also allows account compromise of targeted players.
While this particular rootkit is not significant anymore, similar rootkits have been created since that are also signed by Microsoft via the Windows Hardware Compatibility program.
MALWARE
Malware family identifying win.neteagle. Origin and technical characteristics tracked via Malpedia.
Also known as: Neteagle_Scout • ScoutEagle
NetDooka
Technical ID: win.netdooka
MALWARE
A RAT written in .NET, delivered with a driver to protect it from deletion. Observed being dropped by PrivateLoader.
MALWARE
Malware family identifying win.netc. Origin and technical characteristics tracked via Malpedia.
MALWARE
NESTEGG is a memory-only backdoor that can proxy commands to other
infected systems using a custom routing scheme. It accepts commands to
upload and download files, list and delete files, list and terminate processes, and
start processes. NESTEGG also creates Windows Firewall rules that allows the
backdoor to bind to a specified port number to allow for inbound traffic.
neshta
Technical ID: win.neshta
MALWARE
Neshta is a 2005 Belarusian file infector virus written in Delphi. The name of the virus comes from the Belarusian word "nesta" meaning "something."
Nerbian RAT
Technical ID: win.nerbian_rat
MALWARE
Proofpoint observed distribution of this RAT since late April 2022, it is written on Go and incorporates code from various open-source Git repositories.
Nemty
Technical ID: win.nemty
MALWAREfinancialhigh
Nemty is a ransomware that was discovered in September 2019. Fortinet states that they found it being distributed through similar ways as Sodinokibi and also noted artfifacts they had seen before in Gandcrab.
MALWARE
Malware family identifying win.nemim. Origin and technical characteristics tracked via Malpedia.
Also known as: Nemain
Nemesis
Technical ID: win.nemesis
MALWARE
Malware family identifying win.nemesis. Origin and technical characteristics tracked via Malpedia.
Also known as: Project Nemesis
Nefilim
Technical ID: win.nefilim
MALWAREfinancialhigh
According to Vitali Kremez and Michael Gillespie, this ransomware shares much code with Nemty 2.5. A difference is removal of the RaaS component, which was switched to email communications for payments. Uses AES-128, which is then protected RSA2048.
Also known as: Nephilim
MALWARE
NedDnLoader is an HTTP(S) downloader that uses AES for C&C trafic encryption.
It sends detailed information about the victim's environment, like computer name, user name, type and free disk space of all drives, and a list of currently running processes. It uses three typical parameter names for HTTP POST requests: ned, gl, hl. The usual payload downloaded with NedDnLoader is Torisma.
The internal DLL name of NedDnLoader is usually Dn.dll, Dn64.dll or DnDll.dll. It is deployed either as a standalone payload or within a trojanized MFC application project. It contains specific RTTI symbols like ".?AVCWininet_Protocol@@" or ".?AVCMFC_DLLApp@@".
MALWARE
Malware family identifying win.necurs. Origin and technical characteristics tracked via Malpedia.
Also known as: nucurs
Neconyd
Technical ID: win.neconyd
MALWARE
Malware family identifying win.neconyd. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.nebulae. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ncctrojan. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.navrat. Origin and technical characteristics tracked via Malpedia.
Also known as: JinhoSpy
MALWARE
Malware family identifying win.nautilus. Origin and technical characteristics tracked via Malpedia.
Narilam
Technical ID: win.narilam
MALWARE
Malware family identifying win.narilam. Origin and technical characteristics tracked via Malpedia.
NAPLISTENER
Technical ID: win.naplistener
MALWARE
Malware family identifying win.naplistener. Origin and technical characteristics tracked via Malpedia.
NanoLocker
Technical ID: win.nano_locker
MALWARE
Malware family identifying win.nano_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →MALWARE
Nanocore is a Remote Access Tool used to steal credentials and to spy on cameras. It as been used for a while by numerous criminal actors as well as by nation state threat actors.
Also known as: Nancrat • NanoCore