Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,744 entities
Luca Stealer
Technical ID: win.luca_stealer
MALWARE
According to PCRisk, The Luca stealer can extract a variety of information from compromised machines. It targets data related to the following: operating system, device name, CPUs, desktop environment, network interface, user account name, preferred system language, running processes, etc. This malicious program can steal information from over thirty Chromium-based browsers. From these applications, Luca can obtain Internet cookies, account log-in credentials (usernames/passwords), and credit card numbers. Additionally, the stealer can extract data from password manager and cryptowallet browser extensions compatible with over twenty browsers. This malware also targets various messaging applications like Telegram, Discord, ICQ, Skype, Element, etc. It likewise aims to acquire information from gaming-related software such as Steam and Uplay (Ubisoft Connect). Furthermore, some versions of Luca can take screenshots and download the files stored on victims' devices.
Updated: 2022-12-15
View profile →
LuaDream
Technical ID: win.luadream
MALWARE
Malware family identifying win.luadream. Origin and technical characteristics tracked via Malpedia.
Also known as: DreamLand
Updated: 2023-12-12
View profile →
Lu0Bot
Technical ID: win.lu0bot
MALWARE
According to PCrisk, Lu0bot es un software malicioso. El malware es ligero, por lo que su uso de los recursos del sistema es bajo. Esto complica la detección de Lu0bot, ya que no causa síntomas significativos, como una grave disminución del rendimiento del sistema. El programa malicioso funciona como un recolector de telemetría.
Updated: 2024-06-10
View profile →
lsassDumper
Technical ID: win.lsassdumper
MALWARE
This in Go written malware is lsass process memory dumper, which was custom developed by threat actors according to Security Joes. It has the capability to automatically exfiltrate the results to the free file transfer service "transfer.sh".
Updated: 2022-03-10
View profile →
LPEClient
Technical ID: win.lpeclient
Lazarus Group
MALWARE
LPEClient is an HTTP(S) downloader that expects two command line parameters: an encrypted string containing two URLs (a primary and a secondary C&C server), and the path on the victim's file system to store the downloaded payload. It sends detailed information about the victim's environment, like computer name, type and number of processors, computer manufacturer, product name, major and minor Windows versions, architecture, memory information, installed security software and the version of the ntoskrnl.exe from its version-information resource. LPEClient uses specific 32-bit values to represent its execution state (0x59863F09 when connecting via the WinHTTP interface, 0xA9348B57 via WinINet), or the nature of HTTP requests to the C&C servers (0xF07D6B34 when sending system information, 0xEF8C0D51 when requesting a DLL payload, 0xCB790A25 when reporting the successful loading of the DLL, 0xD7B20A96 when reporting the state of the the DLL execution). As the final step, malware looks for the export CloseEnv and executes it.
Also known as: LPEClientTea
Updated: 2023-11-27
View profile →
LOWZERO
Technical ID: win.lowzero
Lucky Cat
MALWARE
Malware family identifying win.lowzero. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-09
View profile →
LOWKEY
Technical ID: win.lowkey
APT41
MALWARE
Malware family identifying win.lowkey. Origin and technical characteristics tracked via Malpedia.
Also known as: PortReuse
Updated: 2022-03-10
View profile →
LOWBALL
Technical ID: win.lowball
Temper Panda
MALWARE
LOWBALL, uses the legitimate Dropbox cloud-storage service to act as the CnC server. It uses the Dropbox API with a hardcoded bearer access token and has the ability to download, upload, and execute files. The communication occurs via HTTPS over port 443.
Updated: 2021-07-20
View profile →
LoupeLoader
Technical ID: win.loupeloader
MALWARE
Malware family identifying win.loupeloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-11
View profile →
Loup
Technical ID: win.loup
MALWARE
Frank Boldewin describes Loup as a small cli-tool to cash out NCR devices (ATM).
Updated: 2020-08-25
View profile →
Lorenz
Technical ID: win.lorenz
MALWAREfinancialhigh
Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.
Updated: 2023-02-27
View profile →
L0rdix
Technical ID: win.lordix
MALWARE
L0rdix is a multipurpose .NET remote access tool (RAT) first discovered being sold on underground forums in November 2018. Out of the box, L0rdix supports eight commands, although custom commands can be defined and added. These include: Download and execute Update Open page (visible) Open page (invisible) Cmd Kill process Upload file HTTP Flood L0rdix can extract credentials from common web browsers and steal data from crypto wallets and a target's clipboard. Optionally, L0rdix can deploy a cryptominer (XMRig) to its bots.
Also known as: lordix
Updated: 2019-08-15
View profile →
Lookback
Technical ID: win.lookback
TA410
MALWARE
Malware family identifying win.lookback. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-20
View profile →
LooCipher
Technical ID: win.loocipher
MALWAREfinancialhigh
LooCipher is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank to the term “Cipher”) and to the popular mythological figure, Lucifer. Despite its evocative nickname, the functionalities of this malware are pretty straight forward, not very different from those belonging to many other ransomware families.
Updated: 2023-09-11
View profile →
looChiper
Technical ID: win.loochiper
MALWAREfinancialhigh
LooChiper is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank to the term “Cipher”) and to the popular mythological figure, Lucifer. Despite its evocative nickname, the functionalities of this malware are pretty straight forward, not very different from those belonging to many other ransomware families.
Updated: 2023-09-11
View profile →
LONGWATCH
Technical ID: win.longwatch
APT34
MALWARE
The primary function of LONGWATCH is a keylogger that outputs keystrokes to a log.txt file in the Windows temp folder.
Updated: 2021-06-29
View profile →
LOLSnif
Technical ID: win.lolsnif
MALWARE
Malware family identifying win.lolsnif. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-16
View profile →
Lokorrito
Technical ID: win.lokorrito
MALWAREfinancialhigh
According to ESET, this is a banking trojan that was active mainly in Mexico until the beginning of 2020, with builds for Brazil, Chile, and Colombia also having been identified.
Updated: 2022-01-05
View profile →
Loki Password Stealer (PWS)
Technical ID: win.lokipws
SWEEDThe Gorgon GroupCobalt
MALWARE
"Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMe Loki-Bot employs function hashing to obfuscate the libraries utilized. While not all functions are hashed, a vast majority of them are. Loki-Bot accepts a single argument/switch of ‘-u’ that simply delays execution (sleeps) for 10 seconds. This is used when Loki-Bot is upgrading itself. The Mutex generated is the result of MD5 hashing the Machine GUID and trimming to 24-characters. For example: “B7E1C2CC98066B250DDB2123“. Loki-Bot creates a hidden folder within the %APPDATA% directory whose name is supplied by the 8th thru 13th characters of the Mutex. For example: “%APPDATA%\ C98066\”. There can be four files within the hidden %APPDATA% directory at any given time: “.exe,” “.lck,” “.hdb” and “.kdb.” They will be named after characters 13 thru 18 of the Mutex. For example: “6B250D.” Below is the explanation of their purpose: FILE EXTENSION FILE DESCRIPTION .exe A copy of the malware that will execute every time the user account is logged into .lck A lock file created when either decrypting Windows Credentials or Keylogging to prevent resource conflicts .hdb A database of hashes for data that has already been exfiltrated to the C2 server .kdb A database of keylogger data that has yet to be sent to the C2 server If the user is privileged, Loki-Bot sets up persistence within the registry under HKEY_LOCAL_MACHINE. If not, it sets up persistence under HKEY_CURRENT_USER. The first packet transmitted by Loki-Bot contains application data. The second packet transmitted by Loki-Bot contains decrypted Windows credentials. The third packet transmitted by Loki-Bot is the malware requesting C2 commands from the C2 server. By default, Loki-Bot will send this request out every 10 minutes after the initial packet it sent. Communications to the C2 server from the compromised host contain information about the user and system including the username, hostname, domain, screen resolution, privilege level, system architecture, and Operating System. The first WORD of the HTTP Payload represents the Loki-Bot version. The second WORD of the HTTP Payload is the Payload Type. Below is the table of identified payload types: BYTE PAYLOAD TYPE 0x26 Stolen Cryptocurrency Wallet 0x27 Stolen Application Data 0x28 Get C2 Commands from C2 Server 0x29 Stolen File 0x2A POS (Point of Sale?) 0x2B Keylogger Data 0x2C Screenshot The 11th byte of the HTTP Payload begins the Binary ID. This might be useful in tracking campaigns or specific threat actors. This value value is typically “ckav.ru”. If you come across a Binary ID that is different from this, take note! Loki-Bot encrypts both the URL and the registry key used for persistence using Triple DES encryption. The Content-Key HTTP Header value is the result of hashing the HTTP Header values that precede it. This is likely used as a protection against researchers who wish to poke and prod at Loki-Bot’s C2 infrastructure. Loki-Bot can accept the following instructions from the C2 Server: BYTE INSTRUCTION DESCRIPTION 0x00 Download EXE & Execute 0x01 Download DLL & Load #1 0x02 Download DLL & Load #2 0x08 Delete HDB File 0x09 Start Keylogger 0x0A Mine & Steal Data 0x0E Exit Loki-Bot 0x0F Upgrade Loki-Bot 0x10 Change C2 Polling Frequency 0x11 Delete Executables & Exit Suricata Signatures RULE SID RULE NAME 2024311 ET TROJAN Loki Bot Cryptocurrency Wallet Exfiltration Detected 2024312 ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M1 2024313 ET TROJAN Loki Bot Request for C2 Commands Detected M1 2024314 ET TROJAN Loki Bot File Exfiltration Detected 2024315 ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M1 2024316 ET TROJAN Loki Bot Screenshot Exfiltration Detected 2024317 ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M2 2024318 ET TROJAN Loki Bot Request for C2 Commands Detected M2 2024319 ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M2
Also known as: Burkina • Loki • LokiBot • LokiPWS
Updated: 2025-10-15
View profile →
LokiLocker
Technical ID: win.lokilocker
MALWAREfinancialhigh
LokiLocker is a .Net ransomware, which was seen first in August 2021. This malware is protected with NETGuard (modified ConfuserEX) using the additional KoiVM virtualization plugin. The victims were observed ti be scattered around the world, with main concentation in Estern Europe and Asia (BlackBerry).
Updated: 2023-06-12
View profile →
LoJax
Technical ID: win.lojax
APT28
MALWARE
Malware family identifying win.lojax. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
Logtu
Technical ID: win.logtu
MALWARE
Malware family identifying win.logtu. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-11
View profile →
LogPOS
Technical ID: win.logpos
MALWARE
Malware family identifying win.logpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-19
View profile →
Logedrut
Technical ID: win.logedrut
MALWARE
Malware family identifying win.logedrut. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-13
View profile →
LODEINFO
Technical ID: win.lodeinfo
MirrorFace
MALWARE
Malware family identifying win.lodeinfo. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-19
View profile →
Loda
Technical ID: win.loda
MALWARE
Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims. Proofpoint first observed Loda in September of 2016 and it has since grown in popularity. The name Loda is derived from a directory to which the malware author chose to write keylogger logs. It should be noted that some antivirus products currently detect Loda as “Trojan.Nymeria”, although the connection is not well-documented.
Also known as: LodaRAT • Nymeria
Updated: 2023-12-04
View profile →
LockPOS
Technical ID: win.lock_pos
MALWARE
Malware family identifying win.lock_pos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-26
View profile →
Locky Loader
Technical ID: win.locky_loader
MALWARE
For the lack of a better name, this is a VBS-based loader that was used in beginning of 2018 to deliver win.locky.
Updated: 2018-01-11
View profile →
Locky (Decryptor)
Technical ID: win.locky_decryptor
MALWARE
Malware family identifying win.locky_decryptor. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-19
View profile →
Locky
Technical ID: win.locky
TA505
MALWAREfinancialhigh
Locky is a high profile ransomware family that first appeared in early 2016 and was observed being active until end of 2017. It encrypts files on the victim system and asks for ransom in order to have back original files. In its first version it added a .locky extension to the encrypted files, and in recent versions it added the .lukitus extension. The ransom amount is defined in BTC and depends on the actor.
Updated: 2024-11-25
View profile →
LockFile
Technical ID: win.lockfile
MALWAREfinancialhigh
A ransomware first observed in July 2021.
Updated: 2022-09-20
View profile →
LockerGoga
Technical ID: win.lockergoga
FIN6
MALWAREfinancialhigh
According to Trend Micro, LockerGoga is a ransomware that has been used in multiple attacks, most notably against Altran Technologies and Norsk Hydro. It encrypts a range of documents and source code files but certain versions had little to no whitelist that would protect import system files such as the Windows Boot Manager.
Updated: 2024-03-13
View profile →
LockBit
Technical ID: win.lockbit
MALWARE
Malware family identifying win.lockbit. Origin and technical characteristics tracked via Malpedia.
Also known as: ABCD Ransomware
Updated: 2026-02-03
View profile →
LOBSHOT
Technical ID: win.lobshot
MALWAREfinancialhigh
According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to access a victim's computer without being noticed. The hVNC component is effective in evading fraud detection systems. Also, LOBSHOT is being used to carry out financial crimes through the use of banking trojan and information-stealing functionalities.
Updated: 2023-07-21
View profile →
LiteHTTP
Technical ID: win.litehttp
MALWARE
According to AlienVault, LiteHTTP bot is a new HTTP bot programmed in C#. The bot has the ability to collect system information, download and execute programs, and update and kill other bots present on the system. The source is on GitHub: https://github.com/zettabithf/LiteHTTP
Updated: 2019-09-20
View profile →
LiteDuke
Technical ID: win.liteduke
APT29
MALWARE
According to CarbonBlack, LiteDuke is a third stage backdoor. It appears to use the same dropper as PolyglotDuke. Its payload makes use of an AES encrypted SQLite database to store its configuration. LiteDuke supports a large number of individual commands including host information retrieval, file upload and download, and the ability to execute other code. LiteDuke C2 servers appear to be compromised servers, and the malware communicates with them using normal HTTP requests. It attempts to use a realistic User-Agent string to blend in better with normal HTTP traffic. ESET have dubbed it LiteDuke because it uses SQLite to store information such as its configuration.
Updated: 2020-05-18
View profile →
Listrix
Technical ID: win.listrix
Energetic Bear
MALWARE
Malware family identifying win.listrix. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-21
View profile →
LIONTAIL
Technical ID: win.liontail
Scarred Manticore
MALWARE
Malware family identifying win.liontail. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
LinseningSvr
Technical ID: win.linseningsvr
MALWARE
Malware family identifying win.linseningsvr. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-27
View profile →
Limitail
Technical ID: win.limitail
MALWARE
Malware family identifying win.limitail. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →
← PreviousPage 156 / 269Next →