Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,744 entities
LimeRAT
Technical ID: win.limerat
APT-C-36
MALWAREfinancialhigh
## Description Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, It should give you a general knowledge about dotNET malwares and how it behaves. --- ## Main Features - **.NET** - Coded in Visual Basic .NET, Client required framework 2.0 or 4.0 dependency, And server is 4.0 - **Connection** - Using pastebin.com as ip:port , Instead of noip.com DNS. And Also using multi-ports - **Plugin** - Using plugin system to decrease stub's size and lower the AV detection - **Encryption** - The communication between server & client is encrypted with AES - **Spreading** - Infecting all files and folders on USB drivers - **Bypass** - Low AV detection and undetected startup method - **Lightweight** - Payload size is about 25 KB - **Anti Virtual Machines** - Uninstall itself if the machine is virtual to avoid scanning or analyzing - **Ransomware** - Encrypting files on all HHD and USB with .Lime extension - **XMR Miner** - High performance Monero CPU miner with user idle\active optimizations - **DDoS** - Creating a powerful DDOS attack to make an online service unavailable - **Crypto Stealer** - Stealing Cryptocurrency sensitive data - **Screen-Locker** - Prevents user from accessing their Windows GUI - **And more** - On Connect Auto Task - Force enable Windows RDP - Persistence - File manager - Passowrds stealer - Remote desktop - Bitcoin grabber - Downloader - Keylogger
Updated: 2025-08-29
View profile →
LimePad
Technical ID: win.limepad
Operation C-Major
MALWARE
Malware family identifying win.limepad. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-11-12
View profile →
limeminer
Technical ID: win.limeminer
MALWARE
Malware family identifying win.limeminer. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-31
View profile →
limedownloader
Technical ID: win.limedownloader
MALWARE
Malware family identifying win.limedownloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-31
View profile →
Lilith
Technical ID: win.lilith
Silent ChollimaTick
MALWARE
Lilith is a console-based ultra light-weight RAT developed in C++. It features a straight-forward set of commands that allows for near complete control of a machine.
Updated: 2025-04-25
View profile →
Ligsterac
Technical ID: win.ligsterac
MALWARE
Malware family identifying win.ligsterac. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-23
View profile →
LIGHTWORK
Technical ID: win.lightwork
MALWARE
According to Mandiant, LIGHTWORK is a disruption tool written in C++ that implements the IEC-104 protocol to modify the state of RTUs over TCP. It crafts configurable IEC-104 ASDU messages, to change the state of RTU IOAs to ON or OFF. This sample works in tandem with PIEHOP, which sets up the execution.
Updated: 2023-05-26
View profile →
LIGHTRAIL
Technical ID: win.lightrail
MALWARE
According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
Updated: 2024-04-29
View profile →
Lightning Stealer
Technical ID: win.lightning_stealer
MALWARE
Lightning stealer can target 30+ Firefox and Chromium-based browsers and steal crypto wallets, Telegram data, Discord tokens, and Steam user’s data. Unlike other info stealers, Lightning Stealer stores all the stolen data in the JSON format for exfiltration.
Updated: 2022-04-12
View profile →
LightNeuron
Technical ID: win.lightneuron
Turla
MALWARE
Malware family identifying win.lightneuron. Origin and technical characteristics tracked via Malpedia.
Also known as: NETTRANS • XTRANS
Updated: 2025-04-28
View profile →
LightlessCan
Technical ID: win.lightlesscan
Lazarus Group
MALWARE
LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan. In Q2 2022 and Q1 2023, it was deployed in targeted attacks against an aerospace company in Spain and a technology company in India. Besides the support for commands already present in BlindingCan, its most significant update is mimicked functionality of many native Windows commands: • ipconfig • net • netsh advfirewall firewall • netstat • reg • sc • ping (for both IPv4 and IPv6 protocols) • wmic process call create • nslookup • schstasks • systeminfo • arp These native commands are often abused by the attackers after they have gotten a foothold in the target’s system. Lightless is able to execute them discreetly within the RAT itself, rather than being executed visibly in the system console. This provides stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools. LightlessCan use RC6 for decryption of its configuration, and also for encryption and decryption of network traffic.
Also known as: SIDESHOW
Updated: 2025-11-05
View profile →
LIGHTBUNNY
Technical ID: win.lightbunny
MALWARE
Malware family identifying win.lightbunny. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-25
View profile →
Liderc
Technical ID: win.liderc
Tortoiseshell
MALWARE
Malware family identifying win.liderc. Origin and technical characteristics tracked via Malpedia.
Also known as: LEMPO
Updated: 2022-04-05
View profile →
LgoogLoader
Technical ID: win.lgoogloader
MALWARE
LgoogLoader is an installer that drops three files: a batch file, an AutoIt interpreter, and an AutoIt script. After downloading, it executes the batch file.
Updated: 2023-10-11
View profile →
LetMeOut
Technical ID: win.letmeout
MALWARE
Malware family identifying win.letmeout. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-28
View profile →
Lethic
Technical ID: win.lethic
MALWARE
Lethic is a spambot dating back to 2008. It is known to be distributing low-level pharmaceutical spam.
Updated: 2025-03-21
View profile →
Leslieloader
Technical ID: win.leslieloader
MALWARE
Leslieloader is a loader written in Golang, named after the observed AES decryption key referencing deceased actor, Leslie Cheung. The loader assists in the initial infection and deployment of the malicious payload, enabling execution on a system. The loader achieves its goal by decoding and decrypting a secondary payload binary, then injecting it into another process.
Updated: 2025-10-15
View profile →
Leouncia
Technical ID: win.leouncia
APT5
MALWARE
Malware family identifying win.leouncia. Origin and technical characteristics tracked via Malpedia.
Also known as: shoco
Updated: 2021-11-02
View profile →
Lemon Duck
Technical ID: win.lemonduck
MALWARE
Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network. The malware runs its payload mainly in memory. Internal network spreading is performed by SMB RCE Vulnerability (CVE-2017-0144), or brute-force attacks.
Updated: 2022-04-24
View profile →
Lechiket
Technical ID: win.lechiket
MALWARE
Malware family identifying win.lechiket. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-29
View profile →
Leash
Technical ID: win.leash
Magic Hound
MALWARE
Malware family identifying win.leash. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-12-15
View profile →
Leakthemall
Technical ID: win.leakthemall
MALWAREfinancialhigh
Ransomware.
Updated: 2020-09-15
View profile →
LDR4
Technical ID: win.ldr4
MALWAREfinancialhigh
A further branch of the URSNIF collection of malware families. According to Mandiant, it no longer has focus on banking fraud but generic backdoor capabilities instead.
Updated: 2023-01-13
View profile →
LCPDot
Technical ID: win.lcpdot
Lazarus Group
MALWARE
Malware family identifying win.lcpdot. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-03
View profile →
LazyCat
Technical ID: win.lazycat
Leviathan
MALWARE
Malware family identifying win.lazycat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-09-25
View profile →
Laziok
Technical ID: win.laziok
MALWARE
Malware family identifying win.laziok. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-03-01
View profile →
KillDisk (Lazarus)
Technical ID: win.lazarus_killdisk
Lazarus Group
MALWARE
Malware family identifying win.lazarus_killdisk. Origin and technical characteristics tracked via Malpedia.
Also known as: KillDisk.NBO
Updated: 2023-08-31
View profile →
LazarLoader
Technical ID: win.lazarloader
Lazarus Group
MALWARE
Malware family identifying win.lazarloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-29
View profile →
LazarDoor
Technical ID: win.lazardoor
Lazarus Group
MALWARE
Malware family identifying win.lazardoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-27
View profile →
Laturo Stealer
Technical ID: win.laturo
MALWARE
Malware family identifying win.laturo. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-31
View profile →
Latrodectus
Technical ID: win.latrodectus
MALWARE
First discovered in October 2023, BLACKWIDOW is a backdoor written in C that communicates over HTTP using RC4 encrypted requests. The malware has the capability to execute discovery commands, query information about the victim's machine, update itself, as well as download and execute an EXE, DLL, or shellcode. The malware is believed to have been developed by LUNAR SPIDER, the creators of IcedID (aka BokBot) Malware.
Also known as: BLACKWIDOW • IceNova • Latrodectus • Lotus
Updated: 2026-01-14
View profile →
LatentBot
Technical ID: win.latentbot
MALWAREfinancialhigh
FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless. Using Dynamic Threat Intelligence, they have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which they named LATENTBOT – caught attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations.
Updated: 2022-06-09
View profile →
Laplas (Reverseshell)
Technical ID: win.laplas_shell
MALWARE
According to Seqrite, this is a TLS-based reverse shell.
Updated: 2025-11-13
View profile →
LaplasClipper
Technical ID: win.laplas
MALWARE
Clipboard stealer.
Updated: 2023-07-27
View profile →
Lamdelin
Technical ID: win.lamdelin
MALWARE
Malware family identifying win.lamdelin. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-12
View profile →
LambLoad
Technical ID: win.lambload
Lazarus Group
MALWARE
According to Microsoft, this is a downloader used in a supply chain attack involving a malicious variant of an application developed by CyberLink. It is centered around a legitimate CyberLink application installer that has been modified to include malicious code that downloads, decrypts, and loads a second-stage payload. The file, which was signed using a valid certificate issued to CyberLink Corp., is hosted on legitimate update infrastructure owned by CyberLink and includes checks to limit the time window for execution and evade detection by security products.
Also known as: OfficeCertTea
Updated: 2025-09-15
View profile →
Lambert
Technical ID: win.lambert
Longhorn
MALWARE
Malware family identifying win.lambert. Origin and technical characteristics tracked via Malpedia.
Also known as: Plexor
Updated: 2022-05-04
View profile →
LALALA Stealer
Technical ID: win.lalala_stealer
MALWARE
Malware family identifying win.lalala_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-30
View profile →
Ladon
Technical ID: win.ladon
MALWARE
According to its self-description, Ladon is a multi-threaded plug-in comprehensive scanning artifact for large-scale network penetration, including port scanning, service identification, network assets, password blasting, high-risk vulnerability detection and one click getshell. It supports batch a segment / b segment / C segment and cross network segment scanning, as well as URL, host and domain name list scanning.
Updated: 2025-01-15
View profile →
Kwampirs
Technical ID: win.kwampirs
Orangeworm
MALWARE
Kwampirs is a family of malware which uses SMB to spread. It typically will not execute or deploy in environments in which there is no publicly available admin$ share. It is a fully featured backdoor which can download additional modules. Typical C2 traffic is over HTTP and includes "q=[ENCRYPTED DATA]" in the URI.
Updated: 2022-03-15
View profile →
← PreviousPage 157 / 269Next →