Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
MALWAREfinancialhigh
## Description
Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, It should give you a general knowledge about dotNET malwares and how it behaves.
---
## Main Features
- **.NET**
- Coded in Visual Basic .NET, Client required framework 2.0 or 4.0 dependency, And server is 4.0
- **Connection**
- Using pastebin.com as ip:port , Instead of noip.com DNS. And Also using multi-ports
- **Plugin**
- Using plugin system to decrease stub's size and lower the AV detection
- **Encryption**
- The communication between server & client is encrypted with AES
- **Spreading**
- Infecting all files and folders on USB drivers
- **Bypass**
- Low AV detection and undetected startup method
- **Lightweight**
- Payload size is about 25 KB
- **Anti Virtual Machines**
- Uninstall itself if the machine is virtual to avoid scanning or analyzing
- **Ransomware**
- Encrypting files on all HHD and USB with .Lime extension
- **XMR Miner**
- High performance Monero CPU miner with user idle\active optimizations
- **DDoS**
- Creating a powerful DDOS attack to make an online service unavailable
- **Crypto Stealer**
- Stealing Cryptocurrency sensitive data
- **Screen-Locker**
- Prevents user from accessing their Windows GUI
- **And more**
- On Connect Auto Task
- Force enable Windows RDP
- Persistence
- File manager
- Passowrds stealer
- Remote desktop
- Bitcoin grabber
- Downloader
- Keylogger
MALWARE
Malware family identifying win.limepad. Origin and technical characteristics tracked via Malpedia.
limeminer
Technical ID: win.limeminer
MALWARE
Malware family identifying win.limeminer. Origin and technical characteristics tracked via Malpedia.
limedownloader
Technical ID: win.limedownloader
MALWARE
Malware family identifying win.limedownloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
Lilith is a console-based ultra light-weight RAT developed in C++. It features a straight-forward set of commands that allows for near complete control of a machine.
Ligsterac
Technical ID: win.ligsterac
MALWARE
Malware family identifying win.ligsterac. Origin and technical characteristics tracked via Malpedia.
LIGHTWORK
Technical ID: win.lightwork
MALWARE
According to Mandiant, LIGHTWORK is a disruption tool written in C++ that implements the IEC-104 protocol to modify the state of RTUs over TCP. It crafts configurable IEC-104 ASDU messages, to change the state of RTU IOAs to ON or OFF. This sample works in tandem with PIEHOP, which sets up the execution.
LIGHTRAIL
Technical ID: win.lightrail
MALWARE
According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
Lightning Stealer
Technical ID: win.lightning_stealer
MALWARE
Lightning stealer can target 30+ Firefox and Chromium-based browsers and steal crypto wallets, Telegram data, Discord tokens, and Steam user’s data. Unlike other info stealers, Lightning Stealer stores all the stolen data in the JSON format for exfiltration.
MALWARE
Malware family identifying win.lightneuron. Origin and technical characteristics tracked via Malpedia.
Also known as: NETTRANS • XTRANS
MALWARE
LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan.
In Q2 2022 and Q1 2023, it was deployed in targeted attacks against an aerospace company in Spain and a technology company in India.
Besides the support for commands already present in BlindingCan, its most significant update is mimicked functionality of many native Windows commands:
• ipconfig
• net
• netsh advfirewall firewall
• netstat
• reg
• sc
• ping (for both IPv4 and IPv6 protocols)
• wmic process call create
• nslookup
• schstasks
• systeminfo
• arp
These native commands are often abused by the attackers after they have gotten a foothold in the target’s system. Lightless is able to execute them discreetly within the RAT itself, rather than being executed visibly in the system console. This provides stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools.
LightlessCan use RC6 for decryption of its configuration, and also for encryption and decryption of network traffic.
Also known as: SIDESHOW
LIGHTBUNNY
Technical ID: win.lightbunny
MALWARE
Malware family identifying win.lightbunny. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.liderc. Origin and technical characteristics tracked via Malpedia.
Also known as: LEMPO
LgoogLoader
Technical ID: win.lgoogloader
MALWARE
LgoogLoader is an installer that drops three files: a batch file, an AutoIt interpreter, and an AutoIt script. After downloading, it executes the batch file.
LetMeOut
Technical ID: win.letmeout
MALWARE
Malware family identifying win.letmeout. Origin and technical characteristics tracked via Malpedia.
Lethic
Technical ID: win.lethic
MALWARE
Lethic is a spambot dating back to 2008. It is known to be distributing low-level pharmaceutical spam.
Leslieloader
Technical ID: win.leslieloader
MALWARE
Leslieloader is a loader written in Golang, named after the observed AES decryption key referencing deceased actor, Leslie Cheung. The loader assists in the initial infection and deployment of the malicious payload, enabling execution on a system. The loader achieves its goal by decoding and decrypting a secondary payload binary, then injecting it into another process.
MALWARE
Malware family identifying win.leouncia. Origin and technical characteristics tracked via Malpedia.
Also known as: shoco
Lemon Duck
Technical ID: win.lemonduck
MALWARE
Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network. The malware runs its payload mainly in memory. Internal network spreading is performed by SMB RCE Vulnerability (CVE-2017-0144), or brute-force attacks.
Lechiket
Technical ID: win.lechiket
MALWARE
Malware family identifying win.lechiket. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.leash. Origin and technical characteristics tracked via Malpedia.
Leakthemall
Technical ID: win.leakthemall
MALWAREfinancialhigh
Ransomware.
LDR4
Technical ID: win.ldr4
MALWAREfinancialhigh
A further branch of the URSNIF collection of malware families. According to Mandiant, it no longer has focus on banking fraud but generic backdoor capabilities instead.
MALWARE
Malware family identifying win.lcpdot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.lazycat. Origin and technical characteristics tracked via Malpedia.
Laziok
Technical ID: win.laziok
MALWARE
Malware family identifying win.laziok. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.lazarus_killdisk. Origin and technical characteristics tracked via Malpedia.
Also known as: KillDisk.NBO
MALWARE
Malware family identifying win.lazarloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.lazardoor. Origin and technical characteristics tracked via Malpedia.
Laturo Stealer
Technical ID: win.laturo
MALWARE
Malware family identifying win.laturo. Origin and technical characteristics tracked via Malpedia.
Latrodectus
Technical ID: win.latrodectus
MALWARE
First discovered in October 2023, BLACKWIDOW is a backdoor written in C that communicates over HTTP using RC4 encrypted requests. The malware has the capability to execute discovery commands, query information about the victim's machine, update itself, as well as download and execute an EXE, DLL, or shellcode. The malware is believed to have been developed by LUNAR SPIDER, the creators of IcedID (aka BokBot) Malware.
Also known as: BLACKWIDOW • IceNova • Latrodectus • Lotus
LatentBot
Technical ID: win.latentbot
MALWAREfinancialhigh
FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless.
Using Dynamic Threat Intelligence, they have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which they named LATENTBOT – caught attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations.
Laplas (Reverseshell)
Technical ID: win.laplas_shell
MALWARE
According to Seqrite, this is a TLS-based reverse shell.
LaplasClipper
Technical ID: win.laplas
MALWARE
Clipboard stealer.
Lamdelin
Technical ID: win.lamdelin
MALWARE
Malware family identifying win.lamdelin. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Microsoft, this is a downloader used in a supply chain attack involving a malicious variant of an application developed by CyberLink. It is centered around a legitimate CyberLink application installer that has been modified to include malicious code that downloads, decrypts, and loads a second-stage payload. The file, which was signed using a valid certificate issued to CyberLink Corp., is hosted on legitimate update infrastructure owned by CyberLink and includes checks to limit the time window for execution and evade detection by security products.
Also known as: OfficeCertTea
MALWARE
Malware family identifying win.lambert. Origin and technical characteristics tracked via Malpedia.
Also known as: Plexor
LALALA Stealer
Technical ID: win.lalala_stealer
MALWARE
Malware family identifying win.lalala_stealer. Origin and technical characteristics tracked via Malpedia.
Ladon
Technical ID: win.ladon
MALWARE
According to its self-description, Ladon is a multi-threaded plug-in comprehensive scanning artifact for large-scale network penetration, including port scanning, service identification, network assets, password blasting, high-risk vulnerability detection and one click getshell. It supports batch a segment / b segment / C segment and cross network segment scanning, as well as URL, host and domain name list scanning.
MALWARE
Kwampirs is a family of malware which uses SMB to spread. It typically will not execute or deploy in environments in which there is no publicly available admin$ share. It is a fully featured backdoor which can download additional modules. Typical C2 traffic is over HTTP and includes "q=[ENCRYPTED DATA]" in the URI.