Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
Kutaki
Technical ID: win.kutaki
MALWARE
Cofense characterizes Kutaki as a data stealer that uses old-school techniques to detect sandboxes and debugging. Kutaki however works quite well against unhardened virtual machines and other analysis devices. By backdooring a legitimate application, it can fool unsophisticated detection methodologies.
MALWARE
Malware family identifying win.kurton. Origin and technical characteristics tracked via Malpedia.
Kuluoz
Technical ID: win.kuluoz
MALWARE
Malware family identifying win.kuluoz. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-23
View profile →Kuiper
Technical ID: win.kuiper
MALWARE
Malware family identifying win.kuiper. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Threatray, KugelBlitz is a shellcode loader discovered in late 2024. It loads shellcode into memory from a file specified via command line. If no file is specified, it defaults to run.bin.
Kuaibu
Technical ID: win.kuaibu8
MALWARE
Malware family identifying win.kuaibu8. Origin and technical characteristics tracked via Malpedia.
Also known as: Barys • Gofot • Kuaibpy
Updated: 2017-03-29
View profile →MALWARE
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning.
MALWARE
A keylogger used by Turla.
KryptoCibule
Technical ID: win.kryptocibule
MALWARE
Malware family identifying win.kryptocibule. Origin and technical characteristics tracked via Malpedia.
Kronos
Technical ID: win.kronos
MALWAREespionageadvanced
Kronos malware is a sophisticated banking Trojan that first emerged in 2014. It is designed to target financial institutions and steal sensitive banking information. The malware is primarily spread through phishing campaigns and exploit kits. Once installed on a victim's computer, Kronos can capture login credentials, credit card details, and other personal information by keylogging and form grabbing techniques. It can also bypass security measures such as two-factor authentication. Kronos employs advanced evasion techniques to avoid detection by antivirus software and actively updates itself to evade security patches. It has been known to target a wide range of banking systems and has affected numerous organizations worldwide. The malware continues to evolve, making it a significant threat to online banking security.
Also known as: Osiris
KRNRAT
Technical ID: win.krnrat
MALWARE
According to Trend Micro, this is a rootkit with capabilities of a full-featured backdoor with various capabilities, including process manipulation, file hiding, shellcode execution, traffic concealment, and C&C communication. It is controlled through a range of IOCTL codes.
KrDownloader
Technical ID: win.krdownloader
MALWARE
Malware family identifying win.krdownloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-12
View profile →KrBanker
Technical ID: win.krbanker
MALWAREfinancialhigh
ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking institutions. It was discovered in early 2014 and since then has adopted a variety of infection and credential stealing techniques.
Also known as: BlackMoon
KrakenKeylogger
Technical ID: win.krakenkeylogger
MALWARE
KrakenKeylogger is a .NET based Infostealer malware sold in Underground hacking forums
Kraken
Technical ID: win.kraken
MALWAREfinancialhigh
A ransomware that was active in 2018.
Krachulka
Technical ID: win.krachulka
MALWAREfinancialhigh
According to ESET, this malware family is a banking trojan and was active in Brazil until the middle of 2019. Its most noticeable characteristic was its usage of well-known cryptographic methods to encrypt strings, as opposed to the majority of Latin American banking trojans that mainly use custom encryption schemes.
KPOT Stealer
Technical ID: win.kpot_stealer
MALWARE
KPOT is an information-stealing Trojan horse that can steal information from infected computers. It is distributed through phishing emails and malicious websites. Once executed on a computer, KPOT can steal passwords, credit card numbers, and other personal information.
Also known as: Khalesi • Kpot
Kovter
Technical ID: win.kovter
MALWAREfinancialhigh
Kovter is a Police Ransomware
Feb 2012 - Police Ransomware
Aug 2013 - Became AD Fraud
Mar 2014 - Ransomware to AD Fraud malware
June 2014 - Distributed from sweet orange exploit kit
Dec 2014 - Run affiliated node
Apr 2015 - Spread via fiesta and nuclear pack
May 2015 - Kovter become fileless
2016 - Malvertising campaign on Chrome and Firefox
June 2016 - Change in persistence
July 2017 - Nemucod and Kovter was packed together
Jan 2018 - Cyclance report on Persistence
MALWARE
Malware family identifying win.korlia. Origin and technical characteristics tracked via Malpedia.
Also known as: Bisonal
KoobFace
Technical ID: win.koobface
MALWARE
Malware family identifying win.koobface. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Konni is a remote administration tool, observed in the wild since early 2014. The Konni malware family is potentially linked to APT37, a North-Korean cyber espionage group active since 2012. The group primary victims are South-Korean political organizations, as well as Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East.
MALWAREespionageadvanced
KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management, Creating a reverse shell, running WMI queries, retrieving information about the infected system.
Also known as: Splinter RAT
KokoKrypt
Technical ID: win.kokokrypt
MALWARE
Malware family identifying win.kokokrypt. Origin and technical characteristics tracked via Malpedia.
KoiVM
Technical ID: win.koivm
MALWARE
A loader written in .NET.
Koi Stealer
Technical ID: win.koistealer
MALWARE
Malware family identifying win.koistealer. Origin and technical characteristics tracked via Malpedia.
Koi Loader
Technical ID: win.koiloader
MALWARE
Malware family identifying win.koiloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
Koadic is an open-source post-exploitation framework for Windows, created by zerosum0x0 and available on GitHub. The framework is written in Python and can generate JScript and VBScript payloads which can be written to disk or mapped directly into memory. Its capabilities include remote desktop access, command execution, lateral movement via SMB, file transfer, credential theft using Mimikatz, port scanning, and system information collection. It can also collect specific system information and targeted files based on their name or extension.
Knight
Technical ID: win.knight
MALWAREfinancialhigh
According to Symantec, this is a ransomware written in Golang and obfuscated with Gobfuscate. The source code for Knight (originally known as Cyclops) was offered for sale on underground forums in February 2024 after Knight’s developers decided to shut down their operation.
Also known as: Cyclops
MALWARE
Malware family identifying win.klrd. Origin and technical characteristics tracked via Malpedia.
KLogEXE
Technical ID: win.klogexe
MALWARE
Malware family identifying win.klogexe. Origin and technical characteristics tracked via Malpedia.
KlingonRAT
Technical ID: win.klingon_rat
MALWARE
Malware family identifying win.klingon_rat. Origin and technical characteristics tracked via Malpedia.
KleptoParasite Stealer
Technical ID: win.kleptoparasite_stealer
MALWARE
KleptoParasite Stealer is advertised on Hackforums as a noob-friendly stealer. It is modular and comes with a IP retriever module, a Outlook stealer (32bit/64bit) and a Chrome/Firefox stealer (32bit/64bit). Earlier versions come bundled (loader plus modules), newer versions come with a loader (167k) that grabs the modules.
PDB-strings suggest a relationship to JogLog v6 and v7.
Also known as: Joglog • Parasite
MALWARE
Microsoft describes that threat actor ZINC is using Klackring as a malware dropped by ComeBacker, both being used to target security researchers.
kkRAT
Technical ID: win.kk_rat
MALWARE
According to Zscaler, a malware sharing similarities with GhostRAT and Big Bad Wolf. The RAT’s features include clipboard manipulation to replace cryptocurrency addresses and the deployment of remote monitoring tools (i.e. Sunlogin, GotoHTTP).
MALWARE
According to Threatray, KiwiStealer is a simple file stealer first discovered in late 2024. It starts by gathering the computer name and username. It also retrieves the current system time, which will be used later to check the last modification time of files on the machine. KiwiStealer searches through a predefined list of directories to gather files and only exfiltrates files that are smaller than 50MB and have been modified within the past year. It targets these extensions: z7, .txt, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .jpg, .zip, .rar, .apk, .neat, .err, .eln, .ppi, .er9, .azr, .pfx, .ovpn.
KIVARS
Technical ID: win.kivars
MALWARE
Malware family identifying win.kivars. Origin and technical characteristics tracked via Malpedia.
KINS
Technical ID: win.kins
MALWARE
Malware family identifying win.kins. Origin and technical characteristics tracked via Malpedia.
Also known as: Kasper Internet Non-Security • Maple
Kingminer
Technical ID: win.kingminer
MALWARE
According to Sophis, the botnet has been active since 2018, initially, the botmasters operated DDoS tools and backdoors, but later moved on to cryptocurrency miners. They use a DGA to automatically change the hosting
domains every week.
MALWARE
Malware family identifying win.kimsuky. Origin and technical characteristics tracked via Malpedia.