Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,744 entities
KimJongRat
Technical ID: win.kimjongrat
MALWARE
Malware family identifying win.kimjongrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-20
View profile →
KilllSomeOne
Technical ID: win.killsomeone
MALWARE
Malware family identifying win.killsomeone. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-11
View profile →
KillDisk
Technical ID: win.killdisk
SandwormTeleBots
MALWARE
KillDisk is a generic detection name used by ESET to refer to destructive malware with disk wiping capabilities, such as damaging boot sectors and overwriting then deleting (system) files, followed by a reboot to render the machine unusable. Although all KillDisk malware has similar functionality, as a generic detection, individual samples do not necessarily have strong code similarities or relationships. Such generic malware detections usually have many “sub-families”, distinguished by the detection suffix (e.g. KillDisk.NBO, KillDisk.NCV, and KillDisk.NCX). Sub-family variants that do have strong code similarities, are sometimes seen in separate cyberattacks and thus can help researchers make connections between them.
Updated: 2025-02-03
View profile →
KillAV
Technical ID: win.killav
MALWARE
Malware family identifying win.killav. Origin and technical characteristics tracked via Malpedia.
Also known as: BURNTCIGAR
Updated: 2023-11-17
View profile →
Kikothac
Technical ID: win.kikothac
MALWARE
Malware family identifying win.kikothac. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-06
View profile →
KHRAT
Technical ID: win.khrat
DragonOK
MALWARE
According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address. KHRAT provides the threat actors typical RAT features and access to the victim system, including keylogging, screenshot capabilities, remote shell access and so on.
Updated: 2022-11-15
View profile →
Khonsari
Technical ID: win.khonsari
MALWAREfinancialhigh
A compact ransomware written in .NET and delivered as follow-up to Log4J exploitation, targeting Windows servers.
Updated: 2022-07-25
View profile →
KGH_SPY
Technical ID: win.kgh_spy
MALWARE
Malware family identifying win.kgh_spy. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-20
View profile →
KEYMARBLE
Technical ID: win.keymarble
Lazarus Group
MALWARE
Malware family identifying win.keymarble. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-29
View profile →
APT3 Keylogger
Technical ID: win.keylogger_apt3
UPS
MALWAREespionageadvanced
Malware family identifying win.keylogger_apt3. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-05-15
View profile →
Keyhole
Technical ID: win.keyhole
MALWARE
According to Walmart Global Tech, Keyhole is a multi-functional VNC/Backconnect component used extensively by IcedID/Anubis. While the malware contains functionality that has been previously reported on as typical VNC and HDESK capabilities, a general lack of technical information appears to exist around some of the expanded functionality currently present.
Updated: 2025-12-11
View profile →
KeyBoy
Technical ID: win.keyboy
Pirate Panda
MALWARE
Malware family identifying win.keyboy. Origin and technical characteristics tracked via Malpedia.
Also known as: TSSL
Updated: 2020-06-18
View profile →
KeyBase
Technical ID: win.keybase
MALWARE
KeyBase is a .NET credential stealer and keylogger that first emerged in February 2015. It often incorporates Nirsoft tools such as MailPassView and WebBrowserPassView for additional credential grabbing.
Also known as: Kibex
Updated: 2019-02-08
View profile →
Ketrum
Technical ID: win.ketrum
Mirage
MALWARE
Intezer found this family mid May 2020, which appears to be a merger of the family Ketrican and Okrum.
Updated: 2020-08-12
View profile →
Ketrican
Technical ID: win.ketrican
Mirage
MALWAREespionageadvanced
Ketrican is a backdoor trojan used by APT 15.
Updated: 2021-02-25
View profile →
KerrDown
Technical ID: win.kerrdown
APT32
MALWARE
Malware family identifying win.kerrdown. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-25
View profile →
Keona
Technical ID: win.keona
MALWARE
Malware family identifying win.keona. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-01
View profile →
Kematian Stealer
Technical ID: win.kematian
MALWARE
Stealer written in Python, available as open source on Github.
Updated: 2025-04-11
View profile →
Kelihos
Technical ID: win.kelihos
MALWARE
Malware family identifying win.kelihos. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-02
View profile →
KEKW
Technical ID: win.kekw
MALWAREfinancialhigh
Ransomware.
Also known as: KEKW-Locker
Updated: 2020-03-28
View profile →
Kegotip
Technical ID: win.kegotip
MALWARE
Malware family identifying win.kegotip. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
KDC Sponge
Technical ID: win.kdcsponge
MALWARE
Malware family identifying win.kdcsponge. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-07
View profile →
KazyLoader
Technical ID: win.kazyloader
MALWARE
According to Karsten Hahn, a straightforward loader that runs assemblies from images.
Updated: 2022-03-08
View profile →
Kazuar
Technical ID: win.kazuar
Turla
MALWARE
Malware family identifying win.kazuar. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-19
View profile →
Katz Stealer
Technical ID: win.katz_stealer
MALWARE
Malware family identifying win.katz_stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-12-30
View profile →
Kasseika
Technical ID: win.kasseika
MALWAREfinancialhigh
Trend Micro describes this as a Ransomware with possible ties to BlackMatter.
Updated: 2024-02-02
View profile →
KasperAgent
Technical ID: win.kasperagent
MALWARE
Malware family identifying win.kasperagent. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-07-11
View profile →
KarstoRAT
Technical ID: win.karsto_rat
MALWARE
Malware family identifying win.karsto_rat. Origin and technical characteristics tracked via Malpedia.
Karma
Technical ID: win.karma
MALWAREfinancialhigh
Ransomware.
Updated: 2022-04-24
View profile →
Karkoff
Technical ID: win.karkoff
DNSpionageOilRig
MALWARE
Malware family identifying win.karkoff. Origin and technical characteristics tracked via Malpedia.
Also known as: CACTUSPIPE • MailDropper • OILYFACE
Updated: 2023-02-06
View profile →
Karius
Technical ID: win.karius
MALWAREfinancialhigh
According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently implementing webinject attacks only. It comes with an injector that loads an intermediate "proxy" component, which in turn loads the actual banker component. Communication with the c2 are in json format and encrypted with RC4 with a hardcoded key. In the initial version, observed in March 2018, the webinjects were hardcoded in the binary, while in subsequent versions, they were received by the c2.
Updated: 2022-08-28
View profile →
Kardon Loader
Technical ID: win.kardonloader
MALWAREfinancialhigh
According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg. banking trojans/credential theft etc.This malware has been on sale by an actor under the username Yattaze, starting in late April. The actor offers the sale of the malware as a standalone build with charges for each additional rebuild, or the ability to set up a botshop in which case any customer can establish their own operation and further sell access to a new customer base.
Updated: 2018-06-21
View profile →
Karagany
Technical ID: win.karagany
Energetic Bear
MALWARE
Malware family identifying win.karagany. Origin and technical characteristics tracked via Malpedia.
Also known as: Karagny
Updated: 2021-10-26
View profile →
Kapeka
Technical ID: win.kapeka
Sandworm
MALWARE
Malware family identifying win.kapeka. Origin and technical characteristics tracked via Malpedia.
Also known as: ICYWELL • KNUCKLETOUCH • QUEUESEED • WRONGSENS
Updated: 2024-09-13
View profile →
Kaolin RAT
Technical ID: win.kaolin_rat
Lazarus Group
MALWARE
Kaolin RAT is a complex modular RAT, with Release_TMain_x64.dll as its internal DLL name. The malware provides standard backdoor functionality, including manipulation and listing of files and processes, exchanging the configuration, collecting the victim’s system info, opening a TCP connection, and executing local commands and collecting their outputs. Also, it is designed to execute additional DLL payloads in memory via specific exported functions: - _DoMyFunc, - _DoMyFunc2, - _DoMyThread, - _DoMyCommandWork. Functionally, Kaolin RAT relies on an accompanying trojanized curl library to handle network and exfiltration operations, by importing functions such as: - SendDataFromURL, - ZipFolder, - UnzipStr, - curl wrappers. For C&C communication, it employs AES encryption and attempts to evade network detection by randomly selecting words from a hardcoded custom dictionary to populate POST request parameters. The malware's name is derived from one of these dictionary words ("kaolin"). The Kaolin RAT has been observed in Lazarus campaigns as a late-stage payload — typically following loaders like RollFling, RollSling, and RollMid — and serves also as a delivery vector for the FudModule rootkit with a 0-day exploit.
Also known as: KaolinTea
Updated: 2025-11-21
View profile →
KamiKakaBot
Technical ID: win.kami
MALWARE
A Telegram bot with browser stealing capabilities, written using the .NET framework.
Also known as: Kami
Updated: 2025-02-13
View profile →
Kamasers
Technical ID: win.kamasers
MALWARE
Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to download files, receive commands, and execute files, allowing it to perform HTTP and DNS flooding attacks. The bot is also used to access sensitive files. The bot has been seen to be communicating with third-party platforms such as Telegram, Discord, and GitHub, using these platforms as backup C2 servers.
Updated: 2025-10-31
View profile →
KAgent
Technical ID: win.kagent
Cleaver
MALWARE
Malware family identifying win.kagent. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
Jupiter
Technical ID: win.jupiter
Silent Chollima
MALWARE
Malware family identifying win.jupiter. Origin and technical characteristics tracked via Malpedia.
Also known as: EarlyRAT
Updated: 2023-09-01
View profile →
JUMPALL
Technical ID: win.jumpall
APT41
MALWARE
According to FireEye, JUMPALL is a malware dropper that has been observed dropping HIGHNOON/ZXSHELL/SOGU.
Updated: 2019-08-13
View profile →
← PreviousPage 159 / 269Next →