Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
KimJongRat
Technical ID: win.kimjongrat
MALWARE
Malware family identifying win.kimjongrat. Origin and technical characteristics tracked via Malpedia.
KilllSomeOne
Technical ID: win.killsomeone
MALWARE
Malware family identifying win.killsomeone. Origin and technical characteristics tracked via Malpedia.
MALWARE
KillDisk is a generic detection name used by ESET to refer to destructive malware with disk wiping capabilities, such as damaging boot sectors and overwriting then deleting (system) files, followed by a reboot to render the machine unusable. Although all KillDisk malware has similar functionality, as a generic detection, individual samples do not necessarily have strong code similarities or relationships. Such generic malware detections usually have many “sub-families”, distinguished by the detection suffix (e.g. KillDisk.NBO, KillDisk.NCV, and KillDisk.NCX). Sub-family variants that do have strong code similarities, are sometimes seen in separate cyberattacks and thus can help researchers make connections between them.
KillAV
Technical ID: win.killav
MALWARE
Malware family identifying win.killav. Origin and technical characteristics tracked via Malpedia.
Also known as: BURNTCIGAR
Kikothac
Technical ID: win.kikothac
MALWARE
Malware family identifying win.kikothac. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address. KHRAT provides the threat actors typical RAT features and access to the victim system, including keylogging, screenshot capabilities, remote shell access and so on.
Khonsari
Technical ID: win.khonsari
MALWAREfinancialhigh
A compact ransomware written in .NET and delivered as follow-up to Log4J exploitation, targeting Windows servers.
KGH_SPY
Technical ID: win.kgh_spy
MALWARE
Malware family identifying win.kgh_spy. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.keymarble. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Malware family identifying win.keylogger_apt3. Origin and technical characteristics tracked via Malpedia.
Keyhole
Technical ID: win.keyhole
MALWARE
According to Walmart Global Tech, Keyhole is a multi-functional VNC/Backconnect component used extensively by IcedID/Anubis. While the malware contains functionality that has been previously reported on as typical VNC and HDESK capabilities, a general lack of technical information appears to exist around some of the expanded functionality currently present.
MALWARE
Malware family identifying win.keyboy. Origin and technical characteristics tracked via Malpedia.
Also known as: TSSL
KeyBase
Technical ID: win.keybase
MALWARE
KeyBase is a .NET credential stealer and keylogger that first emerged in February 2015. It often incorporates Nirsoft tools such as MailPassView and WebBrowserPassView for additional credential grabbing.
Also known as: Kibex
MALWARE
Intezer found this family mid May 2020, which appears to be a merger of the family Ketrican and Okrum.
MALWAREespionageadvanced
Ketrican is a backdoor trojan used by APT 15.
MALWARE
Malware family identifying win.kerrdown. Origin and technical characteristics tracked via Malpedia.
Keona
Technical ID: win.keona
MALWARE
Malware family identifying win.keona. Origin and technical characteristics tracked via Malpedia.
Kematian Stealer
Technical ID: win.kematian
MALWARE
Stealer written in Python, available as open source on Github.
Kelihos
Technical ID: win.kelihos
MALWARE
Malware family identifying win.kelihos. Origin and technical characteristics tracked via Malpedia.
Kegotip
Technical ID: win.kegotip
MALWARE
Malware family identifying win.kegotip. Origin and technical characteristics tracked via Malpedia.
KDC Sponge
Technical ID: win.kdcsponge
MALWARE
Malware family identifying win.kdcsponge. Origin and technical characteristics tracked via Malpedia.
KazyLoader
Technical ID: win.kazyloader
MALWARE
According to Karsten Hahn, a straightforward loader that runs assemblies from images.
MALWARE
Malware family identifying win.kazuar. Origin and technical characteristics tracked via Malpedia.
Katz Stealer
Technical ID: win.katz_stealer
MALWARE
Malware family identifying win.katz_stealer. Origin and technical characteristics tracked via Malpedia.
Kasseika
Technical ID: win.kasseika
MALWAREfinancialhigh
Trend Micro describes this as a Ransomware with possible ties to BlackMatter.
KasperAgent
Technical ID: win.kasperagent
MALWARE
Malware family identifying win.kasperagent. Origin and technical characteristics tracked via Malpedia.
KarstoRAT
Technical ID: win.karsto_rat
MALWARE
Malware family identifying win.karsto_rat. Origin and technical characteristics tracked via Malpedia.
Karma
Technical ID: win.karma
MALWAREfinancialhigh
Ransomware.
MALWARE
Malware family identifying win.karkoff. Origin and technical characteristics tracked via Malpedia.
Also known as: CACTUSPIPE • MailDropper • OILYFACE
Karius
Technical ID: win.karius
MALWAREfinancialhigh
According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently implementing webinject attacks only.
It comes with an injector that loads an intermediate "proxy" component, which in turn loads the actual banker component.
Communication with the c2 are in json format and encrypted with RC4 with a hardcoded key.
In the initial version, observed in March 2018, the webinjects were hardcoded in the binary, while in subsequent versions, they were received by the c2.
Kardon Loader
Technical ID: win.kardonloader
MALWAREfinancialhigh
According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg. banking trojans/credential theft etc.This malware has been on sale by an actor under the username Yattaze, starting in late April. The actor offers the sale of the malware as a standalone build with charges for each additional rebuild, or the ability to set up a botshop in which case any customer can establish their own operation and further sell access to a new customer base.
MALWARE
Malware family identifying win.karagany. Origin and technical characteristics tracked via Malpedia.
Also known as: Karagny
MALWARE
Malware family identifying win.kapeka. Origin and technical characteristics tracked via Malpedia.
Also known as: ICYWELL • KNUCKLETOUCH • QUEUESEED • WRONGSENS
MALWARE
Kaolin RAT is a complex modular RAT, with Release_TMain_x64.dll as its internal DLL name.
The malware provides standard backdoor functionality, including manipulation and listing of files and processes, exchanging the configuration, collecting the victim’s system info, opening a TCP connection, and executing local commands and collecting their outputs.
Also, it is designed to execute additional DLL payloads in memory via specific exported functions:
- _DoMyFunc,
- _DoMyFunc2,
- _DoMyThread,
- _DoMyCommandWork.
Functionally, Kaolin RAT relies on an accompanying trojanized curl library to handle network and exfiltration operations, by importing functions such as:
- SendDataFromURL,
- ZipFolder,
- UnzipStr,
- curl wrappers.
For C&C communication, it employs AES encryption and attempts to evade network detection by randomly selecting words from a hardcoded custom dictionary to populate POST request parameters. The malware's name is derived from one of these dictionary words ("kaolin").
The Kaolin RAT has been observed in Lazarus campaigns as a late-stage payload — typically following loaders like RollFling, RollSling, and RollMid — and serves also as a delivery vector for the FudModule rootkit with a 0-day exploit.
Also known as: KaolinTea
KamiKakaBot
Technical ID: win.kami
MALWARE
A Telegram bot with browser stealing capabilities, written using the .NET framework.
Also known as: Kami
Kamasers
Technical ID: win.kamasers
MALWARE
Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to download files, receive commands, and execute files, allowing it to perform HTTP and DNS flooding attacks. The bot is also used to access sensitive files.
The bot has been seen to be communicating with third-party platforms such as Telegram, Discord, and GitHub, using these platforms as backup C2 servers.
MALWARE
Malware family identifying win.kagent. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.jupiter. Origin and technical characteristics tracked via Malpedia.
Also known as: EarlyRAT
MALWARE
According to FireEye, JUMPALL is a malware dropper that has been observed
dropping HIGHNOON/ZXSHELL/SOGU.