Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
JuicyPotato
Technical ID: win.juicy_potato
MALWARE
As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM".
MALWARE
Malware family identifying win.jssloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
JSOutProx is a sophisticated attack framework built using both Javascript and .NET. It uses the .NET (de)serialization feature to interact with a Javascript file which is the core module running on a victim machine. Once the malware is run on the victim, the framework can load several plugins performing additional malicious activities on the target.
MALWARE
Malware family identifying win.jripbot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.jqjsnicker. Origin and technical characteristics tracked via Malpedia.
Jolob
Technical ID: win.jolob
MALWARE
Malware family identifying win.jolob. Origin and technical characteristics tracked via Malpedia.
Joao
Technical ID: win.joao
MALWARE
Malware family identifying win.joao. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.joanap. Origin and technical characteristics tracked via Malpedia.
JLORAT
Technical ID: win.jlorat
MALWARE
Malware family identifying win.jlorat. Origin and technical characteristics tracked via Malpedia.
JinxLoader
Technical ID: win.jinxloader
MALWARE
Malware family identifying win.jinxloader. Origin and technical characteristics tracked via Malpedia.
Jimmy
Technical ID: win.jimmy
MALWARE
Malware family identifying win.jimmy. Origin and technical characteristics tracked via Malpedia.
Jigsaw
Technical ID: win.jigsaw
MALWAREfinancialhigh
According to PCrisk, Jigsaw is ransomware that uses the AES algorithm to encrypt various files stored on computers. Targeted files include .jpg, .docx, .mp3, .mp4, and many others.
JhoneRAT
Technical ID: win.jhone_rat
MALWARE
Cisco Talos identified JhoneRAT in January 2020. The RAT is delivered through cloud services (Google Drive) and also submits stolen data to them (Google Drive, Twitter, ImgBB, GoogleForms). The actors using JhoneRAT target Saudi Arabia, Iraq, Egypt, Libya, Algeria, Morocco, Tunisia, Oman, Yemen, Syria, UAE, Kuwait, Bahrain and Lebanon.
MALWARE
JessieConTea is a remote access trojan that uses HTTP(S) for communication. It supports around 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration (both plain and zipped), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 32-bit integers, starting with the value 0x60D49D97.
The malware was delivered in-the-wild via trojanized applications like DeFi Wallet or Citrix Workspace.
JessieConTea generates POST parameters with a specific parameter name, jsessid, from which the initial part of its name is derived. Also, it contains a specific RTTI symbol ".?AVCHttpConn@@", which inspired the second part of the name. It uses RC4 for C&C traffic encryption.
MALWARE
Malware family identifying win.jelus_rat. Origin and technical characteristics tracked via Malpedia.
JCry
Technical ID: win.jcry
MALWAREfinancialhigh
Ransomware written in Go.
MALWARE
Malware family identifying win.jasus. Origin and technical characteristics tracked via Malpedia.
MALWARE
Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails and accounts information. Distributed in a ZIP container the interface is quite intuitive: the Microsoft exchange address and its version shall be provided. Three brute-force methods could be selected: EWS (Exchange Web Service), OAB (Offline Address Book) or both (All). Username and password list can be selected and threads number should be provided in order to optimize the attack balance.
Janeleiro
Technical ID: win.janeleiro
MALWARE
Malware family identifying win.janeleiro. Origin and technical characteristics tracked via Malpedia.
JanelaRAT
Technical ID: win.janela_rat
MALWAREespionageadvanced
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. Its focus is set on harvesting LATAM financial data and its method of extracting window titles for transmission underscores its targeted and stealthy nature. With an adaptive approach utilizing dynamic socket configuration and exploiting DLL side-loading from trusted sources, JanelaRAT poses a significant threat.
MALWARE
Malware family identifying win.jaku. Origin and technical characteristics tracked via Malpedia.
Also known as: C3PRO-RACOON • EQUINOX • KCNA Infostealer • Reconcyc
Jager Decryptor
Technical ID: win.jager_decryptor
MALWARE
Malware family identifying win.jager_decryptor. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →Jaff
Technical ID: win.jaff
MALWARE
Malware family identifying win.jaff. Origin and technical characteristics tracked via Malpedia.
JackPOS
Technical ID: win.jackpos
MALWARE
Malware family identifying win.jackpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →Jackal
Technical ID: win.jackal
MALWAREespionageadvanced
According to Kaspersky Labs, this malware tool set has been used by APT group GoldenJackal, which has been observed since 2019 and which usually targets government and diplomatic entities in the Middle East and South Asia with espionage. It consists of multiple components and is written in .NET.
IXWare
Technical ID: win.ixware
MALWARE
Malware family identifying win.ixware. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.isspace. Origin and technical characteristics tracked via Malpedia.
Also known as: NfLog RAT
ISR Stealer
Technical ID: win.isr_stealer
MALWARE
ISR Stealer is a modified version of the Hackhound Stealer. It is written in VB and often comes in a .NET-wrapper.
ISR Stealer makes use of two Nirsoft tools: Mail PassView and WebBrowserPassView.
Incredibly, it uses an hard-coded user agent string: HardCore Software For : Public
IsraBye
Technical ID: win.israbye
MALWARE
Malware family identifying win.israbye. Origin and technical characteristics tracked via Malpedia.
iSpy Keylogger
Technical ID: win.ispy_keylogger
MALWARE
Malware family identifying win.ispy_keylogger. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ismdoor. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ismagent. Origin and technical characteristics tracked via Malpedia.
MALWARE
2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)
In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest.
The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version.
There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information.
ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled.
In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim.
See win.gozi for additional historical information.
Also known as: Gozi ISFB • IAP • Pandemyia
IsaacWiper
Technical ID: win.isaacwiper
MALWARE
According to Recorded Future, IsaacWiper is a destructive malware that overwrites all physical disks and logical volumes on a victim’s machine.
Also known as: LASAINRAW
IronZero
Technical ID: win.ironzero
MALWARE
Malware family identifying win.ironzero. Origin and technical characteristics tracked via Malpedia.
IronWind
Technical ID: win.ironwind
MALWARE
Malware family identifying win.ironwind. Origin and technical characteristics tracked via Malpedia.
IronNetInjector
Technical ID: win.ironnetinjector
MALWARE
According to Mitre, IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.
MALWARE
IRONHALO is a downloader that uses the HTTP protocol to retrieve a Base64 encoded payload from a hard-coded command-and-control (CnC) server and uniform resource locator (URL) path.
The encoded payload is written to a temporary file, decoded and executed in a hidden window. The encoded and decoded payloads are written to files named igfxHK[%rand%].dat and igfxHK[%rand%].exe respectively, where [%rand%] is a 4-byte hexadecimal number based on the current timestamp. It persists by copying itself to the current user’s Startup folder.
Ironcat
Technical ID: win.ironcat
MALWARE
Malware family identifying win.ironcat. Origin and technical characteristics tracked via Malpedia.