Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,744 entities
JuicyPotato
Technical ID: win.juicy_potato
MALWARE
As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM".
Updated: 2025-06-24
View profile →
JSSLoader
Technical ID: win.jssloader
Anunak
MALWARE
Malware family identifying win.jssloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-09-13
View profile →
JSOutProx
Technical ID: win.jsoutprox
SOLAR SPIDER
MALWARE
JSOutProx is a sophisticated attack framework built using both Javascript and .NET. It uses the .NET (de)serialization feature to interact with a Javascript file which is the core module running on a victim machine. Once the malware is run on the victim, the framework can load several plugins performing additional malicious activities on the target.
Updated: 2024-04-08
View profile →
JripBot
Technical ID: win.jripbot
WildNeutron
MALWARE
Malware family identifying win.jripbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-13
View profile →
JQJSNICKER
Technical ID: win.jqjsnicker
CIA
MALWARE
Malware family identifying win.jqjsnicker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-03-28
View profile →
Jolob
Technical ID: win.jolob
MALWARE
Malware family identifying win.jolob. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-05-03
View profile →
Joao
Technical ID: win.joao
MALWARE
Malware family identifying win.joao. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-23
View profile →
Joanap
Technical ID: win.joanap
Lazarus Group
MALWARE
Malware family identifying win.joanap. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-08-18
View profile →
JLORAT
Technical ID: win.jlorat
MALWARE
Malware family identifying win.jlorat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-26
View profile →
JinxLoader
Technical ID: win.jinxloader
MALWARE
Malware family identifying win.jinxloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-01-31
View profile →
Jimmy
Technical ID: win.jimmy
MALWARE
Malware family identifying win.jimmy. Origin and technical characteristics tracked via Malpedia.
Jigsaw
Technical ID: win.jigsaw
MALWAREfinancialhigh
According to PCrisk, Jigsaw is ransomware that uses the AES algorithm to encrypt various files stored on computers. Targeted files include .jpg, .docx, .mp3, .mp4, and many others.
Updated: 2023-11-22
View profile →
JhoneRAT
Technical ID: win.jhone_rat
MALWARE
Cisco Talos identified JhoneRAT in January 2020. The RAT is delivered through cloud services (Google Drive) and also submits stolen data to them (Google Drive, Twitter, ImgBB, GoogleForms). The actors using JhoneRAT target Saudi Arabia, Iraq, Egypt, Libya, Algeria, Morocco, Tunisia, Oman, Yemen, Syria, UAE, Kuwait, Bahrain and Lebanon.
Updated: 2022-02-09
View profile →
JessieConTea
Technical ID: win.jessiecontea
Lazarus Group
MALWARE
JessieConTea is a remote access trojan that uses HTTP(S) for communication. It supports around 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration (both plain and zipped), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 32-bit integers, starting with the value 0x60D49D97. The malware was delivered in-the-wild via trojanized applications like DeFi Wallet or Citrix Workspace. JessieConTea generates POST parameters with a specific parameter name, jsessid, from which the initial part of its name is derived. Also, it contains a specific RTTI symbol ".?AVCHttpConn@@", which inspired the second part of the name. It uses RC4 for C&C traffic encryption.
Updated: 2023-10-20
View profile →
Jeno
Technical ID: win.jeno
MALWAREfinancialhigh
Ransomware.
Also known as: Valeria • Jest
Updated: 2020-04-20
View profile →
JelusRAT
Technical ID: win.jelus_rat
Silent Chollima
MALWARE
Malware family identifying win.jelus_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-27
View profile →
JCry
Technical ID: win.jcry
MALWAREfinancialhigh
Ransomware written in Go.
Updated: 2019-03-06
View profile →
Jasus
Technical ID: win.jasus
Cleaver
MALWARE
Malware family identifying win.jasus. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
jason
Technical ID: win.jason
OilRig
MALWARE
Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails and accounts information. Distributed in a ZIP container the interface is quite intuitive: the Microsoft exchange address and its version shall be provided. Three brute-force methods could be selected: EWS (Exchange Web Service), OAB (Offline Address Book) or both (All). Username and password list can be selected and threads number should be provided in order to optimize the attack balance.
Updated: 2020-05-23
View profile →
Janeleiro
Technical ID: win.janeleiro
MALWARE
Malware family identifying win.janeleiro. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-06-16
View profile →
JanelaRAT
Technical ID: win.janela_rat
MALWAREespionageadvanced
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. Its focus is set on harvesting LATAM financial data and its method of extracting window titles for transmission underscores its targeted and stealthy nature. With an adaptive approach utilizing dynamic socket configuration and exploiting DLL side-loading from trusted sources, JanelaRAT poses a significant threat.
Updated: 2025-07-07
View profile →
Jaku
Technical ID: win.jaku
DarkHotel
MALWARE
Malware family identifying win.jaku. Origin and technical characteristics tracked via Malpedia.
Also known as: C3PRO-RACOON • EQUINOX • KCNA Infostealer • Reconcyc
Updated: 2022-06-09
View profile →
Jager Decryptor
Technical ID: win.jager_decryptor
MALWARE
Malware family identifying win.jager_decryptor. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →
Jaff
Technical ID: win.jaff
MALWARE
Malware family identifying win.jaff. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-02-21
View profile →
JackPOS
Technical ID: win.jackpos
MALWARE
Malware family identifying win.jackpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
Jackal
Technical ID: win.jackal
MALWAREespionageadvanced
According to Kaspersky Labs, this malware tool set has been used by APT group GoldenJackal, which has been observed since 2019 and which usually targets government and diplomatic entities in the Middle East and South Asia with espionage. It consists of multiple components and is written in .NET.
Updated: 2023-05-23
View profile →
IXWare
Technical ID: win.ixware
MALWARE
Malware family identifying win.ixware. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-19
View profile →
IsSpace
Technical ID: win.isspace
DragonOKSamurai Panda
MALWARE
Malware family identifying win.isspace. Origin and technical characteristics tracked via Malpedia.
Also known as: NfLog RAT
Updated: 2022-07-29
View profile →
ISR Stealer
Technical ID: win.isr_stealer
MALWARE
ISR Stealer is a modified version of the Hackhound Stealer. It is written in VB and often comes in a .NET-wrapper. ISR Stealer makes use of two Nirsoft tools: Mail PassView and WebBrowserPassView. Incredibly, it uses an hard-coded user agent string: HardCore Software For : Public
Updated: 2017-07-18
View profile →
IsraBye
Technical ID: win.israbye
MALWARE
Malware family identifying win.israbye. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-19
View profile →
iSpy Keylogger
Technical ID: win.ispy_keylogger
MALWARE
Malware family identifying win.ispy_keylogger. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-23
View profile →
ISMDoor
Technical ID: win.ismdoor
Greenbug
MALWARE
Malware family identifying win.ismdoor. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
ISMAgent
Technical ID: win.ismagent
GreenbugAPT34
MALWARE
Malware family identifying win.ismagent. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
ISFB
Technical ID: win.isfb
GOLD CABIN
MALWARE
2006 Gozi v1.0, Gozi CRM, CRM, Papras 2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest. The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version. There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information. ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled. In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim. See win.gozi for additional historical information.
Also known as: Gozi ISFB • IAP • Pandemyia
Updated: 2025-12-19
View profile →
IsaacWiper
Technical ID: win.isaacwiper
MALWARE
According to Recorded Future, IsaacWiper is a destructive malware that overwrites all physical disks and logical volumes on a victim’s machine.
Also known as: LASAINRAW
Updated: 2023-05-21
View profile →
IronZero
Technical ID: win.ironzero
MALWARE
Malware family identifying win.ironzero. Origin and technical characteristics tracked via Malpedia.
IronWind
Technical ID: win.ironwind
MALWARE
Malware family identifying win.ironwind. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-14
View profile →
IronNetInjector
Technical ID: win.ironnetinjector
MALWARE
According to Mitre, IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.
Updated: 2023-01-25
View profile →
IRONHALO
Technical ID: win.ironhalo
APT 16APT16
MALWARE
IRONHALO is a downloader that uses the HTTP protocol to retrieve a Base64 encoded payload from a hard-coded command-and-control (CnC) server and uniform resource locator (URL) path. The encoded payload is written to a temporary file, decoded and executed in a hidden window. The encoded and decoded payloads are written to files named igfxHK[%rand%].dat and igfxHK[%rand%].exe respectively, where [%rand%] is a 4-byte hexadecimal number based on the current timestamp. It persists by copying itself to the current user’s Startup folder.
Updated: 2025-10-01
View profile →
Ironcat
Technical ID: win.ironcat
MALWARE
Malware family identifying win.ironcat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-05
View profile →
← PreviousPage 160 / 269Next →