Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
IPStorm
Technical ID: win.ipstorm
MALWARE
Malware family identifying win.ipstorm. Origin and technical characteristics tracked via Malpedia.
iox
Technical ID: win.iox
MALWARE
A maliciously abused open source tool for port forwarding & intranet proxy.
InvisiMole
Technical ID: win.invisimole
MALWAREespionageadvanced
InvisiMole had a modular architecture, starting with a wrapper DLL, and performing its activities using two other modules that were embedded in its resources, named RC2FM and RC2CL. They were feature-rich backdoors and turned the affected computer into a video camera, letting the attackers to spy the victim.
The malicious actors behind this malware were active at least since 2013 in highly targeted campaigns with only a few dozen compromised computers in Ukraine and Russia. The wrapper DLL posed as a legitimate mpr.dll library and was placed in the same folder as explorer.exe, which made it being loaded during the Windows startup into the Windows Explorer process instead of the legitimate library.
Malware came in both 32-bit and 64-bit versions, which made this persistence technique functional on both architectures.
The smaller of the modules, RC2FM, contained a backdoor with fifteen supported commands indexed by numbers. The commands could perform simple changes on the system and spying features like capturing sounds, taking screenshots or monitoring all fixed and removable drives.
The second module, RC2CL, offered features for collecting as much data about the infected computer as possible, rather than for making system changes. The module supported up to 84 commands such as file system operations, file execution, registry key manipulation, remote shell activation, wireless network scanning, listing of installed software etc. Though the backdoor was capable of interfering with the system (e.g. to log off a user, terminate a process or shut down the system), it mostly provided passive operations. Whenever possible, it tried to hide its activities by restoring the original file access time or safe-deleting its traces.
Invicta Stealer
Technical ID: win.invicta_stealer
MALWARE
According to Cyble, The Invicta Stealer can collect system information, system hardware details, wallet data, and browser data and extract information from applications like Steam and Discord.
Interlock
Technical ID: win.interlock
MALWAREfinancialhigh
According to Sekoia, this is the ransomware used by the Interlock ransomware intrusion set, which was first observed in September 2024 conducting Big Game Hunting and double extortion campaigns.
MALWARE
ESET noticed attacks against aerospace and military companies in Europe and the Middle East that took place between September and December 2019, which featured this family. They found a number of hints that points towards Lazarus as potential origin.
MALWARE
InnifiRAT is coded in .NET and targets personal data on infected devices, with it's top priority appearing to be bitcoin and litecoin wallet data.
InffiRAT also includes a backdoor which allows attackers to control the infected host remotely. Possibilities include loggin key stroke, taking pictures with webcam, accessing confidential information, formatting drives, and more.
It attempts to steal browser cookies to steal usernames and passwords and monitors the users activities with screenshot functionality.
InnaputRAT
Technical ID: win.innaput_rat
MALWARE
InnaputRAT, a RAT capable of exfiltrating files from victim machines, was distributed by threat actors using phishing and Godzilla Loader. The RAT has evolved through multiple variants dating back to 2016. Recent campaigns distributing InnaputRAT beaconed to live C2 as of March 26, 2018.
Inlock
Technical ID: win.inlock
MALWARE
Malware family identifying win.inlock. Origin and technical characteristics tracked via Malpedia.
Infy
Technical ID: win.infy
MALWARE
Malware family identifying win.infy. Origin and technical characteristics tracked via Malpedia.
Also known as: Foudre
InfoDot
Technical ID: win.infodot
MALWAREfinancialhigh
Ransomware.
InfinityLock
Technical ID: win.infinitylock
MALWAREfinancialhigh
InfinityLock ransomware is a type of malicious software that encrypts a victim's files and demands a ransom payment in order to decrypt them. It is spread through phishing emails and malicious websites. Once a computer is infected with InfinityLock, it encrypts all important files, such as documents, photos, and videos. It then displays a message that demands the victim pay a ransom of $1,000 in Bitcoin in order to decrypt the files. If the victim does not pay the ransom, the files will be lost permanently.
Inferno
Technical ID: win.inferno
MALWARE
Malware family identifying win.inferno. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.industroyer2. Origin and technical characteristics tracked via Malpedia.
MALWARE
Industroyer is a malware framework considered to have been used in the cyberattack on Ukraine’s power grid on December 17, 2016. The attack cut a fifth of Kiev, the capital, off power for one hour. It is the first ever known malware specifically designed to attack electrical grids.
Also known as: Crash • CrashOverride
Industrial Spy
Technical ID: win.industrial_spy
MALWAREfinancialhigh
A ransomware that emerged in April 2022.
IndigoDrop
Technical ID: win.indigodrop
MALWARE
Malware family identifying win.indigodrop. Origin and technical characteristics tracked via Malpedia.
Incubator
Technical ID: win.incubator
MALWARE
Keylogger written in Visual Basic dating back to at least 2012.
INCONTROLLER
Technical ID: win.incontroller
MALWARE
INCONTROLLER (aka PIPEDREAM) is a set of tools built to target machine automation devices. The tools can interact with specific industrial equipment embedded in different types of machinery leveraged across multiple industries. This tool set is very likely state sponsored and contains capabilities related to disruption, sabotage, and potentially physical destruction.
Also known as: PIPEDREAM
MALWARE
ImprudentCook is an HTTP(S) downloader.
It was delivered in the Operation DreamJob type of activity targeting aerospace and defense companies in South Africa (in Q2 2022) and in Central Europe (in H1 2023), and against an unknown sector in South Korea back in Q2 2021.
It uses the AES cipher implemented through Windows Cryptographic Providers for decryption of its binary configuration, and also for encryption and decryption of the client-server communication.
It’s hidden in an ADS stream (:dat or :zone) of its dropper, together with its configuration (:rsrc) and an AES-128 CBC key with an initialization vector for its decryption (:kgb or :data).
It contains two characteristic arrays of strings that represent cookie names for web services, including Bing, Daum and GitHub:
1. iKc;__uid;OAX;DMP_UID;PCID;_gid;_gat;csrftoken;NID;1P_JAR;JSESSIONID;WLS;SNID;__
utma;BID;SRCHD;GsCK_AC;spintop;eader;XSRF-TOKEN;_gat_gtag_UA;webid_
enabled;EDGE_V;dtck_channel;dtmulti;UUID;XUID;ZIA;IUID;SSID;_gh_sess;_octo
2. channel;post_titles;xfw_exp;wiht_clkey;SGPCOUPLE;NRTK;fbp;uaid;SRCHUSR;GUC;HPVN;dtck_
blog;dtck_media;MUIDB;SRCHHPGUSR;SiteMain
It contains a string, "5.40" or "5.60", looking like version information.
Immortal Stealer
Technical ID: win.immortal_stealer
MALWARE
ZScaler describes Immortal Stealer as a windows malware written in .NET designed to steal sensitive information from an infected machine. The Immortal stealer is sold on the dark web with different build-based subscriptions.
MALWARE
MITRE describes Imminent Monitor as a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.
MALWARE
Malware family identifying win.imecab. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.imap_loader. Origin and technical characteristics tracked via Malpedia.
IISpy
Technical ID: win.iispy
MALWARE
Malware family identifying win.iispy. Origin and technical characteristics tracked via Malpedia.
Also known as: BadIIS
IISniff
Technical ID: win.iisniff
MALWARE
Malware family identifying win.iisniff. Origin and technical characteristics tracked via Malpedia.
IDKEY
Technical ID: win.idkey
MALWARE
Malware family identifying win.idkey. Origin and technical characteristics tracked via Malpedia.
idat loader
Technical ID: win.idat_loader
MALWARE
Malware family identifying win.idat_loader. Origin and technical characteristics tracked via Malpedia.
IcyHeart
Technical ID: win.icyheart
MALWARE
Malware family identifying win.icyheart. Origin and technical characteristics tracked via Malpedia.
Also known as: Troxen
MALWARE
Follow-up payload in 3CX supply chain incident, which according to Volexity is an infostealer collecting information about the system and browser using an embedded copy of the SQLite3 library.
MALWARE
Malware family identifying win.icondown. Origin and technical characteristics tracked via Malpedia.
Ice IX
Technical ID: win.ice_ix
MALWAREfinancialhigh
The ICE IX bot is a banking trojan derived of the Zeus botnet because it uses significant parts of Zeus’s source code. ICE IX communicates using the HTTP protocol, so it can be considered to be a third-generation botnet. While it has been used for a variety of purposes, a primary threat of ICE IX comes from its manipulation of banking operations on compromised machines. As with any bot, execution of the bot results in establishing a master-slave relationship between the botmaster and the compromised computer.
MALWARE
According to nao_sec, this malware is a simple passive-mode backdoor that is installed as a service.
MALWARE
According to nao_sec, this malware is an IIS backdoor.
MALWARE
IceXLoader is a commercial malware used to download and deploy additional malware on infected machines. The latest version is written in Nim, a relatively new language utilized by threat actors the past two years, most notably by the NimzaLoader variant of BazarLoader used by the TrickBot group.
The v1 was written in AutoIT.
Icefog
Technical ID: win.icefog
MALWARE
Malware family identifying win.icefog. Origin and technical characteristics tracked via Malpedia.
Also known as: Fucobha
IcedID Downloader
Technical ID: win.icedid_downloader
MALWARE
Malware family identifying win.icedid_downloader. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
According to Proofpoint, IcedID (aka BokBot) is a malware originally classified as a banking malware and was first observed in 2017. It also acts as a loader for other malware, including ransomware. The well-known IcedID version consists of an initial loader which contacts a Loader C2 server, downloads the standard DLL Loader, which then delivers the standard IcedID Bot. IcedID is developed and operated by the actor named LUNAR SPIDER.
As previously published, historically there has been just one version of IcedID that has remained constant since 2017.
* In November 2022, Proofpoint researchers observed the first new variant of IcedID Proofpoint dubbed 'IcedID Lite' distributed as a follow-on payload in a TA542 Emotet campaign. It was dropped by the Emotet malware soon after the actor returned to the e-crime landscape after a nearly four-month break.
* The IcedID Lite Loader observed in November 2022 contains a static URL to download a 'Bot Pack' file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud.
* Starting in February 2023, Proofpoint observed the new Forked variant of IcedID. This variant was distributed by TA581 and one unattributed threat activity cluster which acted as initial access facilitators. The campaigns used a variety of email attachments such as Microsoft OneNote attachments and somewhat rare to see .URL attachments, which led to the Forked variant of IcedID.
Also known as: BokBot • IceID
Icarus
Technical ID: win.icarus
MALWARE
Icarus is a modular stealer software, written in .NET. One module is the open source r77 rootkit.
I2PRAT
Technical ID: win.i2prat
MALWAREespionageadvanced
According to Cofense, this malware is notable for having several unique tactics, techniques, and procedures (TTPs), such as Secure Email Gateway (SEG) evasion by proxying emails through legitimate infrastructure, fake CAPTCHAs, abusing hardcoded Windows functionality to hide dropped files, and C2 capabilities over Invisible Internet Project (I2P), a peer-to-peer anonymous network with end-to-end encryption. Upon installation, I2Parcae is capable of disabling Windows Defender, enumerating Windows Security Accounts Manager (SAM) for accounts/groups, stealing browser cookies, and remote access to infected hosts. As of November 2024, I2Parcae appears to be delivered via automated spam messages targeting customer support contact forms on multiple websites. The messages deliver an embedded link purporting to be pornography.
Also known as: I2Parcae