Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,744 entities
HZ RAT
Technical ID: win.hzrat
MALWARE
Malware family identifying win.hzrat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Sideloader used by EmissaryPanda
Also known as: FOCUSFJORD • Soldier • Sysupdate
HYPERSCRAPE
Technical ID: win.hyperscrape
MALWARE
Malware family identifying win.hyperscrape. Origin and technical characteristics tracked via Malpedia.
MALWARE
HyperBro is a RAT that has been observed to target primarily within the gambling industries, though it has been spotted in other places as well. The malware typically consists of 3 or more components: a) a genuine loader typically with a signed certification b) a malicious DLL loader loaded from the former component via DLL hijacking c) an encrypted and compressed blob that decrypts to a PE-based payload which has its C2 information hardcoded within.
HxDef
Technical ID: win.hxdef
MALWARE
Malware family identifying win.hxdef. Origin and technical characteristics tracked via Malpedia.
Also known as: HacDef • HackerDefender • HackDef
MALWARE
Malware family identifying win.hussar. Origin and technical characteristics tracked via Malpedia.
HuskLoader
Technical ID: win.huskloader
MALWARE
Malware family identifying win.huskloader. Origin and technical characteristics tracked via Malpedia.
Hupigon
Technical ID: win.hupigon
MALWARE
Malware family identifying win.hupigon. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet controversial threat actor in the cybercrime ecosystem. While initial analysis revealed a code overlap with the dismantled Hive ransomware, the group claims independence, asserting it purchased Hive’s source code rather than directly rebranding. This operational lineage enables advanced double-extortion campaigns prioritizing data exfiltration over encryption, with confirmed theft of medical records, financial data, and proprietary business information. The group's ransomware is written in Rust, a programming language favored for its resilience to reverse engineering and cross-platform compatibility.
Hunter Stealer
Technical ID: win.hunter
MALWARE
Malware family identifying win.hunter. Origin and technical characteristics tracked via Malpedia.
HUI Loader
Technical ID: win.hui_loader
MALWARE
A loader that has been used by multiple threat actor groups since 2015.
Also known as: SIDESTEP
http_troy
Technical ID: win.http_troy
MALWARE
Malware family identifying win.http_troy. Origin and technical characteristics tracked via Malpedia.
MALWARE
The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols.
It accepts up to 10 command line parameters: a 29-byte decryption key, a C&C for data exfiltration, the name of a local RAR split volume, the name of the multivolume archive on the server side, the size of a RAR split (max 200,000 kB), the starting index of a split, the ending index of a split, and the switch -p with a proxy IP address and port
HTTPSnoop
Technical ID: win.httpsnoop
MALWARE
Cisco Talos states that HTTPSnoop is a simple, yet effective, backdoor that consists of novel techniques to interface with Windows HTTP kernel drivers and devices to listen to incoming requests for specific HTTP(S) URLs and execute that content on the infected endpoint.
Also known as: TOFULOAD
httpdropper
Technical ID: win.httpdropper
MALWARE
Malware family identifying win.httpdropper. Origin and technical characteristics tracked via Malpedia.
Also known as: httpdr0pper
MALWARE
Malware family identifying win.httpbrowser. Origin and technical characteristics tracked via Malpedia.
Also known as: HttpDump
MALWARE
Malware family identifying win.htran. Origin and technical characteristics tracked via Malpedia.
Also known as: HUC Packet Transmit Tool • lcx
htpRAT
Technical ID: win.htprat
MALWARE
Malware family identifying win.htprat. Origin and technical characteristics tracked via Malpedia.
HtBot
Technical ID: win.htbot
MALWARE
Malware family identifying win.htbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-29
View profile →Houdini
Technical ID: win.houdini
MALWARE
Houdini is a VBS-based RAT dating back to 2013. Past in the days, it used to be wrapped in an .exe but started being spamvertized or downloaded by other malware directly as .vbs in 2018. In 2019, WSHRAT appeared, a Javascript-based version of Houdini, recoded by the name of Kognito.
Also known as: Hworm • Jenxcus • Kognito • Njw0rm • WSHRAT
MALWARE
HOTWAX is a module that upon starting imports all necessary system API functions, and searches for a .CHM file. HOTWAX decrypts a payload using the Spritz algorithm with a hard-coded key and then searches the target process and attempts to inject the decrypted payload module from the CHM file into the address space of the target process.
MALWARE
Malware family identifying win.hotcroissant. Origin and technical characteristics tracked via Malpedia.
Horus Eyes RAT
Technical ID: win.horus_eyes_rat
MALWAREfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
HorusEyes RAT
Technical ID: win.horuseyes
MALWARE
Remote Acess Tool Written in VB.NET.
MALWARE
According to Check Point Research, this is a custom-built agent for Mythic, the open-source red teaming C2 framework. Written in C++, the implant shows no significant overlap with known C-based Mythic agents, aside from commonalities in the generic logic related to Mythic C2 communications.
Hopscotch
Technical ID: win.hopscotch
MALWARE
Hopscotch is part of the Regin framework.
MALWARE
Malware family identifying win.hoplight. Origin and technical characteristics tracked via Malpedia.
Also known as: HANGMAN
HookInjEx
Technical ID: win.hookinjex
MALWARE
Malware family identifying win.hookinjex. Origin and technical characteristics tracked via Malpedia.
MALWARE
a 64-bit Windows password dumper/cracker that has previously been used in conjunction with AIRBREAK and BADFLICK backdoors. Some strings are obfuscated with XOR x56. The malware accepts up to two arguments at the command line: one to display cleartext credentials for each login session, and a second to display cleartext credentials, NTLM hashes, and malware version for each login session.
HOLERUN
Technical ID: win.holerun
MALWARE
Malware family identifying win.holerun. Origin and technical characteristics tracked via Malpedia.
Also known as: LAGTOY
Holcus Installer (Adware)
Technical ID: win.holcus
MALWARE
Adware, tied to eGobbler and Nephos7 campaigns,
MALWARE
Malware family identifying win.hodur. Origin and technical characteristics tracked via Malpedia.
HLUX
Technical ID: win.hlux
MALWARE
Malware family identifying win.hlux. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-26
View profile →Hi-Zor RAT
Technical ID: win.hi_zor_rat
MALWARE
Malware family identifying win.hi_zor_rat. Origin and technical characteristics tracked via Malpedia.
Hive
Technical ID: win.hive
MALWAREfinancialhigh
Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe.
In 2022 there was a switch from GoLang to Rust.
Hisoka
Technical ID: win.hisoka
MALWARE
Malware family identifying win.hisoka. Origin and technical characteristics tracked via Malpedia.
Himera Loader
Technical ID: win.himera_loader
MALWARE
Malware family identifying win.himera_loader. Origin and technical characteristics tracked via Malpedia.
himan
Technical ID: win.himan
MALWARE
Malware family identifying win.himan. Origin and technical characteristics tracked via Malpedia.
HILDACRYPT
Technical ID: win.hildacrypt
MALWAREfinancialhigh
A new ransomware family was discovered in August 2019. Called HILDACRYPT, it is named after the Netflix cartoon “Hilda” because the TV show’s YouTube trailer was included in the ransom note of the original version of the malware.
MALWARE
Malware family identifying win.hikit. Origin and technical characteristics tracked via Malpedia.