Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
gcman
Technical ID: win.gcman
MALWARE
Malware family identifying win.gcman. Origin and technical characteristics tracked via Malpedia.
GCleaner
Technical ID: win.gcleaner
MALWARE
Malware family identifying win.gcleaner. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.gazer. Origin and technical characteristics tracked via Malpedia.
Also known as: WhiteBear
Gazavat
Technical ID: win.gazavat
MALWARE
Gazavat (which is often tagged as Expiro by AV vendors) is a multi-functional backdoor that has code overlaps with the POS malware DMSniff. Functionality includes:
- Loading other executables
- Load hash cracking plugin
- Load DMSniff plugin
- Perform webinjection and webfakes
- Form grabbing
- Command execution
- Download file from infected system
- Convert infection into proxy
- DDOS
- Spreading and EXE infecting
Gauss
Technical ID: win.gauss
MALWARE
Malware family identifying win.gauss. Origin and technical characteristics tracked via Malpedia.
Gaudox
Technical ID: win.gaudox
MALWARE
Gaudox is a http loader, written in C/C++. The author claims to have put much effort into making this bot efficient and stable. Its rootkit functionality hides it in Windows Explorer (32bit only).
Gasket
Technical ID: win.gasket
MALWAREfinancialhigh
A backdoor used by Mespinoza ransomware gang to maintain access to a compromised network.
MALWAREfinancialhigh
GandCrab was a Ransomware-as-a-Service (RaaS) emerged in January 28, 2018, managed by a criminal organization known to be confident and vocal, while running a rapidly evolving ransomware campaign. Through their aggressive, albeit unusual, marketing strategies and constant recruitment of affiliates, they were able to globally distribute a high volume of their malware.
In a surprising announcement on May 31, 2019, the GandCrab’s operators posted on a dark web forum, announced the end of a little more than a year of ransomware operations, citing staggering profit figures. However, If there’s one thing that sets these threat actors apart from other groups, it is that they are unpredictable; so there is always the possibility that they might re-surface in one form or another.
Also known as: GrandCrab
GAMYBEAR
Technical ID: win.gamybear
MALWARE
GAMYBEAR
A software tool developed using the Go programming language. Its main functionality is to receive (“listener”), execute (‘executor’) commands, and send (“sender”) results to the control server in BASE64-encoded form using the HTTP protocol.
When launched, it generates a unique identifier (UUID), receives basic information about the computer (“whoami”, “wmic nicconfig where IPEnabled=true get IPAddress”), creates a helper file %APPDATA%\ updater.json, where the URL of the control server is stored in JSON format (key “update_server”), as well as other listed data in BASE64-encoded form (keys: “uuid”, ‘hostname’, “ip”, respectively).
During operation, the software regularly sends requests to the control server (URI: “/c2/get_commands/”) and waits for a response in JSON format with the ‘command’ and “arguments” fields. If the “Nop” command is received, a 15-second pause is initiated. After the commands are executed, the result and other data are encoded using BASE64, stored in a JSON structure (keys: “uuid”, “command”, ‘output’) and sent to the control server with a request to the URI “/c2/command_out/”.
The consistency of the launch is ensured by another program (script) at the stage of the initial infection of the computer by creating a key in the “Run” branch of the operating system registry.
Gamotrol
Technical ID: win.gamotrol
MALWARE
Malware family identifying win.gamotrol. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →GamePlayerFramework
Technical ID: win.game_player_framework
MALWARE
Malware family identifying win.game_player_framework. Origin and technical characteristics tracked via Malpedia.
Gameover P2P
Technical ID: win.gameover_p2p
MALWAREfinancialhigh
Gameover ZeuS is a peer-to-peer botnet based on components from the earlier ZeuS trojan. According to a report by Symantec, Gameover Zeus has largely been used for banking fraud and distribution of the CryptoLocker ransomware. In early June 2014, the U.S. Department of Justice announced that an international inter-agency collaboration named Operation Tovar had succeeded in temporarily cutting communication between Gameover ZeuS and its command and control servers.
Also known as: GOZ • Gameover ZeuS • Mapp • ZeuS P2P
Gameover DGA
Technical ID: win.gameover_dga
MALWARE
Malware family identifying win.gameover_dga. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-18
View profile →gamapos
Technical ID: win.gamapos
MALWARE
Malware family identifying win.gamapos. Origin and technical characteristics tracked via Malpedia.
Also known as: pios
GalaxyLoader
Technical ID: win.galaxyloader
MALWARE
GalaxyLoader is a simple .NET loader. Its name stems from the .pdb and the function naming.
It seems to make use of iplogger.com for tracking.
It employed WMI to check the system for
- IWbemServices::ExecQuery - SELECT * FROM Win32_Processor
- IWbemServices::ExecQuery - select * from Win32_VideoController
- IWbemServices::ExecQuery - SELECT * FROM AntivirusProduct
Updated: 2018-03-26
View profile →Gaganode
Technical ID: win.gaganode
MALWARE
According to Synthient, Gaganode is a decentralized bandwidth monetization service that enables both users and publishers to earn crypto for their bandwidth or monetize other people's bandwidth. The SDK intentionally implements RCE, thus aligning Gaganode more closely with malware than standard commercial SDKs.
Gacrux
Technical ID: win.gacrux
MALWARE
Malware family identifying win.gacrux. Origin and technical characteristics tracked via Malpedia.
GaboonGrabber
Technical ID: win.gaboongrabber
MALWARE
According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless stages. Additionally, it has the tendency to camouflage itself as a legitimate application, going so far as to mimic legitimate applications in its decompiled code. It also includes a steganographic image used to prepare further payloads.
GaboonGrabber's final stage can deploy various types of malware, including Snake Keylogger, AgentTesla, Redline, Lokibot, and more.
FuxSocy
Technical ID: win.fuxsocy
MALWARE
FuxSocy has some similarities to win.cerber but is tracked as its own family for now.
MALWARE
FuwuqiDrama is a server-side RAT. It manages client connections by utilizing I/O completion ports, which are usually used in high-performance server applications as an elegant solution to manage many clients at once.
It contains two distinguishing hardcoded lists.
First is a list of ~50 video files of South Korean TV series, having their titles translated to Mandarin Chinese, but encoded in the form of Pinyin romanization. That means the sounds are spelled in Latin alphabet without tone marks, for example meiyounihuobuxiaqu.avi represents Can't Live Without You (a K-drama from 2012) or wulalafufu.avi translates to Ohlala Couple (also from 2012).
Second is the list of the following corporations: NVIDIA, Amazon, Intel, Skype, 360Safe, Rising, Tencent, Mozilla, Adobe, Yahoo, Google. The same list is contained in some of the WannaCryptor samples.
FuwuqiDrama stores its configuration in the INI file data\package_con_x86.cat. It contains the port number and a bot identifier, all within a single section called Fuwuqi – the romanized Chinese word for server.
MALWARE
Malware family identifying win.fusiondrive. Origin and technical characteristics tracked via Malpedia.
Furtim
Technical ID: win.furtim
MALWARE
Malware family identifying win.furtim. Origin and technical characteristics tracked via Malpedia.
FunnyDream
Technical ID: win.funny_dream
MALWARE
Malware family identifying win.funny_dream. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.funnyswitch. Origin and technical characteristics tracked via Malpedia.
Also known as: RouterGod
FunkSec
Technical ID: win.funksec
MALWAREfinancialhigh
According to Check Point Research, a ransomware written in Rust that was likely developed using the aid of an LLM to produce code snippets.
FULLMETAL
Technical ID: win.fullmetal
MALWARE
Malware family identifying win.fullmetal. Origin and technical characteristics tracked via Malpedia.
MALWARE
Fujinama is a custom VB info stealer capable to execute custom commands and custom exfiltrations, keylogging and screenshot. It was involved in the compromise of Leonardo SpA, a major Italian aerospace and defense company.
MALWARE
FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.
Also known as: LIGHTSHOW
Fs0ciety
Technical ID: win.fs0ciety
MALWARE
Malware family identifying win.fs0ciety. Origin and technical characteristics tracked via Malpedia.
FROZENHILL
Technical ID: win.frozenhill
MALWARE
FROZENHILL is a launcher written in C++ that is configured to utilize existing files for execution and also infects newly attached storage volumes with additional malware.
FrostyGoop
Technical ID: win.frostygoop
MALWARE
Malware family identifying win.frostygoop. Origin and technical characteristics tracked via Malpedia.
Also known as: BUSTLEBERM
MALWARE
Malware family identifying win.friedex. Origin and technical characteristics tracked via Malpedia.
Also known as: BitPaymer • DoppelPaymer • IEncrypt
MALWARE
Malware family identifying win.freenki. Origin and technical characteristics tracked via Malpedia.
Also known as: SHUTTERSPEED
FRat
Technical ID: win.frat
MALWARE
A RAT employing Node.js, Sails, and Socket.IO to collect information on a target
FPSpy
Technical ID: win.fpspy
MALWARE
Malware family identifying win.fpspy. Origin and technical characteristics tracked via Malpedia.
FoxSocket
Technical ID: win.foxsocket
MALWARE
Malware family identifying win.foxsocket. Origin and technical characteristics tracked via Malpedia.
FortuneCrypt
Technical ID: win.fortunecrypt
MALWARE
Malware family identifying win.fortunecrypt. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.former_first_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: ffrat
MALWARE
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
Also known as: win.xloader
MALWARE
Malware family identifying win.forest_tiger. Origin and technical characteristics tracked via Malpedia.
Also known as: ScoringMathTea