Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
fengine
Technical ID: win.fengine
MALWARE
Malware family identifying win.fengine. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.felixroot. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.felismus. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.feed_load. Origin and technical characteristics tracked via Malpedia.
MALWARE
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta. It functions as a simple malware downloader and is based on the TouchSocket framework over the Duplex Message Transport Protocol (DMTP). In one campaign, threat actors embedded FDMTP in the data section of a DLL. This allows it to be launched through DLL side-loading. The embedded network configurations are encoded and encrypted to enhance security and evade detection, utilizing Base64 and DES encryption methods. It has been observed to serve as a secondary control tool, often deployed by the PUBLOAD backdoor.
Fauppod
Technical ID: win.fauppod
MALWARE
Malware family identifying win.fauppod. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
According to ESET Research, FatDuke is the current flagship backdoor of APT29 and is only deployed on the most interesting machines. It is generally dropped by the MiniDuke backdoor, but ESET also have seen the operators dropping FatDuke using lateral movement tools such as PsExec.The operators regularly repack this malware in order to evade detections. The most recent sample of FatDuke that ESET have seen was compiled on May 24, 2019. They have seen them trying to regain control of a machine multiple times in a few days, each time with a different sample. Their packer, described in a later section, adds a lot of code, leading to large binaries. While the effective code should not be larger than 1MB, ESET have seen one sample weighing in at 13MB, hence our name for this backdoor component: FatDuke.
FatalRat
Technical ID: win.fatal_rat
MALWARE
FatalRAT is a most-likely chinese remote access tool distributed through forums and Telegram channels. FatalRAT executes various anti-virtual machine tests to avoid detection before fully infecting systems. Upon successful infiltration, it decrypts configuration strings, disables the CTRL+ALT+DELETE function, and activates a keylogger.
The malware can establish persistence via registry modifications or service creation, collect sensitive data, and communicate with its command and control (C&C) server using encrypted methods. FatalRAT also employs techniques like brute-force attacks against weak passwords to propagate within networks.
Also known as: Sainbox RAT
FastPOS
Technical ID: win.fast_pos
MALWARE
Malware family identifying win.fast_pos. Origin and technical characteristics tracked via Malpedia.
FastLoader
Technical ID: win.fastloader
MALWARE
FastLoader is a small .NET downloader, which name comes from PDB strings seen in samples. It typically downloads TrickBot. It may create a list of processes and uploads it together with screenshot(s). In more recent versions, it employs simple anti-analysis checks (VM detection) and comes with string obfuscations.
Farseer
Technical ID: win.farseer
MALWARE
Malware family identifying win.farseer. Origin and technical characteristics tracked via Malpedia.
FantomCrypt
Technical ID: win.fantomcrypt
MALWAREfinancialhigh
According to PCrisk, Fantom is a ransomware-type virus that imitates the Windows update procedure while encrypting files. This is unusual, since most ransomware encrypts files stealthily without showing any activity. During encryption, Fantom appends the names of encrypted files with the ".locked4", ".fantom" or ".locked" extension.
MALWARE
Malware family identifying win.fanny. Origin and technical characteristics tracked via Malpedia.
Also known as: DEMENTIAWHEEL
MALWARE
FancyFilter is a piece of code that documents code overlap between frameworks used by Regin and Equation Group.
Also known as: 0xFancyFilter
FakeWord
Technical ID: win.fakeword
MALWARE
Malware family identifying win.fakeword. Origin and technical characteristics tracked via Malpedia.
FakeTC
Technical ID: win.faketc
MALWARE
Malware family identifying win.faketc. Origin and technical characteristics tracked via Malpedia.
FakeRean
Technical ID: win.fakerean
MALWARE
Malware family identifying win.fakerean. Origin and technical characteristics tracked via Malpedia.
Also known as: Braviax
FakeCry
Technical ID: win.fakecry
MALWARE
Malware written in .NET that mimics WannaCry.
Fabookie
Technical ID: win.fabookie
MALWARE
Fabookie is facebook account info stealer.
MALWAREespionageadvanced
EYService is the main part of the backdoor used by Nazar APT. This a passive backdoor that relies on, now discontinued, Packet Sniffer SDK (PSSDK) from Microolap.
Eye Pyramid
Technical ID: win.eye_pyramid
MALWARE
Malware family identifying win.eye_pyramid. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
According to Trend MIcro, Extreme RAT (XTRAT, Xtreme Rat) is a Remote Access Trojan that can steal information. This RAT has been used in attacks targeting Israeli and Syrian governments last 2012.
This malware family of backdoors has the capability to receive commands such as File Management (Download, Upload, and Execute Files), Registry Management (Add, Delete, Query, and Modify Registry), Perform Shell Command, Computer Control (Shutdown, Log on/off), and Screen capture from a remote attacker. In addition, it can also log keystrokes of the infected systems.
Also known as: ExtRat
ExplosiveRAT
Technical ID: win.explosive_rat
MALWARE
Malware family identifying win.explosive_rat. Origin and technical characteristics tracked via Malpedia.
Expiro
Technical ID: win.expiro
MALWARE
Expiro malware has been around for more than a decade, and the malware authors sill continue their work and update it with more features. Also the infection routine was changed in samples fround in 2017 (described by McAfee).
Expiro "infiltrates" executables on 32- and 64bit Windows OS versions.
It has capabilities to install browser extensions, change security behaviour/settings on the infected system, and steal information (e.g. account credentials).
There is a newly described EPO file infector source code called m0yv in 2022, which is wrongly identified as expiro by some AVs.
Also known as: Xpiro
Exorcist
Technical ID: win.exorcist
MALWAREfinancialhigh
According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a ransom string of characters.
For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.
ExMatter
Technical ID: win.exmatter
MALWAREfinancialhigh
Exfiltration tool written in .NET, used by at least one BlackMatter ransomware operator.
MALWAREespionageadvanced
ExileRAT is a simple RAT platform capable of getting information on the system (computer name, username, listing drives, network adapter, process name), getting/pushing files and executing/terminating processes.
MALWARE
Malware family identifying win.exchange_tool. Origin and technical characteristics tracked via Malpedia.
Excalibur
Technical ID: win.excalibur
MALWARE
Malware family identifying win.excalibur. Origin and technical characteristics tracked via Malpedia.
Also known as: Sabresac • Saber
ExByte
Technical ID: win.exbyte
MALWAREfinancialhigh
ExByte is a custom data exfiltration tool and infostealer observed being used during BlackByte ransomware attacks.
MALWARE
Malware family identifying win.exaramel. Origin and technical characteristics tracked via Malpedia.
Evrial
Technical ID: win.evrial
MALWARE
Malware family identifying win.evrial. Origin and technical characteristics tracked via Malpedia.
EvilPony
Technical ID: win.evilpony
MALWARE
Privately modded version of the Pony stealer.
Also known as: CREstealer
EvilPlayout
Technical ID: win.evilplayout
MALWARE
A wiper used against in an attack against Iran’s state broadcaster. Using campaign name coined by Check Point in lack of a better name for the wiper component.
EVILNUM
Technical ID: win.evilnum
MALWARE
Malware family identifying win.evilnum. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.evilgrab. Origin and technical characteristics tracked via Malpedia.
Also known as: Vidgrab
EvilExtractor
Technical ID: win.evilextractor
MALWARE
Malware family identifying win.evilextractor. Origin and technical characteristics tracked via Malpedia.
EvilConwi
Technical ID: win.evilconwi
MALWARE
EvilConwi is a malicious variant of the legitimate ScreenConnect software by ConnectWise.
This software is a remote access software. Threat actors modify the configuration extensively so that any signs of an active remote connection are removed. EvilConwi often pretends to perform a Windows update by using fake Windows update images embedded in the config. The purpose is to keep the system running while the threat actor connect remotely.
Other EvilConwi signs are fake application icons. E.g., it may pretend to be an installer for Zoom and use its icons and application titles in the ConnectWise config.
MALWARE
Malware family identifying win.evilbunny. Origin and technical characteristics tracked via Malpedia.