Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
MALWARE
Malware family identifying win.etumbot. Origin and technical characteristics tracked via Malpedia.
Also known as: HighTide
Eternity Worm
Technical ID: win.eternity_worm
MALWARE
This malware is part of the Eternity Malware "Framework".
Eternity Stealer
Technical ID: win.eternity_stealer
MALWARE
This Stealer is part of the eternity malware project.
Eternity Ransomware
Technical ID: win.eternity_ransomware
MALWAREfinancialhigh
Eternity Framework Ransomware Payload
Eternity Clipper
Technical ID: win.eternity_clipper
MALWARE
This malware is part of the Eternity Malware "Framework".
MALWAREfinancialhigh
According to proofpoint, Bad Rabbit is a strain of ransomware that first appeared in 2017 and is a suspected variant of Petya. Like other strains of ransomware, Bad Rabbit virus infections lock up victims’ computers, servers, or files preventing them from regaining access until a ransom—usually in Bitcoin—is paid.
Also known as: ExPetr • Pnyetya • Petna • NotPetya • Nyetya
EternalRocks
Technical ID: win.eternalrocks
MALWARE
Malware family identifying win.eternalrocks. Origin and technical characteristics tracked via Malpedia.
Also known as: MicroBotMassiveNet
ESPecter
Technical ID: win.especter
MALWARE
Malware family identifying win.especter. Origin and technical characteristics tracked via Malpedia.
Erica Ransomware
Technical ID: win.erica_ransomware
MALWAREfinancialhigh
Malware family identifying win.erica_ransomware. Origin and technical characteristics tracked via Malpedia.
Eredel
Technical ID: win.eredel
MALWARE
Eredel Stealer is a low price malware that allows for extracting passwords, cookies, screen desktop from browsers and programs.
According to nulled[.]to:
Supported browsers
Chromium Based: Chromium, Google Chrome, Kometa, Amigo, Torch, Orbitum, Opera, Opera Neon, Comodo Dragon, Nichrome (Rambler), Yandex Browser, Maxthon5, Sputnik, Epic Privacy Browser, Vivaldi, CocCoc and other Chromium Based browsers.
- Stealing FileZilla
- Stealing an account from Telegram
- Stealing AutoFill
- Theft of wallets: Bitcoin | Dash | Monero | Electrum | Ethereum | Litecoin
- Stealing files from the desktop. Supports any formats, configurable via telegram-bot
Erebus
Technical ID: win.erebus
MALWARE
Malware family identifying win.erebus. Origin and technical characteristics tracked via Malpedia.
Erbium Stealer
Technical ID: win.erbium_stealer
MALWARE
Erbium is an information stealer advertised and sold as a Malware-as-a-Service on cybercrime forums and Telegram since at least July 2022. Its capabilities are those of a classic information stealer, with a focus on cryptocurrency wallets, and file grabber capabilities.
Equationgroup (Sorting)
Technical ID: win.equationgroup
MALWARE
Rough collection EQGRP samples, to be sorted
MALWARE
Malware family identifying win.equationdrug. Origin and technical characteristics tracked via Malpedia.
Epsilon Stealer
Technical ID: win.epsilon_stealer
MALWARE
Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon". This malware is distributed as a game, mainly on discord, but steals user credentials, crypto wallets, and stored cookies. It evades static detection by being packed with NSIS, which then launches a malicious Electron package.
Epsilon Red
Technical ID: win.epsilon_red
MALWAREfinancialhigh
According to PCrisk, Epsilon is a ransomware-type program. This malware is designed to encrypt the data of infected systems in order to demand payment for decryption.
Also known as: BlackCocaine
EnvyScout
Technical ID: win.envyscout
MALWARE
Malware family identifying win.envyscout. Origin and technical characteristics tracked via Malpedia.
Also known as: ROOTSAW
Enviserv
Technical ID: win.enviserv
MALWARE
According to Microsoft, Enviserv is a malicious program that is unable to spread of its own accord. It may perform a number of actions of an attacker's choice on an affected computer.
EntryShell
Technical ID: win.entryshell
MALWARE
Fileless malware 'EntryShell', a variant of the KeyBoy malware, due to similarities in backdoor command IDs and debug messages with old KeyBoy samples. The embedded malware config was encrypted with a unique algorithm.
Entropy
Technical ID: win.entropy
MALWAREfinancialhigh
Entropy is a ransomware first seen in 1st quarter of 2022, is being used in conjunction of Dridex infection. The ransomware uses a custom packer to pack itself which has been seen in some early dridex samples.
Enigma Loader
Technical ID: win.enigma_loader
MALWARE
According to Trend Micro, this is a downloader, dedicated to stage execution of a second stage malware called Enigma Stealer.
Enfal
Technical ID: win.enfal
MALWARE
Malware family identifying win.enfal. Origin and technical characteristics tracked via Malpedia.
Also known as: Lurid
Emudbot
Technical ID: win.emudbot
MALWARE
Supposedly a worm that was active around 2012-2013.
Empire Downloader
Technical ID: win.empire_downloader
MALWARE
Malware family identifying win.empire_downloader. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
While Emotet historically was a banking malware organized in a botnet, nowadays Emotet is mostly seen as infrastructure as a service for content delivery. For example, since mid 2018 it is used by Trickbot for installs, which may also lead to ransomware attacks using Ryuk, a combination observed several times against high-profile targets.
It is always stealing information from victims but what the criminal gang behind it did, was to open up another business channel by selling their infrastructure delivering additional malicious software. From malware analysts it has been classified into epochs depending on command and control, payloads, and delivery solutions which change over time.
Emotet had been taken down by authorities in January 2021, though it appears to have sprung back to life in November 2021.
Also known as: Geodo • Heodo
Emmenhtal
Technical ID: win.emmenhtal
MALWARE
Emmenhtal is a malicious loader likely distributed since early 2024, and publicly detailed by Orange Cyberdefense CERT in August 2024.
Emmenhtal is an obfuscated multistage payload that spawns an execution of the LOLBIN mshta.exe to read a first HTA stage that embeds a malicious JavaScript code. Once interpreted and executed, the JavaScript decodes and runs a PowerShell script. The latter decrypts an obfuscated PowerShell loader which finally downloads and runs final-stage stealers and commodity RATs.
As of March 2025, Orange Cyberdefense CERT has identified three versions of the loader, all actively distributed.
Also known as: IDATDropper • PEAKLIGHT
Emissary
Technical ID: win.emissary
MALWARE
Malware family identifying win.emissary. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.emdivi. Origin and technical characteristics tracked via Malpedia.
MALWARE
ELMER is a non-persistent proxy-aware HTTP backdoor written in Delphi, and is capable of performing file uploads and downloads, file execution, and process and directory listings. To retrieve commands, ELMER sends HTTP GET requests to a hard-coded CnC server, and parses the HTTP response packets received from the CnC server for an integer string corresponding to the command that needs to be executed.
Also known as: Elmost
MALWARE
This dropper masquerades itself as Adobe software, titled as Adobe.msi. It is used to executes the python written Backdoor used by this threat actor.
MALWARE
Malware family identifying win.eliza_rat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.elise. Origin and technical characteristics tracked via Malpedia.
Also known as: EVILNEST
Elirks
Technical ID: win.elirks
MALWARE
Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. Mostly attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. Multiple Elirks variants using Japanese blog services for the last couple of years.
ElectricPowder
Technical ID: win.electric_powder
MALWARE
Malware family identifying win.electric_powder. Origin and technical characteristics tracked via Malpedia.
MALWARE
The application is a command-line utility and its primary purpose is to tunnel traffic between two IP addresses. The application accepts command-line arguments allowing it to be configured with a destination IP address and port, a source IP address and port, a proxy IP address and port, and a user name and password, which can be utilized to authenticate with a proxy server. It will attempt to establish TCP sessions with the source IP address and the destination IP address. If a connection is made to both the source and destination IPs, this malicious utility will implement a custom protocol, which will allow traffic to rapidly and efficiently be tunneled between two machines. If necessary, the malware can authenticate with a proxy to be able to reach the destination IP address. A configured proxy server is not required for this utility.
Ekipa RAT
Technical ID: win.ekipa
MALWARE
Malware family identifying win.ekipa. Origin and technical characteristics tracked via Malpedia.
EHDevel
Technical ID: win.ehdevel
MALWARE
Malware family identifying win.ehdevel. Origin and technical characteristics tracked via Malpedia.
Egregor
Technical ID: win.egregor
MALWAREfinancialhigh
According to Heimdal, Egregor ransomware infection happens via a loader, then, in the victim’s firewall, it enables the Remote Desktop Protocol. After this part, the malware is free to move inside the victim’s network, identifying and disabling all the antivirus software it can find. The next step is the encryption of the data and the insertion of a ransom note named “RECOVER-FILES.txt” in all the compromised folders.