Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
EDRSilencer
Technical ID: win.edr_silencer
MALWARE
Trend Micro describes EDRSilencer as a red team tool originally designed to interfere with endpoint detection and response solutions via the Windows Filtering Platform, which is actively being used by threat actors.
Updated: 2024-11-07
View profile →
EDDIESTEALER
Technical ID: win.eddiestealer
MALWARE
According to Elastic Security Labs, this is a newly discovered Rust infostealer targeting Windows hosts, which receives a task list from the C2 server identifying data to target.
Updated: 2025-06-02
View profile →
Edam
Technical ID: win.edam
MALWARE
According to Orange Cyberdefense, Edam is written in C++ and its PDB path indicates it is called "droper_dll". It is capable of establishing persistence by setting up a Run key as Setting App which points towards its own file and then of downloading from another C2 a final stage using HTTP GET.
Also known as: SECONDBEST
Updated: 2024-12-09
View profile →
EDA2
Technical ID: win.eda2_ransom
MALWAREfinancialhigh
EDA2 is a successor of HiddenTear. Just like HiddenTear it was developed as an open-source project by a security researcher and published on Github. It was meant as "educational ransomware" and purposefully had flaws in the encryption process that allow decryption of ransomed files. This backfired, when threat actors began to modify HiddenTear and EDA2 source code. Some modifications introduced bugs where encrypted files were destroyed, others fixed the encryption flaws and made decryption without a key impossible.
Updated: 2023-11-22
View profile →
EchoGather
Technical ID: win.echo_gather
MALWARE
According to Intezer, the malware gathers system information and transmits this via (proxy-aware) HTTP requests.
Updated: 2026-01-05
View profile →
Echelon
Technical ID: win.echelon
MALWARE
Malware family identifying win.echelon. Origin and technical characteristics tracked via Malpedia.
Also known as: Echelon-Stealer
Updated: 2024-06-05
View profile →
Easy Stealer
Technical ID: win.easystealer
MALWARE
Easy Stealer is a new information stealer written in Golang that is under active development. Since July 2023, the information stealer has been sold on the underground market, advertising a variety of capabilities, such as the ability to target crypto wallets and passwords. Based on VirusTotal data, it appears that developer test samples were uploaded in June 2023. The panel for the stealer is installed on the buyer's own infrastructure, allowing for exclusive control. The stated pricing models are: $35 for 7 days, $115 for 30 days, and $250 for 90 days. Given its user-friendly panel design and the affordable price range, combined with similar capabilities to other information stealers, Easy Stealer is likely to see an increase in distribution among various cyber criminals as it continues through active development.
Updated: 2023-11-13
View profile →
EASYNIGHT
Technical ID: win.easynight
APT41
MALWARE
FireEye describes EASYNIGHT is a loader observed used with several malware families, including HIGHNOON and HIGHNOON.LITE. The loader often acts as a persistence mechanism via search order hijacking. Examples include a patched bcrypt.dll with no other modification than an additional import entry, in the observed case "printwin.dll!gzwrite64" (breaking the file signature).
Updated: 2019-10-18
View profile →
Earthworm
Technical ID: win.earthworm
MALWARE
According to Cisco Talos, Earthworm is network tunneling tool that has extensively been used by Chinese-speaking threat actors in intrusions to expose internal endpoints to attacker-owned remote infrastructure.
Updated: 2026-01-16
View profile →
EagleMonitorRAT
Technical ID: win.eagle_monitor_rat
MALWARE
This RAT written in C# was derived from HorusEyesRat. It was modified by "Arsium" and published on GitHub. There is also a client builder included. Github Source: https://github.com/arsium/EagleMonitorRAT
Updated: 2022-04-20
View profile →
EagerBee
Technical ID: win.eagerbee
MALWAREespionageadvanced
According to Elastic, EagerBee loads additional capabilities using remotely-downloaded PE files, hosted in C2. However, its implementation and coding practices reveal a lack of advanced skills from the author, relying on basic techniques. During their research, they identified string formatting and underlying behavior that aligns with previous research attributed to a Chinese-speaking threat actor referred to as LuckyMouse (APT27, EmissaryPanda).
Also known as: Thumtais
Updated: 2025-06-16
View profile →
Dyre
Technical ID: win.dyre
WIZARD SPIDER
MALWAREespionageadvanced
The Dyre Banking Trojan, discovered in June 2014, targets online banking websites for credential theft and fraud. It uses a man-in-the-browser approach, encryption, and spam emails for distribution. Dyre's architecture includes a dropper and main DLL module, with techniques for persistence and evasion. Its command and control infrastructure is hidden through proxies, and it can adapt using a domain generation algorithm and I2P integration. Researchers have linked Dyre to the Gozi and Neverquest families.
Also known as: Dyreza
Updated: 2024-05-15
View profile →
DynoWiper
Technical ID: win.dynowiper
MALWARE
Malware family identifying win.dynowiper. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-02-17
View profile →
DynamicStealer
Technical ID: win.dynamicstealer
MALWARE
Dynamic Stealer is a Github Project C# written code by L1ghtN4n. This code collects passwords and uploads these to Telegram. According to Cyble this Eternity Stealer leverages code from this project and also Jester Stealer could be rebranded from it.
Updated: 2022-06-09
View profile →
dynamichttp
Technical ID: win.dynamichttp
RomCom
MALWARE
According to its source repository, dynamichttp is a Mythic C2 Profile, which simply provides a way to get HTTP messages off the wire and forward them to the Mythic server.
Updated: 2025-11-26
View profile →
DYEPACK
Technical ID: win.dyepack
Lazarus Group
MALWARE
Malware family identifying win.dyepack. Origin and technical characteristics tracked via Malpedia.
Also known as: BanSwift • swift
Updated: 2023-08-21
View profile →
Duuzer
Technical ID: win.duuzer
Lazarus Group
MALWARE
Malware family identifying win.duuzer. Origin and technical characteristics tracked via Malpedia.
Also known as: Escad
Updated: 2020-12-08
View profile →
DustyHammock
Technical ID: win.dusty_hammock
MALWARE
According to Proofpoint, DustyHammock is a minimalist backdoor that can run commands via cmd.exe, as well as download and execute additional files. The beacon structure of the DustyHammock communications is highly similar to that of SingleCamper, which suggests that both variants can be administered from the same panel.
DUSTTRAP
Technical ID: win.dusttrap
APT41
MALWARE
Malware family identifying win.dusttrap. Origin and technical characteristics tracked via Malpedia.
Also known as: CurveLoad • DodgeBox • StealthReacher
Updated: 2024-11-04
View profile →
DUSTPAN
Technical ID: win.dustpan
MALWARE
Malware family identifying win.dustpan. Origin and technical characteristics tracked via Malpedia.
Also known as: StealthVector
Updated: 2024-10-21
View profile →
DUSTMAN
Technical ID: win.dustman
MALWARE
In 2019, multiple destructive attacks were observed targeting entities within the Middle East. The National Cyber Security Centre (NCSC), a part of the National Cybersecurity Authority (NCA), detected a new malware named "DUSTMAN" that was detonated on December 29, 2019. Based on analyzed evidence and artifacts found on machines in a victim’s network that were not wiped by the malware. NCSC assess that the threat actor behind the attack had some kind of urgency on executing the files on the date of the attack due to multiple OPSEC failures observed on the infected network. NCSC is calling the malware used in this attack "DUSTMAN" after the filename and string embedded in the malware. "DUSTMAN" can be considered as a new variant of "ZeroCleare" malware, published in December 2019.
Updated: 2023-01-19
View profile →
DuQu
Technical ID: win.duqu
Unit 8200
MALWARE
Malware family identifying win.duqu. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-28
View profile →
Dumador
Technical ID: win.dumador
MALWARE
Malware family identifying win.dumador. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
DUCKTAIL
Technical ID: win.ducktail
MALWARE
According to Tony Lambert, this is a malware written in .NET. It was observed to be delivered using the .NET Single File deployment feature.
Updated: 2024-01-18
View profile →
DUBrute
Technical ID: win.dubrute
MALWARE
Malware family identifying win.dubrute. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-13
View profile →
DarkHotel
Technical ID: win.dubnium_darkhotel
DarkHotel
MALWARE
Malware family identifying win.dubnium_darkhotel. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-26
View profile →
DualToy
Technical ID: win.dualtoy
MALWARE
Malware family identifying win.dualtoy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-22
View profile →
Dtrack
Technical ID: win.dtrack
Lazarus GroupSilent Chollima
MALWARE
Dtrack is a Remote Administration Tool (RAT) developed by the Lazarus group. Its core functionality includes operations to upload a file to the victim's computer, download a file from the victim's computer, dump disk volume data, persistence and more. A variant of Dtrack was found on Kudankulam Nuclear Power Plant (KNPP) which was used for a targeted attack.
Also known as: Preft • TroyRAT
Updated: 2024-11-29
View profile →
DROPSHOT
Technical ID: win.dropshot
APT33
MALWARE
Malware family identifying win.dropshot. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-25
View profile →
DropBook
Technical ID: win.dropbook
Molerats
MALWARE
DropBook is a backdoor developed by the Molerats group and first appeared in late 2020. The backdoor abuses Facebook and Dropbox platforms for C2 purposes, where fake Facebook accounts are used by the operators to control the backdoor by posting commands on the accounts.
Updated: 2022-02-09
View profile →
Drokbk
Technical ID: win.drokbk
APT35
MALWAREespionageadvanced
Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure. This makes it difficult to detect and remove, as GitHub is not traditionally associated with malicious activities. Drokbk attacks have been linked to the Iranian APT group Nemesis Kitten. This group is believed to use Drokbk for cyberespionage and financial information theft activities.
Updated: 2024-04-15
View profile →
DriveOcean
Technical ID: win.driveocean
APT28
MALWARE
Communicates via Google Drive.
Also known as: Google Drive RAT
Updated: 2023-11-14
View profile →
Dripion
Technical ID: win.dripion
MALWARE
Malware family identifying win.dripion. Origin and technical characteristics tracked via Malpedia.
Also known as: Masson
Updated: 2019-09-06
View profile →
DRIFTPIN
Technical ID: win.driftpin
Anunak
MALWARE
Driftpin is a small and simple backdoor that enables the attackers to assess the victim. When executed the trojan connects to a C&C server and receives commands to grab screenshots, enumerate running processes and get information about the system and campaign ID.
Also known as: Toshliph • Spy.Agent.ORM
Updated: 2022-05-05
View profile →
Dridex
Technical ID: win.dridex
Evil CorpINDRIK SPIDERTA505
MALWAREfinancialhigh
OxCERT blog describes Dridex as "an evasive, information-stealing malware variant; its goal is to acquire as many credentials as possible and return them via an encrypted tunnel to a Command-and-Control (C&C) server. These C&C servers are numerous and scattered all over the Internet, if the malware cannot reach one server it will try another. For this reason, network-based measures such as blocking the C&C IPs is effective only in the short-term." According to MalwareBytes, "Dridex uses an older tactic of infection by attaching a Word document that utilizes macros to install malware. However, once new versions of Microsoft Office came out and users generally updated, such a threat subsided because it was no longer simple to infect a user with this method." IBM X-Force discovered "a new version of the Dridex banking Trojan that takes advantage of a code injection technique called AtomBombing to infect systems. AtomBombing is a technique for injecting malicious code into the 'atom tables' that almost all versions of Windows uses to store certain application data. It is a variation of typical code injection attacks that take advantage of input validation errors to insert and to execute malicious code in a legitimate process or application. Dridex v4 is the first malware that uses the AtomBombing process to try and infect systems."
Updated: 2024-04-15
View profile →
DreamBot
Technical ID: win.dreambot
MALWARE
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*) 2014 Dreambot (Gozi ISFB variant) In 2014, a variant of Gozi ISFB was developed. Mainly, the dropper performs additional anti-vm checks (vmware, vbox, qemu), while the actual bot-dll remains unchanged in most parts. New functionality, such as TOR support, was added though and often, the Fluxxy fast-flux network is used. See win.gozi for additional historical information.
Updated: 2022-08-28
View profile →
DRATzarus
Technical ID: win.dratzarus
Lazarus Group
MALWARE
Malware family identifying win.dratzarus. Origin and technical characteristics tracked via Malpedia.
Also known as: ThreatNeedle • ThreatNeedleTea
Updated: 2025-11-19
View profile →
DRAT
Technical ID: win.drat
TAG-140
MALWARE
Malware family identifying win.drat. Origin and technical characteristics tracked via Malpedia.
DramNudge
Technical ID: win.dramnudge
MALWARE
Malware family identifying win.dramnudge. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
DragonForce
Technical ID: win.dragonforce
MALWAREfinancialhigh
According to Idan Malihi, this ransomware is based on the LockBit builder from 2022, utilizing similar configurations and attack methods. The ransomware’s icon and wallpaper are embedded in the binary’s overlay, compressed with Zlib, and loaded dynamically during execution.
Updated: 2026-02-05
View profile →
← PreviousPage 171 / 269Next →