Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
DragonBreath
Technical ID: win.dragonbreath
MALWARE
Malware family identifying win.dragonbreath. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-18
View profile →
DracuLoader
Technical ID: win.dracu_loader
Earth Estries
MALWARE
Cyber Defense Institute stated that this shellcode PE loader was observed staging win.hemigate.
Updated: 2025-10-29
View profile →
DownPaper
Technical ID: win.downpaper
Charming Kitten
MALWAREespionageadvanced
DownPaper, sometimes delivered as sami.exe, is a Backdoor trojan. Its main functionality is to download and run a second stage. This malware has been observed in campaigns involving Charming Kitten, an Iranian cyberespionage group.
Updated: 2022-06-22
View profile →
DownEx
Technical ID: win.downex
UAC-0063
MALWARE
According to Bitdefender, this is an exfiltration tool, scanning local and network drives for sensitive files, like documents, archives, certificates, and cryptographic keys.
Updated: 2025-07-11
View profile →
Downeks
Technical ID: win.downeks
MALWARE
Malware family identifying win.downeks. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-03-03
View profile →
Downdelph
Technical ID: win.downdelph
APT28
MALWARE
Malware family identifying win.downdelph. Origin and technical characteristics tracked via Malpedia.
Also known as: DELPHACY
Updated: 2021-04-20
View profile →
DoubleZero
Technical ID: win.doublezero
MALWARE
A wiper identified by CERT-UA on March 17th, written in C#.
Also known as: FiberLake
Updated: 2023-04-25
View profile →
DoublePulsar
Technical ID: win.doublepulsar
Equation GroupUPS
MALWARE
Malware family identifying win.doublepulsar. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-06-08
View profile →
DOUBLELOADER
Technical ID: win.doubleloader
MALWARE
Malware family identifying win.doubleloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-02
View profile →
DoubleFinger
Technical ID: win.doublefinger
MALWARE
Malware family identifying win.doublefinger. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-03
View profile →
DoubleFantasy
Technical ID: win.doublefantasy
Equation Group
MALWARE
Malware family identifying win.doublefantasy. Origin and technical characteristics tracked via Malpedia.
Also known as: VALIDATOR
Updated: 2022-05-23
View profile →
DOUBLEBACK
Technical ID: win.doubleback
MALWARE
DOUBLEBACK is a newly discovered fileless malware deployed as part of an attack campaign that took place in December 2020. The threat actors responsible for the operations are tracked as UNC2529 by researchers. According to their findings, DOUBLEBACK is the final payload delivered onto the compromised systems. Its task is to establish and maintain a backdoor on the victim's machine.
Updated: 2023-05-16
View profile →
Dot Ransomware
Technical ID: win.dot_ransomware
MALWAREfinancialhigh
Malware family identifying win.dot_ransomware. Origin and technical characteristics tracked via Malpedia.
Also known as: MZP Ransomware
Updated: 2024-02-09
View profile →
DOSTEALER
Technical ID: win.dostealer
MALWARE
According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data. It is also capable of taking screenshots and logging keystrokes.
Updated: 2023-11-17
View profile →
Dosia
Technical ID: win.dosia
NoName057(16)
MALWARE
Infrastructure and programs used for, as its name suggests, DDoSing. It used to be written in Python, nowadays it's written in Go. Clients: - Are written in Go. (Used to be written in Python.) - Do not seem to differ significantly across OS deployments. (Confirmed on Windows, MacOS, Linux, Android) - Seem to be partly run by NoName themselves. - Partly also run voluntarily, recruited via dedicated Telegram channels. Participants are rewarded with cryptocurrency. Prints a suggestion to use a VPN for Russia-based launches. (This yields IP-based blocking as rather ineffective, consider behavioral analysis instead.) Configuration: - Rotates near-daily. Can be browsed on https://witha.name/ (also reachable via http://withanamemwesdvodfhthjq25a5a3uas24cpgoa7qm6gchcerzpis6qd.onion/). - Is sent encrypted between C2 and Client. - Specifies target hostname, subpath, vector protocols, methods, ports, whether SSL is used, headers for HTTP, request bodies. - Any given config property can be randomly generated with per-use constraints. - Is provided by a multi-level hierarchy of C2 servers.
Also known as: DDOSIA
Updated: 2025-10-01
View profile →
Dorshel
Technical ID: win.dorshel
Energetic Bear
MALWARE
Malware family identifying win.dorshel. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-21
View profile →
NgrBot
Technical ID: win.dorkbot_ngrbot
MALWARE
Malware family identifying win.dorkbot_ngrbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-09
View profile →
DoppelPaymer
Technical ID: win.doppelpaymer
DOPPEL SPIDER
MALWAREfinancialhigh
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Also known as: Pay OR Grief
Updated: 2023-12-27
View profile →
DoppelDridex
Technical ID: win.doppeldridex
DOPPEL SPIDER
MALWARE
DoppelDridex is a fork of Indrik Spider's Dridex malware. DoppelDridex has been run as a parallel operation to Dridex with a different malware versioning system, different RSA key, and with different infrastructure.
Updated: 2023-12-27
View profile →
DOPLUGS
Technical ID: win.doplugs
MUSTANG PANDA
MALWARE
Malware family identifying win.doplugs. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-03-21
View profile →
DoorMe
Technical ID: win.doorme
MALWARE
Malware family identifying win.doorme. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-28
View profile →
donut_injector
Technical ID: win.donut_injector
MALWARE
Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It was used during attacks against U.S. organisations according to Threat Hunter Team (Symantec) and U.S. Defence contractors (Unit42). Github: https://github.com/TheWover/donut
Also known as: Donut
Updated: 2025-08-25
View profile →
DONOT
Technical ID: win.donot
VICEROY TIGER
MALWARE
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
Updated: 2024-06-05
View profile →
Donex
Technical ID: win.donex
MALWARE
Malware family identifying win.donex. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-29
View profile →
Minodo
Technical ID: win.domino
MALWARE
Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more sophisticated backdoors like Cobalt Strike. This backdoor collects basic system information, which it then transmits to the C2 server. In return, it receives an AES-encrypted payload. Notably, the Minodo Backdoor is designed to contact a different C2 address for domain-joined systems. This suggests that more capable backdoors, such as Cobalt Strike, are downloaded on higher-value targets instead of Project Nemesis.
Updated: 2023-10-05
View profile →
DogHousePower
Technical ID: win.doghousepower
MALWAREfinancialhigh
DogHousePower is a PyInstaller-based ransomware targeting web and database servers. It is delivered through a PowerShell downloader and was hosted on Github.
Also known as: Shelma
Updated: 2018-01-03
View profile →
dnWipe
Technical ID: win.dnwipe
MALWARE
Malware family identifying win.dnwipe. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-11-21
View profile →
DNSpionage
Technical ID: win.dnspionage
DNSpionage
MALWARE
Malware family identifying win.dnspionage. Origin and technical characteristics tracked via Malpedia.
Also known as: Agent Drable • AgentDrable • Webmask
Updated: 2024-10-14
View profile →
DNSMessenger
Technical ID: win.dnsmessenger
Anunak
MALWARE
DNSMessenger makes use of DNS TXT record queries and responses to create a bidirectional Command and Control (C2) channel. This allows the attacker to use DNS communications to submit new commands to be run on infected machines and return the results of the command execution to the attacker.
Also known as: TEXTMATE
Updated: 2023-07-05
View profile →
DNSChanger
Technical ID: win.dnschanger
MALWARE
Malware family identifying win.dnschanger. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-07-08
View profile →
DneSpy
Technical ID: win.dnespy
MALWAREespionageadvanced
DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.
Updated: 2020-11-09
View profile →
DMSniff
Technical ID: win.dmsniff
MALWARE
DMSniff is a point-of-sale malware previously only privately sold. It has been used in breaches of small- and medium-sized businesses in the restaurant and entertainment industries. It uses a domain generation algorithm (DGA) to create lists of command-and-control domains on the fly.
Updated: 2023-08-31
View profile →
DMA Locker
Technical ID: win.dma_locker
MALWARE
Malware family identifying win.dma_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →
DLRAT
Technical ID: win.dlrat
MALWARE
Malware family identifying win.dlrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-15
View profile →
Dizzyvoid
Technical ID: win.dizzyvoid
Earth Lusca
MALWARE
Malware family identifying win.dizzyvoid. Origin and technical characteristics tracked via Malpedia.
Also known as: Errorroot
Updated: 2024-03-25
View profile →
Diztakun
Technical ID: win.diztakun
MALWARE
Malware family identifying win.diztakun. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-15
View profile →
Divergent
Technical ID: win.divergent
MALWARE
Malware family identifying win.divergent. Origin and technical characteristics tracked via Malpedia.
Also known as: Novter
Updated: 2020-05-18
View profile →
DistTrack
Technical ID: win.disttrack
ShamoonMagic HoundTimberwormCOBALT GIPSY
MALWARE
Malware family identifying win.disttrack. Origin and technical characteristics tracked via Malpedia.
Also known as: Shamoon
Updated: 2023-01-19
View profile →
DispenserXFS
Technical ID: win.dispenserxfs
MALWARE
Malware family identifying win.dispenserxfs. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-07
View profile →
DispCashBR
Technical ID: win.dispcashbr
MALWARE
Malware family identifying win.dispcashbr. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-18
View profile →
← PreviousPage 172 / 269Next →