Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
DragonBreath
Technical ID: win.dragonbreath
MALWARE
Malware family identifying win.dragonbreath. Origin and technical characteristics tracked via Malpedia.
MALWARE
Cyber Defense Institute stated that this shellcode PE loader was observed staging win.hemigate.
MALWAREespionageadvanced
DownPaper, sometimes delivered as sami.exe, is a Backdoor trojan. Its main functionality is to download
and run a second stage. This malware has been observed in campaigns involving Charming Kitten, an Iranian cyberespionage group.
MALWARE
According to Bitdefender, this is an exfiltration tool, scanning local and network drives for sensitive files, like documents, archives, certificates, and cryptographic keys.
Downeks
Technical ID: win.downeks
MALWARE
Malware family identifying win.downeks. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.downdelph. Origin and technical characteristics tracked via Malpedia.
Also known as: DELPHACY
DoubleZero
Technical ID: win.doublezero
MALWARE
A wiper identified by CERT-UA on March 17th, written in C#.
Also known as: FiberLake
MALWARE
Malware family identifying win.doublepulsar. Origin and technical characteristics tracked via Malpedia.
DOUBLELOADER
Technical ID: win.doubleloader
MALWARE
Malware family identifying win.doubleloader. Origin and technical characteristics tracked via Malpedia.
DoubleFinger
Technical ID: win.doublefinger
MALWARE
Malware family identifying win.doublefinger. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.doublefantasy. Origin and technical characteristics tracked via Malpedia.
Also known as: VALIDATOR
DOUBLEBACK
Technical ID: win.doubleback
MALWARE
DOUBLEBACK is a newly discovered fileless malware deployed as part of an attack campaign that took place in December 2020. The threat actors responsible for the operations are tracked as UNC2529 by researchers. According to their findings, DOUBLEBACK is the final payload delivered onto the compromised systems. Its task is to establish and maintain a backdoor on the victim's machine.
Dot Ransomware
Technical ID: win.dot_ransomware
MALWAREfinancialhigh
Malware family identifying win.dot_ransomware. Origin and technical characteristics tracked via Malpedia.
Also known as: MZP Ransomware
DOSTEALER
Technical ID: win.dostealer
MALWARE
According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data. It is also capable of taking screenshots and logging keystrokes.
MALWARE
Infrastructure and programs used for, as its name suggests, DDoSing.
It used to be written in Python, nowadays it's written in Go. Clients:
- Are written in Go. (Used to be written in Python.)
- Do not seem to differ significantly across OS deployments. (Confirmed on Windows, MacOS, Linux, Android)
- Seem to be partly run by NoName themselves.
- Partly also run voluntarily, recruited via dedicated Telegram channels. Participants are rewarded with cryptocurrency. Prints a suggestion to use a VPN for Russia-based launches. (This yields IP-based blocking as rather ineffective, consider behavioral analysis instead.)
Configuration:
- Rotates near-daily. Can be browsed on https://witha.name/ (also reachable via http://withanamemwesdvodfhthjq25a5a3uas24cpgoa7qm6gchcerzpis6qd.onion/).
- Is sent encrypted between C2 and Client.
- Specifies target hostname, subpath, vector protocols, methods, ports, whether SSL is used, headers for HTTP, request bodies.
- Any given config property can be randomly generated with per-use constraints.
- Is provided by a multi-level hierarchy of C2 servers.
Also known as: DDOSIA
MALWARE
Malware family identifying win.dorshel. Origin and technical characteristics tracked via Malpedia.
NgrBot
Technical ID: win.dorkbot_ngrbot
MALWARE
Malware family identifying win.dorkbot_ngrbot. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
Doppelpaymer is a ransomware family that encrypts user data and later on it asks for a ransom in order to restore original files. It is recognizable by its trademark file extension added to encrypted files: .doppeled. It also creates a note file named: ".how2decrypt.txt".
Also known as: Pay OR Grief
MALWARE
DoppelDridex is a fork of Indrik Spider's Dridex malware. DoppelDridex has been run as a parallel operation to Dridex with a different malware versioning system, different RSA key, and with different infrastructure.
MALWARE
Malware family identifying win.doplugs. Origin and technical characteristics tracked via Malpedia.
DoorMe
Technical ID: win.doorme
MALWARE
Malware family identifying win.doorme. Origin and technical characteristics tracked via Malpedia.
donut_injector
Technical ID: win.donut_injector
MALWARE
Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It was used during attacks against U.S. organisations according to Threat Hunter Team (Symantec) and U.S. Defence contractors (Unit42).
Github: https://github.com/TheWover/donut
Also known as: Donut
MALWARE
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
Donex
Technical ID: win.donex
MALWARE
Malware family identifying win.donex. Origin and technical characteristics tracked via Malpedia.
Minodo
Technical ID: win.domino
MALWARE
Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more sophisticated backdoors like Cobalt Strike. This backdoor collects basic system information, which it then transmits to the C2 server. In return, it receives an AES-encrypted payload. Notably, the Minodo Backdoor is designed to contact a different C2 address for domain-joined systems. This suggests that more capable backdoors, such as Cobalt Strike, are downloaded on higher-value targets instead of Project Nemesis.
DogHousePower
Technical ID: win.doghousepower
MALWAREfinancialhigh
DogHousePower is a PyInstaller-based ransomware targeting web and database servers. It is delivered through a PowerShell downloader and was hosted on Github.
Also known as: Shelma
dnWipe
Technical ID: win.dnwipe
MALWARE
Malware family identifying win.dnwipe. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.dnspionage. Origin and technical characteristics tracked via Malpedia.
Also known as: Agent Drable • AgentDrable • Webmask
MALWARE
DNSMessenger makes use of DNS TXT record queries and responses to create a bidirectional Command and Control (C2) channel. This allows the attacker to use DNS communications to submit new commands to be run on infected machines and return the results of the command execution to the attacker.
Also known as: TEXTMATE
DNSChanger
Technical ID: win.dnschanger
MALWARE
Malware family identifying win.dnschanger. Origin and technical characteristics tracked via Malpedia.
DneSpy
Technical ID: win.dnespy
MALWAREespionageadvanced
DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.
DMSniff
Technical ID: win.dmsniff
MALWARE
DMSniff is a point-of-sale malware previously only privately sold. It has been used in breaches of small- and medium-sized businesses in the restaurant and entertainment industries. It uses a domain generation algorithm (DGA) to create lists of command-and-control domains on the fly.
DMA Locker
Technical ID: win.dma_locker
MALWARE
Malware family identifying win.dma_locker. Origin and technical characteristics tracked via Malpedia.
DLRAT
Technical ID: win.dlrat
MALWARE
Malware family identifying win.dlrat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.dizzyvoid. Origin and technical characteristics tracked via Malpedia.
Also known as: Errorroot
Diztakun
Technical ID: win.diztakun
MALWARE
Malware family identifying win.diztakun. Origin and technical characteristics tracked via Malpedia.
Divergent
Technical ID: win.divergent
MALWARE
Malware family identifying win.divergent. Origin and technical characteristics tracked via Malpedia.
Also known as: Novter
MALWARE
Malware family identifying win.disttrack. Origin and technical characteristics tracked via Malpedia.
Also known as: Shamoon
DispenserXFS
Technical ID: win.dispenserxfs
MALWARE
Malware family identifying win.dispenserxfs. Origin and technical characteristics tracked via Malpedia.
DispCashBR
Technical ID: win.dispcashbr
MALWARE
Malware family identifying win.dispcashbr. Origin and technical characteristics tracked via Malpedia.