Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
Disk Knight
Technical ID: win.disk_knight
MALWARE
Malware family identifying win.disk_knight. Origin and technical characteristics tracked via Malpedia.
DirtyMoe
Technical ID: win.dirtymoe
MALWARE
Malware family identifying win.dirtymoe. Origin and technical characteristics tracked via Malpedia.
DirCrypt
Technical ID: win.dircrypt
MALWARE
Malware family identifying win.dircrypt. Origin and technical characteristics tracked via Malpedia.
MALWARE
Downloader.
DinodasRAT
Technical ID: win.dinodas_rat
MALWARE
Malware family identifying win.dinodas_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: XDealer
Dimnie
Technical ID: win.dimnie
MALWARE
Malware family identifying win.dimnie. Origin and technical characteristics tracked via Malpedia.
MALWARE
Downloader.
MALWAREespionageadvanced
APT10's fork of the (open-source) Quasar RAT.
DICELOADER
Technical ID: win.diceloader
MALWARE
A RAT written in .NET, used by FIN7 since 2021. In some instances dropped by ps1.powertrash.
Also known as: Lizar
Diavol
Technical ID: win.diavol
MALWAREfinancialhigh
A ransomware with potential ties to Wizard Spider.
DiamondFox
Technical ID: win.diamondfox
MALWARE
According to PCrisk, DiamondFox is highly modular malware offered as malware-as-a-service, and is for sale on various hacker forums. Therefore, cyber criminals who are willing to use DiamondFox do not necessarily require any technical knowledge to perform their attacks.
Once purchased, this malware can be used to log keystrokes, steal credentials (e.g., usernames, email addresses, passwords), hijack cryptocurrency wallets, perform distributed denial of service (DDoS) attacks, and to carry out other malicious tasks.
DiamondFox allows cyber criminals to choose which plug-ins to keep activated and see infection statistics in real-time.
Also known as: Crystal • Gorynych • Gorynch
Dharma
Technical ID: win.dharma
MALWAREfinancialhigh
According to MalwareBytes, the Dharma Ransomware family is installed manually by attackers hacking into computers over Remote Desktop Protocol Services (RDP). The attackers will scan the Internet for computers running RDP, usually on TCP port 3389, and then attempt to brute force the password for the computer.
Once they gain access to the computer they will install the ransomware and let it encrypt the computer. If the attackers are able to encrypt other computers on the network, they will attempt to do so as well.
Also known as: Arena • Crysis • Wadhrama • ncov
Dexter
Technical ID: win.dexter
MALWARE
Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security firm Seculert, in December 2012. It infects PoS systems worldwide and steals sensitive information such as Credit Card and Debit Card information.
Also known as: LusyPOS
Dexphot
Technical ID: win.dexphot
MALWARE
Dexphot is a cryptominer Malware attacking windows machines to gain profit from their resources. It implements many techniques to evade common security systems and a file-less technology to become inject malicious behavior. According to Microsoft the Dexphot It hijacked legitimate system processes to disguise malicious activity. If not stopped, Dexphot is equipped by monitoring services and scheduled tasks triggering re-infection when defenders attempt to remove the malware.
MALWARE
Malware family identifying win.dexbia. Origin and technical characteristics tracked via Malpedia.
Also known as: CONIME
DevOpt
Technical ID: win.devopt
MALWARE
Malware family identifying win.devopt. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
DEVMAN is a ransomware which shares a large part of its codebase with DragonForce ransomware. It is highly probable that the group used a DragonForce ransomware build and simply changed the extension added to the encrypted files (from .dragonforce_encrypted to .devman). In one of the first observed samples, the ransom note still claimed to be part of the DragonForce Ransomware Cartel.
The ransomware implements common features such as the deletion of ShadowCopies, and avoid encrypting files with some extensions present in a hard-coded list. The ransomware implements multiple encryption modes:
- Full encryption
- Header-only encryption
- Custom encryption
These modes allow the operator to choose between a quick or a strong encryption depending on the scenario. The ransomware also tries to connect to SMB folders.
DEVMAN ransomware creates a temporary session under the following registry key: `HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000`. The use of the Restart Manager to bypass file locks and ensure encrypted access to active user session files. This capability seems to be a legacy of Conti ransomware, which inspired DragonForce and DEVMAN. As part of this legacy, the ransomware use a hard-coded mutex to prevent multiple instances from running in parallel.
Devil's Rat
Technical ID: win.devils_rat
MALWARE
Malware family identifying win.devils_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-18
View profile →MALWARE
According to Microsoft, DevilsTongue is a complex modular multi-threaded piece of malware written in C and C++ with several novel capabilities.
For files on disk, PDB paths and PE timestamps are scrubbed, strings and configs are encrypted, and each file has a unique hash. The main functionality resides in DLLs that are encrypted on disk and only decrypted in memory, making detection more difficult. Configuration and tasking data is separate from the malware, which makes analysis harder. DevilsTongue has both user mode and kernel mode capabilities.
DesertBlade
Technical ID: win.desertblade
MALWARE
According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity. DesertBlade is responsible for iteratively overwriting and then deleting overwritten files on all accessible drives (sparing the system if it is a domain controller).
MALWAREespionageadvanced
A DLL backdoor also reported publicly as “Derusbi”, capable of obtaining directory, file, and drive listing; creating a reverse shell; performing screen captures; recording video and audio; listing, terminating, and creating processes; enumerating, starting, and deleting registry keys and values; logging keystrokes, returning usernames and passwords from protected storage; and renaming, deleting, copying, moving, reading, and writing to files.
Also known as: PHOTO
DeroHE
Technical ID: win.derohe
MALWAREfinancialhigh
DeroHE is a ransomware that was spread to users after IObit, a Windows utility developer, was hacked. The malware is delivered a DLL that is sideloaded by a legitimate, signed IObit License Manager application.
DeriaLock
Technical ID: win.deria_lock
MALWARE
Malware family identifying win.deria_lock. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.deputydog. Origin and technical characteristics tracked via Malpedia.
Deputy
Technical ID: win.deputy
MALWARE
According to IBM X-Force, this is a loader component for Sheriff.
MALWARE
According to ESET Research, DePriMon is a malicious downloader, with several stages and using many non-traditional techniques. To achieve persistence, the malware registers a new local port monitor – a trick falling under the “Port Monitors” technique in the MITRE ATT&CK knowledgebase. For that, the malware uses the “Windows Default Print Monitor” name; that’s why we have named it DePriMon. Due to its complexity and modular architecture, researcher believe it to be a framework.
DePriMon has been active since at least March 2017. DePriMon was detected in a private company, based in Central Europe, and at dozens of computers in the Middle East.
Dented
Technical ID: win.dented
MALWAREfinancialhigh
Dented is a banking bot written in C. It supports IE, Firefox, Chrome, Opera and Edge and comes with a simple POS grabber. Due to its modularity, reverse socks 5, tor and vnc can be added.
Updated: 2017-11-16
View profile →DeltaStealer
Technical ID: win.deltastealer
MALWARE
Rust-based infostealer.
MALWARE
Malware family identifying win.deltas. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-07-12
View profile →MALWARE
According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking. Its specificity is the presence of a server part, which is usually installed on compromised MS Exchange servers in the form of a MOF (Managed Object Format) file using the Desired State Configuration (DCS) PowerShell tool), effectively turning a legitimate server into a malware control center.
Also known as: GAMEDAY • CAPIBAR
DeimosC2
Technical ID: win.deimos_c2
MALWARE
Trend Micro describes DeimosC2 as an open-source C&C framework that was released in June 2020. It is a fully-functional framework that allows for multiple attackers to access, create payloads for, and interact with victim computers. As a post-exploitation C&C framework, DeimosC2 will generate the payloads that need to be manually executed on computer servers that have been compromised through other means such as social engineering, exploitation, or brute-force attacks. Once it is deployed, the threat actors will gain the same access to the systems as the user account that the payload was executed as, either as an administrator or a regular user. Note that DeimosC2 does not perform active or privilege escalation of any kind.
Deimos
Technical ID: win.deimos
MALWARE
Described by Elastic as being associated with win.jupyter, and being used in the context of initial access, persistence, and C&C capabilities.
Defray
Technical ID: win.defray
MALWAREfinancialhigh
Defray is ransomware that appeared in 2017, and is targeted ransomware, mainly on the healthcare vertical.
The distribution of Defray has several notable characteristics:
According to Proofpoint:
"
Defray is currently being spread via Microsoft Word document attachments in email
The campaigns are as small as several messages each
The lures are custom crafted to appeal to the intended set of potential victims
The recipients are individuals or distribution lists, e.g., group@ and websupport@
Geographic targeting is in the UK and US
Vertical targeting varies by campaign and is narrow and selective
"
Also known as: Glushkov
DeerStealer
Technical ID: win.deerstealer
MALWARE
According to Broadcom, DeerStealer is an information stealer written in Delphi and targeting devices running an windows operating system. The malware has hidden VNC capabilities for stealthy remote desktop control, collecting crypto wallets from USB sticks and over 800 browser extensions. It exfiltrates the stolen data in form of a ZIP archive to a botnet C2 server.
DeepRAT
Technical ID: win.deep_rat
MALWARE
Malware family identifying win.deep_rat. Origin and technical characteristics tracked via Malpedia.
DEEPPOST
Technical ID: win.deeppost
MALWARE
According to Volexity, DEEPPOST is a post-exploitation data exfiltration tool used to send files to a remote system.
DEEPDATA
Technical ID: win.deepdata
MALWARE
According to Volexity, DEEPDATA is a modular post-exploitation tool for Windows that facilitates collection of sensitive information from a compromised system. This tool must be run from the command line of a system by an attacker.
MALWARE
Malware family identifying win.deepcreep. Origin and technical characteristics tracked via Malpedia.
Decebal
Technical ID: win.decebal
MALWARE
Malware family identifying win.decebal. Origin and technical characteristics tracked via Malpedia.
DECAF
Technical ID: win.decaf
MALWAREfinancialhigh
Ransomware written in Go.