Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
DeathRansom
Technical ID: win.deathransom
MALWAREfinancialhigh
Also known as Wacatac ransomware due to its .wctc extension.
Also known as: deathransom • wacatac
dearcry
Technical ID: win.dearcry
MALWAREfinancialhigh
According to PCrisk, DearCry ransomware has been observed infecting systems via ProxyLogon vulnerabilities of Microsoft Exchange servers - mail and calendaring servers developed by Microsoft. While a patch has been released addressing these vulnerabilities, thousands of Microsoft Exchange servers remained unpatched at the time of research.
Also known as: DoejoCrypt
DealPly
Technical ID: win.dealply
MALWARE
Malware family identifying win.dealply. Origin and technical characteristics tracked via Malpedia.
DEADWOOD
Technical ID: win.deadwood
MALWARE
Malware family identifying win.deadwood. Origin and technical characteristics tracked via Malpedia.
Also known as: Agrius • SQLShred • DETBOSIT
MALWARE
Malware family identifying win.ddkong. Origin and technical characteristics tracked via Malpedia.
DDKeylogger
Technical ID: win.ddkeylogger
MALWARE
Malware family identifying win.ddkeylogger. Origin and technical characteristics tracked via Malpedia.
DCSrv
Technical ID: win.dcsrv
MALWAREfinancialhigh
A ransomware as used by MosesStaff, built around the DiskCryptor tool.
Also known as: DCrSrv
DCRat
Technical ID: win.dcrat
MALWARE
DCRat is a typical RAT that has been around since at least June 2019.
Also known as: DarkCrystal RAT
DcDcrypt
Technical ID: win.dcdcrypt
MALWAREfinancialhigh
Ransomware written in .NET.
MALWARE
This malware uses DropBox as C&C channel.
DBatLoader
Technical ID: win.dbatloader
MALWARE
This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component. The Delphi stager has the actual payload embedded as a resource and starts it.
Also known as: ModiLoader • NatsoLoader
Daxin
Technical ID: win.daxin
MALWARE
Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors. The malware has a custom TCP/IP stack and is capable of hijacking connections.
Also known as: DELIMEAT
MALWARE
Malware family identifying win.datper. Origin and technical characteristics tracked via Malpedia.
DataExfiltrator
Technical ID: win.data_exfiltrator
MALWARE
Malware family identifying win.data_exfiltrator. Origin and technical characteristics tracked via Malpedia.
Also known as: FileSender
MALWARE
Malware family identifying win.daserf. Origin and technical characteristics tracked via Malpedia.
Also known as: Muirim • Nioupale
DarkVNC
Technical ID: win.darkvnc
MALWARE
According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online. it is can be used as a Virtual Network Computing service, which means that the attackers can get full access to the targeted system via this malware. However, unlike a genuine Virtual Network Computing utility, the DarkVNC threat operates in the background silently. Therefore, it is highly likely that the victims may not notice that their systems have been compromised.
DarkVision RAT
Technical ID: win.darkvision_rat
MALWAREespionageadvanced
DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020. Written in C/C++ and assembler, it has gained popularity due to its low cost and broad range of functionalities, including keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. In July 2024, a malware campaign was observed distributing DarkVision_RAT using PureCrypter as a loader. This RAT communicates with its command and control server through a custom network protocol via sockets. It also employs evasion and privilege escalation techniques such as DLL hijacking, self-elevation, and process injection. DarkVision_RAT supports a wide array of commands and plugins, enabling additional capabilities like keylogging, remote access, password theft, audio recording, and screenshot capture.
Darktrack RAT
Technical ID: win.darktrack_rat
MALWARE
According to PCrisk, DarkTrack is a malicious program classified as a Remote Access Trojan (RAT). This type of malware enables remote access and control over an infected device. The level of control these programs have varies, however, some can allow user-level manipulation of the affected machine.
The functionalities of RATs likewise varies and so does the scope of potential misuse. DarkTrack has a broad range of functions/capabilities, which make this Trojan a highly-dangerous piece of software.
DarkTortilla
Technical ID: win.darktortilla
MALWARE
DarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015. It typically delivers popular information stealers and remote access trojans (RATs) such as AgentTesla, AsyncRat, NanoCore, and RedLine. While it appears to primarily deliver commodity malware, Secureworks® Counter Threat Unit™ (CTU) researchers identified DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit. It can also deliver "addon packages" such as additional malicious payloads, benign decoy documents, and executables. It features robust anti-analysis and anti-tamper controls that can make detection, analysis, and eradication challenging.
From January 2021 through May 2022, an average of 93 unique DarkTortilla samples per week were uploaded to the VirusTotal analysis service. Code similarities suggest possible links between DarkTortilla and other malware: a crypter operated by the RATs Crew threat group, which was active between 2008 and 2012, and the Gameloader malware that emerged in 2021.
DarkTequila
Technical ID: win.darktequila
MALWAREfinancialhigh
Dark Tequila is a complex malicious campaign targeting Mexican users, with the primary purpose of stealing financial information, as well as login credentials to popular websites that range from code versioning repositories to public file storage accounts and domain registrars.
DarkStRat
Technical ID: win.darkstrat
MALWARE
Malware family identifying win.darkstrat. Origin and technical characteristics tracked via Malpedia.
Darksky
Technical ID: win.darksky
MALWARE
DarkSky is a botnet that is capable of downloading malware, conducting a number of network and application-layer distributed denial-of-service (DDoS) attacks, and detecting and evading security controls, such as sandboxes and virtual machines. It is advertised for sale on the dark web for $20. Much of the malware that DarkSky has available to download onto targeted systems is associated with cryptocurrency-mining activity. The DDoS attacks that DarkSky can perform include DNS amplification attacks, TCP (SYN) flood, UDP flood, and HTTP flood. The botnet can also perform a check to determine whether or not the DDoS attack succeeded and turn infected systems into a SOCKS/HTTP proxy to route traffic to a remote server.
DarkSide
Technical ID: win.darkside
MALWAREfinancialhigh
FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable disks, or network shares. The malware can be customized by the affiliates to create a build for specific victims.
Also known as: BlackMatter
DarkShell
Technical ID: win.darkshell
MALWARE
DarkShell is a DDoS bot seemingly of Chinese origin, discovered in 2011. During 2011, DarkShell was reported to target the industrial food processing industry.
DarkRat
Technical ID: win.darkrat
MALWARE
Malware family identifying win.darkrat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.darkpulsar. Origin and technical characteristics tracked via Malpedia.
Darkmoon
Technical ID: win.darkmoon
MALWARE
Malware family identifying win.darkmoon. Origin and technical characteristics tracked via Malpedia.
Also known as: Chymine
DarkMegi
Technical ID: win.darkmegi
MALWARE
Malware family identifying win.darkmegi. Origin and technical characteristics tracked via Malpedia.
DarkMe
Technical ID: win.darkme
MALWARE
Malware family identifying win.darkme. Origin and technical characteristics tracked via Malpedia.
DarkLoader
Technical ID: win.darkloader
MALWARE
Malware family identifying win.darkloader. Origin and technical characteristics tracked via Malpedia.
DarkIRC
Technical ID: win.darkirc
MALWARE
Malware family identifying win.darkirc. Origin and technical characteristics tracked via Malpedia.
DarkGate
Technical ID: win.darkgate
MALWARE
First documented in 2018, DarkGate is a commodity loader with features that include the ability to download and execute files to memory, a Hidden Virtual Network Computing (HVNC) module, keylogging, information-stealing capabilities, and privilege escalation. DarkGate makes use of legitimate AutoIt files and typically runs multiple AutoIt scripts. New versions of DarkGate have been advertised on a Russian language eCrime forum since May 2023.
Also known as: Meh • MehCrypter
DarkEye
Technical ID: win.darkeye
MALWARE
Malware family identifying win.darkeye. Origin and technical characteristics tracked via Malpedia.
DARKDEW
Technical ID: win.darkdew
MALWARE
Mandiant associates this with UNC4191, this malware spreads to removable drives.
MALWARE
DarkComet is one of the most famous RATs, developed by Jean-Pierre Lesueur in 2008. After being used in the Syrian civil war in 2011, Lesuer decided to stop developing the trojan. Indeed, DarkComet is able to enable control over a compromised system through use of a simple graphic user interface. Experts think that this user friendliness is the key of its mass success.
Also known as: Breut • Fynloski • klovbot
DarkCloud Stealer
Technical ID: win.darkcloud
MALWARE
Stealer is written in Visual Basic.
DarkBit
Technical ID: win.darkbit
MALWARE
Malware family identifying win.darkbit. Origin and technical characteristics tracked via Malpedia.
Daolpu
Technical ID: win.daolpu
MALWARE
Malware family identifying win.daolpu. Origin and technical characteristics tracked via Malpedia.
Dante
Technical ID: win.dante
MALWARE
According to Kaspersky Labs, Dante is the commercial spyware developed by Memento Labs (formerly Hacking Team).
DanderSpritz
Technical ID: win.danderspritz
MALWARE
Malware family identifying win.danderspritz. Origin and technical characteristics tracked via Malpedia.
Also known as: Dsz