Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
DeathRansom
Technical ID: win.deathransom
MALWAREfinancialhigh
Also known as Wacatac ransomware due to its .wctc extension.
Also known as: deathransom • wacatac
Updated: 2025-12-15
View profile →
dearcry
Technical ID: win.dearcry
MALWAREfinancialhigh
According to PCrisk, DearCry ransomware has been observed infecting systems via ProxyLogon vulnerabilities of Microsoft Exchange servers - mail and calendaring servers developed by Microsoft. While a patch has been released addressing these vulnerabilities, thousands of Microsoft Exchange servers remained unpatched at the time of research.
Also known as: DoejoCrypt
Updated: 2023-05-21
View profile →
DealPly
Technical ID: win.dealply
MALWARE
Malware family identifying win.dealply. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-25
View profile →
DEADWOOD
Technical ID: win.deadwood
MALWARE
Malware family identifying win.deadwood. Origin and technical characteristics tracked via Malpedia.
Also known as: Agrius • SQLShred • DETBOSIT
Updated: 2023-01-19
View profile →
DDKONG
Technical ID: win.ddkong
RANCOR
MALWARE
Malware family identifying win.ddkong. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
DDKeylogger
Technical ID: win.ddkeylogger
MALWARE
Malware family identifying win.ddkeylogger. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-27
View profile →
DCSrv
Technical ID: win.dcsrv
MALWAREfinancialhigh
A ransomware as used by MosesStaff, built around the DiskCryptor tool.
Also known as: DCrSrv
Updated: 2021-11-17
View profile →
DCRat
Technical ID: win.dcrat
MALWARE
DCRat is a typical RAT that has been around since at least June 2019.
Also known as: DarkCrystal RAT
Updated: 2026-01-19
View profile →
DcDcrypt
Technical ID: win.dcdcrypt
MALWAREfinancialhigh
Ransomware written in .NET.
Updated: 2022-09-30
View profile →
DBoxAgent
Technical ID: win.dboxagent
APT41
MALWARE
This malware uses DropBox as C&C channel.
Updated: 2022-11-18
View profile →
DBatLoader
Technical ID: win.dbatloader
MALWARE
This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component. The Delphi stager has the actual payload embedded as a resource and starts it.
Also known as: ModiLoader • NatsoLoader
Updated: 2025-05-20
View profile →
Daxin
Technical ID: win.daxin
MALWARE
Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors. The malware has a custom TCP/IP stack and is capable of hijacking connections.
Also known as: DELIMEAT
Updated: 2023-07-19
View profile →
Datper
Technical ID: win.datper
Tick
MALWARE
Malware family identifying win.datper. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-02
View profile →
DataExfiltrator
Technical ID: win.data_exfiltrator
MALWARE
Malware family identifying win.data_exfiltrator. Origin and technical characteristics tracked via Malpedia.
Also known as: FileSender
Updated: 2021-07-21
View profile →
Daserf
Technical ID: win.daserf
Tick
MALWARE
Malware family identifying win.daserf. Origin and technical characteristics tracked via Malpedia.
Also known as: Muirim • Nioupale
Updated: 2020-05-23
View profile →
DarkVNC
Technical ID: win.darkvnc
MALWARE
According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online. it is can be used as a Virtual Network Computing service, which means that the attackers can get full access to the targeted system via this malware. However, unlike a genuine Virtual Network Computing utility, the DarkVNC threat operates in the background silently. Therefore, it is highly likely that the victims may not notice that their systems have been compromised.
Updated: 2023-05-21
View profile →
DarkVision RAT
Technical ID: win.darkvision_rat
MALWAREespionageadvanced
DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020. Written in C/C++ and assembler, it has gained popularity due to its low cost and broad range of functionalities, including keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. In July 2024, a malware campaign was observed distributing DarkVision_RAT using PureCrypter as a loader. This RAT communicates with its command and control server through a custom network protocol via sockets. It also employs evasion and privilege escalation techniques such as DLL hijacking, self-elevation, and process injection. DarkVision_RAT supports a wide array of commands and plugins, enabling additional capabilities like keylogging, remote access, password theft, audio recording, and screenshot capture.
Updated: 2024-11-25
View profile →
Darktrack RAT
Technical ID: win.darktrack_rat
MALWARE
According to PCrisk, DarkTrack is a malicious program classified as a Remote Access Trojan (RAT). This type of malware enables remote access and control over an infected device. The level of control these programs have varies, however, some can allow user-level manipulation of the affected machine. The functionalities of RATs likewise varies and so does the scope of potential misuse. DarkTrack has a broad range of functions/capabilities, which make this Trojan a highly-dangerous piece of software.
Updated: 2025-02-25
View profile →
DarkTortilla
Technical ID: win.darktortilla
MALWARE
DarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015. It typically delivers popular information stealers and remote access trojans (RATs) such as AgentTesla, AsyncRat, NanoCore, and RedLine. While it appears to primarily deliver commodity malware, Secureworks® Counter Threat Unit™ (CTU) researchers identified DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit. It can also deliver "addon packages" such as additional malicious payloads, benign decoy documents, and executables. It features robust anti-analysis and anti-tamper controls that can make detection, analysis, and eradication challenging. From January 2021 through May 2022, an average of 93 unique DarkTortilla samples per week were uploaded to the VirusTotal analysis service. Code similarities suggest possible links between DarkTortilla and other malware: a crypter operated by the RATs Crew threat group, which was active between 2008 and 2012, and the Gameloader malware that emerged in 2021.
Updated: 2023-01-05
View profile →
DarkTequila
Technical ID: win.darktequila
MALWAREfinancialhigh
Dark Tequila is a complex malicious campaign targeting Mexican users, with the primary purpose of stealing financial information, as well as login credentials to popular websites that range from code versioning repositories to public file storage accounts and domain registrars.
Updated: 2018-08-31
View profile →
DarkStRat
Technical ID: win.darkstrat
MALWARE
Malware family identifying win.darkstrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-11
View profile →
Darksky
Technical ID: win.darksky
MALWARE
DarkSky is a botnet that is capable of downloading malware, conducting a number of network and application-layer distributed denial-of-service (DDoS) attacks, and detecting and evading security controls, such as sandboxes and virtual machines. It is advertised for sale on the dark web for $20. Much of the malware that DarkSky has available to download onto targeted systems is associated with cryptocurrency-mining activity. The DDoS attacks that DarkSky can perform include DNS amplification attacks, TCP (SYN) flood, UDP flood, and HTTP flood. The botnet can also perform a check to determine whether or not the DDoS attack succeeded and turn infected systems into a SOCKS/HTTP proxy to route traffic to a remote server.
Updated: 2018-03-27
View profile →
DarkSide
Technical ID: win.darkside
MALWAREfinancialhigh
FireEye describes DARKSIDE as a ransomware written in C and configurable to target files whether on fixed, removable disks, or network shares. The malware can be customized by the affiliates to create a build for specific victims.
Also known as: BlackMatter
Updated: 2025-02-19
View profile →
DarkShell
Technical ID: win.darkshell
MALWARE
DarkShell is a DDoS bot seemingly of Chinese origin, discovered in 2011. During 2011, DarkShell was reported to target the industrial food processing industry.
Updated: 2023-07-24
View profile →
DarkRat
Technical ID: win.darkrat
MALWARE
Malware family identifying win.darkrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-04-15
View profile →
DarkPulsar
Technical ID: win.darkpulsar
Equation Group
MALWARE
Malware family identifying win.darkpulsar. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-01
View profile →
Darkmoon
Technical ID: win.darkmoon
MALWARE
Malware family identifying win.darkmoon. Origin and technical characteristics tracked via Malpedia.
Also known as: Chymine
Updated: 2018-06-28
View profile →
DarkMegi
Technical ID: win.darkmegi
MALWARE
Malware family identifying win.darkmegi. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-28
View profile →
DarkMe
Technical ID: win.darkme
MALWARE
Malware family identifying win.darkme. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-14
View profile →
DarkLoader
Technical ID: win.darkloader
MALWARE
Malware family identifying win.darkloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-22
View profile →
DarkIRC
Technical ID: win.darkirc
MALWARE
Malware family identifying win.darkirc. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-31
View profile →
DarkGate
Technical ID: win.darkgate
MALWARE
First documented in 2018, DarkGate is a commodity loader with features that include the ability to download and execute files to memory, a Hidden Virtual Network Computing (HVNC) module, keylogging, information-stealing capabilities, and privilege escalation. DarkGate makes use of legitimate AutoIt files and typically runs multiple AutoIt scripts. New versions of DarkGate have been advertised on a Russian language eCrime forum since May 2023.
Also known as: Meh • MehCrypter
Updated: 2025-07-01
View profile →
DarkEye
Technical ID: win.darkeye
MALWARE
Malware family identifying win.darkeye. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-09-07
View profile →
DARKDEW
Technical ID: win.darkdew
MALWARE
Mandiant associates this with UNC4191, this malware spreads to removable drives.
Updated: 2022-12-02
View profile →
DarkComet
Technical ID: win.darkcomet
APT33Lazarus GroupOperation C-Major
MALWARE
DarkComet is one of the most famous RATs, developed by Jean-Pierre Lesueur in 2008. After being used in the Syrian civil war in 2011, Lesuer decided to stop developing the trojan. Indeed, DarkComet is able to enable control over a compromised system through use of a simple graphic user interface. Experts think that this user friendliness is the key of its mass success.
Also known as: Breut • Fynloski • klovbot
Updated: 2024-11-29
View profile →
DarkCloud Stealer
Technical ID: win.darkcloud
MALWARE
Stealer is written in Visual Basic.
Updated: 2025-05-23
View profile →
DarkBit
Technical ID: win.darkbit
MALWARE
Malware family identifying win.darkbit. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-08-21
View profile →
Daolpu
Technical ID: win.daolpu
MALWARE
Malware family identifying win.daolpu. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-21
View profile →
Dante
Technical ID: win.dante
MALWARE
According to Kaspersky Labs, Dante is the commercial spyware developed by Memento Labs (formerly Hacking Team).
Updated: 2025-11-05
View profile →
DanderSpritz
Technical ID: win.danderspritz
MALWARE
Malware family identifying win.danderspritz. Origin and technical characteristics tracked via Malpedia.
Also known as: Dsz
Updated: 2025-10-20
View profile →
← PreviousPage 174 / 269Next →