Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
danbot
Technical ID: win.danbot
MALWARE
Danbot is a backdoor malware that is originally written in C#. Recent versions of Danbot are written in C++. Danbot is capable of giving a remote attacker remote access features such as running a cmd command, upload and download files, move and copy files. The backdoor commands are transmitted by either using HTTP or DNS protocols. The commands are encapsulated in an XML file that gets stored in disk. Danbot's backdoor component picks up the XML file where it decodes and decrypts the commands.
Updated: 2022-02-14
View profile →
DanaBot
Technical ID: win.danabot
SCULLY SPIDER
MALWARE
Proofpoints describes DanaBot as the latest example of malware focused on persistence and stealing useful information that can later be monetized rather than demanding an immediate ransom from victims. The social engineering in the low-volume DanaBot campaigns we have observed so far has been well-crafted, again pointing to a renewed focus on “quality over quantity” in email-based threats. DanaBot’s modular nature enables it to download additional components, increasing the flexibility and robust stealing and remote monitoring capabilities of this banker.
Also known as: DanaTools
Updated: 2025-11-25
View profile →
Dairy
Technical ID: win.dairy
Comment Crew
MALWARE
Malware family identifying win.dairy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
DADSTACHE
Technical ID: win.dadstache
Leviathan
MALWARE
Malware family identifying win.dadstache. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-11
View profile →
DADJOKE
Technical ID: win.dadjoke
Leviathan
MALWAREespionageadvanced
DADJOKE was discovered as being distributed via email, targeting a South-East Asian Ministry of Defense. It is delivered as an embedded EXE file in a Word document using remote templates and a unique macro using multiple GET requests. The payload is deployed using load-order hijacking with a benign Windows Defender executable. Stage 1 has only beacon+download functionality, made to look like a PNG file. Additional analysis by Kaspersky found 8 campaigns over 2019 and no activity prior to January 2019, DADJOKE is attributed with medium confidence to APT40.
Updated: 2020-02-09
View profile →
Dacls
Technical ID: win.dacls
Lazarus Group
MALWARE
According to PCrisk, Dacls is the name of a remote access Trojan (RAT), a malicious program that allows cyber criminals to control infected computers remotely. Research shows that this malware is tied to Lazarus Group (a group of cyber criminals) and targets Linux and the Windows Operating System. Typically, cyber criminals use RATs to steal sensitive, confidential information, infect systems with other malware, and so on. In any case, no RAT is harmless and should be uninstalled immediately.
Also known as: MATA
Updated: 2024-11-25
View profile →
cysxl
Technical ID: win.cysxl
MALWARE
Malware family identifying win.cysxl. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-25
View profile →
Cyrat
Technical ID: win.cyrat
MALWAREfinancialhigh
According to gdatasoftware, Cyrat ransomware uses Fernet to encrypt files. This is a symmetric encryption method meant for small data files that fit into RAM. While Fernet is not unusual itself, it is not common for ransomware and in this case even problematic.
Updated: 2023-05-21
View profile →
Cyclops
Technical ID: win.cyclops
MALWARE
According to HarfangLabs, Cyclops is a malware platform written in Go which dates back to December 2023, and that they believe has been deployed against targets in the Middle-East in 2024. Cyclops allows operators to execute arbitrary commands on the target’s file system, as well as pivot inside the infected network. Notably, Cyclops is controlled through a HTTP REST API which is exposed to operators within an SSH tunnel.
Updated: 2025-02-28
View profile →
CycBot
Technical ID: win.cycbot
MALWARE
Malware family identifying win.cycbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-01-19
View profile →
CyberSplitter
Technical ID: win.cyber_splitter
MALWARE
Malware family identifying win.cyber_splitter. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-27
View profile →
CyberGate
Technical ID: win.cybergate
MALWARE
According to Subex Secure, CyberGate is a Remote Access Trojan (RAT) that allows an attacker to gain unauthorized access to the victim’s system. Attackers can remotely connect to the compromised system from anywhere around the world. The Malware author generally uses this program to steal private information like passwords, files, etc. It might also be used to install malicious software on the compromised systems.
Also known as: Rebhip
Updated: 2024-08-15
View profile →
Cutwail
Technical ID: win.cutwail
NARWHAL SPIDER
MALWARE
Malware family identifying win.cutwail. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
Cutlet
Technical ID: win.cutlet
MALWARE
Malware family identifying win.cutlet. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-04-25
View profile →
CustomerLoader
Technical ID: win.customerloader
MALWARE
CustomerLoader is a .Net-based loader that drops more than 40 different malware families. It appeared in June 2023 and is being distributed via phishing, YouTube videos and malicious websites.
Updated: 2024-12-09
View profile →
Cursed Murderer
Technical ID: win.cursed_murderer
MALWAREfinancialhigh
Ransomware.
Updated: 2020-02-10
View profile →
CurlBack RAT
Technical ID: win.curlback
SideCopy
MALWARE
Malware family identifying win.curlback. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-04-09
View profile →
Curator
Technical ID: win.curator
MALWAREfinancialhigh
Profero describes this as a ransomware family using CryptoPP as library to enable file encryption with the Salsa20 algorithm and protecting the encryption keys with RSA2048.
Also known as: Ever101 • SunnyDay
Updated: 2023-01-05
View profile →
Cur1Downloader
Technical ID: win.cur1_downloader
Lazarus Group
MALWARE
Potential Lazarus sample.
Updated: 2023-07-12
View profile →
Cueisfry
Technical ID: win.cueisfry
MALWARE
Malware family identifying win.cueisfry. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-03-23
View profile →
Cuegoe
Technical ID: win.cuegoe
APT32
MALWARE
Malware family identifying win.cuegoe. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-19
View profile →
Cuba
Technical ID: win.cuba
MALWAREfinancialhigh
Ransomware.
Also known as: COLDDRAW
Updated: 2025-03-05
View profile →
CTB Locker
Technical ID: win.ctb_locker
MALWARE
Malware family identifying win.ctb_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-09-12
View profile →
csharp-streamer RAT
Technical ID: win.csharpstreamer
MALWARE
Malware family identifying win.csharpstreamer. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-25
View profile →
CsExt
Technical ID: win.csext
Cleaver
MALWARE
Malware family identifying win.csext. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-21
View profile →
Crytox
Technical ID: win.crytox
MALWAREfinancialhigh
Ransomware.
Updated: 2023-06-05
View profile →
Crystal Rans0m
Technical ID: win.crystal_ransom
MALWARE
Malware family identifying win.crystal_ransom. Origin and technical characteristics tracked via Malpedia.
Also known as: CrystalRansom
Updated: 2024-11-26
View profile →
CryptXXXX
Technical ID: win.cryptxxxx
MALWARE
Malware family identifying win.cryptxxxx. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-26
View profile →
CryptoRansomeware
Technical ID: win.crypto_ransomeware
MALWARE
Malware family identifying win.crypto_ransomeware. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-15
View profile →
CryptoFortress
Technical ID: win.crypto_fortress
MALWARE
Malware family identifying win.crypto_fortress. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-25
View profile →
CryptoWire
Technical ID: win.cryptowire
MALWARE
Malware family identifying win.cryptowire. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-13
View profile →
Cryptowall
Technical ID: win.cryptowall
MALWAREfinancialhigh
CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a Trojan horse to deliver the malicious payload.
Updated: 2024-11-25
View profile →
CRYPTOSLAY
Technical ID: win.cryptoslay
UNC1860
MALWARE
Malware family identifying win.cryptoslay. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-18
View profile →
CryptoShuffler
Technical ID: win.cryptoshuffler
MALWARE
Malware family identifying win.cryptoshuffler. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-11-17
View profile →
CryptoShield
Technical ID: win.cryptoshield
MALWARE
Malware family identifying win.cryptoshield. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-03-23
View profile →
Cryptorium
Technical ID: win.cryptorium
MALWARE
Malware family identifying win.cryptorium. Origin and technical characteristics tracked via Malpedia.
CryptoPatronum
Technical ID: win.cryptopatronum
MALWAREfinancialhigh
CryptoPatronum is a ransomware that encrypts user data through AES-256 (CBC) and it asks for BTC / ETH in order to get back the original files. In the ransom note there is not a title but only a reference to crsss.exe: its original file name. Once the files are encrypted, CryptoPatronum adds a .enc extension.
Updated: 2020-02-03
View profile →
CryptoMix
Technical ID: win.cryptomix
MALWARE
A variant of CryptoMix is win.clop.
Also known as: Azer • CryptFile2
Updated: 2023-02-06
View profile →
CryptoLuck
Technical ID: win.cryptoluck
MALWARE
Malware family identifying win.cryptoluck. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-27
View profile →
CryptoLocker
Technical ID: win.cryptolocker
MALWARE
CryptoLocker is a new sophisticated malware that was launched in the late 2013. It is designed to attack Windows operating system by encrypting all the files from the system using a RSA-2048 public key. To decrypt the mentioned files, the user has to pay a ransom (usually 300 USD/EUR) or 2 BitCoins.
Updated: 2021-09-19
View profile →
← PreviousPage 175 / 269Next →