Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,745 entities
CryptoJoker
Technical ID: win.cryptojoker
MALWAREfinancialhigh
CryptoJoker is an open source ransomware written in C#. CryptoJoker uses a combination of a "custom XOR" encryption and RSA. A private public/private pair key is generated for every computer.
Also known as: PlutoCrypt
Updated: 2023-04-18
View profile →
CryptoDarkRubix
Technical ID: win.cryptodarkrubix
MALWARE
Malware family identifying win.cryptodarkrubix. Origin and technical characteristics tracked via Malpedia.
Also known as: Ranet
Updated: 2020-07-30
View profile →
CryptoClippy
Technical ID: win.cryptoclippy
MALWARE
Malware family identifying win.cryptoclippy. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-04-23
View profile →
CryptNET
Technical ID: win.cryptnet
MALWAREfinancialhigh
According to OALabs, this ransomware has the following features: * Files are encrypted with AES CBC using a generated 256 bit key and IV. * The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
Updated: 2024-04-10
View profile →
CrypticConvo
Technical ID: win.cryptic_convo
Scarlet Mimic
MALWARE
CrypticConvo is a dropper trojan which appears to be embedded in an automatic generator framework to deliver the FakeM trojan. According to PaloaltoNetworks CrypticConvo and several additional trojans are believed to be included in a meta framework used by the "Scarlet Mimic" threat actor in order to quickly evade AV systems.
Updated: 2020-01-26
View profile →
CryptBot
Technical ID: win.cryptbot
MALWARE
A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2.
Updated: 2025-01-07
View profile →
Crypt0l0cker
Technical ID: win.crypt0l0cker
MALWARE
Malware family identifying win.crypt0l0cker. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-08-04
View profile →
CrypMic
Technical ID: win.crypmic
MALWARE
Malware family identifying win.crypmic. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-12-13
View profile →
CryLocker
Technical ID: win.crylocker
MALWARE
Malware family identifying win.crylocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-27
View profile →
Cryakl
Technical ID: win.cryakl
MALWARE
Malware family identifying win.cryakl. Origin and technical characteristics tracked via Malpedia.
Also known as: CryLock
Updated: 2023-03-20
View profile →
Crutch
Technical ID: win.crutch
Turla
MALWARE
Malware family identifying win.crutch. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-05-03
View profile →
CruLoader
Technical ID: win.cruloader
MALWARE
Malware family identifying win.cruloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-06
View profile →
Croxloader
Technical ID: win.croxloader
MALWAREespionageadvanced
According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
Updated: 2023-05-04
View profile →
CROSSWALK
Technical ID: win.crosswalk
APT41
MALWARE
According to FireEye, CROSSWALK is a skeletal, modular backdoor capable of system survey and adding modules in response to C&C replies.
Also known as: ProxIP • Motnug • TOMMYGUN
Updated: 2026-01-28
View profile →
CrossLock
Technical ID: win.crosslock
MALWARE
Malware family identifying win.crosslock. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-04-25
View profile →
Cring
Technical ID: win.cring
MALWAREfinancialhigh
Ransomware.
Updated: 2025-02-20
View profile →
CrimsonIAS
Technical ID: win.crimsonias
Mustang Panda
MALWARE
According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017. It enables operators to run command line tools, exfiltrate files, and upload files to the infected machine. CrimsonIAS is notable as it listens for incoming connections only; making it different from typical Windows backdoors that beacons out.
Updated: 2024-03-07
View profile →
Crimson RAT
Technical ID: win.crimson
Operation C-Major
MALWARE
It was first discovered in 2017 and has since been used to attack organizations around the world. The malware is often distributed through phishing emails or by exploiting vulnerabilities in outdated security software. Once Crimson RAT is installed on a computer, it can be used to steal data, spy on users, and even take control of the infected computers. Some of the features of Crimson RAT include: Remote control of infected computers Data theft, such as passwords, files, and emails User spying Takeover of infected computers Locking of infected computers Extortion of payments
Also known as: SEEDOOR • Scarimson
Updated: 2025-05-20
View profile →
Crenufs
Technical ID: win.crenufs
MALWARE
Malware family identifying win.crenufs. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →
CreepExfil
Technical ID: win.creep_exfil
POLONIUM
MALWARE
Malware family identifying win.creep_exfil. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-12
View profile →
CreepySnail
Technical ID: win.creepysnail
POLONIUM
MALWARE
Malware family identifying win.creepysnail. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-12
View profile →
Credraptor
Technical ID: win.credraptor
TeleBots
MALWAREespionageadvanced
Malware family identifying win.credraptor. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-03-04
View profile →
CredoMap
Technical ID: win.credomap
APT28
MALWARE
Malware family identifying win.credomap. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-17
View profile →
CreateHiddenAccount
Technical ID: win.create_hidden_account
MALWARE
A tool that implements the creation of a hidden account on Windows through cloning accounts via the Registry.
Updated: 2025-01-29
View profile →
CREAMSICLE
Technical ID: win.creamsicle
APT 30
MALWARE
Malware family identifying win.creamsicle. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-04-17
View profile →
CrazyHunter
Technical ID: win.crazyhunter
MALWARE
Malware family identifying win.crazyhunter. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-09
View profile →
CRAT
Technical ID: win.crat
Lazarus Group
MALWARE
According to Cisco Talos, CRAT is a remote access trojan with plugin capabilites, used by Lazarus since at least May 2020.
Updated: 2021-04-06
View profile →
CradleCore
Technical ID: win.cradlecore
MALWARE
Malware family identifying win.cradlecore. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-12
View profile →
crackshot
Technical ID: win.crackshot
APT41
MALWARE
CRACKSHOT is a downloader that can download files, including binaries, and run them from the hard disk or execute them directly in memory. It is also capable of placing itself into a dormant state.
Updated: 2019-08-13
View profile →
CrackedCantil
Technical ID: win.crackedcantil
MALWAREfinancialhigh
According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware. The families include more loaders, information stealers, cryptominers, a proxy bot, and ultimately also ransomware. The execution order is orchestrated, e.g. as in data is stolen and exfiltrated before encryption. It is distributed through advertized cracked software, e.g. IDA Pro.
Updated: 2024-12-09
View profile →
COZYDUKE
Technical ID: win.cozyduke
APT29
MALWARE
CozyDuke is not simply a malware toolset; rather, it is a modular malware platform formed around a core backdoor component. This component can be instructed by the C&C server to download and execute arbitrary modules, and it is these modules that provide CozyDuke with its vast array of functionality. Known CozyDuke modules include: • Command execution module for executing arbitrary Windows Command Prompt commands • Password stealer module • NT LAN Manager (NTLM) hash stealer module • System information gathering module • Screenshot module
Also known as: CozyCar • Cozer • CozyBear • EuroAPT
Updated: 2022-12-01
View profile →
CoViper
Technical ID: win.coviper
MALWARE
PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the pandemic. It operates by rewriting the system Master Boot Record (MBR). It does not delete the original, but rather creates a backup and replaces it with a custom MBR. Typically, malicious software that modifies MBRs do so to prevent the Operating System (OS) from being booted (i.e., started). It also displays a screen-encompassing message, often containing a ransom message - this disables user access to the device.
Updated: 2022-11-15
View profile →
Covid22
Technical ID: win.covid22
MALWARE
Destructive "joke" malware that ultimately deploys a wiper for the MBR.
Updated: 2021-11-17
View profile →
Covicli
Technical ID: win.covicli
MuddyWater
MALWARE
Covicli is a modified SSLeay32 dynamic library designated as a backdoor. The dynamic library allows the attacker to communicate with the C2 over openSSL.
Also known as: Covically
Updated: 2021-08-17
View profile →
Cova
Technical ID: win.cova
MALWARE
Malware family identifying win.cova. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-07
View profile →
CountLoader
Technical ID: win.count_loader
MALWAREfinancialhigh
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.
Updated: 2025-12-19
View profile →
Cotx RAT
Technical ID: win.cotx
TA428
MALWARE
Malware family identifying win.cotx. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-11
View profile →
CosmicDuke
Technical ID: win.cosmicduke
APT29
MALWARE
Malware family identifying win.cosmicduke. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-20
View profile →
CoronaVirus Ransomware
Technical ID: win.coronavirus_ransomware
MALWAREfinancialhigh
Malware family identifying win.coronavirus_ransomware. Origin and technical characteristics tracked via Malpedia.
Also known as: CoronaVirus Cover-Ransomware
Updated: 2020-04-21
View profile →
Coreshell
Technical ID: win.coreshell
APT28
MALWARE
Malware family identifying win.coreshell. Origin and technical characteristics tracked via Malpedia.
Also known as: SOURFACE
Updated: 2022-05-04
View profile →
← PreviousPage 176 / 269Next →