Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
CryptoJoker
Technical ID: win.cryptojoker
MALWAREfinancialhigh
CryptoJoker is an open source ransomware written in C#.
CryptoJoker uses a combination of a "custom XOR" encryption and RSA. A private public/private pair key is generated for every computer.
Also known as: PlutoCrypt
CryptoDarkRubix
Technical ID: win.cryptodarkrubix
MALWARE
Malware family identifying win.cryptodarkrubix. Origin and technical characteristics tracked via Malpedia.
Also known as: Ranet
CryptoClippy
Technical ID: win.cryptoclippy
MALWARE
Malware family identifying win.cryptoclippy. Origin and technical characteristics tracked via Malpedia.
CryptNET
Technical ID: win.cryptnet
MALWAREfinancialhigh
According to OALabs, this ransomware has the following features:
* Files are encrypted with AES CBC using a generated 256 bit key and IV.
* The generated AES keys are encrypted using a hard coded RSA key and appended to the encrypted files.
MALWARE
CrypticConvo is a dropper trojan which appears to be embedded in an automatic generator framework to deliver the FakeM trojan. According to PaloaltoNetworks CrypticConvo and several additional trojans are believed to be included in a meta framework used by the "Scarlet Mimic" threat actor in order to quickly evade AV systems.
CryptBot
Technical ID: win.cryptbot
MALWARE
A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2.
Crypt0l0cker
Technical ID: win.crypt0l0cker
MALWARE
Malware family identifying win.crypt0l0cker. Origin and technical characteristics tracked via Malpedia.
CrypMic
Technical ID: win.crypmic
MALWARE
Malware family identifying win.crypmic. Origin and technical characteristics tracked via Malpedia.
CryLocker
Technical ID: win.crylocker
MALWARE
Malware family identifying win.crylocker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-27
View profile →Cryakl
Technical ID: win.cryakl
MALWARE
Malware family identifying win.cryakl. Origin and technical characteristics tracked via Malpedia.
Also known as: CryLock
MALWARE
Malware family identifying win.crutch. Origin and technical characteristics tracked via Malpedia.
CruLoader
Technical ID: win.cruloader
MALWARE
Malware family identifying win.cruloader. Origin and technical characteristics tracked via Malpedia.
Croxloader
Technical ID: win.croxloader
MALWAREespionageadvanced
According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
MALWARE
According to FireEye, CROSSWALK is a skeletal, modular backdoor capable of system survey and adding modules in response to C&C replies.
Also known as: ProxIP • Motnug • TOMMYGUN
CrossLock
Technical ID: win.crosslock
MALWARE
Malware family identifying win.crosslock. Origin and technical characteristics tracked via Malpedia.
Cring
Technical ID: win.cring
MALWAREfinancialhigh
Ransomware.
MALWARE
According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017. It enables operators to run command line tools, exfiltrate files, and upload files to the infected machine. CrimsonIAS is notable as it listens for incoming connections only; making it different from typical Windows backdoors that beacons out.
MALWARE
It was first discovered in 2017 and has since been used to attack organizations around the world. The malware is often distributed through phishing emails or by exploiting vulnerabilities in outdated security software. Once Crimson RAT is installed on a computer, it can be used to steal data, spy on users, and even take control of the infected computers.
Some of the features of Crimson RAT include:
Remote control of infected computers
Data theft, such as passwords, files, and emails
User spying
Takeover of infected computers
Locking of infected computers
Extortion of payments
Also known as: SEEDOOR • Scarimson
Crenufs
Technical ID: win.crenufs
MALWARE
Malware family identifying win.crenufs. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →MALWARE
Malware family identifying win.creep_exfil. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.creepysnail. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
Malware family identifying win.credraptor. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.credomap. Origin and technical characteristics tracked via Malpedia.
CreateHiddenAccount
Technical ID: win.create_hidden_account
MALWARE
A tool that implements the creation of a hidden account on Windows through cloning accounts via the Registry.
MALWARE
Malware family identifying win.creamsicle. Origin and technical characteristics tracked via Malpedia.
CrazyHunter
Technical ID: win.crazyhunter
MALWARE
Malware family identifying win.crazyhunter. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Cisco Talos, CRAT is a remote access trojan with plugin capabilites, used by Lazarus since at least May 2020.
CradleCore
Technical ID: win.cradlecore
MALWARE
Malware family identifying win.cradlecore. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-12
View profile →MALWARE
CRACKSHOT is a downloader that can download files, including binaries, and run them from the hard disk or execute them directly in memory. It is also capable of placing itself into a dormant state.
CrackedCantil
Technical ID: win.crackedcantil
MALWAREfinancialhigh
According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware.
The families include more loaders, information stealers, cryptominers, a proxy bot, and ultimately also ransomware.
The execution order is orchestrated, e.g. as in data is stolen and exfiltrated before encryption.
It is distributed through advertized cracked software, e.g. IDA Pro.
MALWARE
CozyDuke is not simply a malware toolset; rather, it is a modular malware platform formed around
a core backdoor component. This component can be instructed by the C&C server to download
and execute arbitrary modules, and it is these modules that provide CozyDuke with its vast array
of functionality. Known CozyDuke modules include:
• Command execution module for executing arbitrary Windows Command Prompt commands
• Password stealer module
• NT LAN Manager (NTLM) hash stealer module
• System information gathering module
• Screenshot module
Also known as: CozyCar • Cozer • CozyBear • EuroAPT
CoViper
Technical ID: win.coviper
MALWARE
PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the pandemic. It operates by rewriting the system Master Boot Record (MBR). It does not delete the original, but rather creates a backup and replaces it with a custom MBR.
Typically, malicious software that modifies MBRs do so to prevent the Operating System (OS) from being booted (i.e., started). It also displays a screen-encompassing message, often containing a ransom message - this disables user access to the device.
Covid22
Technical ID: win.covid22
MALWARE
Destructive "joke" malware that ultimately deploys a wiper for the MBR.
MALWARE
Covicli is a modified SSLeay32 dynamic library designated as a backdoor.
The dynamic library allows the attacker to communicate with the C2 over openSSL.
Also known as: Covically
Cova
Technical ID: win.cova
MALWARE
Malware family identifying win.cova. Origin and technical characteristics tracked via Malpedia.
CountLoader
Technical ID: win.count_loader
MALWAREfinancialhigh
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.
MALWARE
Malware family identifying win.cotx. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.cosmicduke. Origin and technical characteristics tracked via Malpedia.
CoronaVirus Ransomware
Technical ID: win.coronavirus_ransomware
MALWAREfinancialhigh
Malware family identifying win.coronavirus_ransomware. Origin and technical characteristics tracked via Malpedia.
Also known as: CoronaVirus Cover-Ransomware
MALWARE
Malware family identifying win.coreshell. Origin and technical characteristics tracked via Malpedia.
Also known as: SOURFACE