Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,745 entities
MALWARE
Malware family identifying win.coredn. Origin and technical characteristics tracked via Malpedia.
Corebot
Technical ID: win.corebot
MALWARE
Malware family identifying win.corebot. Origin and technical characteristics tracked via Malpedia.
CopperStealer
Technical ID: win.copper_stealer
MALWARE
According to PCRIsk, CopperStealer, also known as Mingloa, is a malicious program designed to steal sensitive/personal information. It also has the capability to cause chain infections (i.e., download/install additional malware).
Significant activity of CopperStealer has been observed in Brazil, India, Indonesia, Pakistan, and the Philippines. At the time of research, this malware had been noted being spread via websites offering illegal activation tools ("cracks") for licensed software products.
Also known as: Mingloa
MALWARE
According to Trend Micro, CopperStealth’s infection chain involves dropping and loading a rootkit, which later injects its payload into explorer.exe and another system process. These payloads are responsible for downloading and running additional tasks. The rootkit also blocks access to blocklisted registry keys and prevents certain executables and drivers from running. The task module is able to download and run additional payloads.
MALWARE
Malware family identifying win.cookiebag. Origin and technical characteristics tracked via Malpedia.
MALWARE
FireEye described this malware as a proxy-aware backdoor that communicates using a custom-encrypted binary protocol. It may use the registry to store optional configuration data. The backdoor has been observed to support 26 commands that include directory traversal, file system manipulation, data archival and transmission, and command execution.
Also known as: WHITEOUT
MALWAREfinancialhigh
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
Confucius
Technical ID: win.confucius
MALWARE
Malware family identifying win.confucius. Origin and technical characteristics tracked via Malpedia.
Conficker
Technical ID: win.conficker
MALWARE
Malware family identifying win.conficker. Origin and technical characteristics tracked via Malpedia.
Also known as: traffic converter • downadup • Kido
concealment_troy
Technical ID: win.concealment_troy
MALWARE
Malware family identifying win.concealment_troy. Origin and technical characteristics tracked via Malpedia.
ComradeCircle
Technical ID: win.comrade_circle
MALWARE
Malware family identifying win.comrade_circle. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.computrace. Origin and technical characteristics tracked via Malpedia.
Also known as: lojack
COMpfun
Technical ID: win.compfun
MALWARE
Malware family identifying win.compfun. Origin and technical characteristics tracked via Malpedia.
Also known as: Reductor RAT
ComodoSec
Technical ID: win.comodosec
MALWARE
Malware family identifying win.comodosec. Origin and technical characteristics tracked via Malpedia.
CommonMagic
Technical ID: win.common_magic
MALWARE
Malware family identifying win.common_magic. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
ComLook is a malicious plugin for the mail client "The Bat!", written in C++ and compiled with MSVC 10.0. It implements malicious commands like PutFile, GetFile, SetConfig, GetConfig, and Command. It contains hard-coded email addresses and other information, indicating a target in Azerbaijan. It was first uploaded to VirusTotal on January 12, 2022, and is associated with the APT group Turla. It appears to be a targeted deployment.
Comfoo
Technical ID: win.comfoo
MALWARE
Malware family identifying win.comfoo. Origin and technical characteristics tracked via Malpedia.
MALWARE
ComeBacker was found in a backdoored Visual Studio project that was used to target security researchers in Q4 2020 and early 2021.
It is an HTTP(S) downloader.
It uses the AES CBC cipher implemented through the OpenSSL's EVP interface for decryption of its configuration, and also for encryption and decryption of the client-server communication.
The parameter names in HTTP POST requests of the client are generated randomly. As the initial connection, the client exchanges the keys with the server via the Diffie–Hellman key agreement protocol for the elliptic curve secp521r1. The client generates a random 32-bytes long private key, and the server responds with its public key in a buffer starting with the wide character "0".
Next, the clients sends the current local time, and the server responds with a buffer containing multiple values separated with the pipe symbol. The typical values are the encrypted payload, the export to execute, and the MD5 hash of the decrypted DLL to verify the authenticity of the payload.
There are variants of ComeBacker without statically linked OpenSSL. In that case, the key exchange is omitted and AES CBC is replaced with HC-256.
MALWARE
Malware family identifying win.combos. Origin and technical characteristics tracked via Malpedia.
Combojack
Technical ID: win.combojack
MALWARE
Malware family identifying win.combojack. Origin and technical characteristics tracked via Malpedia.
Colony
Technical ID: win.colony
MALWARE
Malware family identifying win.colony. Origin and technical characteristics tracked via Malpedia.
Also known as: Bandios • GrayBird
CollectorGoomba
Technical ID: win.collectorgoomba
MALWARE
Malware family identifying win.collectorgoomba. Origin and technical characteristics tracked via Malpedia.
Also known as: Collector Stealer
MALWARE
Malware family identifying win.collection_rat. Origin and technical characteristics tracked via Malpedia.
Colibri Loader
Technical ID: win.colibri
MALWARE
According to cloudsek, Colibri Loader is a form of malware designed to facilitate the installation of additional malware types on an already compromised system. This loader employs various techniques to evade detection, such as excluding the Import Address Table (IAT) and utilizing encrypted strings to complicate analysis. Similar to other loader malware, Colibri can be utilized to deploy information-stealing malware, potentially leading to significant loss of sensitive data. As a result, users should exercise caution when encountering unfamiliar files on their systems.
ColdStealer
Technical ID: win.coldstealer
MALWARE
ColdStealer is a relatively new malicious program that was discovered in 2022. Like many other stealers its main purpose is to steal credentials and information from web browsers, in addition to stealing cryptocurrency wallets, FTP credentials, various files and information about the system such as OS version, system language, processor type and clipboard data. When the infostealer collects information that will be stolen, it saves the information in the ZIP form instead of files in the memory. Doing so will allow the malware to bypass detection as there are no traces of files and execution. The only known method of delivering stolen information to cybercriminals is by sending a ZIP archive to the hardcoded command and control (C2) server.
Cold$eal
Technical ID: win.coldseal
MALWARE
Cold$eal is a packer for encrypting (sealing) malware. It contains some AV-evasion techniques as well as some sandbox-detection. It was developed by $@dok (aka Sadok aka Coldseal).
It was available as a cryptor service under the url coldseal.us and was later sold as a toolkit consisting of the cryptor and a custom made cryptostub including a FuD garantee backed by free update to the cryptostub. The payload was encrypted using RC4 and added to the cryptostub as a resource. The encryption key itself was stored inside the resource as well. Upon start the cryptostub would extract the key, decrypt the payload and perform a selfinjection using the now decrypted payload.
Note: The packed sample provided contains some harmless payload, while the unpacked sample is the bare cryptostub without a payload.
Also known as: ColdSeal
MALWARE
Malware family identifying win.coldlock. Origin and technical characteristics tracked via Malpedia.
coldbrew
Technical ID: win.coldbrew
MALWARE
Malware family identifying win.coldbrew. Origin and technical characteristics tracked via Malpedia.
Coinminer
Technical ID: win.coinminer
MALWARE
Coinminer is an unwanted malicious software which uses the victim's computational power (CPU and RAM mostly) to mine for coins (for example Monero or Zcash). The malware achieves persistence by adding one of the opensource miners on startup without the victim's consensus. Most sophisticated coin miners use timer settings or cap the CPU usage in order to remain stealthy.
Cohhoc
Technical ID: win.cohhoc
MALWARE
Malware family identifying win.cohhoc. Origin and technical characteristics tracked via Malpedia.
CoffeeLoader
Technical ID: win.coffee_loader
MALWARE
Zscaler ThreatLabz states that this sophisticated malware family likely originated around September 2024. The purpose of the malware is to download and execute second-stage payloads while evading detection by endpoint-based security products. The malware uses numerous techniques to bypass security solutions, including a specialized packer called Armoury that utilizes the GPU, call stack spoofing, sleep obfuscation, and the use of Windows fibers. It also contains a backup DGA and is capable of deploying Rhadamanthys shellcode. ThreatLabz has observed CoffeeLoader being distributed via SmokeLoader, and both malware families share some behavioral similarities.
CodeCore
Technical ID: win.code_core
MALWAREfinancialhigh
Ransomware.
CodeKey
Technical ID: win.codekey
MALWARE
Malware family identifying win.codekey. Origin and technical characteristics tracked via Malpedia.
CockBlocker
Technical ID: win.cockblocker
MALWARE
Malware family identifying win.cockblocker. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.cobra. Origin and technical characteristics tracked via Malpedia.
Also known as: Carbon
MALWARE
CobInt, is a self-developed backdoor of the Cobalt group. The modular tool has capabilities to collect initial intelligence information about the compromised machine and stream video from its desktop. If the operator decides that the system is of interest, the backdoor will download and launch CobaltStrike framework stager. It's CRM mailslot module was also observed being downloaded by ISFB.
Also known as: COOLPANTS
Cobian RAT
Technical ID: win.cobian_rat
MALWARE
Malware family identifying win.cobian_rat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Cobalt Strike is a paid penetration testing product that allows an attacker to deploy an agent named 'Beacon' on the victim machine. Beacon includes a wealth of functionality to the attacker, including, but not limited to command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in that it consists of stageless or multi-stage shellcode that once loaded by exploiting a vulnerability or executing a shellcode loader, will reflectively load itself into the memory of a process without touching the disk. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit for developing shellcode loaders, called Artifact Kit.
The Beacon implant has become popular amongst targeted attackers and criminal users as it is well written, stable, and highly customizable.
Also known as: Agentemis • BEACON • CobaltStrike • cobeacon
CobaltMirage FRP
Technical ID: win.cobaltmirage_tunnel
MALWARE
This Go written malware was observed during campaign of COBALT MIRAGE; it includes FRP (Fast Reverse Proxy) published by fatedier on GitHub (https://github.com/fatedier/frp) and other projects additionally.
CoalaBot
Technical ID: win.coalabot
MALWARE
Malware family identifying win.coalabot. Origin and technical characteristics tracked via Malpedia.