Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
CMSTAR
Technical ID: win.cmstar
MALWARE
Malware family identifying win.cmstar. Origin and technical characteristics tracked via Malpedia.
Also known as: meciv
Updated: 2022-07-25
View profile →
CMSBrute
Technical ID: win.cmsbrute
MALWARE
Malware family identifying win.cmsbrute. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-09-07
View profile →
cmoon
Technical ID: win.cmoon
MALWARE
Malware family identifying win.cmoon. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-23
View profile →
Cmimai Stealer
Technical ID: win.cmimai
MALWARE
Malware family identifying win.cmimai. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-08-18
View profile →
CloudScout
Technical ID: win.cloud_scout
Evasive Panda
MALWARE
According to ESET Research, CloudScout is a toolset is capable of retrieving data from various cloud services by leveraging stolen web session cookies. Through a plugin, CloudScout works seamlessly with MgBot, Evasive Panda’s signature malware framework.
Updated: 2024-10-29
View profile →
CloudDuke
Technical ID: win.cloud_duke
APT29
MALWARE
F-Secure describes CloudDuke as a malware toolset known to consist of, at least, a downloader, a loader and two backdoor variants. The CloudDuke downloader will download and execute additional malware from a preconfigured location. Interestingly, that location may be either a web address or a Microsoft OneDrive account. Both CloudDuke backdoor variants support simple backdoor functionality, similar to SeaDuke. While one variant will use a preconfigured C&C server over HTTP or HTTPS, the other variant will use a Microsoft OneDrive account to exchange commands and stolen data with its operators.
Also known as: MiniDionis • CloudLook
Updated: 2022-11-15
View profile →
CloudWizard
Technical ID: win.cloudwizard
MALWARE
Malware family identifying win.cloudwizard. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-01
View profile →
CloudEyE
Technical ID: win.cloudeye
MALWARE
CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.
Also known as: GuLoader • vbdropper
Updated: 2025-11-28
View profile →
CLOUDBURST
Technical ID: win.cloudburst
Lazarus Group
MALWARE
CLOUDBURST aka NickelLoader is an HTTP(S) downloader. It recognizes a set of four basic commands, all five letters long, like abcde, avdrq, gabnc and dcrqv (alternatively: eknag, eacec, hjmwk, wohnp). The most important functionality is to load a received buffer, either as a DLL via the MemoryModule implementation, or as a shellcode. It uses AES for encryption and decryption of network traffic. It usually sends the following information back to its C&C server: computer name, product name and the list of running processes. Typically, it uses two hardcoded parameter names for its initial HTTP POST requests: gametype and type (alternatively: type and code). The CLOUDBURST payload is disguised as mscoree.dll and is side-loaded via a legitimate Windows binary PresentationHost.exe with the argument -embeddingObject. It comes either as a trojanized plugin project for Notepad++ (usually FingerText by erinata), or as a standalone DLL loaded by a dropper, which is a trojanized plugin project as well (usually NppyPlugin by Jari Pennanen). The CLOUDBURST malware was used in Operation DreamJob attacks against an aerospace company and a network running Microsoft Intune software in Q2-Q3 2022.
Also known as: NickelLoader
Updated: 2025-09-15
View profile →
Clop
Technical ID: win.clop
TA505
MALWAREfinancialhigh
Clop is a ransomware which uses the .clop extension after having encrypted the victim's files. Another unique characteristic belonging with Clop is in the string: "Dont Worry C|0P" included into the ransom notes. It is a variant of CryptoMix ransomware, but it additionally attempts to disable Windows Defender and to remove the Microsoft Security Essentials in order to avoid user space detection.
Updated: 2025-11-09
View profile →
Clipog
Technical ID: win.clipog
MALWARE
A keylogger.
Updated: 2023-10-20
View profile →
ClipBanker
Technical ID: win.clipbanker
MALWAREfinancialhigh
The ClipBanker Trojan is known as an information stealer and spy trojan, it aims to steal and record any type of sensitive information from the infected environment such as browser history, cookies, Outlook data, Skype, Telegram, or cryptocurrency wallet account addresses. The main goal of this threat is to steal confidential information. The ClipBanker uses PowerShell commands for executing malicious activities. The thing that made the ClipBanker unique is its ability to record various banking actions of the user and manipulate them for its own benefit. The distribution method of the ClipBanker is through phishing emails or through social media posts that lure users to download malicious content.
Updated: 2025-10-20
View profile →
Client Maximus
Technical ID: win.client_maximus
MALWARE
Malware family identifying win.client_maximus. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-06-03
View profile →
CLEANTOAD
Technical ID: win.cleantoad
Lazarus Group
MALWARE
CLEANTOAD is a disruption tool that will delete file system artifacts, including those related to BLINDTOAD, and will run after a date obtained from a configuration file. The malware injects shellcode into notepad.exe and it overwrites and deletes files, modifies registry keys, deletes services, and clears Windows event logs.
Updated: 2019-11-13
View profile →
CLASSFON
Technical ID: win.classfon
MALWARE
Malware family identifying win.classfon. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-08-09
View profile →
Clambling
Technical ID: win.clambling
MALWARE
Clambling was discovered by Trend Micro and TalentJump. It is a custom malware used by an actor they refer to as DRBControl, which targets gambling and betting companies in Southeast Asia. One version of Clambling uses Dropbox as C&C channel to hide its communication.
Updated: 2021-01-11
View profile →
Citadel
Technical ID: win.citadel
MALWARE
Malware family identifying win.citadel. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-24
View profile →
Cinoshi
Technical ID: win.cinoshi
MALWARE
Malware family identifying win.cinoshi. Origin and technical characteristics tracked via Malpedia.
Also known as: Agniane
Updated: 2023-08-31
View profile →
Cinobi
Technical ID: win.cinobi
MALWARE
Malware family identifying win.cinobi. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-08-09
View profile →
cifty
Technical ID: win.cifty
MALWARE
Malware family identifying win.cifty. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-25
View profile →
Cicada3301
Technical ID: win.cicada3301
MALWARE
Malware family identifying win.cicada3301. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-09
View profile →
Chthonic
Technical ID: win.chthonic
MALWARE
Malware family identifying win.chthonic. Origin and technical characteristics tracked via Malpedia.
Also known as: AndroKINS
Updated: 2021-09-19
View profile →
Chrysalis
Technical ID: win.chrysalis
LOTUS PANDA
MALWARE
According to Rapid7, Chrysalis is a custom, feature-rich backdoor. Its wide array of capabilities indicates it is a sophisticated and permanent tool, not a simple throwaway utility. It uses legitimate binaries to sideload a crafted DLL with a generic name, which makes simple filename-based detection unreliable. It relies on custom API hashing in both the loader and the main module, each with its own resolution logic. This is paired with layered obfuscation and a fairly structured approach to C2 communication.
Updated: 2026-02-03
View profile →
ChrGetPdsi Stealer
Technical ID: win.chrgetpdsi_stealer
MALWARE
ChrGetPdsi is a basic infostealer written in Golang which is designed to steal browser history and logins, and targets Chrome, Edge, and Firefox. The output is written to a text file named chrgetpdsi.txt. Based on the samples analysed, the malware does not appear to have networking capabilities, and therefore it is likely that it is intended to be used in a post-compromise situation where the attacker already has access to the target system and can retrieve the created output file via other means.ChrGetPdsi has been observed being deployed by the Broomstick malware.
Updated: 2024-06-24
View profile →
Choziosi
Technical ID: win.choziosi
MALWARE
Choziosi is a browser hijacker for Chrome. It was first seen in January 2022. It commonly infects users via pirated media downloads like games, software, wallpapers or movies. The initial infectors are available for several platforms such as Mac and Windows. Its main component is the Chrome browser extension written in JavaScript with the purpose of serving advertisments and hijacking search requests to Google, Yahoo and Bing.
Also known as: ChromeLoader
Updated: 2023-11-23
View profile →
ChiserClient
Technical ID: win.chiser_client
Pirate Panda
MALWARE
Malware family identifying win.chiser_client. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-03-30
View profile →
Chisel
Technical ID: win.chisel
MALWAREfinancialhigh
Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP. It is available across platforms and written in Go. While benign in itself, Chisel has been utilized by multiple threat actors. It was for example observed by SentinelOne during a PYSA ransomware campaign to achieve persistence and used as backdoor. Github: https://github.com/jpillora/chisel
Updated: 2024-11-05
View profile →
Chir
Technical ID: win.chir
MALWARE
Malware family identifying win.chir. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-01-17
View profile →
Chinoxy
Technical ID: win.chinoxy
MALWARE
Malware family identifying win.chinoxy. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-08-28
View profile →
Chinotto
Technical ID: win.chinotto
APT37
MALWARE
Malware family identifying win.chinotto. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-22
View profile →
ChinaJm
Technical ID: win.chinajm
MALWAREfinancialhigh
Ransomware.
Updated: 2020-08-05
View profile →
Chinad
Technical ID: win.chinad
MALWARE
Adware that shows advertisements using plugin techniques for popular browsers
Updated: 2023-06-01
View profile →
CHINACHOPPER
Technical ID: win.chinachopper
APT41EMISSARY PANDAGALLIUMHAFNIUM+2 more
MALWARE
a simple code injection webshell that executes Microsoft .NET code within HTTP POST commands. This allows the shell to upload and download files, execute applications with web server account permissions, list directory contents, access Active Directory, access databases, and any other action allowed by the .NET runtime.
Updated: 2025-10-20
View profile →
Chimera
Technical ID: win.chimera
MALWAREfinancialhigh
According to PCrisk, Chimera is a ransomware virus that encrypts files stored on infected systems. It is distributed using various false job applications, business offers, and infected email attachments. After encrypting the files, Chimera adds a . crypt extension to each file.
Updated: 2023-06-19
View profile →
Chihuahua
Technical ID: win.chihuahua
MALWARE
Malware family identifying win.chihuahua. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-05-19
View profile →
ChewBacca
Technical ID: win.chewbacca
MALWARE
Malware family identifying win.chewbacca. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-26
View profile →
CherryPicker POS
Technical ID: win.cherry_picker
MALWARE
Malware family identifying win.cherry_picker. Origin and technical characteristics tracked via Malpedia.
Also known as: cherrypickerpos • cherrypicker • cherry_picker
Updated: 2022-12-01
View profile →
CherryLoader
Technical ID: win.cherryloader
MALWARE
Malware family identifying win.cherryloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-02-02
View profile →
Chernolocker
Technical ID: win.chernolocker
MALWAREfinancialhigh
Chernolocker is a ransomware that encrypts a victim's files by using AES-256 and it asks for BTC ransom. Different versions are classified by the attacker's email address which changes over time.
Updated: 2020-01-26
View profile →
CHEESETRAY
Technical ID: win.cheesetray
Lazarus Group
MALWARE
CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line parameters. The backdoor is capable of enumerating files and processes, enumerating drivers, enumerating remote desktop sessions, uploading and downloading files, creating and terminating processes, deleting files, creating a reverse shell, acting as a proxy server, and hijacking processes among its other functionality. The backdoor communicates with its C&C server using a custom binary protocol over TCP with port specified as a command-line parameter.
Also known as: CROWDEDFLOUNDER
Updated: 2020-02-27
View profile →
← PreviousPage 178 / 269Next →