Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
CMSTAR
Technical ID: win.cmstar
MALWARE
Malware family identifying win.cmstar. Origin and technical characteristics tracked via Malpedia.
Also known as: meciv
CMSBrute
Technical ID: win.cmsbrute
MALWARE
Malware family identifying win.cmsbrute. Origin and technical characteristics tracked via Malpedia.
cmoon
Technical ID: win.cmoon
MALWARE
Malware family identifying win.cmoon. Origin and technical characteristics tracked via Malpedia.
Cmimai Stealer
Technical ID: win.cmimai
MALWARE
Malware family identifying win.cmimai. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to ESET Research, CloudScout is a toolset is capable of retrieving data from various cloud services by leveraging stolen web session cookies. Through a plugin, CloudScout works seamlessly with MgBot, Evasive Panda’s signature malware framework.
MALWARE
F-Secure describes CloudDuke as a malware toolset known to consist of, at least, a downloader, a loader and two backdoor variants. The CloudDuke downloader will download and execute additional malware from a preconfigured location. Interestingly, that location may be either a web address or a Microsoft OneDrive account. Both CloudDuke backdoor variants support simple backdoor functionality, similar to SeaDuke. While one variant will use a preconfigured C&C server over HTTP or HTTPS, the other variant will use a Microsoft OneDrive account to exchange commands and stolen data with its operators.
Also known as: MiniDionis • CloudLook
CloudWizard
Technical ID: win.cloudwizard
MALWARE
Malware family identifying win.cloudwizard. Origin and technical characteristics tracked via Malpedia.
CloudEyE
Technical ID: win.cloudeye
MALWARE
CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.
Also known as: GuLoader • vbdropper
MALWARE
CLOUDBURST aka NickelLoader is an HTTP(S) downloader.
It recognizes a set of four basic commands, all five letters long, like abcde, avdrq, gabnc and dcrqv (alternatively: eknag, eacec, hjmwk, wohnp). The most important functionality is to load a received buffer, either as a DLL via the MemoryModule implementation, or as a shellcode.
It uses AES for encryption and decryption of network traffic. It usually sends the following information back to its C&C server: computer name, product name and the list of running processes. Typically, it uses two hardcoded parameter names for its initial HTTP POST requests: gametype and type (alternatively: type and code).
The CLOUDBURST payload is disguised as mscoree.dll and is side-loaded via a legitimate Windows binary PresentationHost.exe with the argument -embeddingObject. It comes either as a trojanized plugin project for Notepad++ (usually FingerText by erinata), or as a standalone DLL loaded by a dropper, which is a trojanized plugin project as well (usually NppyPlugin by Jari Pennanen).
The CLOUDBURST malware was used in Operation DreamJob attacks against an aerospace company and a network running Microsoft Intune software in Q2-Q3 2022.
Also known as: NickelLoader
MALWAREfinancialhigh
Clop is a ransomware which uses the .clop extension after having encrypted the victim's files. Another unique characteristic belonging with Clop is in the string: "Dont Worry C|0P" included into the ransom notes. It is a variant of CryptoMix ransomware, but it additionally attempts to disable Windows Defender and to remove the Microsoft Security Essentials in order to avoid user space detection.
ClipBanker
Technical ID: win.clipbanker
MALWAREfinancialhigh
The ClipBanker Trojan is known as an information stealer and spy trojan, it aims to steal and record any type of sensitive information from the infected environment such as browser history, cookies, Outlook data, Skype, Telegram, or cryptocurrency wallet account addresses. The main goal of this threat is to steal confidential information.
The ClipBanker uses PowerShell commands for executing malicious activities. The thing that made the ClipBanker unique is its ability to record various banking actions of the user and manipulate them for its own benefit. The distribution method of the ClipBanker is through phishing emails or through social media posts that lure users to download malicious content.
Client Maximus
Technical ID: win.client_maximus
MALWARE
Malware family identifying win.client_maximus. Origin and technical characteristics tracked via Malpedia.
MALWARE
CLEANTOAD is a disruption tool that will delete file system artifacts, including those related to BLINDTOAD, and will run after a date obtained from a configuration file. The malware injects shellcode into notepad.exe and it overwrites and deletes files, modifies registry keys, deletes services, and clears Windows event logs.
CLASSFON
Technical ID: win.classfon
MALWARE
Malware family identifying win.classfon. Origin and technical characteristics tracked via Malpedia.
Clambling
Technical ID: win.clambling
MALWARE
Clambling was discovered by Trend Micro and TalentJump. It is a custom malware used by an actor they refer to as DRBControl, which targets gambling and betting companies in Southeast Asia. One version of Clambling uses Dropbox as C&C channel to hide its communication.
Citadel
Technical ID: win.citadel
MALWARE
Malware family identifying win.citadel. Origin and technical characteristics tracked via Malpedia.
Cinoshi
Technical ID: win.cinoshi
MALWARE
Malware family identifying win.cinoshi. Origin and technical characteristics tracked via Malpedia.
Also known as: Agniane
Cinobi
Technical ID: win.cinobi
MALWARE
Malware family identifying win.cinobi. Origin and technical characteristics tracked via Malpedia.
cifty
Technical ID: win.cifty
MALWARE
Malware family identifying win.cifty. Origin and technical characteristics tracked via Malpedia.
Cicada3301
Technical ID: win.cicada3301
MALWARE
Malware family identifying win.cicada3301. Origin and technical characteristics tracked via Malpedia.
Chthonic
Technical ID: win.chthonic
MALWARE
Malware family identifying win.chthonic. Origin and technical characteristics tracked via Malpedia.
Also known as: AndroKINS
MALWARE
According to Rapid7, Chrysalis is a custom, feature-rich backdoor. Its wide array of capabilities indicates it is a sophisticated and permanent tool, not a simple throwaway utility. It uses legitimate binaries to sideload a crafted DLL with a generic name, which makes simple filename-based detection unreliable. It relies on custom API hashing in both the loader and the main module, each with its own resolution logic. This is paired with layered obfuscation and a fairly structured approach to C2 communication.
ChrGetPdsi Stealer
Technical ID: win.chrgetpdsi_stealer
MALWARE
ChrGetPdsi is a basic infostealer written in Golang which is designed to steal browser history and logins, and targets Chrome, Edge, and Firefox. The output is written to a text file named chrgetpdsi.txt. Based on the samples analysed, the malware does not appear to have networking capabilities, and therefore it is likely that it is intended to be used in a post-compromise situation where the attacker already has access to the target system and can retrieve the created output file via other means.ChrGetPdsi has been observed being deployed by the Broomstick malware.
Choziosi
Technical ID: win.choziosi
MALWARE
Choziosi is a browser hijacker for Chrome. It was first seen in January 2022. It commonly infects users via pirated media downloads like games, software, wallpapers or movies. The initial infectors are available for several platforms such as Mac and Windows.
Its main component is the Chrome browser extension written in JavaScript with the purpose of serving advertisments and hijacking search requests to Google, Yahoo and Bing.
Also known as: ChromeLoader
MALWARE
Malware family identifying win.chiser_client. Origin and technical characteristics tracked via Malpedia.
Chisel
Technical ID: win.chisel
MALWAREfinancialhigh
Chisel is an open-source project by Jaime Pillora (jpillora) that allows tunneling TCP and UDP connections via HTTP. It is available across platforms and written in Go. While benign in itself, Chisel has been utilized by multiple threat actors. It was for example observed by SentinelOne during a PYSA ransomware campaign to achieve persistence and used as backdoor.
Github: https://github.com/jpillora/chisel
Chir
Technical ID: win.chir
MALWARE
Malware family identifying win.chir. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-01-17
View profile →Chinoxy
Technical ID: win.chinoxy
MALWARE
Malware family identifying win.chinoxy. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.chinotto. Origin and technical characteristics tracked via Malpedia.
ChinaJm
Technical ID: win.chinajm
MALWAREfinancialhigh
Ransomware.
Chinad
Technical ID: win.chinad
MALWARE
Adware that shows advertisements using plugin techniques for popular browsers
MALWARE
a simple code injection webshell that executes Microsoft .NET code within HTTP POST commands. This allows the shell to upload and download files, execute applications with web server account permissions, list directory contents, access Active Directory, access databases, and any other action allowed by the .NET runtime.
Chimera
Technical ID: win.chimera
MALWAREfinancialhigh
According to PCrisk, Chimera is a ransomware virus that encrypts files stored on infected systems. It is distributed using various false job applications, business offers, and infected email attachments. After encrypting the files, Chimera adds a . crypt extension to each file.
Chihuahua
Technical ID: win.chihuahua
MALWARE
Malware family identifying win.chihuahua. Origin and technical characteristics tracked via Malpedia.
ChewBacca
Technical ID: win.chewbacca
MALWARE
Malware family identifying win.chewbacca. Origin and technical characteristics tracked via Malpedia.
CherryPicker POS
Technical ID: win.cherry_picker
MALWARE
Malware family identifying win.cherry_picker. Origin and technical characteristics tracked via Malpedia.
Also known as: cherrypickerpos • cherrypicker • cherry_picker
CherryLoader
Technical ID: win.cherryloader
MALWARE
Malware family identifying win.cherryloader. Origin and technical characteristics tracked via Malpedia.
Chernolocker
Technical ID: win.chernolocker
MALWAREfinancialhigh
Chernolocker is a ransomware that encrypts a victim's files by using AES-256 and it asks for BTC ransom. Different versions are classified by the attacker's email address which changes over time.
MALWARE
CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line parameters. The backdoor is capable of enumerating files and processes, enumerating drivers, enumerating remote desktop sessions, uploading and downloading files, creating and terminating processes, deleting files, creating a reverse shell, acting as a proxy server, and hijacking processes among its other functionality. The backdoor communicates with its C&C server using a custom binary protocol over TCP with port specified as a command-line parameter.
Also known as: CROWDEDFLOUNDER