Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
MALWARE
Malware family identifying win.chches. Origin and technical characteristics tracked via Malpedia.
Also known as: HAYMAKER • Ham Backdoor
CHCH
Technical ID: win.chch
MALWAREfinancialhigh
CHCH is a Ransomware spotted in the wild in December 2019. It encrypts victim files and adds the extension .chch to them while it drops a ransomware note named: READ_ME.TXT
Charon
Technical ID: win.charon
MALWAREfinancialhigh
According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.
ChargeWeapon
Technical ID: win.chargeweapon
MALWARE
Malware family identifying win.chargeweapon. Origin and technical characteristics tracked via Malpedia.
Chaperone
Technical ID: win.chaperone
MALWAREespionageadvanced
According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky Lab in the autumn of 2018. This full-blown spying framework consists of two packages named Tokyo and Yokohama. It includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers, and even its own file indexer for the victim’s machine. We discovered up to 80 malicious modules stored in its encrypted Virtual File System, one of the highest numbers of plugins they have ever seen for an APT toolset.
Also known as: Taj Mahal
Chaos
Technical ID: win.chaos
MALWAREfinancialhigh
In-development ransomware family which was released in June 2021 by an unknown threat actor. The builder initially claimed to be a "Ryuk .Net Ransomware Builder" even though it was completely unrelated to the Ryuk malware family. Presently it appears to contain trojan-like features, but lacks features commonly found in ransomware such as data exfiltration.
Also known as: FakeRyuk • RyukJoke • Yashma
MALWARE
Malware family identifying win.chairsmack. Origin and technical characteristics tracked via Malpedia.
Chainshot
Technical ID: win.chainshot
MALWARE
Malware family identifying win.chainshot. Origin and technical characteristics tracked via Malpedia.
Chaes
Technical ID: win.chaes
MALWARE
This malware made its first appearance during the middle to end of 2020, it specifically targets Brazil and the largest e-commerce company in Latin America, Mercado Livre. It is a multistage malware deployment which uses several legitimate Windows processes and open source tools to remain undetected.
ChaChi
Technical ID: win.chachi
MALWARE
Malware family identifying win.chachi. Origin and technical characteristics tracked via Malpedia.
CetaRAT
Technical ID: win.ceta_rat
MALWARE
Malware family identifying win.ceta_rat. Origin and technical characteristics tracked via Malpedia.
Cerber
Technical ID: win.cerber
MALWAREfinancialhigh
A prolific ransomware which originally added ".cerber" as a file extension to encrypted files. Has undergone multiple iterations in which the extension has changed. Uses a very readily identifiable set of of UDP activity to checkin and report infections. Primarily uses TOR for payment information.
CenterPOS
Technical ID: win.centerpos
MALWARE
Malware family identifying win.centerpos. Origin and technical characteristics tracked via Malpedia.
Also known as: cerebrus
MALWARE
Mandiant characterizes this malware as a downloader and shellcode stager.
CCleaner Backdoor
Technical ID: win.ccleaner_backdoor
MALWARE
According to CrowdStrike, this backdoor was discovered embedded in the legitimate, signed version of CCleaner 5.33, and thus constitutes a supply chain attack.
Also known as: DIRTCLEANER
MALWARE
Malware family identifying win.catchamas. Origin and technical characteristics tracked via Malpedia.
CatB
Technical ID: win.catb
MALWARE
Malware family identifying win.catb. Origin and technical characteristics tracked via Malpedia.
CASTLELOADER
Technical ID: win.castleloader
MALWARE
CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the loader that, in turn, connects to the C2 server in order to fetch and execute the next-stage malware.
MALWARE
ESET describes Casper as a well-developed reconnaissance tool, making extensive efforts to remain unseen on targeted machines. Of particular note are the specific strategies adopted against anti-malware software. Casper was used against Syrian targets in April 2014, which makes it the most recent malware from this group publicly known at this time.
CashRansomware
Technical ID: win.cashransom
MALWARE
Malware family identifying win.cashransom. Origin and technical characteristics tracked via Malpedia.
CarrotBat
Technical ID: win.carrotbat
MALWARE
Malware family identifying win.carrotbat. Origin and technical characteristics tracked via Malpedia.
CARROTBALL
Technical ID: win.carrotball
MALWARE
CARROTBALL is a simple FTP downloader built to deploy SYSCON, a Remote Access Trojan used by the same threat actor. Discovered by Unit 42 in late 2019, the downloader was adopted for use in spear phishing attacks against US government agencies.
CargoBay
Technical ID: win.cargobay
MALWARE
CargoBay is a newer malware family which was first observed in 2022 and is notable for being written in the Rust language. CargoBay is likely based on source code taken from 'Black Hat Rust' GitHub project (https://github.com/skerkour/black-hat-rust). CargoBay is usually distributed via phishing emails, and the malware binaries may be disguised as legitimate applications. Upon execution, the malware starts by performing environmental checks such as checking its execution path and the configured system language. If the tests pass, then the malware proceeds to gather basic system information and register with its C2 via HTTP from which it receives JSON-formatted jobs to carry out. CargoBay can execute commands via the command line and downloading additional malware binaries.
MALWARE
Malware family identifying win.careto. Origin and technical characteristics tracked via Malpedia.
Also known as: TheMask
Cardinal RAT
Technical ID: win.cardinal_rat
MALWAREespionageadvanced
Cardinal RAT is a remote access Trojan capable of stealing username and credentials, cleaning out cookies from browsers, keylogging and capturing screenshots on targeted systems. It is delivered via a downloader dubbed “Carp” which uses malicious macros in Microsoft Excel documents to compile embedded source code into an executable, which then deploys the Cardinal RAT malware family.
Carberp
Technical ID: win.carberp
MALWARE
Malware family identifying win.carberp. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
MyCERT states that Carbanak is a remote backdoor designed for espionage, data exfiltration, and to remote control.
The attacker deploy malware via spear phishing email to lure the user to open and run the malicious attachment that will infect the machine. The main objective of this campaign is primarily to remotely control the infected machine and gain control of the internal destinations of money processing services such as Automated Teller Machines(ATM) and financial accounts. The following information are the malware capabilities:
Also known as: Anunak • Sekur RAT
MALWARE
Malware family identifying win.cannon. Origin and technical characteristics tracked via Malpedia.
Cannibal Rat
Technical ID: win.cannibal_rat
MALWARE
Cannibal Rat is a python written remote access trojan with 4 versions as of March 2018. The RAT is reported to impact users of a Brazilian public sector management school. The RAT is distributed in a py2exe format, with the python27.dll and the python bytecode stored as a PE resource and the additional libraries zipped in the overlay of the executable.
CamuBot
Technical ID: win.camubot
MALWARE
There is no lot of IOCs in this article so we take one sample and try to extract some interesting IOCs, our findings below :
CamuBot sample : 37ca2e37e1dc26d6b66ba041ed653dc8ee43e1db71a705df4546449dd7591479
Dropped Files on disk :
C:\Users\user~1\AppData\Local\Temp\protecao.exe : 0af612461174eedec813ce670ba35e74a9433361eacb3ceab6d79232a6fe13c1
C:\Users\user~1\AppData\Local\Temp\Renci.SshNet.dll : 3E3CD9E8D94FC45F811720F5E911B892A17EE00F971E498EAA8B5CAE44A6A8D8
C:\ProgramData\m.msi : AD90D4ADFED0BDCB2E56871B13CC7E857F64C906E2CF3283D30D6CFD24CD2190
Protecao.exe try to download hxxp://www.usb-over-network.com/usb-over-network-64bit.msi
A new driver is installed : C:\Windows\system32\drivers\ftusbload2.sys : 9255E8B64FB278BC5FFE5B8F70D68AF8
ftusbload2.sys set 28 IRP handlers.
campoloader
Technical ID: win.campoloader
MALWARE
Malware family identifying win.campoloader. Origin and technical characteristics tracked via Malpedia.
Cameleon
Technical ID: win.cameleon
MALWARE
PWC describes this malware as a backdoor, capable of file management, upload and download of files, and execution of commands.
Also known as: StormKitty
MALWARE
Malware family identifying win.calmthorn. Origin and technical characteristics tracked via Malpedia.
CadelSpy
Technical ID: win.cadelspy
MALWAREespionageadvanced
CadelSpy is a spyware supposedly used by Iranian threat actors. It has several functions such as logging keystrokes, record audio, capture screenshots and webcam photos, and steal any documents that are sent to a printer.
Also known as: Cadelle
MALWARE
CaddyWiper is another destructive malware believed to be deployed to target Ukraine.
CaddyWiper wipes all files under C:\Users and all also all files under available drives from D: to Z: by overwriting the data with NULL value. If the target file is greater than 0xA00000 bytes in size (10MB), it will only wipe the first 0xA00000 bytes.
It also wipes disk partitions from \\.\PHYSICALDRIVE9 to \\.\PHYSICALDRIVE0 by overwriting the first 0x780 bytes with NULL.
Also known as: KillDisk.NCX
Cactus
Technical ID: win.cactus
MALWARE
Malware family identifying win.cactus. Origin and technical characteristics tracked via Malpedia.
CabArt
Technical ID: win.cabart
MALWARE
Malware family identifying win.cabart. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-18
View profile →c0d0so0
Technical ID: win.c0d0so0
MALWARE
Malware family identifying win.c0d0so0. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-25
View profile →BypassBoss
Technical ID: win.bypassboss
MALWARE
Malware family identifying win.bypassboss. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.byeby. Origin and technical characteristics tracked via Malpedia.