Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
ChChes
Technical ID: win.chches
Stone Panda
MALWARE
Malware family identifying win.chches. Origin and technical characteristics tracked via Malpedia.
Also known as: HAYMAKER • Ham Backdoor
Updated: 2020-05-23
View profile →
CHCH
Technical ID: win.chch
MALWAREfinancialhigh
CHCH is a Ransomware spotted in the wild in December 2019. It encrypts victim files and adds the extension .chch to them while it drops a ransomware note named: READ_ME.TXT
Updated: 2019-12-18
View profile →
Charon
Technical ID: win.charon
MALWAREfinancialhigh
According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.
Updated: 2025-12-30
View profile →
ChargeWeapon
Technical ID: win.chargeweapon
MALWARE
Malware family identifying win.chargeweapon. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-10-06
View profile →
Chaperone
Technical ID: win.chaperone
MALWAREespionageadvanced
According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky Lab in the autumn of 2018. This full-blown spying framework consists of two packages named Tokyo and Yokohama. It includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers, and even its own file indexer for the victim’s machine. We discovered up to 80 malicious modules stored in its encrypted Virtual File System, one of the highest numbers of plugins they have ever seen for an APT toolset.
Also known as: Taj Mahal
Updated: 2020-08-13
View profile →
Chaos
Technical ID: win.chaos
MALWAREfinancialhigh
In-development ransomware family which was released in June 2021 by an unknown threat actor. The builder initially claimed to be a "Ryuk .Net Ransomware Builder" even though it was completely unrelated to the Ryuk malware family. Presently it appears to contain trojan-like features, but lacks features commonly found in ransomware such as data exfiltration.
Also known as: FakeRyuk • RyukJoke • Yashma
Updated: 2025-12-11
View profile →
CHAIRSMACK
Technical ID: win.chairsmack
Charming Kitten
MALWARE
Malware family identifying win.chairsmack. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-11-17
View profile →
Chainshot
Technical ID: win.chainshot
MALWARE
Malware family identifying win.chainshot. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-07-20
View profile →
Chaes
Technical ID: win.chaes
MALWARE
This malware made its first appearance during the middle to end of 2020, it specifically targets Brazil and the largest e-commerce company in Latin America, Mercado Livre. It is a multistage malware deployment which uses several legitimate Windows processes and open source tools to remain undetected.
Updated: 2024-09-02
View profile →
ChaChi
Technical ID: win.chachi
MALWARE
Malware family identifying win.chachi. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-31
View profile →
CetaRAT
Technical ID: win.ceta_rat
MALWARE
Malware family identifying win.ceta_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-25
View profile →
Cerber
Technical ID: win.cerber
MALWAREfinancialhigh
A prolific ransomware which originally added ".cerber" as a file extension to encrypted files. Has undergone multiple iterations in which the extension has changed. Uses a very readily identifiable set of of UDP activity to checkin and report infections. Primarily uses TOR for payment information.
Updated: 2024-11-25
View profile →
CenterPOS
Technical ID: win.centerpos
MALWARE
Malware family identifying win.centerpos. Origin and technical characteristics tracked via Malpedia.
Also known as: cerebrus
Updated: 2018-04-23
View profile →
CEELOADER
Technical ID: win.ceeloader
UNC2452
MALWARE
Mandiant characterizes this malware as a downloader and shellcode stager.
Updated: 2024-12-13
View profile →
CCleaner Backdoor
Technical ID: win.ccleaner_backdoor
MALWARE
According to CrowdStrike, this backdoor was discovered embedded in the legitimate, signed version of CCleaner 5.33, and thus constitutes a supply chain attack.
Also known as: DIRTCLEANER
Updated: 2024-12-06
View profile →
Catchamas
Technical ID: win.catchamas
Thrip
MALWARE
Malware family identifying win.catchamas. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-06-25
View profile →
CatB
Technical ID: win.catb
MALWARE
Malware family identifying win.catb. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-04
View profile →
CASTLELOADER
Technical ID: win.castleloader
MALWARE
CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the loader that, in turn, connects to the C2 server in order to fetch and execute the next-stage malware.
Updated: 2026-02-17
View profile →
Casper
Technical ID: win.casper
SNOWGLOBE
MALWARE
ESET describes Casper as a well-developed reconnaissance tool, making extensive efforts to remain unseen on targeted machines. Of particular note are the specific strategies adopted against anti-malware software. Casper was used against Syrian targets in April 2014, which makes it the most recent malware from this group publicly known at this time.
Updated: 2018-01-17
View profile →
CashRansomware
Technical ID: win.cashransom
MALWARE
Malware family identifying win.cashransom. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-25
View profile →
CarrotBat
Technical ID: win.carrotbat
MALWARE
Malware family identifying win.carrotbat. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-01-26
View profile →
CARROTBALL
Technical ID: win.carrotball
MALWARE
CARROTBALL is a simple FTP downloader built to deploy SYSCON, a Remote Access Trojan used by the same threat actor. Discovered by Unit 42 in late 2019, the downloader was adopted for use in spear phishing attacks against US government agencies.
Updated: 2020-02-04
View profile →
CargoBay
Technical ID: win.cargobay
MALWARE
CargoBay is a newer malware family which was first observed in 2022 and is notable for being written in the Rust language. CargoBay is likely based on source code taken from 'Black Hat Rust' GitHub project (https://github.com/skerkour/black-hat-rust). CargoBay is usually distributed via phishing emails, and the malware binaries may be disguised as legitimate applications. Upon execution, the malware starts by performing environmental checks such as checking its execution path and the configured system language. If the tests pass, then the malware proceeds to gather basic system information and register with its C2 via HTTP from which it receives JSON-formatted jobs to carry out. CargoBay can execute commands via the command line and downloading additional malware binaries.
Updated: 2023-02-27
View profile →
Careto
Technical ID: win.careto
Careto
MALWARE
Malware family identifying win.careto. Origin and technical characteristics tracked via Malpedia.
Also known as: TheMask
Updated: 2025-05-26
View profile →
Cardinal RAT
Technical ID: win.cardinal_rat
MALWAREespionageadvanced
Cardinal RAT is a remote access Trojan capable of stealing username and credentials, cleaning out cookies from browsers, keylogging and capturing screenshots on targeted systems. It is delivered via a downloader dubbed “Carp” which uses malicious macros in Microsoft Excel documents to compile embedded source code into an executable, which then deploys the Cardinal RAT malware family.
Updated: 2025-09-09
View profile →
Carberp
Technical ID: win.carberp
MALWARE
Malware family identifying win.carberp. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-09
View profile →
Carbanak
Technical ID: win.carbanak
FIN7
MALWAREespionageadvanced
MyCERT states that Carbanak is a remote backdoor designed for espionage, data exfiltration, and to remote control. The attacker deploy malware via spear phishing email to lure the user to open and run the malicious attachment that will infect the machine. The main objective of this campaign is primarily to remotely control the infected machine and gain control of the internal destinations of money processing services such as Automated Teller Machines(ATM) and financial accounts. The following information are the malware capabilities:
Also known as: Anunak • Sekur RAT
Updated: 2025-09-09
View profile →
Cannon
Technical ID: win.cannon
APT28
MALWARE
Malware family identifying win.cannon. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-29
View profile →
Cannibal Rat
Technical ID: win.cannibal_rat
MALWARE
Cannibal Rat is a python written remote access trojan with 4 versions as of March 2018. The RAT is reported to impact users of a Brazilian public sector management school. The RAT is distributed in a py2exe format, with the python27.dll and the python bytecode stored as a PE resource and the additional libraries zipped in the overlay of the executable.
Updated: 2018-03-17
View profile →
CamuBot
Technical ID: win.camubot
MALWARE
There is no lot of IOCs in this article so we take one sample and try to extract some interesting IOCs, our findings below : CamuBot sample : 37ca2e37e1dc26d6b66ba041ed653dc8ee43e1db71a705df4546449dd7591479 Dropped Files on disk : C:\Users\user~1\AppData\Local\Temp\protecao.exe : 0af612461174eedec813ce670ba35e74a9433361eacb3ceab6d79232a6fe13c1 C:\Users\user~1\AppData\Local\Temp\Renci.SshNet.dll : 3E3CD9E8D94FC45F811720F5E911B892A17EE00F971E498EAA8B5CAE44A6A8D8 C:\ProgramData\m.msi : AD90D4ADFED0BDCB2E56871B13CC7E857F64C906E2CF3283D30D6CFD24CD2190 Protecao.exe try to download hxxp://www.usb-over-network.com/usb-over-network-64bit.msi A new driver is installed : C:\Windows\system32\drivers\ftusbload2.sys : 9255E8B64FB278BC5FFE5B8F70D68AF8 ftusbload2.sys set 28 IRP handlers.
Updated: 2018-09-07
View profile →
campoloader
Technical ID: win.campoloader
MALWARE
Malware family identifying win.campoloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-08-06
View profile →
Cameleon
Technical ID: win.cameleon
MALWARE
PWC describes this malware as a backdoor, capable of file management, upload and download of files, and execution of commands.
Also known as: StormKitty
Updated: 2024-05-14
View profile →
CALMTHORN
Technical ID: win.calmthorn
Tonto Team
MALWARE
Malware family identifying win.calmthorn. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-02-09
View profile →
CadelSpy
Technical ID: win.cadelspy
MALWAREespionageadvanced
CadelSpy is a spyware supposedly used by Iranian threat actors. It has several functions such as logging keystrokes, record audio, capture screenshots and webcam photos, and steal any documents that are sent to a printer.
Also known as: Cadelle
Updated: 2023-10-17
View profile →
CaddyWiper
Technical ID: win.caddywiper
APT28Sandworm
MALWARE
CaddyWiper is another destructive malware believed to be deployed to target Ukraine. CaddyWiper wipes all files under C:\Users and all also all files under available drives from D: to Z: by overwriting the data with NULL value. If the target file is greater than 0xA00000 bytes in size (10MB), it will only wipe the first 0xA00000 bytes. It also wipes disk partitions from \\.\PHYSICALDRIVE9 to \\.\PHYSICALDRIVE0 by overwriting the first 0x780 bytes with NULL.
Also known as: KillDisk.NCX
Updated: 2024-06-13
View profile →
Cactus
Technical ID: win.cactus
MALWARE
Malware family identifying win.cactus. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-09
View profile →
CabArt
Technical ID: win.cabart
MALWARE
Malware family identifying win.cabart. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-18
View profile →
c0d0so0
Technical ID: win.c0d0so0
MALWARE
Malware family identifying win.c0d0so0. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-04-25
View profile →
BypassBoss
Technical ID: win.bypassboss
MALWARE
Malware family identifying win.bypassboss. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-06-03
View profile →
BYEBY
Technical ID: win.byeby
Calypso groupKarma Panda
MALWARE
Malware family identifying win.byeby. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-07-25
View profile →
← PreviousPage 179 / 269Next →