Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
Buzus
Technical ID: win.buzus
MALWARE
Malware family identifying win.buzus. Origin and technical characteristics tracked via Malpedia.
Also known as: Yimfoca
Updated: 2018-10-18
View profile →
Buterat
Technical ID: win.buterat
MALWARE
Malware family identifying win.buterat. Origin and technical characteristics tracked via Malpedia.
Also known as: spyvoltar
Updated: 2018-06-19
View profile →
BURNBOOK
Technical ID: win.burnbook
UNC2970
MALWARE
According to Mandiant, BURNBOOK is a dropper for TEARPAGE.
Updated: 2025-11-21
View profile →
BunnyLoader
Technical ID: win.bunnyloader
MALWARE
Malware family identifying win.bunnyloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-25
View profile →
Bunitu
Technical ID: win.bunitu
MALWARE
Bunitu is a trojan that exposes infected computers to be used as a proxy for remote clients. It registers itself at startup by providing its address and open ports. Access to Bunitu proxies is available by using criminal VPN services (e.g.VIP72).
Updated: 2021-04-12
View profile →
BundleBot
Technical ID: win.bundlebot
MALWARE
Bundlebot is an info stealer that abuses the single-file dotnet bundle which operates as a self-contained executable that does not require any preinstalled dotnet runtime version. Bundlebot functionality targets a wide variety of data including the victim's system information, browser data, telegram data, discord token, Facebook account information, and screenshots.
Updated: 2023-07-26
View profile →
Bundestrojaner
Technical ID: win.bundestrojaner
MALWARE
Malware family identifying win.bundestrojaner. Origin and technical characteristics tracked via Malpedia.
Also known as: R2D2 • 0zapftis
Updated: 2018-09-10
View profile →
BumbleBee
Technical ID: win.bumblebee
EXOTIC LILYGOLD CABINTA578TA579
MALWARE
This malware is delivered by an ISO file, with an DLL inside with a custom loader. Because of the unique user-agent "bumblebee" this malware was dubbed BUMBLEBEE. At the time of Analysis by Google's Threat Analysis Group (TAG) BumbleBee was observed to fetch Cobalt Strike Payloads.
Also known as: COLDTRAIN • SHELLSTING • Shindig
Updated: 2025-11-25
View profile →
Buhtrap
Technical ID: win.buhtrap
BuhTrap
MALWARE
Malware family identifying win.buhtrap. Origin and technical characteristics tracked via Malpedia.
Also known as: Ratopak
Updated: 2021-02-06
View profile →
bugsleep
Technical ID: win.bugsleep
MALWARE
Malware family identifying win.bugsleep. Origin and technical characteristics tracked via Malpedia.
Also known as: MuddyRot
Updated: 2024-12-16
View profile →
BUGHATCH
Technical ID: win.bughatch
MALWARE
According to Elastic, BUGHATCH is an in-memory implant loaded by an obfuscated PowerShell script that decodes and executes an embedded shellcode blob in its allocated memory space using common Windows APIs (VirtualAlloc, CreateThread, WaitForSingleObject).
Updated: 2023-05-15
View profile →
BUFFETLINE
Technical ID: win.buffetline
Lazarus Group
MALWARE
Malware family identifying win.buffetline. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-27
View profile →
Buer
Technical ID: win.buer
MALWARE
Buer is a downloader sold on underground forums and used by threat actors to deliver payload malware onto target machines. It has been observed in email campaigns and has been sold as a service since August 2019.
Also known as: Buerloader • RustyBuer
Updated: 2023-01-31
View profile →
BUBBLEWRAP
Technical ID: win.bubblewrap
Temper Panda
MALWARE
BUBBLEWRAP is a full-featured backdoor that is set to run when the system boots, and can communicate using HTTP, HTTPS, or a SOCKS proxy. This backdoor collects system information, including the operating system version and hostname, and includes functionality to check, upload, and register plugins that can further enhance its capabilities.
Updated: 2019-04-12
View profile →
BTCWare
Technical ID: win.btcware
MALWAREfinancialhigh
According to PCRisk, BTCWare is an updated version of a ransomware-type virus called Crptxxx. This ransomware is distributed via a malicious application called "Rogers Hi-Speed Internet". Once infiltrated, BTCWare encrypts files and appends filenames with the ".btcware" extension. Newer variants of this ransomware append .shadow, .payday, .wyvern, .nuclear, .aleta, .gryphon, .nopasaran, .blocking, .xfile, .master, .onyon, .theva, .cryptobyte or .cryptowin extensions to encrypted files. BTCWare then creates an HTM file ("#_HOW_TO_FIX_!.hta.htm"), placing it on the desktop. Other variants of this ransomware use !#_RESTORE_FILES_#!.inf file to store their ransom demanding message.
Updated: 2024-05-14
View profile →
BS2005
Technical ID: win.bs2005
Mirage
MALWARE
Malware family identifying win.bs2005. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-29
View profile →
BrutPOS
Technical ID: win.brutpos
MALWARE
Malware family identifying win.brutpos. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-04-23
View profile →
Brute Ratel C4
Technical ID: win.brute_ratel_c4
MALWAREespionageadvanced
Brute Ratel C4 (BRC4) is a commercial framework for red-teaming and adversarial attack simulation, which made its first appearance in December 2020. It was specifically designed to evade detection by endpoint detection and response (EDR) and antivirus (AV) capabilities. BRC4 allows operators to deploy a backdoor agent known as Badger (aka BOLDBADGER) within a target environment. This agent enables arbitrary command execution, facilitating lateral movement, privilege escalation, and the establishment of additional persistence avenues. The Badger backdoor agent can communicate with a remote server via DNS over HTTPS, HTTP, HTTPS, SMB, and TCP, using custom encrypted channels. It supports a variety of backdoor commands including shell command execution, file transfers, file execution, and credential harvesting. Additionally, the Badger agent can perform tasks such as port scanning, screenshot capturing, and keystroke logging. Notably, in September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.
Also known as: BOLDBADGER • BruteRatel
Updated: 2025-10-15
View profile →
BrushaLoader
Technical ID: win.brushaloader
MALWARE
Malware family identifying win.brushaloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-11-20
View profile →
Bruh Wiper
Technical ID: win.bruh_wiper
MALWARE
Malware family identifying win.bruh_wiper. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-01-25
View profile →
Broomstick
Technical ID: win.broomstick
MALWAREfinancialhigh
Oyster is a backdoor malware written in C++ that first appeared in July 2023. It allows for remote sessions, supporting tasks such as file transfer and command-line processing. This malware has been used by numerous threat actors as a tool to facilitate ransomware intrusions. The distribution of Oyster has likely occurred through various methods, as suggested by the build identifiers found in examined samples. Additionally, Oyster is capable of collecting basic system data and communicates with a command-and-control (C2) server. It can execute commands via cmd.exe and run additional files. In August 2024, a new version of Oyster was discovered that featured a new command-and-control (C2) communication protocol format. This 2024 version contained plaintext strings and lacked code obfuscation, suggesting it was still in development. In contrast to the 2024 version, the new 2025 Oyster version does not send C2 messages in plaintext, instead reintroducing the substitution cipher that was present in earlier versions of Oyster.
Also known as: CLEANBOOST • CleanUp • CleanUpLoader • Oyster
Updated: 2026-01-14
View profile →
BROLER
Technical ID: win.broler
Tick
MALWARE
Malware family identifying win.broler. Origin and technical characteristics tracked via Malpedia.
Also known as: down_new
Updated: 2020-06-02
View profile →
BROKEYOLK
Technical ID: win.brokeyolk
MALWARE
According to Mandiant, BROKEYOLK is a .NET downloader that downloads and executes a file from a hard-coded command and control (C2) server. The malware communicates via SOAP (Simple Object Access Protocol) requests using HTTP.
Updated: 2023-11-17
View profile →
BrittleBush
Technical ID: win.brittle_bush
Molerats
MALWARE
Malware family identifying win.brittle_bush. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-09
View profile →
Bredolab
Technical ID: win.bredolab
MALWARE
Malware family identifying win.bredolab. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-01-28
View profile →
Breakthrough
Technical ID: win.breakthrough_loader
MALWARE
There is no reference available for this family and all known samples have version 1.0.0. Pdb-strings in the samples suggest that this is an "exclusive" loader, known as "breakthrough" (maybe), e.g. C:\Users\Exclusiv\Desktop\хп-пробив\Release\build.pdb The communication url parameters are pretty unique in this combination: gate.php?hwid=<guid>&os=<OS>&build=1.0.0&cpu=8 <OS> is one of: Windows95 Windows98 WindowsMe Windows95family WindowsNT3 WindowsNT4 Windows2000 WindowsXP WindowsServer2003 WindowsNTfamily WindowsVista Windows7 Windows8 Windows10
Updated: 2018-09-21
View profile →
BreachRAT
Technical ID: win.breach_rat
Operation C-Major
MALWARE
This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++. The malware name is derived from the hardcoded PDB path found in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb
Updated: 2019-04-08
View profile →
BrbBot
Technical ID: win.brbbot
MALWARE
Malware family identifying win.brbbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-09
View profile →
BravoNC
Technical ID: win.bravonc
Lazarus Group
MALWARE
Malware family identifying win.bravonc. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-23
View profile →
Brambul
Technical ID: win.brambul
Lazarus Group
MALWARE
Brambul is a worm that spreads by using a list of hard-coded login credentials to launch a brute-force password attack against an SMB protocol for access to a victim’s networks.
Also known as: SORRYBRUTE
Updated: 2022-03-02
View profile →
BRAIN
Technical ID: win.brain
MALWARE
Malware family identifying win.brain. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-07
View profile →
BQTlock
Technical ID: win.bqtlock
MALWARE
Malware family identifying win.bqtlock. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-09-30
View profile →
Bozok
Technical ID: win.bozok
Operation C-MajorTemper Panda
MALWARE
Malware family identifying win.bozok. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-04-29
View profile →
BoxCaon
Technical ID: win.boxcaon
MALWARE
According to Checkpoint Research, this malware family has the ability to download and upload files, run commands and send the attackers the results. It has been observed being used by threat actor IndigoZebra.
Updated: 2022-10-25
View profile →
Bouncer
Technical ID: win.bouncer
Comment Crew
MALWARE
Malware family identifying win.bouncer. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-02-10
View profile →
BottomLoader
Technical ID: win.bottomloader
MALWARE
Malware family identifying win.bottomloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-15
View profile →
Borr
Technical ID: win.borr
MALWARE
Malware family identifying win.borr. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-13
View profile →
Borat RAT
Technical ID: win.boratrat
MALWAREfinancialhigh
The Borat RAT comes bundled with its components (e.g. binary builder, supporting modules, server certificates). According to Cyble this malware is an unique combination of RAT, Spyware, and ransomware. The supporting modules are included; a few of the capabilities: Keylogger, Ransomware, Audio/Webcam Recording, Process Hollowing, Browser Credential/Discord Token Stealing, etc.
Updated: 2022-05-08
View profile →
BOOTWRECK
Technical ID: win.bootwreck
Lazarus Group
MALWARE
BOOTWRECK is a master boot record wiper malware.
Also known as: MBRkiller
Updated: 2019-10-12
View profile →
BOOSTWRITE
Technical ID: win.boostwrite
Anunak
MALWARE
FireEye describes BOOSTWRITE as a loader crafted to be launched via abuse of the DLL search order of applications which load the legitimate ‘Dwrite.dll’ provided by the Microsoft DirectX Typography Services. The application loads the ‘gdi’ library, which loads the ‘gdiplus’ library, which ultimately loads ‘Dwrite’. Mandiant identified instances where BOOSTWRITE was placed on the file system alongside the RDFClient binary to force the application to import DWriteCreateFactory from it rather than the legitimate DWrite.dll.
Updated: 2022-05-05
View profile →
← PreviousPage 180 / 269Next →