Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
MALWARE
Malware family identifying win.boombox. Origin and technical characteristics tracked via Malpedia.
Bookworm
Technical ID: win.bookworm
MALWARE
Malware family identifying win.bookworm. Origin and technical characteristics tracked via Malpedia.
Book of Eli
Technical ID: win.bookofeli
MALWAREespionageadvanced
This in .Net written malware is a classic information stealer. It can collect various information and can be depoyed in different configurations: "The full-featured version of the malware can log keystrokes, collect profile files of Mozilla Firefox and Google Chrome browsers, record sound from the microphone, grab desktop screenshots, capture photo from the webcam, and collect information about the version of the operation system and installed anti-virus software." (ESET)
This malware has been active since at least 2012.
MALWARE
BookCodesRAT is a remote access trojan that uses HTTP(S) for communication. It supports around 25 commands that include operations on the victim’s filesystem, basic process management and the download and execution of additional tools from the attacker’s arsenal. They are indexed by 32-bit integers, starting with the value 0x97853646.
BookCodesRAT uses mostly compromised South Korean web servers for the C&C traffic and is usually deployed against South Korean targets.
Also known as: BookCodesTea
Bolek
Technical ID: win.bolek
MALWARE
Malware family identifying win.bolek. Origin and technical characteristics tracked via Malpedia.
Also known as: KBOT
BOLDMOVE
Technical ID: win.boldmove
MALWARE
According to Mandiant, this malware family is attributed to potential chinese background and its Linux variant is related to exploitation of Fortinet's SSL-VPN (CVE-2022-42475).
Bohmini
Technical ID: win.bohmini
MALWARE
Malware family identifying win.bohmini. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-24
View profile →Bofamet
Technical ID: win.bofamet
MALWARE
Bofamet Stealer is an infostealer managed through a web-based Command and Control (C2) panel, allowing attackers to configure operations, monitor infected hosts, and retrieve stolen data in real time.
BockLit
Technical ID: win.bocklit
MALWAREfinancialhigh
According to Trend Micro, this is a ransomware written in Go, targeting Windows and MacOS environments that tries to disguise as LockBit by changing the wallpaper into a LockBit 2 screen. Most of the samples contained hard-coded AWS credentials, and the stolen data were uploaded to an Amazon S3 bucket controlled by the threat actor.
Bobik
Technical ID: win.bobik
MALWARE
This malware offers remote access capabilities but also has a DDoS module that was used against supporters of Ukraine.
Boaxxe
Technical ID: win.boaxxe
MALWARE
Malware family identifying win.boaxxe. Origin and technical characteristics tracked via Malpedia.
MALWARE
FIN7 uses this malware as helper module during intrusion operations. BOATLAUNCH is continuously looking for PowerShell processes on infected systems and patches them to bypuss Windows AntiMalware Scan Interface (AMSI).
BMANAGER
Technical ID: win.bmanager
MALWARE
Malware family identifying win.bmanager. Origin and technical characteristics tracked via Malpedia.
BluStealer
Technical ID: win.blustealer
MALWARE
Avast describe this malware as a recombination of other malware including SpyEx, ThunderFox, ChromeRecovery, StormKitty, and firepwd.
Also known as: a310logger
MALWARE
Malware family identifying win.bluether. Origin and technical characteristics tracked via Malpedia.
Also known as: CAPGELD
BlueSky
Technical ID: win.bluesky
MALWAREfinancialhigh
Ransomware.
BlueShell
Technical ID: win.blueshell
MALWARE
According to AhnLab, BlueShell is a backdoor malware developed in Go language, published on Github, and it supports Windows, Linux, and Mac operating systems. Currently, the original Github repository is presumed to have been deleted, but the BlueShell source code can still be obtained from other repositories. It features an explanatory ReadMe file in Chinese, indicating the possibility that the creator is a Chinese user.
MALWARE
This family contains the BlueNoroff toolkit used for SWIFT manipulation, as used by the Lazarus activity cluster also referred to as BlueNoroff.
MALWARE
Malware family used to deliver follow up payloads, variants using Microsoft Graph API and Google Web Apps have been observed.
BLUEHAZE
Technical ID: win.bluehaze
MALWARE
Mandiant associates this with UNC4191, this malware is a launcher for NCAT to establish a reverse tunnel.
BlueFox
Technical ID: win.bluefox
MALWARE
BlueFox is a .NET infostealer sold on forums as a Maware-as-a-Service. Its capabilities are those of a classic information stealer, with a focus on cryptocurrency wallets, and file grabber and loader capabilities.
BloodyStealer
Technical ID: win.bloodystealer
MALWARE
Malware family identifying win.bloodystealer. Origin and technical characteristics tracked via Malpedia.
BloodAlchemy
Technical ID: win.bloodalchemy
MALWARE
This malware family is the suspected successor to ShadowPad and Deed rat.
Blister
Technical ID: win.blister
MALWARE
Elastic observed this loader coming with valid code signatures, being used to deploy secondary payloads in-memory.
Also known as: COLORFAKE
BlindEDR
Technical ID: win.blind_edr
MALWARE
According to Cyderes, this is a tool to clear kernel callbacks registered by a range of security solutions.
MALWARE
BLINDTOAD is 64-bit Service DLL that loads an encrypted file from disk and executes it in memory.
MALWARE
BLINDINGCAN is a remote access trojan that communicates with its C&C server via HTTP(S).
It uses a (custom) RC4 or AES for encryption and decryption of its configuration and network traffic.
It sends information about the victim's environment, like computer name, IP, Windows product name and processor name.
It supports around 30 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, configuration update, and the download and execution of additional payloads from the attackers' C&C. The commands are indexed by 16-bit integers, starting with the index 0x2009 and going incrementally up to 0x2057, with some indicis being skipped.
It uses various parameter names in its HTTP POST requests, mostly associated with web servers running bulletin board systems, like bbs, article, boardid, s_board, page, idx_num, etc.
It contains specific RTTI symbols like ".?AVCHTTP_Protocol@@", ".?AVCFileRW@@" or ".?AVCSinSocket@@".
BLINDINGCAN RAT is a flagship payload deployed in many Lazarus attacks, especially in the Operation DreamJob campaigns happening in 2020-2022.
Also known as: AIRDRY • ZetaNile
BleachGap
Technical ID: win.bleachgap
MALWARE
Malware family identifying win.bleachgap. Origin and technical characteristics tracked via Malpedia.
Blackworm RAT
Technical ID: win.blackworm_rat
MALWARE
Malware family identifying win.blackworm_rat. Origin and technical characteristics tracked via Malpedia.
BlackSuit
Technical ID: win.blacksuit
MALWAREfinancialhigh
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
BlackSoul
Technical ID: win.blacksoul
MALWARE
Malware family identifying win.blacksoul. Origin and technical characteristics tracked via Malpedia.
BlackSnake
Technical ID: win.blacksnake
MALWARE
Malware family identifying win.blacksnake. Origin and technical characteristics tracked via Malpedia.
BlackShades
Technical ID: win.blackshades
MALWARE
Malware family identifying win.blackshades. Origin and technical characteristics tracked via Malpedia.
Blackruby
Technical ID: win.blackruby
MALWAREfinancialhigh
Ransomware.
BlackRouter
Technical ID: win.blackrouter
MALWARE
Malware family identifying win.blackrouter. Origin and technical characteristics tracked via Malpedia.
Also known as: BLACKHEART
BlackRevolution
Technical ID: win.blackrevolution
MALWARE
Malware family identifying win.blackrevolution. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-05-31
View profile →BlackRemote
Technical ID: win.blackremote
MALWARE
Malware family identifying win.blackremote. Origin and technical characteristics tracked via Malpedia.
Also known as: BlackRAT
BlackPOS
Technical ID: win.blackpos
MALWARE
BlackPOS infects computers running on Windows that have credit card readers connected to them and are part of a POS system. POS system computers can be easily infected if they do not have the most up to date operating systems and antivirus programs to prevent security breaches or if the computer database systems have weak administration login credentials.
Also known as: Kaptoxa • MMon • POSWDS • Reedum
BlackNix RAT
Technical ID: win.blacknix_rat
MALWARE
Malware family identifying win.blacknix_rat. Origin and technical characteristics tracked via Malpedia.
BlackNET RAT
Technical ID: win.blacknet_rat
MALWARE
Advanced and modern Windows botnet with PHP panel developed using VB.NET. It has a lot of functionalities including: stealing/grabbing files and passwords, keylogging, cryptojacking, loading files, executing commands, etc. It is open source and emerged at the end of 2019.