Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
BlackMatter
Technical ID: win.blackmatter
MALWAREfinancialhigh
According to PCrisk, BlackMatter is a piece of malicious software categorized as ransomware. It operates by encrypting data for the purpose of making ransom demands for the decryption tools. In other words, files affected by BlackMatter are rendered inaccessible, and victims are asked to pay - to recover access to their data.
During the encryption process, files are appended with an extension consisting of a random character string. For example, a file initially named "1.jpg" would appear as something similar to "1.jpg.k5RO9fVOl". After this process is complete, the ransomware changes the desktop wallpaper and created a ransom note - "[random_string].README.txt" (e.g., k5RO9fVOl.README.txt).
BlackMagic
Technical ID: win.blackmagic
MALWAREfinancialhigh
Ransomware
BlackLotus
Technical ID: win.blacklotus
MALWARE
Malware family identifying win.blacklotus. Origin and technical characteristics tracked via Malpedia.
BlackKingdom Ransomware
Technical ID: win.blackkingdom_ransomware
MALWAREfinancialhigh
Malware family identifying win.blackkingdom_ransomware. Origin and technical characteristics tracked via Malpedia.
BlackGuard
Technical ID: win.blackguard
MALWARE
According to Zscaler, BlackGuard has the capability to steal all types of information related to Crypto wallets, VPN, Messengers, FTP credentials, saved browser credentials, and email clients.
MALWAREfinancialhigh
BlackEnergy, its first version shortened as BE1, started as a crimeware being sold in the Russian cyber underground as early as 2007. Initially, it was designed as a toolkit for creating botnets for conducting DDoS attacks. It supported a variety of flooding commands including protocols like ICMP, TCP SYN, UDP, HTTP and DNS. Among the high profile targets of cyber attacks utilising BE1 were a Norwegian bank and government websites in Georgia three weeks before Russo-Georgian War.
Version 2 of BlackEnergy, BE2, came in 2008 with a complete code rewrite that introduced a protective layer, a kernel-mode rootkit and a modular architecture. Plugins included mostly DDoS attacks, a spam plugin and two banking authentication plugins to steal from Russian nad Ukrainian banks. The banking plugin was paired with a module designed to destroy the filesystem. Moreover, BE2 was able to
- download and execute a remote file;
- execute a local file on the infected computer;
- update the bot and its plugins;
The Industrial Control Systems Cyber Emergency Response Team issued an alert warning that BE2 was leveraging the human-machine interfaces of industrial control systems like GE CIMPLICITY, Advantech/Broadwin WebAccess, and Siemens WinCC to gain access to critical infrastructure networks.
In 2014, the BlackEnergy toolkit, BE3, switched to a lighter footprint with no kernel-mode driver component. Its plugins included:
- operations with victim's filesystem
- spreading with a parasitic infector
- spying features like keylogging, screenshoots or a robust password stealer
- Team viewer and a simple pseudo “remote desktop”
- listing Windows accounts and scanning network
- destroying the system
Typical for distribution of BE3 was heavy use of spear-phishing emails containing Microsoft Word or Excel documents with a malicious VBA macro, Rich Text Format (RTF) documents embedding exploits or a PowerPoint presentation with zero-day exploit CVE-2014-4114.
On 23 December 2015, attackers behind the BlackEnergy malware successfully caused power outages for several hours in different regions of Ukraine. This cyber sabotage against three energy companies has been confirmed by the Ukrainian government. The power grid compromise has become known as the first-of-its-kind cyber warfare attack affecting civilians.
MALWARE
a backdoor that obfuscates its communications as normal traffic to legitimate websites such as Github and Microsoft's Technet portal.
Also known as: PNGRAT • gresim • ZoxPNG
MALWAREfinancialhigh
ALPHV, also known as BlackCat or Noberus, is a ransomware family that is deployed as part of Ransomware as a Service (RaaS) operations. ALPHV is written in the Rust programming language and supports execution on Windows, Linux-based operating systems (Debian, Ubuntu, ReadyNAS, Synology), and VMWare ESXi. ALPHV is marketed as ALPHV on cybercrime forums, but is commonly called BlackCat by security researchers due to an icon of a black cat appearing on its leak site. ALPHV has been observed being deployed in ransomware attacks since November 18, 2021.
ALPHV can be configured to encrypt files using either the AES or ChaCha20 algorithms. In order to maximize the amount of ransomed data, ALPHV can delete volume shadow copies, stop processes and services, and stop virtual machines on ESXi servers. ALPHV can self-propagate by using PsExec to remote execute itself on other hosts on the local network.
Also known as: ALPHV • Noberus
BlackByte
Technical ID: win.blackbyte
MALWAREfinancialhigh
Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.
MALWAREfinancialhigh
"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.
Also known as: no_name_software
BKA Trojaner
Technical ID: win.bka_trojaner
MALWAREfinancialhigh
BKA Trojaner is a screenlocker ransomware that was active in 2011, displaying a police-themed message in German language.
Also known as: bwin3_bka
Bizzaro
Technical ID: win.bizarro
MALWAREfinancialhigh
Kaspersky Labs characterizes Bizarro as yet another banking Trojan family originating from Brazil that is now found in other regions of the world. They have seen users being targeted in Spain, Portugal, France and Italy. Attempts have now been made to steal credentials from customers of 70 banks from different European and South American countries.
BitRAT
Technical ID: win.bit_rat
MALWARE
According to Bitdefender, BitRAT is a notorious remote access trojan (RAT) marketed on underground cybercriminal web markets and forums. Its price tag of $20 for lifetime access makes it irresistible to cybercriminals and helps the malicious payload spread.
Furthermore, each buyer’s modus operandi makes BitRAT even harder to stop, considering it can be employed in various operations, such as trojanized software, phishing and watering hole attacks.
BitRAT’s popularity arises from its versatility. The malicious tool can perform a wide range of operations, including data exfiltration, UAC bypass, DDoS attacks, clipboard monitoring, gaining unauthorized webcam access, credential theft, audio recording, XMRig coin mining and generic keylogging.
Bitter RAT
Technical ID: win.bitter_rat
MALWARE
Malware family identifying win.bitter_rat. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
SHADYCAT is a dropper and spreader component for the HERMES 2.1 RANSOMWARE radical edition.
Also known as: SHADYCAT
BITSloth
Technical ID: win.bitsloth
MALWARE
Malware family identifying win.bitsloth. Origin and technical characteristics tracked via Malpedia.
BitPyLock
Technical ID: win.bitpylock
MALWAREfinancialhigh
Bitpylock is a ransomware that encrypts files by using asymmetric keys and puts '.bitpy' as suffix once the encryption phase ended. The ransom note appears on the affected user's Desktop with the following name: "# # HELP_TO_DECRYPT_YOUR_FILES # .html". At the time of writing the ransom request is 0.8 BTC and the communication email is: helpbitpy@cock.li.
MALWARE
Malware family identifying win.bistromath. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.biscuit. Origin and technical characteristics tracked via Malpedia.
Also known as: zxdosml
MALWARE
BIOPASS RAT is a malware family which targets online gambling companies in China by leveraging a watering hole attack. This Remote Access Trojan (RAT) is unique in that it leverages the Open Broadcaster Software (OBS) framework to monitor the user's screen.
MALWARE
Malware family identifying win.bioload. Origin and technical characteristics tracked via Malpedia.
BioData
Technical ID: win.biodata
MALWARE
Malware family identifying win.biodata. Origin and technical characteristics tracked via Malpedia.
Binanen
Technical ID: win.binanen
MALWARE
Binanen is a dropper that drops and executes a section of itself into a hidden dummy process. According to F-Secure, it executes command line tools such as (for example) asipconfig, which is useful to retrieve the network configuration. The malware aims to steal information about the machine, the username, installed software and, more generally speaking, it potentially can carry out actions on the compromised machine.
BillGates
Technical ID: win.billgates
MALWARE
BillGates is a modularized malware, of supposedly Chinese origin. Its main functionality is to perform DDoS attacks, with support for DNS amplification. Often, BillGates is delivered with one or many backdoor modules.
BillGates is available for *nix-based systems as well as for Windows.
On Windows, the (Bill)Gates installer typically contains the various modules as linked resources.
MALWARE
Malware family identifying win.bifrose. Origin and technical characteristics tracked via Malpedia.
BI_D Ransomware
Technical ID: win.bid_ransomware
MALWAREfinancialhigh
Small and relatively simple ransomware for Windows. Gives files the .BI_D extension after encrypting them with a combination of RSA/AES. Persistence achieved via the Windows Registry. Kills all processes on the victim machine besides itself and a small whitelist of mostly Windows sytem processes and kills shadow copies.
MALWARE
A Windows version of the BiBi wiper that was found by BlackBerry.
Also known as: BiBi-Windows
BianLian
Technical ID: win.bianlian
MALWAREfinancialhigh
BianLian is a GoLang-based ransomware that continues to breach several industries and demand large ransom amounts. The threat actors also use the double extortion method by stealing an affected organization’s files and leaking them online if the ransom is not paid on time. BianLian gains access to victim systems through valid Remote Desktop Protocol (RDP) credentials, uses open-source tools and command-line scripting for discovery and credential harvesting, and exfiltrates victim data via File Transfer Protocol (FTP), Rclone, or Mega. BianLian originally employed a double-extortion model in which they encrypted victims’ systems after exfiltrating the data; however, around January 2023, they shifted to primarily exfiltration-based extortion. The BianLian ransomware uses goroutines and encrypts files in chunks to quickly hijack an infected system. The ransomware adds its own extension to each encrypted file.
BH_A006
Technical ID: win.bh_a006
MALWARE
According to Volexity, a loader observed to be used with multiple malware families, among them LIGHTSPY.
BHunt
Technical ID: win.bhunt
MALWARE
BHunt collects the crypto wallets of its victims. The malware consists of several functions/modules, e.g. a reporting module that reports the presence of crypto wallets on the target computers to the C2 server. It searches for many different cryptocurrencies (e.g. Atomic, Bitcoin, Electrum, Ethereum, Exodus, Jaxx and Litecoin). The Blackjack module is used to steal wallets, Sweet_Bonanza steals victims' browser passwords. There are also modules like the Golden7 or the Chaos_crew module.
BfBot
Technical ID: win.bfbot
MALWARE
Malware family identifying win.bfbot. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-29
View profile →MALWARE
Bezigate is a Trojan horse that opens a back door on the compromised computer. It may also download potentially malicious files.
The Trojan may perform the following actions:
List, move, and delete drives
List, move, and delete files
List processes and running Windows titles
List services
List registry values
Kill processes
Maximize, minimize, and close windows
Upload and download files
Execute shell commands
Uninstall itself
BetaBot
Technical ID: win.betabot
MALWAREfinancialhigh
Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012. The malware began as a banking Trojan and is now packed with features that allow its operators to practically take over a victim’s machine and steal sensitive information.
Also known as: Neurevt
BestKorea
Technical ID: win.bestkorea
MALWARE
Malware family identifying win.bestkorea. Origin and technical characteristics tracked via Malpedia.
Bert
Technical ID: win.bert
MALWARE
Malware family identifying win.bert. Origin and technical characteristics tracked via Malpedia.
Berserk Stealer
Technical ID: win.berserk_stealer
MALWARE
Malware family identifying win.berserk_stealer. Origin and technical characteristics tracked via Malpedia.
BernhardPOS
Technical ID: win.bernhardpos
MALWARE
Malware family identifying win.bernhardpos. Origin and technical characteristics tracked via Malpedia.
Berbomthum
Technical ID: win.berbomthum
MALWARE
Malware family identifying win.berbomthum. Origin and technical characteristics tracked via Malpedia.
Berbew
Technical ID: win.berbew
MALWARE
Malware family identifying win.berbew. Origin and technical characteristics tracked via Malpedia.
Belonard
Technical ID: win.belonard
MALWARE
Once set up in the system, Trojan.Belonard replaces the list of available game servers in the game client and creates proxies on the infected computer to spread the Trojan. As a rule, proxy servers show a lower ping, so other players will see them at the top of the list. By selecting one of them, a player gets redirected to a malicious server where their computer become infected with Trojan.Belonard.