Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
BellaCiao
Technical ID: win.bellaciao
MALWARE
Malware family identifying win.bellaciao. Origin and technical characteristics tracked via Malpedia.
BeepService
Technical ID: win.beepservice
MALWARE
Malware family identifying win.beepservice. Origin and technical characteristics tracked via Malpedia.
beep
Technical ID: win.beep
MALWARE
Malware family identifying win.beep. Origin and technical characteristics tracked via Malpedia.
MALWARE
BEENDOOR is a XMPP based trojan. It is capable of taking screenshots of the victim's desktop.
Bee
Technical ID: win.bee
MALWARE
Malware family observed in conjunction with PlugX infrastructure in 2013.
Bedep
Technical ID: win.bedep
MALWARE
Bedep has been mostly observed in ad-fraud campaigns, although it can also generally load modules for different tasks. It was dropped by the Angler Exploit Kit.
MALWARE
Malware family identifying win.beavertail. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C. BEATDROP uses Trello to store victim information and retrieve AES-encrypted shellcode payloads to be executed. BEATDROP then injects and executes downloaded payloads into a suspended process. Upon execution, BEATDROP maps a copy of ntdll.dll into memory to execute shellcode in its own process. The sample then creates a suspended thread with RtlCreateUserThread the thread points to NtCreateFile. The sample changes execution to shellcode and resumes the thread. The shellcode payload is retrieved from Trello and is targeted per victim. Once the payload has been retrieved, it is deleted from Trello.
MALWAREfinancialhigh
Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.
Also known as: blacklockbit
MALWARE
According to CERT-UA, this is a malware developed using the C++ programming language. It provides capabilities for downloading, decryption (chacha20-poly150) and performing PowerShell scripts, as well as uploading the command's results.
Beapy
Technical ID: win.beapy
MALWARE
According to Symantec, Beapy is a cryptojacking campaign impacting enterprises that uses the EternalBlue exploit and stolen and hardcoded credentials to spread rapidly across networks.
MALWARE
According to Threatray, BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use until at least 2025.
BBtok
Technical ID: win.bbtok
MALWAREfinancialhigh
360 Security Center describes BBtok as a banking trojan targeting Mexico.
BBSRAT
Technical ID: win.bbsrat
MALWARE
Malware family identifying win.bbsrat. Origin and technical characteristics tracked via Malpedia.
BazarNimrod
Technical ID: win.bazarnimrod
MALWARE
A rewrite of Bazarloader in the Nim programming language.
Also known as: NimzaLoader
MALWARE
BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor. Its called team9 backdoor (and the corresponding loader: team9 restart loader).
For now, it exclusively uses Emercoin domains (.bazar), thus the naming. FireEye uses KEGTAP as name for BazarLoader and BEERBOT for BazarBackdoor.
Also known as: BEERBOT • KEGTAP • Team9Backdoor • bazaloader • bazarloader
BATLOADER
Technical ID: win.bat_loader
MALWARE
According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise. This malware is used to execute payloads like Ursnif. Our team has discovered BATLOADER after executing installers for legitimate software (such as Zoom, TeamViewer Visual Studio) bundled with this malware. We have found those installers on compromised websites.
Batel
Technical ID: win.batel
MALWARE
Malware family identifying win.batel. Origin and technical characteristics tracked via Malpedia.
BatchWiper
Technical ID: win.batchwiper
MALWARE
Malware family identifying win.batchwiper. Origin and technical characteristics tracked via Malpedia.
Bart
Technical ID: win.bart
MALWARE
Malware family identifying win.bart. Origin and technical characteristics tracked via Malpedia.
barkiofork
Technical ID: win.barkiofork
MALWARE
Malware family identifying win.barkiofork. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.barbwire. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.barbie. Origin and technical characteristics tracked via Malpedia.
BaoLoader
Technical ID: win.baoloader
MALWARE
According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.
MALWARE
BanPolMex is a remote access trojan that uses TCP for communication.
It uses an RC4-like stream cipher called Spritz for encryption of its configuration and network traffic.
It sends detailed information about the victim's environment, like computer name, Windows version, free space of memory and all drives, processor identifier and architecture, system locale, system metrics, manufacturer, and network configuration.
It supports almost 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration, and the download and execution of additional tools from the attacker’s C&C server. As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. However, in this case the indicis are convertible into a meaningful ASCII representation, that even suggests the functionality: SLEP, HIBN, DRIV, DIR, DIRP, CHDR, RUN, RUNX, DEL, WIPE, MOVE, FTIM, NEWF, DOWN, ZDWN, UPLD, PVEW, PKIL, CMDL, DIE, GCFG, SCFG, TCON, PEEX, PEIN.
It has aclui.dll as the internal DLL name. It contains statically linked code from open-source libraries like libcurl (version 7.47.1) or zLib (version 0.15).
BanPolMex RAT was delivered for victims of a watering hole campaign targeting employees of Polish and Mexican banks, that was discovered in February 2017. It is usually loaded by HOTWAX.
MALWARE
Malware family identifying win.bankshot. Origin and technical characteristics tracked via Malpedia.
Also known as: COPPERHEDGE • FoggyBrass
Banjori
Technical ID: win.banjori
MALWARE
Malware family identifying win.banjori. Origin and technical characteristics tracked via Malpedia.
Also known as: MultiBanker 2 • BankPatch • BackPatcher
MALWARE
Malware family identifying win.bangat. Origin and technical characteristics tracked via Malpedia.
MALWARE
Bandook malware is a remote access trojan (RAT) first seen in 2007 and has been active for several years. Written in both Delphi and C++, it was first seen as a commercial RAT developed by a Lebanese creator named PrinceAli. Over the years, several variants of Bandook were leaked online, and the malware became available for public download.
Also known as: Bandok
Bandit Stealer
Technical ID: win.bandit
MALWARE
Malware family identifying win.bandit. Origin and technical characteristics tracked via Malpedia.
bancos
Technical ID: win.bancos
MALWARE
Malware family identifying win.bancos. Origin and technical characteristics tracked via Malpedia.
Banatrix
Technical ID: win.banatrix
MALWARE
Malware family identifying win.banatrix. Origin and technical characteristics tracked via Malpedia.
Bamital
Technical ID: win.bamital
MALWARE
Malware family identifying win.bamital. Origin and technical characteristics tracked via Malpedia.
BalkanRAT
Technical ID: win.balkan_rat
MALWARE
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf. BalkanDoor) is to deploy and leverage legitimate commercial software for remote administration. The malware has several additional components to help load, install and conceal the existence of the remote desktop software. A single long-term campaign involving BalkanRAT has been active at least from January 2016 and targeted accouting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina (considered that the contents of the emails, included links and decoy PDFs all were involving taxes). It was legitimaly signed and installed by an exploit of the WinRAR ACE vulnerability (CVE-2018-20250).
BalkanDoor
Technical ID: win.balkan_door
MALWARE
According to ESET, BalkanDoor is a simple backdoor with a small number of commands (download and execute a file, create a remote shell, take a screenshot). It can be used to automate tasks on the compromised computer or to automatically control several affected computers at once. We have seen six versions of the backdoor, with a range of supported commands, evolve since 2016.
Baldr
Technical ID: win.baldr
MALWARE
Malware family identifying win.baldr. Origin and technical characteristics tracked via Malpedia.
Also known as: Baldir
Bahamut
Technical ID: win.bahamut
MALWARE
Malware family identifying win.bahamut. Origin and technical characteristics tracked via Malpedia.
Bagle
Technical ID: win.bagle
MALWARE
Malware family identifying win.bagle. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.badpaw. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.badnews. Origin and technical characteristics tracked via Malpedia.