Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
BellaCiao
Technical ID: win.bellaciao
MALWARE
Malware family identifying win.bellaciao. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-10-15
View profile →
BeepService
Technical ID: win.beepservice
MALWARE
Malware family identifying win.beepservice. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-27
View profile →
beep
Technical ID: win.beep
MALWARE
Malware family identifying win.beep. Origin and technical characteristics tracked via Malpedia.
beendoor
Technical ID: win.beendoor
Operation C-Major
MALWARE
BEENDOOR is a XMPP based trojan. It is capable of taking screenshots of the victim's desktop.
Updated: 2019-04-08
View profile →
Bee
Technical ID: win.bee
MALWARE
Malware family observed in conjunction with PlugX infrastructure in 2013.
Updated: 2021-01-29
View profile →
Bedep
Technical ID: win.bedep
MALWARE
Bedep has been mostly observed in ad-fraud campaigns, although it can also generally load modules for different tasks. It was dropped by the Angler Exploit Kit.
Updated: 2024-06-28
View profile →
Beavertail
Technical ID: win.beavertail
WageMole
MALWARE
Malware family identifying win.beavertail. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-11-17
View profile →
BEATDROP
Technical ID: win.beatdrop
APT29
MALWARE
According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C. BEATDROP uses Trello to store victim information and retrieve AES-encrypted shellcode payloads to be executed. BEATDROP then injects and executes downloaded payloads into a suspended process. Upon execution, BEATDROP maps a copy of ntdll.dll into memory to execute shellcode in its own process. The sample then creates a suspended thread with RtlCreateUserThread the thread points to NtCreateFile. The sample changes execution to shellcode and resumes the thread. The shellcode payload is retrieved from Trello and is targeted per victim. Once the payload has been retrieved, it is deleted from Trello.
Updated: 2024-02-02
View profile →
MALWAREfinancialhigh
Beast is a Ransomware-as-a-service (RaaS) product which provides functionality such as SMB scanning, file encryption, service and process starting and stopping, and geographic identification to avoid encryption in CIS countries.
Also known as: blacklockbit
BEARDSHELL
Technical ID: win.beardshell
APT28
MALWARE
According to CERT-UA, this is a malware developed using the C++ programming language. It provides capabilities for downloading, decryption (chacha20-poly150) and performing PowerShell scripts, as well as uploading the command's results.
Updated: 2025-09-17
View profile →
Beapy
Technical ID: win.beapy
MALWARE
According to Symantec, Beapy is a cryptojacking campaign impacting enterprises that uses the EternalBlue exploit and stolen and hardcoded credentials to spread rapidly across networks.
Updated: 2023-05-15
View profile →
BDarkRAT
Technical ID: win.bdark_rat
HAZY TIGER
MALWARE
According to Threatray, BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use until at least 2025.
Updated: 2025-06-05
View profile →
BBtok
Technical ID: win.bbtok
MALWAREfinancialhigh
360 Security Center describes BBtok as a banking trojan targeting Mexico.
Updated: 2024-09-27
View profile →
BBSRAT
Technical ID: win.bbsrat
MALWARE
Malware family identifying win.bbsrat. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-06-23
View profile →
BazarNimrod
Technical ID: win.bazarnimrod
MALWARE
A rewrite of Bazarloader in the Nim programming language.
Also known as: NimzaLoader
Updated: 2021-07-27
View profile →
BazarBackdoor
Technical ID: win.bazarbackdoor
UNC1878
MALWARE
BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor. Its called team9 backdoor (and the corresponding loader: team9 restart loader). For now, it exclusively uses Emercoin domains (.bazar), thus the naming. FireEye uses KEGTAP as name for BazarLoader and BEERBOT for BazarBackdoor.
Also known as: BEERBOT • KEGTAP • Team9Backdoor • bazaloader • bazarloader
Updated: 2023-10-16
View profile →
BATLOADER
Technical ID: win.bat_loader
MALWARE
According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise. This malware is used to execute payloads like Ursnif. Our team has discovered BATLOADER after executing installers for legitimate software (such as Zoom, TeamViewer Visual Studio) bundled with this malware. We have found those installers on compromised websites.
Updated: 2024-08-29
View profile →
Batel
Technical ID: win.batel
MALWARE
Malware family identifying win.batel. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-04-21
View profile →
BatchWiper
Technical ID: win.batchwiper
MALWARE
Malware family identifying win.batchwiper. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-10-05
View profile →
Bart
Technical ID: win.bart
MALWARE
Malware family identifying win.bart. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-14
View profile →
barkiofork
Technical ID: win.barkiofork
MALWARE
Malware family identifying win.barkiofork. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-01-25
View profile →
BarbWire
Technical ID: win.barbwire
AridViper
MALWARE
Malware family identifying win.barbwire. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-11-04
View profile →
Barb(ie) Downloader
Technical ID: win.barbie
AridViper
MALWARE
Malware family identifying win.barbie. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-06-27
View profile →
BaoLoader
Technical ID: win.baoloader
MALWARE
According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.
Updated: 2025-09-23
View profile →
BanPolMex RAT
Technical ID: win.banpolmex
Lazarus Group
MALWARE
BanPolMex is a remote access trojan that uses TCP for communication. It uses an RC4-like stream cipher called Spritz for encryption of its configuration and network traffic. It sends detailed information about the victim's environment, like computer name, Windows version, free space of memory and all drives, processor identifier and architecture, system locale, system metrics, manufacturer, and network configuration. It supports almost 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration, and the download and execution of additional tools from the attacker’s C&C server. As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. However, in this case the indicis are convertible into a meaningful ASCII representation, that even suggests the functionality: SLEP, HIBN, DRIV, DIR, DIRP, CHDR, RUN, RUNX, DEL, WIPE, MOVE, FTIM, NEWF, DOWN, ZDWN, UPLD, PVEW, PKIL, CMDL, DIE, GCFG, SCFG, TCON, PEEX, PEIN. It has aclui.dll as the internal DLL name. It contains statically linked code from open-source libraries like libcurl (version 7.47.1) or zLib (version 0.15). BanPolMex RAT was delivered for victims of a watering hole campaign targeting employees of Polish and Mexican banks, that was discovered in February 2017. It is usually loaded by HOTWAX.
Updated: 2023-08-31
View profile →
Bankshot
Technical ID: win.bankshot
Lazarus Group
MALWARE
Malware family identifying win.bankshot. Origin and technical characteristics tracked via Malpedia.
Also known as: COPPERHEDGE • FoggyBrass
Updated: 2025-10-31
View profile →
Banjori
Technical ID: win.banjori
MALWARE
Malware family identifying win.banjori. Origin and technical characteristics tracked via Malpedia.
Also known as: MultiBanker 2 • BankPatch • BackPatcher
Updated: 2018-07-31
View profile →
bangat
Technical ID: win.bangat
Comment Crew
MALWARE
Malware family identifying win.bangat. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-09-11
View profile →
Bandook
Technical ID: win.bandook
Dark Caracal
MALWARE
Bandook malware is a remote access trojan (RAT) first seen in 2007 and has been active for several years. Written in both Delphi and C++, it was first seen as a commercial RAT developed by a Lebanese creator named PrinceAli. Over the years, several variants of Bandook were leaked online, and the malware became available for public download.
Also known as: Bandok
Updated: 2025-12-08
View profile →
Bandit Stealer
Technical ID: win.bandit
MALWARE
Malware family identifying win.bandit. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-05-14
View profile →
bancos
Technical ID: win.bancos
MALWARE
Malware family identifying win.bancos. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-31
View profile →
Banatrix
Technical ID: win.banatrix
MALWARE
Malware family identifying win.banatrix. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-22
View profile →
Bamital
Technical ID: win.bamital
MALWARE
Malware family identifying win.bamital. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-10-21
View profile →
BalkanRAT
Technical ID: win.balkan_rat
MALWARE
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf. BalkanDoor) is to deploy and leverage legitimate commercial software for remote administration. The malware has several additional components to help load, install and conceal the existence of the remote desktop software. A single long-term campaign involving BalkanRAT has been active at least from January 2016 and targeted accouting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina (considered that the contents of the emails, included links and decoy PDFs all were involving taxes). It was legitimaly signed and installed by an exploit of the WinRAR ACE vulnerability (CVE-2018-20250).
Updated: 2019-09-09
View profile →
BalkanDoor
Technical ID: win.balkan_door
MALWARE
According to ESET, BalkanDoor is a simple backdoor with a small number of commands (download and execute a file, create a remote shell, take a screenshot). It can be used to automate tasks on the compromised computer or to automatically control several affected computers at once. We have seen six versions of the backdoor, with a range of supported commands, evolve since 2016.
Updated: 2019-09-03
View profile →
Baldr
Technical ID: win.baldr
MALWARE
Malware family identifying win.baldr. Origin and technical characteristics tracked via Malpedia.
Also known as: Baldir
Updated: 2019-08-07
View profile →
Bahamut
Technical ID: win.bahamut
MALWARE
Malware family identifying win.bahamut. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-08
View profile →
Bagle
Technical ID: win.bagle
MALWARE
Malware family identifying win.bagle. Origin and technical characteristics tracked via Malpedia.
Updated: 2021-12-31
View profile →
BadPaw
Technical ID: win.badpaw
APT28
MALWARE
Malware family identifying win.badpaw. Origin and technical characteristics tracked via Malpedia.
BadNews
Technical ID: win.badnews
QUILTED TIGER
MALWARE
Malware family identifying win.badnews. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-09-23
View profile →
← PreviousPage 183 / 269Next →