Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
MALWARE
Malware family identifying win.badhatch. Origin and technical characteristics tracked via Malpedia.
MALWARE
BADFLICK, a backdoor that is capable of modifying the file system, generating a reverse shell, and modifying its command-and-control configuration.
BadEncript
Technical ID: win.badencript
MALWARE
Malware family identifying win.badencript. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.badcall. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Google, BADAUDIO is a custom first-stage downloader written in C++ that downloads, decrypts, and executes an AES-encrypted payload from a hard-coded command and control (C2) server. The malware collects basic system information, encrypts it using a hard-coded AES key, and sends it as a cookie value with the GET request to fetch the payload. The payload, in one case identified as Cobalt Strike Beacon, is decrypted with the same key and executed in memory.
BackSwap
Technical ID: win.backswap
MALWARE
Malware family identifying win.backswap. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.backspace. Origin and technical characteristics tracked via Malpedia.
Also known as: Lecna • ZRLnk
MALWARE
According to EclecticIQ, this is a downloader written in Go, able to exclude paths from Windows Defender in order to execute fetched payloads without raising alerts.
Backoff POS
Technical ID: win.backoff
MALWARE
Malware family identifying win.backoff. Origin and technical characteristics tracked via Malpedia.
BackNet
Technical ID: win.backnet
MALWARE
Malware family identifying win.backnet. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.backconfig. Origin and technical characteristics tracked via Malpedia.
MALWARE
FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed. When executed, BACKBEND checks for the presence of the mutexes MicrosoftZj or MicrosoftZjBak (both associated with BACKSPACE variants). If either of the mutexes exist, the malware exits.
Bachosens
Technical ID: win.bachosens
MALWARE
Malware family identifying win.bachosens. Origin and technical characteristics tracked via Malpedia.
MALWARE
BabyShark is Microsoft Visual Basic (VB) script-based malware family first seen in November 2018. The malware is launched by executing the first stage HTA from a remote location, thus it can be delivered via different file types including PE files as well as malicious documents. It exfiltrates system information to C2 server, maintains persistence on the system, and waits for further instruction from the operator
Also known as: LATEOP
MALWARE
BABYMETAL is a command line network tunnel utility based on the TinyMet Meterpreter tool, primarily used to execute Meterpreter reverse shell payloads.
BabyLon RAT
Technical ID: win.babylon_rat
MALWARE
Malware family identifying win.babylon_rat. Origin and technical characteristics tracked via Malpedia.
Babuk
Technical ID: win.babuk
MALWAREfinancialhigh
Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.
Also known as: Babyk • Vasa Locker
MALWARE
Malware family identifying win.babar. Origin and technical characteristics tracked via Malpedia.
Also known as: SNOWBALL
Babadeda
Technical ID: win.babadeda
MALWARE
According to PCrisk, Babadeda is a new sample in the crypters family, allowing threat actors to encrypt and obfuscate the malicious samples. The obfuscation allows malware to bypass the majority of antivirus protections without triggering any alerts. According to the researchers’ analysis, Babadeda leverages a sophisticated and complex obfuscation that shows a very low detection rate by anti-virus engines.
B0
Technical ID: win.b0
MALWAREfinancialhigh
According to Porthas, this is a ransomware written in Golang, using a time-based kill switch to limit its execution.
Azov Wiper
Technical ID: win.azov_wiper
MALWAREfinancialhigh
According to Checkpoint, this malware is a wiper instead of ransomware as self-announced. It is manually written in FASM, unrecoverably overwriting data in blocks of 666 bytes, using multi-threading.
MALWARE
AZORult is a credential and payment card information stealer. Among other things, version 2 added support for .bit-domains. It has been observed in conjunction with Chthonic as well as being dropped by Ramnit.
Also known as: PuffStealer • Rultazo
Ayegent
Technical ID: win.ayegent
MALWARE
Malware family identifying win.ayegent. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →AXLocker
Technical ID: win.axlocker
MALWARE
Malware family identifying win.axlocker. Origin and technical characteristics tracked via Malpedia.
Avzhan
Technical ID: win.avzhan
MALWARE
Malware family identifying win.avzhan. Origin and technical characteristics tracked via Malpedia.
Unidentified 061
Technical ID: win.avrecon
MALWARE
Was previously wrongly tagged as PoweliksDropper, now looking for additional context.
Updated: 2019-07-31
View profile →AvosLocker
Technical ID: win.avos_locker
MALWAREfinancialhigh
AvosLocker is a ransomware-as-a-service (RaaS) gang that first appeared in mid-2021. It has since become notorious for its attacks targeting critical infrastructure in the United States, including the sectors of financial services, critical manufacturing, and government facilities.
In March 2022, the FBI and US Treasury Department issued a warning about the attacks.
MALWARE
Information stealer which uses AutoIT for wrapping.
Also known as: AVE_MARIA • AveMariaRAT • Warzone RAT • WarzoneRAT • avemaria
Aveo
Technical ID: win.aveo
MALWARE
Malware family identifying win.aveo. Origin and technical characteristics tracked via Malpedia.
AvD Crypto Stealer
Technical ID: win.avd
MALWARE
Cyble Research discovered this .Net written malware dubbed "AvD Crypto Stealer". The name of this malware is misleading, because this is a kind of clipper malware. Assumption of Cyble is, that this malware could target other threat actors as scenario.
AVCrypt
Technical ID: win.avcrypt
MALWAREfinancialhigh
Bleeping Computer notes about discovery of AVCrypt, a malware that tries to uninstall existing security software before it encrypts a computer. Furthermore, as it removes numerous services, including Windows Update, and provides no contact information, this ransomware may be a wiper.
AvastDisabler
Technical ID: win.avast_disabler
MALWARE
Malware family identifying win.avast_disabler. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
Avaddon is a ransomware malware targeting Windows systems often spread via malicious spam. The first known attack where Avaddon ransomware was distributed was in February 2020. Avaddon encrypts files using the extension .avdn and uses a TOR payment site for the ransom payment.
Aurora Stealer
Technical ID: win.aurora_stealer
MALWARE
First advertised as a Malware-as-a-Service (MaaS) on Russian-speaking underground forums in April 2022, Aurora Stealer is a Golang-based information stealer with downloading and remote access capabilities. The malware targets data from multiple browsers, cryptocurrency wallets, local systems, and act as a loader. During execution, the malware runs several commands through WMIC to collect basic host information, snaps a desktop image, and exfiltrates data to the C2 server within a single base64-encoded JSON file.
MALWAREfinancialhigh
Ransomware
Also known as: OneKeyLocker
MALWARE
Malware family identifying win.auriga. Origin and technical characteristics tracked via Malpedia.
Also known as: Riodrv
Aura Stealer
Technical ID: win.aurastealer
MALWARE
In July 2025, threat actor AuraCorp began advertising Aura Stealer as a Malware-as-a-Service (MaaS) program with multiple subscription tiers on underground forums. The information stealer targets credentials from over 110 browsers, 70 applications, and 250+ browser extensions, including cryptocurrency wallets and 2FA tools, while using AES-256 encryption for C2 communications. Notable features include seamless Chromium cookie harvesting without process termination, server-side App-Bound data decryption, and a built-in payload loader with custom morphing for detection evasion.
Also known as: AURA Stealer • AURASTEAL
AuKill
Technical ID: win.aukill
MALWAREfinancialhigh
According to Sophos, the AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system.
Also known as: SophosKill
August Stealer
Technical ID: win.august_stealer
MALWARE
Malware family identifying win.august_stealer. Origin and technical characteristics tracked via Malpedia.