Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Attor
Technical ID: win.attor
MALWAREespionageadvanced
Attor is a cyberespionage platform used in targeted attacks against diplomatic missions and governmental institutions since at least 2013. Its most interesting features are a complex modular architecture, elaborate network communications, and a unique plugin to fingerprint GSM/GPRS devices.
Attor’s core lies in its dispatcher, which serves as a management unit for additional plugins which provide all of malware’s key capabilities. This allows the attackers to customize the platform on a per-victim basis. Plugins themselves are heavily synchronized. Network communication is based on Tor, aiming for anonymity and untraceability.
The most notable plugin can detect connected GSM/GPRS modems or mobile devices. Attor speaks to them directly using the AT command set, in order to collect sensitive information such as the IMEI, IMSI or MSISDN numbers, possibly identifying both the device and its subscriber. Other plugins provide persistence, an exfiltration channel, C&C communication and several further spying capabilities. The plugin responsible for capturing victim's screen targets social networks and blogging platforms, email services, office software, archiving utilities, file sharing and messaging services.
ATOMSILO
Technical ID: win.atomsilo
MALWARE
According to PCrisk, AtomSilo is a type of malware that blocks access to files by encrypting them and renames every encrypted file by appending the ".ATOMSILO" to its filename. It renames "1.jpg" to "1.jpg.ATOMSILO", "2.jpg" to "2.jpg.ATOMSILO", and so on. As its ransom note, AtomSilo creates the "README-FILE-#COMPUTER-NAME#-#CREATION-TIME#.hta" file.
MALWARE
The ATMSpitter family consists of command-line tools designed to control the cash dispenser of an ATM through function calls to either CSCWCNG.dll or MFSXFS.dll.
Both libraries are legitimate Windows drivers used to interact with the components of different ATM models.
MALWARE
Malware family identifying win.atmosphere. Origin and technical characteristics tracked via Malpedia.
ATMitch
Technical ID: win.atmitch
MALWARE
Malware family identifying win.atmitch. Origin and technical characteristics tracked via Malpedia.
ATMii
Technical ID: win.atmii
MALWARE
Malware family identifying win.atmii. Origin and technical characteristics tracked via Malpedia.
AtlasAgent
Technical ID: win.atlas_agent
MALWARE
Malware family identifying win.atlas_agent. Origin and technical characteristics tracked via Malpedia.
Atlantida
Technical ID: win.atlantida
MALWARE
Malware family identifying win.atlantida. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.ati_agent. Origin and technical characteristics tracked via Malpedia.
AthenaGo RAT
Technical ID: win.athenago
MALWARE
Malware family identifying win.athenago. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-02-13
View profile →Athena
Technical ID: win.athena
MALWARE
Part of the Mythic framework, payload in C# (.NET 6), support HTTP, Websockets, Slack, SMB for C2.
MALWARE
Malware family identifying win.atharvan. Origin and technical characteristics tracked via Malpedia.
AsyncRAT
Technical ID: win.asyncrat
MALWARE
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victim’s computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques.
AstraLocker
Technical ID: win.astralocker
MALWARE
Malware family identifying win.astralocker. Origin and technical characteristics tracked via Malpedia.
Astasia
Technical ID: win.astasia
MALWAREfinancialhigh
Astasia is a banking trojan that spreads through phishing emails that contain an executable attachment. Once the attachment is executed, Astasia downloads and installs a trojan that runs in the background. The trojan can steal personal information, such as passwords and credit card numbers, from victims.
Astaroth
Technical ID: win.astaroth
MALWAREfinancialhigh
First spotted in the wild in 2017, Astaroth is a highly prevalent, information-stealing Latin American banking trojan. It is written in Delphi and has some innovative execution and attack techniques. Originally, this malware variant targeted Brazilian users, but Astaroth now targets users both in North America and Europe.
Also known as: Guildma
AstarionRAT
Technical ID: win.astarion_rat
MALWARE
According to Huntress, AstarionRAT is a full-featured RAT with 24 commands, including credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution, with RSA-encrypted C2 communication disguised as application telemetry.
Also known as: MIMICRAT
MALWARE
Malware family identifying win.asruex. Origin and technical characteristics tracked via Malpedia.
Asprox
Technical ID: win.asprox
MALWARE
Malware family identifying win.asprox. Origin and technical characteristics tracked via Malpedia.
Also known as: Aseljo • BadSrc
ASPC
Technical ID: win.aspc
MALWARE
Malware family identifying win.aspc. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-19
View profile →MALWARE
According to Unit 42, Ashen / AshTag is a modular .NET toolset currently in active development, with extensive features, including file exfiltration, content download and in-memory execution of additional modules.
Also known as: AshTag
AscentLoader
Technical ID: win.ascentloader
MALWARE
Malware family identifying win.ascentloader. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-07-05
View profile →Asbit
Technical ID: win.asbit
MALWARE
Malware family identifying win.asbit. Origin and technical characteristics tracked via Malpedia.
Artra Downloader
Technical ID: win.artra
MALWARE
Malware family identifying win.artra. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.artfulpie. Origin and technical characteristics tracked via Malpedia.
ARS VBS Loader
Technical ID: win.ars_loader
MALWARE
ARS Loader, also known as ARS VBS Loader, is written in Visual Basic Script and its main purpose is to control an infected machine via different available commands, acting as a remote access trojan (RAT). Its code is based on ASPC, another Visual Basic Script malware, which at the same time seems to be based on SafeLoader.
ArrowRAT
Technical ID: win.arrowrat
MALWARE
It is available as a service, purchasable by anyone to use in their own campaigns. It’s features are generally fairly typical of a RAT, with its most notable aspect being the hVNC module which basically gives an attacker full remote access with minimal need for technical knowledge to use it.
Arkei Stealer
Technical ID: win.arkei_stealer
MALWARE
Arkei is a stealer that appeared around May 2018. It collects data about browsers (saved passwords and autofill forms), cryptocurrency wallets, and steal files matching an attacker-defined pattern. It then exfiltrates everything in a zip file uploaded to the attacker's panel. Later, it was forked and used as a base to create Vidar stealer.
Also known as: ArkeiStealer
Arik Keylogger
Technical ID: win.arik_keylogger
MALWARE
Malware family identifying win.arik_keylogger. Origin and technical characteristics tracked via Malpedia.
Also known as: Aaron Keylogger
MALWARE
Helper malware associated with AridGopher, which will provide an alternative persistence mechanism in case "360 total security" is found on a target system.
MALWARE
This malware is a Go written variant of Micropsia and according to DeepInstinct it is still in development.
MALWARE
Malware family identifying win.ariabody. Origin and technical characteristics tracked via Malpedia.
MALWARE
During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by ESET researchers. ArguePatch is a modified version of Hex-Ray's Remote Debugger Server (win32_remote.exe).
ArguePatch expects a decryption key and the file of the CaddyWiper shellcode as command line parameters.
AresLoader
Technical ID: win.aresloader
MALWARE
AresLoader is a new malware "downloader" that has been advertised on some Russian language Dark Web forums “RAMP and "XSS" by a threat actor called "DarkBLUP". Researchers assess this loader is likely a legitimate penetration testing tool that is now being abused by threat actors. This is because of a similar project, dubbed “Project Ares,” was previously uploaded to GitHub as a proof-of-concept (PoC) by the well-regarded user and red teamer “CerberSec.”
The loader mimics legitimate software to trick victims into executing malware with administrator rights on their machines. Additional features of the loader include:
1. Written in C/C++
2. Supports 64-bit payloads
3. Makes it look like malware spawned by another process
4. Prevents non-Microsoft signed binaries from being injected into malware
5. Hides suspicious imported Windows APIs
6. Leverages anti-analysis techniques to avoid reverse engineering
Furthermore, It was observed that SystemBC, Amadey, and several Raccoon Stealers were directly installing AresLoader. To date, the AresLoader downloader has been seen delivering payloads like SystemBC, Lumma Stealer, StealC, Aurora Stealer, and Laplas Clipper.
Ares
Technical ID: win.ares
MALWAREfinancialhigh
A banking trojan, derived from the source code of win.kronos. In August 2022 it started to incorporate DGA code from win.qakbot.
Arefty
Technical ID: win.arefty
MALWARE
Malware family identifying win.arefty. Origin and technical characteristics tracked via Malpedia.
ArdaMax
Technical ID: win.ardamax
MALWAREespionageadvanced
According to f-secure, Ardamax is a commercial keylogger program that can be installed onto the system from the product's website.& When run, the program can capture a range of user activities, such as keystrokes typed, instant messenger chat logs, web browser activity and even screenshots of the active desktop.
This program can be configured to a complete stealth mode, with password protection, to avoid user detection.
The information gathered is stored in an encrypted log file, which is only viewable using the built-in Log Viewer. The log file can be sent to an external party through e-mail, via a local area network (LAN) or by upload to an FTP server (in either HTML or encrypted format).
Archer RAT
Technical ID: win.archer_rat
MALWARE
Malware family identifying win.archer_rat. Origin and technical characteristics tracked via Malpedia.
Also known as: RustyWater
ArcaneStealer
Technical ID: win.arcane_stealer
MALWARE
Malware family identifying win.arcane_stealer. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.appleseed. Origin and technical characteristics tracked via Malpedia.
Also known as: JamBog