Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
MALWARE
Malware family identifying win.applejeus. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
Malware used by suspected Iranian threat actor Agrius, turned from wiper into ransomware.
MALWARE
According to Microsoft, ApolloShadow has the capability to install a trusted root certificate to trick devices into trusting malicious actor-controlled sites, enabling Secret Blizzard to maintain persistence on diplomatic devices, likely for intelligence collection. It has been used in a campaign where Secret Blizzard has been targeting embassies located in Moscow using an adversary-in-the-middle (AiTM) position.
Apollo
Technical ID: win.apollo
MALWARE
This is an implant usable with the Mythic C2 framework. Apollo is a Windows agent written in C# using the 4.0 .NET Framework designed to be used in SpecterOps training offerings.
Apocalypse
Technical ID: win.apocalypse_ransom
MALWARE
Malware family identifying win.apocalypse_ransom. Origin and technical characteristics tracked via Malpedia.
Apocalipto
Technical ID: win.apocalipto
MALWARE
Malware family identifying win.apocalipto. Origin and technical characteristics tracked via Malpedia.
APERETIF
Technical ID: win.aperetif
MALWARE
Malware family identifying win.aperetif. Origin and technical characteristics tracked via Malpedia.
Anubis Loader
Technical ID: win.anubis_loader
MALWARE
A loader written in Go, tracked since at least October 2021 by ZeroFox. Originally named Kraken and rebranded to Anubis in February 2022.
Also known as: Kraken • Pepega
Anubis
Technical ID: win.anubis
MALWAREfinancialhigh
According to Microsoft Security Intelligence, Anubis is an information stealer sold on underground forums since June 2020. The name overlaps with the Android banking malware but is unrelated. It contains code forked from Loki PWS.
Also known as: Anubis Stealer
Antilam
Technical ID: win.antilam
MALWARE
Malware family identifying win.antilam. Origin and technical characteristics tracked via Malpedia.
Also known as: Latinus
Updated: 2018-07-24
View profile →AnteFrigus
Technical ID: win.antefrigus
MALWAREfinancialhigh
Ransomware that demands payment in Bitcoin.
MALWARE
Malware family identifying win.anel. Origin and technical characteristics tracked via Malpedia.
Also known as: UPPERCUT • lena
MALWARE
According to Proofpoint, AndroMut is a new downloader malware written in C++ that Proofpoint researchers began observing in the wild in June 2019. The “Andro” part of the name comes from some of the pieces which bear resemblance to another downloader malware known as Andromeda [1] and “Mut” is based off a mutex that the analyzed sample creates: “mutshellmy777”.
Also known as: Gelup
MALWARE
Malware family identifying win.andromeda. Origin and technical characteristics tracked via Malpedia.
Also known as: Gamarue • B106-Gamarue • B67-SS-Gamarue • b66
MALWARE
Malware family identifying win.andardoor. Origin and technical characteristics tracked via Malpedia.
Also known as: ROCKHATCH
MALWARE
Recon/Loader malware attributed to Lazarus, disguised as Notepad++ shell extension.
AnchorMail
Technical ID: win.anchormail
MALWARE
Malware family identifying win.anchormail. Origin and technical characteristics tracked via Malpedia.
Also known as: ANCHOR.MAIL • Delegatz
MALWARE
Anchor is a sophisticated backdoor served as a module to a subset of TrickBot installations. Operating since August 2018 it is not delivered to everybody, but contrary is delivered only to high-profile targets. Since its C2 communication scheme is very similar to the one implemented in the early TrickBot, multiple experts believe it could be attributed to the same authors.
Anatova Ransomware
Technical ID: win.anatova_ransom
MALWAREfinancialhigh
Anatova is a ransomware family with the goal of ciphering all the files that it can and then requesting payment from the victim. It will also check if network shares are connected and will encrypt the files on these shares too. The code is also prepared to support modular extensions.
MALWARE
Malware family identifying win.amtsol. Origin and technical characteristics tracked via Malpedia.
Also known as: Adupihan
Amatera
Technical ID: win.amatera
MALWARE
Amatera is a stealer written in C++. It conducts anti-sandbox analysis before enumerating browsers, exfiltrating found cryptocurrency files/wallets and possibly credentials.
Amadey
Technical ID: win.amadey
MALWARE
Amadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware.
Alureon
Technical ID: win.alureon
MALWARE
Malware family identifying win.alureon. Origin and technical characteristics tracked via Malpedia.
Also known as: Olmarik • Pihar • TDL • TDSS • wowlik
MALWARE
Alreay is a remote access trojan that uses HTTP(S) or TCP for communication with its C&C server.
It uses either RC4 or DES for encryption of its configuration, which is stored in the registry.
It sends detailed information about the victim's environment, like computer name, Windows version,
system locale, and network configuration.
It supports almost 25 commands that include operations on the victim’s filesystem, basic process management, file exfiltration, command line execution, and process injection of an executable downloaded from the attacker’s C&C server. As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers, starting with values like 0x21A8B293, 0x23FAE29C or 0x91B93485.
It comes either as an EXE or as a DLL with the internal DLL name t_client_dll.dll. It may contain statically linked code from open-source libraries like Mbed TLS or zLib (version 1.0.1).
Alreay RAT was observed in 2016-2017, running on networks of banks operating SWIFT Alliance software.
MALWARE
Malware family identifying win.alphaseed. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.alphanc. Origin and technical characteristics tracked via Malpedia.
AlphaLocker
Technical ID: win.alphalocker
MALWAREfinancialhigh
A new form of ransomware named AlphaLocker that is built by cybercriminals for cybercriminals. Like all incarnations of Ransomware As A Service (RaaS), the AlphaLocker malware program can be purchased and launched by pretty much anyone who wants to get into the ransomware business. What makes AlphaLocker different from other forms of RaaS is its relatively cheap cost. The ransomware can be purchased for just $65 in bitcoin.
AlphaLocker, also known as Alpha Ransomware, is based on the EDA2 ransomware, an educational project open-sourced on GitHub last year by Turkish researcher Utku Sen. A Russian coder seems to have cloned this repository before it was taken down and used it to create his ransomware, a near-perfect clone of EDA2. The ransomware's author, is said to be paying a great deal of attention to updating the ransomware with new features, so it would always stay ahead of antivirus engines, and evade detection.
AlphaLocker's encryption process starts when the ransomware contacts its C&C server. The server generates a public and a private key via the RSA-2048 algorithm, sending the public key to the user's computer and saving the private key to its server. On the infected computer, the ransomware generates an AES-256 key for each file it encrypts, and then encrypts this key with the public RSA key, and sent to the C&C server.
To decrypt their files, users have to get ahold of the private RSA key which can decrypt the AES-encrypted files found on their computers. Users have to pay around 0.35 Bitcoin (~$450) to get this key, packaged within a nice decrypter.
Alphabet Ransomware
Technical ID: win.alphabet_ransomware
MALWAREfinancialhigh
The Alphabet ransomware is a new screenlocker that is currently being developed by a criminal developer. As the malware is not ready it does not affect any user files.
The virus includes a screenlocking function which locks the user’s screen and prohibits any interaction with the computer.
ALPC Local PrivEsc
Technical ID: win.alpc_lpe
MALWARE
Malware family identifying win.alpc_lpe. Origin and technical characteristics tracked via Malpedia.
MALWAREespionageadvanced
According to Threatray, AlmondRAT is a .NET Remote Access Trojan deployed by the Bitter APT group. It is capable of collecting system information, modifying and exfiltrating data and allows for remote command execution and shares similar functionality with BDarkRAT.
AlmaLocker
Technical ID: win.alma_locker
MALWARE
Malware family identifying win.alma_locker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-26
View profile →MALWARE
Malware family identifying win.alma_communicator. Origin and technical characteristics tracked via Malpedia.
Almanahe
Technical ID: win.almanahe
MALWARE
Malware family identifying win.almanahe. Origin and technical characteristics tracked via Malpedia.
AllcomeClipper
Technical ID: win.allcomeclipper
MALWARE
Allcome is classified as a clipper malware. Clippers are threats designed to access information saved in the clipboard (the temporary buffer space where copied data is stored) and substitute it with another. This attack is targeted at users who are active in the cryptocurrency sector mainly.
AllaSenha
Technical ID: win.allasenha
MALWARE
According to HarfangLabs, AllaSenha is specifically aimed at stealing credentials that are required to access Brazilian bank accounts, leverages Azure cloud as command and control (C2) infrastructure, and is another custom variant of AllaKore, an infamous open-source RAT which is frequently leveraged to target users in Latin America.
Allaple
Technical ID: win.allaple
MALWARE
Malware family identifying win.allaple. Origin and technical characteristics tracked via Malpedia.
Also known as: Starman
AllaKore
Technical ID: win.allakore
MALWARE
AllaKore is a simple Remote Access Tool written in Delphi, first observed in 2015 but still in early stages of development. It implements the RFB protocol which uses frame buffers and thus is able to send back only the changes of screen frames to the controller, speeding up the transport and visualization control.
Alina POS
Technical ID: win.alina_pos
MALWARE
Malware family identifying win.alina_pos. Origin and technical characteristics tracked via Malpedia.
Also known as: alina_spark • katrina • alina_eagle
Project Alice
Technical ID: win.alice_atm
MALWARE
Malware family identifying win.alice_atm. Origin and technical characteristics tracked via Malpedia.
Also known as: PrAlice • AliceATM
Alfonso Stealer
Technical ID: win.alfonso_stealer
MALWARE
Malware family identifying win.alfonso_stealer. Origin and technical characteristics tracked via Malpedia.