Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Aldibot
Technical ID: win.aldibot
MALWARE
According to Trend Micro Encyclopia:
ALDIBOT first appeared in late August 2012 in relevant forums. Variants can steal passwords from the browser Mozilla Firefox, instant messenger client Pidgin, and the download manager jDownloader. ALDIBOT variants send the gathered information to their command-and-control (C&C) servers.
This malware family can also launch Distributed Denial of Service (DDoS) attacks using different protocols such as HTTP, TCP, UDP, and SYN. It can also perform flood attacks via Slowloris and Layer 7.
This bot can also be set up as a SOCKS proxy to abuse the infected machine as a proxy for any protocols.
This malware family can download and execute arbitrary files, and update itself. Variants can steal information, gathering the infected machine’s hardware identification (HWID), host name, local IP address, and OS version.
This backdoor executes commands from a remote malicious user, effectively compromising the affected system.
MALWARE
Malware family identifying win.albaniiutas. Origin and technical characteristics tracked via Malpedia.
Also known as: BlueTraveller
MALWARE
Malware family identifying win.akira. Origin and technical characteristics tracked via Malpedia.
Also known as: REDBIKE
MALWARE
AkdoorTea is a simple TCP RAT.
In August 2025, it was contained in a trojanized Nvidia CUDA toolkit package, delivered probably via the ClickFix technique. The package also contained an obfuscated BeaverTail payload, which suggests its attribution to the Contagious Interview campaigns.
AkdoorTea uses Base64 encryption combined with a single-byte XOR key for network traffic obfuscation.
The RAT supports five commands, one of which is to report its internal version, which is "01.01".
Its name was inspired by the similarity to a TCP RAT, referred to as "Akdoor", that was used in attacks leveraging ActiveX exploits against South Korean targets in April 2018.
MALWARE
According to Unit 42, this malware steals information from browsers and uses a covert channel through the AirWatch API.
Ahtapot
Technical ID: win.ahtapot
MALWARE
Malware family identifying win.ahtapot. Origin and technical characteristics tracked via Malpedia.
AgfSpy
Technical ID: win.agfspy
MALWARE
The agfSpy backdoor retrieves configuration and commands from its C&C server. These commands allow the backdoor to execute shell commands and send the execution results back to the server. It also enumerates directories and can list, upload, download, and execute files, among other functions. The capabilities of agfSpy are very similar to dneSpy, except each backdoor uses a different C&C server and various formats in message exchanges.
MALWARE
A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
Also known as: AgenTesla • AgentTesla • Negasteal
Agent Racoon
Technical ID: win.agent_racoon
MALWARE
Agent Racoon is a .NET-based backdoor malware that leverages DNS for covert C2 communication, employing randomized subdomains and Punycode encoding to evade detection. It features encrypted communication using a unique key per sample, supports remote command execution, and facilitates file transfers. Despite lacking an inherent persistence mechanism, it relies on external methods like scheduled tasks for execution. The malware, active since at least 2020, has targeted organizations in the U.S., Middle East, and Africa, including non-profits and government sectors. It disguises itself as legitimate binaries such as Google Update and MS OneDrive Updater, using obfuscation techniques like Base64 encoding and timestamp modifications to avoid detection.
MALWARE
Malware family identifying win.agent_btz. Origin and technical characteristics tracked via Malpedia.
Also known as: ComRAT • Minit • Sun rootkit
AgendaCrypt
Technical ID: win.agendacrypt
MALWAREfinancialhigh
Ransomware written in Go.
Also known as: Agenda • Qilin
Afrodita
Technical ID: win.afrodita
MALWARE
Malware family identifying win.afrodita. Origin and technical characteristics tracked via Malpedia.
AESRT
Technical ID: win.aesrt
MALWAREfinancialhigh
Ransomware written using .NET.
Adylkuzz
Technical ID: win.adylkuzz
MALWARE
Malware family identifying win.adylkuzz. Origin and technical characteristics tracked via Malpedia.
AdvisorsBot
Technical ID: win.advisorsbot
MALWARE
AdvisorsBot is a downloader named after early command and control domains that all contained the word "advisors". The malware is written in C and employs a number of anti-analysis features such as junk code, stack strings and Windows API function hashing.
AdKoob
Technical ID: win.adkoob
MALWARE
Malware family identifying win.adkoob. Origin and technical characteristics tracked via Malpedia.
Adhubllka
Technical ID: win.adhubllka
MALWAREfinancialhigh
Some Ransomware distributed by TA547 in Australia
AdaptixC2
Technical ID: win.adaptix_c2
MALWAREespionageadvanced
AdaptixC2 is a open-source post-exploitation and adversarial emulation framework that lets penetration testers control compromised hosts and execute system actions. While being created for red-teaming it is also used by threat actors for attacks.
AdamLocker
Technical ID: win.adam_locker
MALWAREfinancialhigh
Adam Locker (detected as RANSOM_ADAMLOCK.A) is a ransomware that encrypts targeted files on a victim’s system but offers them a free decryption key which can be accessed through Adf.ly, a URL shortening and advertising service.
Adamantium Thief
Technical ID: win.adamantium_thief
MALWARE
Malware family identifying win.adamantium_thief. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.action_rat. Origin and technical characteristics tracked via Malpedia.
ACR Stealer
Technical ID: win.acr_stealer
MALWARE
First introduced in March 2024, ACR Stealer is an information stealer sold as a Malware-as-a-Service (MaaS) on Russian-speaking cybercrime forums by a threat actor named "SheldIO". Researchers posit that this malware is an evolved version of the GrMsk Stealer, which likely aligns with the private stealer that SheldIO has been selling since July 2023. The malware, written in C++, is compatible with Windows 7 through 10, and the seller manages all command and control (C2) infrastructure. ACR Stealer can harvest system information, stored credentials, web browser cookies, cryptocurrency wallets, and configuration files for various programs. Additionally, it employs the dead drop resolver (DDR) technique to obfuscate the actual C2 infrastructure.
Acronym
Technical ID: win.acronym
MALWARE
Malware family identifying win.acronym. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-04-06
View profile →AcridRain
Technical ID: win.acridrain
MALWARE
AcridRain is a password stealer written in C/C++. This malware can steal credentials, cookies, credit cards from multiple browsers. It can also dump Telegram and Steam sessions, rob Filezilla recent connections, and more.
AcidBox
Technical ID: win.acidbox
MALWARE
Unit42 found AcidBox in February 2019 and describes it as a malware family used by an unknown threat actor in 2017 against Russian entities, as stated by Dr.Web. It reused and improved an exploit for VirtualBox previously used by Turla. The malware itself is a modular toolkit, featuring both usermode and kernelmode components and anti-analysis techniques such as stack-based string obfuscation or dynamic XOR-encoded API usage.
Also known as: MagicScroll
MALWARE
ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload. To execute, a password is necessary (e.g. 9839D7F1A0) and the individual modules are addressed with parameters (-m, -w, -h).
ACBackdoor
Technical ID: win.acbackdoor
MALWARE
A Linux backdoor that was apparently ported to Windows. This entry represents the Windows version. It appears the Linux version was written first and the Windows version was ported later, without full functionality. The Linux version offers persistence as well as some process manipulation techniques, though both versions apparently offer the ability to access the command line and execute programs as well as self-update.
AbSent Loader
Technical ID: win.absentloader
MALWARE
Malware family identifying win.absentloader. Origin and technical characteristics tracked via Malpedia.
MALWARE
Malware family identifying win.abcsync. Origin and technical characteristics tracked via Malpedia.
Abbath Banker
Technical ID: win.abbath_banker
MALWARE
Malware family identifying win.abbath_banker. Origin and technical characteristics tracked via Malpedia.
Updated: 2016-12-28
View profile →abantes
Technical ID: win.abantes
MALWARE
Malware family identifying win.abantes. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-10-18
View profile →AbaddonPOS
Technical ID: win.abaddon_pos
MALWARE
MajorGeeks describes this malware as trying to locate credit card data by reading the memory of all processes except itself by first blacklisting its own PID using the GetCurrentProcessId API. Once that data is discovered, it sends this data back to a command and control server using a custom binary protocol instead of HTTP.
Also known as: PinkKite • TinyPOS
Abaddon
Technical ID: win.abaddon
MALWAREfinancialhigh
Uses Discord as C&C, has ransomware feature.
MALWAREespionageadvanced
9002 RAT is a Remote Access Tool typically observed to be used by an APT to control a victim's machine. It has been spread over via zero day exploits (e.g. targeting Internet Explorer) as well as via email attachments. The infection chain starts by opening a .LNK (an OLE packager shell object) that executes a Powershell command.
Also known as: McRAT • Hydraq • HOMEUNIX
MALWARE
8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT. According to Proofpoint the attack was developed against a number of government agencies in East Asia overseeing government information technology, domestic affairs, foreign affairs, economic development, and political processes. The dropper was delivered through an RTF document exploiting CVE-2018-0798.
Also known as: 8t_dropper • RoyalRoad
8Base
Technical ID: win.8base
MALWAREfinancialhigh
The 8Base ransomware group has remained relatively unknown despite the massive spike in activity in Summer of 2023. The group utilizes encryption paired with “name-and-shame” techniques to compel their victims to pay their ransoms. 8Base has an opportunistic pattern of compromise with recent victims spanning across varied industries. Despite the high amount of compromises, the information regarding identities, methodology, and underlying motivation behind these incidents still remains a mystery. Samples of their ransomware show they are using customized Phobos with SmokeLoader.
7ev3n
Technical ID: win.7ev3n
MALWAREfinancialhigh
The NJCCIC describes 7ev3n as a ransomware "that targets the Windows OS and spreads via spam emails containing malicious attachments, as well as file sharing networks. It installs multiple files in the LocalAppData folder, each of which controls different functions including disabling bootup recovery options, deleting the ransomware installation file, encrypting data, and gaining administrator privileges. This variant also adds registry keys that disables various Windows function keys such as F1, F3, F4, F10, Alt, Num Lock, Ctrl, Enter, Escape, Shift, and Tab. Files encrypted by 7ev3n are labeled with a .R5A extension. It also locks victims out of Windows recovery options making it challenging to repair the damage done by 7ev3n."
5.t Downloader
Technical ID: win.5t_downloader
MALWAREespionageadvanced
Downloader used in suspected APT attack against Vietnam.
MALWARE
Malware family identifying win.4h_rat. Origin and technical characteristics tracked via Malpedia.
404 Keylogger
Technical ID: win.404keylogger
MALWARE
Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victim’s sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.
Also known as: 404KeyLogger • Snake Keylogger