Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
3CX Backdoor
Technical ID: win.3cx_backdoor
Lazarus Group
MALWARE
According to CrowdStrike, this backdoor was discovered being embedded in a legitimate, signed version of 3CXDesktopApp, and thus constitutes a supply chain attack.
Also known as: SUDDENICON
Updated: 2025-09-15
View profile →
0bj3ctivityStealer
Technical ID: win.0bj3ctivity_stealer
MALWARE
Information stealer, based on strings it seems to target crypto currencies, instant messengers, and browser data.
Also known as: PXRECVOWEIWOEI
Updated: 2024-10-14
View profile →
000Stealer
Technical ID: win.000stealer
MALWARE
Malware family identifying win.000stealer. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-04
View profile →
WhiteShadow
Technical ID: vbs.whiteshadow
APT GROUP
Malware family identifying vbs.whiteshadow. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-02-26
View profile →
WasabiSeed
Technical ID: vbs.wasabiseed
APT GROUP
Malware family identifying vbs.wasabiseed. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-10-25
View profile →
VBREVSHELL
Technical ID: vbs.vbrevshell
APT GROUP
According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.
Updated: 2023-12-04
View profile →
Unidentified VBS 006 (Telegram Loader)
Technical ID: vbs.unidentified_006
Gamaredon Group
APT GROUP
Malware family identifying vbs.unidentified_006. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-15
View profile →
Unidentified VBS 005 (Telegram Loader)
Technical ID: vbs.unidentified_005
APT GROUP
Malware family identifying vbs.unidentified_005. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-15
View profile →
Unidentified VBS 004 (RAT)
Technical ID: vbs.unidentified_004
MuddyWater
APT GROUP
Lab52 describes this as a light first-stage RAT used by MuddyWater and observed samples between at least November 2020 and January 2022.
Updated: 2023-01-25
View profile →
Unidentified 003 (Gamaredon Downloader)
Technical ID: vbs.unidentified_003
Gamaredon Group
APT GROUP
Malware family identifying vbs.unidentified_003. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-03-15
View profile →
Unidentified 002 (Operation Kremlin)
Technical ID: vbs.unidentified_002
APT GROUP
Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up via winrar.
Updated: 2021-01-11
View profile →
Unidentified VBS 001
Technical ID: vbs.unidentified_001
APT GROUP
Malware family identifying vbs.unidentified_001. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-05-18
View profile →
TAMECAT
Technical ID: vbs.tamecat
APT42
APT GROUP
TAMECAT is PowerShell-based backdoor with modular components designed to facilitate data exfiltration and remote control
Updated: 2025-11-14
View profile →
STARWHALE
Technical ID: vbs.starwhale
MuddyWater
APT GROUP
Malware family identifying vbs.starwhale. Origin and technical characteristics tracked via Malpedia.
Also known as: Canopy • SloughRAT
Updated: 2022-12-02
View profile →
Starfighter
Technical ID: vbs.starfighter
APT GROUP
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on local powershell availability.
Updated: 2020-04-07
View profile →
RandomQuery
Technical ID: vbs.randomquery
Kimsuky
APT GROUP
According to SentinelLabs, this is a VisualBasic-based malware that gathers system and file information and exfiltrates the data using InternetExplorer.Application or Microsoft.XMLHTTP objects.
Updated: 2023-05-30
View profile →
NodeJS Ransomware
Technical ID: vbs.nodejs_ransom
APT GROUP
Downloads NodeJS when deployed.
Updated: 2020-03-27
View profile →
MOUSEISLAND
Technical ID: vbs.mouseisland
APT GROUP
MOUSEISLAND is a Microsoft Word macro downloader used as the first infection stage and is delivered inside a password-protected zip attached to a phishing email. Based on Fireeye intrusion data from responding to ICEDID related incidents, the secondary payload delivered by MOUSEISLAND has been PHOTOLOADER, which acts as an intermediary downloader to install ICEDID.
Updated: 2021-06-29
View profile →
LOSTKEYS
Technical ID: vbs.lostkeys
Callisto
APT GROUP
According to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.
Updated: 2025-05-20
View profile →
lockscreen
Technical ID: vbs.lockscreen
APT GROUP
Malware family identifying vbs.lockscreen. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-07-30
View profile →
LitterDrifter
Technical ID: vbs.litterdrifter
Gamaredon Group
APT GROUP
Malware family identifying vbs.litterdrifter. Origin and technical characteristics tracked via Malpedia.
Updated: 2023-12-04
View profile →
LCRYX
Technical ID: vbs.lcryx
APT GROUP
Malware family identifying vbs.lcryx. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-02-26
View profile →
lampion
Technical ID: vbs.lampion
APT GROUPfinancialhigh
Malware is delivered by emails, containing links to ZIP files or ZIP attachments. The ZIP contains a VBscript that, when executed, downloads additional files from AWS S3, Google Drive or other cloud hosting services. The downloaded files are encrypted .exe and .dll files. The malware targets banking clients in Portugal.
Updated: 2023-11-13
View profile →
Janicab
Technical ID: vbs.janicab
Evilnum
APT GROUP
Malware family identifying vbs.janicab. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-12-14
View profile →
Iloveyou
Technical ID: vbs.iloveyou
APT GROUP
Malware family identifying vbs.iloveyou. Origin and technical characteristics tracked via Malpedia.
Also known as: LoveLetter • Love Bug
Updated: 2019-05-20
View profile →
HOMESTEEL
Technical ID: vbs.homesteel
APT GROUP
Malware family identifying vbs.homesteel. Origin and technical characteristics tracked via Malpedia.
Updated: 2026-01-26
View profile →
HATVIBE
Technical ID: vbs.hatvibe
UAC-0063
APT GROUP
According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server. Once received, HATVIBE uses a simple XOR algorithm to decrypt each module, contact it between two <script> tags before adding it to the HTML body of the HTA file, leading to the automatic execution of the received module.
Updated: 2025-07-11
View profile →
HALFBAKED
Technical ID: vbs.halfbaked
Anunak
APT GROUPfinancialhigh
The HALFBAKED malware family consists of multiple components designed to establish and maintain a foothold in victim networks, with the ultimate goal of gaining access to sensitive financial information. HALFBAKED listens for the following commands from the C2 server: info: Sends victim machine information (OS, Processor, BIOS and running processes) using WMI queries processList: Send list of process running screenshot: Takes screen shot of victim machine (using 58d2a83f777688.78384945.ps1) runvbs: Executes a VB script runexe: Executes EXE file runps1: Executes PowerShell script delete: Delete the specified file update: Update the specified file
Updated: 2020-06-25
View profile →
Grinju Downloader
Technical ID: vbs.grinju
APT GROUP
Malware family identifying vbs.grinju. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-05
View profile →
GlowSpark
Technical ID: vbs.glowspark
APT GROUP
Malware family identifying vbs.glowspark. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-02-17
View profile →
GGLdr
Technical ID: vbs.ggldr
APT GROUP
Malware family identifying vbs.ggldr. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-05-27
View profile →
GamaWiper
Technical ID: vbs.gamawiper
Gamaredon Group
APT GROUP
According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880). They assess with medium confidence a link to Gamaredon.
Updated: 2025-12-12
View profile →
forbiks
Technical ID: vbs.forbiks
APT GROUP
Malware family identifying vbs.forbiks. Origin and technical characteristics tracked via Malpedia.
Also known as: Forbix
Updated: 2019-09-03
View profile →
CageyChameleon
Technical ID: vbs.cageychameleon
APT GROUP
CageyChameleon Malware is a VBS-based backdoor which has the capability to enumerate the list of running processes and check for the presence of several antivirus products. CageyChameleon will collect user host information, system current process information, etc. The collected information is sent back to the C2 server, and continue to initiate requests to perform subsequent operations.
Also known as: Cabbage RAT
Updated: 2023-12-11
View profile →
BASICSTAR
Technical ID: vbs.basicstar
APT GROUP
Malware family identifying vbs.basicstar. Origin and technical characteristics tracked via Malpedia.
Updated: 2024-03-28
View profile →
FlexiSpy
Technical ID: symbian.flexispy
APT GROUP
Malware family identifying symbian.flexispy. Origin and technical characteristics tracked via Malpedia.
Updated: 2017-05-01
View profile →
xzbot
Technical ID: sh.xzbot
APT GROUP
A backdoor brought into version 5.6.0 and 5.6.1 of compression library/tool xz/liblzma, which was intended to enable access via (Open)SSH on affected servers.
Also known as: xzorcist
Updated: 2024-04-15
View profile →
PANIX
Technical ID: sh.panix
APT GROUP
According to its author, PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.
Updated: 2025-02-28
View profile →
KV
Technical ID: sh.kv
Volt Typhoon
APT GROUP
Malware family identifying sh.kv. Origin and technical characteristics tracked via Malpedia.
Updated: 2025-07-24
View profile →
WIREFIRE
Technical ID: py.wirefire
APT GROUP
Malware family identifying py.wirefire. Origin and technical characteristics tracked via Malpedia.
Also known as: GIFTEDVISITOR
Updated: 2025-04-28
View profile →
← PreviousPage 188 / 269Next →