Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
MALWARE
According to CrowdStrike, this backdoor was discovered being embedded in a legitimate, signed version of 3CXDesktopApp, and thus constitutes a supply chain attack.
Also known as: SUDDENICON
0bj3ctivityStealer
Technical ID: win.0bj3ctivity_stealer
MALWARE
Information stealer, based on strings it seems to target crypto currencies, instant messengers, and browser data.
Also known as: PXRECVOWEIWOEI
000Stealer
Technical ID: win.000stealer
MALWARE
Malware family identifying win.000stealer. Origin and technical characteristics tracked via Malpedia.
WhiteShadow
Technical ID: vbs.whiteshadow
APT GROUP
Malware family identifying vbs.whiteshadow. Origin and technical characteristics tracked via Malpedia.
WasabiSeed
Technical ID: vbs.wasabiseed
APT GROUP
Malware family identifying vbs.wasabiseed. Origin and technical characteristics tracked via Malpedia.
VBREVSHELL
Technical ID: vbs.vbrevshell
APT GROUP
According to Mandiant, VBREVSHELL is a VBA macro that spawns a reverse shell relying exclusively on Windows API calls.
APT GROUP
Malware family identifying vbs.unidentified_006. Origin and technical characteristics tracked via Malpedia.
Unidentified VBS 005 (Telegram Loader)
Technical ID: vbs.unidentified_005
APT GROUP
Malware family identifying vbs.unidentified_005. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Lab52 describes this as a light first-stage RAT used by MuddyWater and observed samples between at least November 2020 and January 2022.
APT GROUP
Malware family identifying vbs.unidentified_003. Origin and technical characteristics tracked via Malpedia.
Unidentified 002 (Operation Kremlin)
Technical ID: vbs.unidentified_002
APT GROUP
Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up via winrar.
Unidentified VBS 001
Technical ID: vbs.unidentified_001
APT GROUP
Malware family identifying vbs.unidentified_001. Origin and technical characteristics tracked via Malpedia.
APT GROUP
TAMECAT is PowerShell-based backdoor with modular components designed to facilitate data exfiltration and remote control
APT GROUP
Malware family identifying vbs.starwhale. Origin and technical characteristics tracked via Malpedia.
Also known as: Canopy • SloughRAT
Starfighter
Technical ID: vbs.starfighter
APT GROUP
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on local powershell availability.
APT GROUP
According to SentinelLabs, this is a VisualBasic-based malware that gathers system and file information and exfiltrates the data using InternetExplorer.Application or Microsoft.XMLHTTP objects.
NodeJS Ransomware
Technical ID: vbs.nodejs_ransom
APT GROUP
Downloads NodeJS when deployed.
MOUSEISLAND
Technical ID: vbs.mouseisland
APT GROUP
MOUSEISLAND is a Microsoft Word macro downloader used as the first infection stage and is delivered inside a password-protected zip attached to a phishing email. Based on Fireeye intrusion data from responding to ICEDID related incidents, the secondary payload delivered by MOUSEISLAND has been PHOTOLOADER, which acts as an intermediary downloader to install ICEDID.
APT GROUP
According to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.
lockscreen
Technical ID: vbs.lockscreen
APT GROUP
Malware family identifying vbs.lockscreen. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying vbs.litterdrifter. Origin and technical characteristics tracked via Malpedia.
LCRYX
Technical ID: vbs.lcryx
APT GROUP
Malware family identifying vbs.lcryx. Origin and technical characteristics tracked via Malpedia.
lampion
Technical ID: vbs.lampion
APT GROUPfinancialhigh
Malware is delivered by emails, containing links to ZIP files or ZIP attachments. The ZIP contains a VBscript that, when executed, downloads additional files from AWS S3, Google Drive or other cloud hosting services. The downloaded files are encrypted .exe and .dll files.
The malware targets banking clients in Portugal.
APT GROUP
Malware family identifying vbs.janicab. Origin and technical characteristics tracked via Malpedia.
Iloveyou
Technical ID: vbs.iloveyou
APT GROUP
Malware family identifying vbs.iloveyou. Origin and technical characteristics tracked via Malpedia.
Also known as: LoveLetter • Love Bug
HOMESTEEL
Technical ID: vbs.homesteel
APT GROUP
Malware family identifying vbs.homesteel. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server. Once received, HATVIBE uses a simple XOR algorithm to decrypt each module, contact it between two <script> tags before adding it to the HTML body of the HTA file, leading to the automatic execution of the received module.
APT GROUPfinancialhigh
The HALFBAKED malware family consists of multiple components designed to establish and maintain a foothold in victim networks, with the ultimate goal of gaining access to sensitive financial information.
HALFBAKED listens for the following commands from the C2 server:
info: Sends victim machine information (OS, Processor, BIOS and running processes) using WMI
queries
processList: Send list of process running
screenshot: Takes screen shot of victim machine (using 58d2a83f777688.78384945.ps1)
runvbs: Executes a VB script
runexe: Executes EXE file
runps1: Executes PowerShell script
delete: Delete the specified file
update: Update the specified file
Grinju Downloader
Technical ID: vbs.grinju
APT GROUP
Malware family identifying vbs.grinju. Origin and technical characteristics tracked via Malpedia.
GlowSpark
Technical ID: vbs.glowspark
APT GROUP
Malware family identifying vbs.glowspark. Origin and technical characteristics tracked via Malpedia.
GGLdr
Technical ID: vbs.ggldr
APT GROUP
Malware family identifying vbs.ggldr. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to ClearSky, this is a VBS-based wiper, deployed via exploitation of a vulnerable WinRAR version (CVE-2025-80880). They assess with medium confidence a link to Gamaredon.
forbiks
Technical ID: vbs.forbiks
APT GROUP
Malware family identifying vbs.forbiks. Origin and technical characteristics tracked via Malpedia.
Also known as: Forbix
CageyChameleon
Technical ID: vbs.cageychameleon
APT GROUP
CageyChameleon Malware is a VBS-based backdoor which has the capability to enumerate the list of running processes and check for the presence of several antivirus products. CageyChameleon will collect user host information, system current process information, etc. The collected information is sent back to the C2 server, and continue to initiate requests to perform subsequent operations.
Also known as: Cabbage RAT
BASICSTAR
Technical ID: vbs.basicstar
APT GROUP
Malware family identifying vbs.basicstar. Origin and technical characteristics tracked via Malpedia.
FlexiSpy
Technical ID: symbian.flexispy
APT GROUP
Malware family identifying symbian.flexispy. Origin and technical characteristics tracked via Malpedia.
xzbot
Technical ID: sh.xzbot
APT GROUP
A backdoor brought into version 5.6.0 and 5.6.1 of compression library/tool xz/liblzma, which was intended to enable access via (Open)SSH on affected servers.
Also known as: xzorcist
PANIX
Technical ID: sh.panix
APT GROUP
According to its author, PANIX is a powerful, modular, and highly customizable Linux persistence framework designed for security researchers, detection engineers, penetration testers, CTF enthusiasts, and more. Built with versatility in mind, PANIX emphasizes functionality, making it an essential tool for understanding and implementing a wide range of persistence techniques.
APT GROUP
Malware family identifying sh.kv. Origin and technical characteristics tracked via Malpedia.
WIREFIRE
Technical ID: py.wirefire
APT GROUP
Malware family identifying py.wirefire. Origin and technical characteristics tracked via Malpedia.
Also known as: GIFTEDVISITOR