Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
APT GROUP
A loader written in Powershell, usually delivered packaged in MSI/MSIX files.
Also known as: FakeBat • NUMOZYLOD • PaykLoader
APT GROUP
According to Trend Micro, DarkWisp is a PowerShell-based backdoor and reconnaissance utility designed for unauthorized system access and intelligence gathering. It enables attackers to exfiltrate sensitive data while maintaining persistent control over the compromised system. The malware collects extensive information about the compromised system to create a detailed profile. It determines whether the user has administrative privileges, checks for membership in a corporate domain, and identifies the presence of cryptocurrency wallets or VPN software by scanning specified directories and applications. It also gathers data about the system's operating environment, including public IP address, geographic location, installed antivirus products, firewall status, and system uptime. This information is compiled into a structured format and transmitted to the C&C server.
APT GROUP
According to CERT-UA, COOKBOX is a PowerShell script that implements the functionality of downloading and executing PowerShell cmdlets. For each affected computer, a unique identifier is calculated using cryptographic transformations (SHA256/MD5 hash functions) based on a combination of computer name and disk serial number, which is transmitted in the “X-Cookie” header of HTTP requests when interacting with the management server. The persistence of the backdoor is ensured by the corresponding key in the Run branch of the operating system (OS) registry, which is created at the stage of the initial infection by a third-party PowerShell script (including the COOKBOX deployer). As a rule, obfuscation elements are used in the program code: chr-character encoding, character replacement (replace()), base64 conversion, GZIP compression.
CASHY200
Technical ID: ps1.cashy200
APT GROUP
Malware family identifying ps1.cashy200. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying ps1.bondupdater. Origin and technical characteristics tracked via Malpedia.
Also known as: Poison Frog • Glimpse
BlackSun
Technical ID: ps1.blacksun
APT GROUPfinancialhigh
Ransomware.
Silence DDoS
Technical ID: pl.silence_ddos
APT GROUP
Malware family identifying pl.silence_ddos. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying php.wso. Origin and technical characteristics tracked via Malpedia.
Also known as: Webshell by Orb
APT GROUP
A PHP webshell that allows file system management, data exfiltration and command execution.
APT GROUP
Malware family identifying php.redhat_hacker. Origin and technical characteristics tracked via Malpedia.
PS1Bot
Technical ID: php.ps1bot
APT GROUPespionageadvanced
According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality, including the ability to deliver follow-on modules including an information stealer, keylogger, screen capture collector and more. It also establishes persistence to continue operations following system reboots. The design of this malware framework appears to attempt to minimize artifacts left on infected systems by facilitating the delivery and execution of modules in-memory, without requiring them to be written to disk. Due to similarities in the design and implementation with the malware family AHK Bot, we are referring to this PowerShell-based malware as “PS1Bot.”
Prometheus Backdoor
Technical ID: php.prometheus_backdoor
APT GROUP
Backdoor written in php
PAS
Technical ID: php.pas
APT GROUP
Malware family identifying php.pas. Origin and technical characteristics tracked via Malpedia.
Parrot TDS WebShell
Technical ID: php.parrot_tds_shell
APT GROUP
In combination with Parrot TDS the usage of a classical web shell was observed by DECODED Avast.io.
p0wnyshell
Technical ID: php.p0wnyshell
APT GROUP
Malware family identifying php.p0wnyshell. Origin and technical characteristics tracked via Malpedia.
Also known as: Pownyshell • Ponyshell
Glutton
Technical ID: php.glutton
APT GROUP
According to Xlab, Glutton is a modular PHP fileless attack framework, capable of data exfiltration and running backdoors.
Ensikology
Technical ID: php.ensikology
APT GROUP
Malware family identifying php.ensikology. Origin and technical characteristics tracked via Malpedia.
Also known as: Ensiko
DollyWay
Technical ID: php.dollyway
APT GROUP
PHP/JavaScript malware for WordPress that injects multi-stage scripts, turning compromised sites into distributed TDS/C2 nodes. Delivers signed payloads, maintains persistence via helper files, and redirects traffic to monetized scam networks.
DEWMODE
Technical ID: php.dewmode
APT GROUP
FireEye discovered the DEWMODE webshell starting mid-December 2020 after exploitation of zero-day vulnerabilities in Accellion's File Transfer Appliance. It is a PHP webshell that allows threat actors to view and download files in the victim machine. It also contains cleanup function to remove itself and clean the Apache log.
c99shell
Technical ID: php.c99
APT GROUP
C99shell is a PHP backdoor that provides a lot of functionality, for example:
* run shell commands;
* download/upload files from and to the server (FTP functionality);
* full access to all files on the hard disk;
* self-delete functionality.
Also known as: c99
Behinder
Technical ID: php.behinder
APT GROUP
A webshell for multiple web languages (asp/aspx, jsp/jspx, php), openly distributed through Github.
APT GROUP
ASPXSpy is an open-source web shell written in C# that allows a threat actor to accomplish various post-exploitation tasks, including file access and command execution.
APT GROUP
Antak is a webshell written in ASP.Net which utilizes PowerShell.
Ani-Shell
Technical ID: php.anishell
APT GROUP
Ani-Shell is a simple PHP shell with some unique features like Mass Mailer, a simple Web-Server Fuzzer, Dosser, Back Connect, Bind Shell, Back Connect, Auto Rooter etc.
Also known as: anishell
ZuRu
Technical ID: osx.zuru
APT GROUP
A malware that was observed being embedded alongside legitimate applications (such as iTerm2) offered for download on suspicious websites pushed in search engines. It uses a Python script to perform reconnaissance on the compromised system an pulls additional payload(s).
APT GROUP
Malware family identifying osx.yort. Origin and technical characteristics tracked via Malpedia.
XSLCmd
Technical ID: osx.xslcmd
APT GROUP
Malware family identifying osx.xslcmd. Origin and technical characteristics tracked via Malpedia.
Xloader
Technical ID: osx.xloader
APT GROUP
Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well.
Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent.
Not to be confused with apk.xloader or ios.xloader.
Also known as: Formbook
XCSSET
Technical ID: osx.xcsset
APT GROUP
Malware family identifying osx.xcsset. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.xagent. Origin and technical characteristics tracked via Malpedia.
Wirenet
Technical ID: osx.wirenet
APT GROUP
Malware family identifying osx.wirenet. Origin and technical characteristics tracked via Malpedia.
WireLurker
Technical ID: osx.wirelurker
APT GROUP
Malware family identifying osx.wirelurker. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.winnti. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.windtail. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to Mandiant, WAVESHAPER is a backdoor written in C++ and packed by an unknown packer that targets macOS. The backdoor supports downloading and executing arbitrary payloads retrieved from its command-and-control (C2 or C&C) server, which is provided via the command-line parameters. To communicate with the adversary infrastructure, WAVESHAPER leverages the curl library for either HTTP or HTTPS, depending on the command-line argument provided.
WAVESHAPER also runs as a daemon by forking itself into a child process that runs in the background detached from the parent session and collects system information, which is sent to the C&C server in a HTTP POST request.
APT GROUP
Malware family identifying osx.watchcat. Origin and technical characteristics tracked via Malpedia.
Vigram
Technical ID: osx.vigram
APT GROUP
Malware family identifying osx.vigram. Origin and technical characteristics tracked via Malpedia.
Also known as: WizardUpdate
APT GROUP
Malware family identifying osx.uroburos. Origin and technical characteristics tracked via Malpedia.
UpdateAgent
Technical ID: osx.update_agent
APT GROUP
Malware family identifying osx.update_agent. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying osx.unidentified_001. Origin and technical characteristics tracked via Malpedia.