Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Crisis
Technical ID: osx.crisis
APT GROUP
Malware family identifying osx.crisis. Origin and technical characteristics tracked via Malpedia.
CreativeUpdater
Technical ID: osx.creative_updater
APT GROUP
Malware family identifying osx.creative_updater. Origin and technical characteristics tracked via Malpedia.
CpuMeaner
Technical ID: osx.cpumeaner
APT GROUP
Malware family identifying osx.cpumeaner. Origin and technical characteristics tracked via Malpedia.
Convuster
Technical ID: osx.convuster
APT GROUP
Malware family identifying osx.convuster. Origin and technical characteristics tracked via Malpedia.
Coldroot RAT
Technical ID: osx.coldroot_rat
APT GROUP
Malware family identifying osx.coldroot_rat. Origin and technical characteristics tracked via Malpedia.
CoinThief
Technical ID: osx.cointhief
APT GROUP
CoinThief was a malware package designed to steal Bitcoins from the victim, consisting of a binary patcher, browser extensions, and a backdoor component.
It was spreading in early 2014 from several different sources:
- on Github (where the trojanized compiled binary didn’t match the displayed source code), o
- on popular and trusted download sites line CNET's Download.com or MacUpdate.com, and
- as cracked applications via torrents camouflaged as Bitcoin Ticker TTM, BitVanity, StealthBit, Litecoin Ticker, BBEdit, Pixelmator, Angry Birds and Delicious Library.
The patcher‘s role was to locate and modify legitimate versions of the Bitcoin-Qt wallet application. The analyzed malware samples targeted versions of Bitcoin-Qt 0.8.1, 0.8.0 and 0.8.5. The earlier patch modified Bitcoin-Qt adding malicious code that would send nearly all the victim’s Bitcoins to one of the hard-coded addresses belonging to the attacker.
The browser extensions targeted Chrome and Firefox and are disguised as a “Pop-up blocker”. The extensions monitored visited websites, download malicious JavaScripts and injected them into various Bitcoin-related websites (mostly Bitcoin exchanges and online wallet sites). The injected JS scripts were able to modify transactions to redirect Bitcoin transfers to an attacker’s address or simply harvest login credentials to the targeted online service.
The backdoor enabled the attacker to take full control over the victim’s computer:
- collect information about the infected computer
- execute arbitrary shell scripts on the target computer
- upload an arbitrary file from the victim’s hard drive to a remote server
- update itself to a newer version
CloudMensis
Technical ID: osx.cloud_mensis
APT GROUP
Malware family identifying osx.cloud_mensis. Origin and technical characteristics tracked via Malpedia.
Also known as: BadRAT
Choziosi
Technical ID: osx.choziosi
APT GROUP
A loader delivering malicious Chrome and Safari extensions.
Also known as: ChromeLoader • Chropex
CDDS
Technical ID: osx.cdds
APT GROUP
Google TAG has observed this malware being delivered via watering hole attacks using 0-day exploits, targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political group.
Also known as: Macma
APT GROUP
Malware family identifying osx.casso. Origin and technical characteristics tracked via Malpedia.
Careto
Technical ID: osx.careto
APT GROUP
Malware family identifying osx.careto. Origin and technical characteristics tracked via Malpedia.
Also known as: Mask • Appetite
Bundlore
Technical ID: osx.bundlore
APT GROUP
Malware family identifying osx.bundlore. Origin and technical characteristics tracked via Malpedia.
Also known as: SurfBuyer
Bella
Technical ID: osx.bella
APT GROUP
Malware family identifying osx.bella. Origin and technical characteristics tracked via Malpedia.
BeaverTail
Technical ID: osx.beavertail
APT GROUP
Malware family identifying osx.beavertail. Origin and technical characteristics tracked via Malpedia.
BANSHEE
Technical ID: osx.banshee
APT GROUP
Malware family identifying osx.banshee. Origin and technical characteristics tracked via Malpedia.
APT GROUP
According to PcRisk AppleJeus is the name of backdoor malware that was distributed by the Lazarus group. They spread this malicious software through a fake app disguised as a cryptocurrency trading application called Celas Trade Pro.
AMOS
Technical ID: osx.amos
APT GROUP
Malware family identifying osx.amos. Origin and technical characteristics tracked via Malpedia.
Also known as: Atomic macOS Stealer
APT GROUP
Malware family identifying osx.3cx_backdoor. Origin and technical characteristics tracked via Malpedia.
APT GROUP
webshell
Godzilla Webshell
Technical ID: jsp.godzilla_webshell
APT GROUP
Malware family identifying jsp.godzilla_webshell. Origin and technical characteristics tracked via Malpedia.
witchcoven
Technical ID: js.witchcoven
APT GROUP
Malware family identifying js.witchcoven. Origin and technical characteristics tracked via Malpedia.
WEEVILPROXY
Technical ID: js.weevilproxy
APT GROUP
WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS. The developer has put in concerted effort to develop the malware’s breadth of capabilities, including novel techniques not observed in any prior malware campaigns - to our knowledge. These new TTPs include methods to modify Windows Setup and Windows Recovery to enable long-term persistence, as well as methods to patch browser extensions ‘on the fly’.
Also known as: JSCEAL
APT GROUP
The threat actor of this family compromised Chrome extension developer accounts and attached malicious code to the extensions. Web Developer 0.4.9, Chrometana 1.1.3, Infinity New Tab 3.12.3, CopyFish 2.8.5, Web Paint 1.2.1, and Social Fixer 20.1.1 were affected by this. TouchVPN and BetterVPN were assumed to be targets as well.
This lead to the execution of another Javascript that substitutes ad banners for their own, effectively hijacking ad traffic. It is also reported that fake pop-up alerts were used to lure victims to download possibly other malware.
Valak
Technical ID: js.valak
APT GROUP
According to PCrisk, Valak is malicious software that downloads JScript files and executes them. What happens next depends on the actions performed by the executed JScript files. It is very likely that cyber criminals behind Valak attempt to use this malware to cause chain infections (i.e., using Valak to distribute other malware).
Research shows that Valak is distributed through spam campaigns, however, in some cases, it infiltrates systems when they are already infected with malicious program such as Ursnif (also known as Gozi).
Also known as: Valek
Unidentified JS 002
Technical ID: js.unidentified_js_002
APT GROUP
Malware family identifying js.unidentified_js_002. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-06-21
View profile →APT GROUP
A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.
Unidentified JS 005 (Stealer)
Technical ID: js.unidentified_005
APT GROUP
Malware family identifying js.unidentified_005. Origin and technical characteristics tracked via Malpedia.
Unidentified JS 004
Technical ID: js.unidentified_004
APT GROUP
A simple loader written in JavaScript found by Marco Ramilli.
APT GROUP
According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages. The first stage is an office file that contains a macro. This macro then loads the second stage, which is either a PowerShell script or a piece of JavaScript, which is this family entry.
APT GROUP
Malware family identifying js.unidentified_001. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Expects a parameter to run: needs to be started as 'maintools.js EzZETcSXyKAdF_e5I2i1'.
APT GROUP
Malware family identifying js.turla_ff_ext. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying js.tsundere. Origin and technical characteristics tracked via Malpedia.
Also known as: DinDoor
Swid
Technical ID: js.swid
APT GROUP
Malware family identifying js.swid. Origin and technical characteristics tracked via Malpedia.
StarFish
Technical ID: js.starfish
APT GROUP
According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.
Starfighter
Technical ID: js.starfighter
APT GROUP
According to the author, this is a JavaScript based Empire launcher that runs with its own embedded powershell host to not be dependent on local powershell availability.
APT GROUP
SQLRat campaigns typically involve a lure document that includes an image overlayed by a VB Form trigger. Once a user has double-clicked the embedded image, the form executes a VB setup script. The script writes files to the path %appdata%\Roaming\Microsoft\Templates\, then creates two task entries triggered to run daily. The scripts are responsible for deobfuscating and executing the main JavaScript file mspromo.dot. The file uses a character insertion obfuscation technique, making it appear to contain Chinese characters. After deobfuscating the file, the main JavaScript is easily recognizable. It contains a number of functions designed to drop files and execute scripts on a host system. The SQLRat script is designed to make a direct SQL connection to a Microsoft database controlled by the attackers and execute the contents of various tables.
APT GROUP
According to ESET, SpyPress is a set of Javascript payloads targeting different webmail frameworks (HORDE, MDAEMON, ROUNDCUBE, ZIMBRA). The observed payloads have common characteristics. All are similarly obfuscated, with variable and function names replaced with random-looking strings. Furthermore, strings used by the code, such as webmail and C&C server URLs, are also obfuscated and contained in an encrypted list. Each of those strings is only decrypted when it is used. Note that the variable and function names are randomized for each sample, so the final SpyPress payloads will have different hashes. Another common characteristic is that there are no persistence or update mechanisms. The payload is fully contained in the email and only executed when the email message is viewed from a vulnerable webmail instance.
Finally, all payloads communicate with their hardcoded C&C servers via HTTP POST requests. There is a small number of C&C servers that are shared by all payloads (there is no separation by victim or payload type).
Smokest Stealer
Technical ID: js.smokest
APT GROUP
Malware family identifying js.smokest. Origin and technical characteristics tracked via Malpedia.
SmartApeSG
Technical ID: js.smartapesg
APT GROUP
According to Proofpoint, this is a cluster of fake update campaigns delivering payloads like NetSupportManager RAT and Lumma Stealer.
Also known as: HANEYMANEY • ZPHP