Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
Shai-Hulud
Technical ID: js.shai_hulud
APT GROUP
A Javascript-based worm propagating through GitHub repositories and exfiltrating tokens and other credentials.
APT GROUP
Malware family identifying js.scanbox. Origin and technical characteristics tracked via Malpedia.
s1ngularity Stealer
Technical ID: js.s1ngularity
APT GROUP
According to StepSecurity, this is a stealer deployed through a compromised Nx package, targeting system environment properties, cryptocurrency wallets, and development credentials. Data is exfiltrated to Github using stolen tokens.
RunForestRun
Technical ID: js.runforestrun
APT GROUP
Active around 2012-2013, this family deployed small JavaScript snippets on infected websites to load exploit kit scripts from DGA-generated domains.
It commonly used the Blackhole exploit kit and the Sutra Traffic Distribution System (TDS), which caused it to sometimes be misnamed as Blackhole or Sutra.
Also known as: Blackhole • Sutra
APT GROUP
QUICKCAFE is an encrypted JavaScript downloader for QUICKRIDE.POWER that exploits the ActiveX M2Soft vulnerabilities. QUICKCAFE is obfuscated using JavaScript Obfuscator.
QNodeService
Technical ID: js.qnodeservice
APT GROUP
According to Trend Micro, this is a Node.js based malware, that can download/upload/execute files, steal credentials from Chrome/Firefox browsers, and perform file management, among other things. It targets Windows and has components for both 32 and 64bit.
Powmet
Technical ID: js.powmet
APT GROUP
Malware family identifying js.powmet. Origin and technical characteristics tracked via Malpedia.
PindOS
Technical ID: js.pindos
APT GROUP
Malware family identifying js.pindos. Origin and technical characteristics tracked via Malpedia.
PeckBirdy
Technical ID: js.peckbirdy
APT GROUP
According to Trend Micro, PeckBirdy is a script-based framework which, while possessing advanced capabilities, is implemented using JScript, an old script language. This is to ensure that the framework could be launched across different execution environments via LOLBins (Living off the land binaries). This flexibility allowed to use PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.
PeaceNotWar
Technical ID: js.peacenotwar
APT GROUP
PeaceNotWar was integrated into the nodejs module node-ipc as a piece of malware/protestware with wiper characteristics. It targets machines with a public IP address located in Russia and Belarus (using geolocation) and overwrites files recursively using a heart emoji.
Parrot TDS
Technical ID: js.parrot_tds
APT GROUP
This malicious code written in JavaScript is used as Traffic Direction System (TDS). This TDS showes similarities to the Prometheus TDS. According to DECODED Avast.io this TDS has been active since October 2021.
ParaSiteSnatcher
Technical ID: js.parasitesnatcher
APT GROUP
Malware family identifying js.parasitesnatcher. Origin and technical characteristics tracked via Malpedia.
APT GROUP
Malware family identifying js.otter_cookie. Origin and technical characteristics tracked via Malpedia.
OtterCandy
Technical ID: js.ottercandy
APT GROUP
OtterCandy is a modular JavaScript backdoor that combines features from earlier malware families like OtterCookie and RATatouille (aka INVISIBLEFERRET.JAVASCRIPT). It steals sensitive information including browser credentials and cryptocurrency wallet data, and can execute commands like uploading files, changing directories, and self-termination. The malware communicates via socket.io protocol over port 5000 to receive and execute commands from attackers.
Also known as: HardHatRAT • UNSEENMINK
ostap
Technical ID: js.ostap
APT GROUP
Ostap is a commodity JScript downloader first seen in campaigns in 2016. It has been observed being delivered in ACE archives and VBA macro-enabled Microsoft Office documents. Recent versions of Ostap query WMI to check for a blacklist of running processes:
AgentSimulator.exe
anti-virus.EXE
BehaviorDumper
BennyDB.exe
ctfmon.exe
fakepos_bin
FrzState2k
gemu-ga.exe (Possible misspelling of Qemu hypervisor’s guest agent, qemu-ga.exe)
ImmunityDebugger.exe
KMS Server Service.exe
ProcessHacker
procexp
Proxifier.exe
python
tcpdump
VBoxService
VBoxTray.exe
VmRemoteGuest
vmtoolsd
VMware2B.exe
VzService.exe
winace
Wireshark
If a blacklisted process is found, the malware terminates.
Ostap has been observed delivering other malware families, including Nymaim, Backswap and TrickBot.
OFFODE
Technical ID: js.offode
APT GROUP
According to the author, this is a project that will give understanding of bypassing Multi Factor Authentication (MFA) of an outlook account. It is build in node.js and uses playwright for the automation in the backend.
APT GROUP
Malware family identifying js.node_rat. Origin and technical characteristics tracked via Malpedia.
NodeCordRAT
Technical ID: js.nodecordrat
APT GROUPespionageadvanced
NodeCordRAT is a cross-platform Remote Access Trojan and information stealer written in Node.js that targets Windows, macOS, and Linux systems through malicious NPM packages in software supply chain attacks. The malware executes automatically when developers unknowingly install compromised dependencies, providing attackers with comprehensive system access and data
exfiltration capabilities. Its core functions include remote code execution through shell access, credential theft from Google Chrome and MetaMask wallets, extraction of developer secrets from .env files, live screen capture, complete file system navigation and exfiltration, and system information gathering for victim profiling. NodeCordRAT achieves persistence through process managers like
pm2 that maintain the malware as a background service, while its command-and-control communications leverage the Discord API over HTTPS with hardcoded bot tokens, allowing malicious traffic to masquerade as legitimate web activity and enabling attackers to receive stolen data and issue commands through private Discord channels.
APT GROUP
NanHaiShu is a remote access tool and JScript backdoor used by Leviathan. NanHaiShu has been used to target government and private-sector organizations that have relations to the South China Sea dispute.
APT GROUP
More_eggs is a JavaScript backdoor used by the Cobalt group. It attempts to connect to its C&C server and retrieve tasks to carry out, some of which are:
- d&exec = download and execute PE file
- gtfo = delete files/startup entries and terminate
- more_eggs = download additional/new scripts
- more_onion = run new script and terminate current script
- more_power = run command shell commands
Also known as: SpicyOmelette • SKID
MintsLoader
Technical ID: js.mints_loader
APT GROUP
According to Orange Cyberdefense, MintsLoader is a little-known, multi-stage malware loader that has been used since at least February 2023. It has been observed in widespread distribution campaigns between July and October 2024. The name comes from a very characteristic use of an URL parameter “1.php?s=mintsXX" (with XX being numbers).
MintsLoader primarily delivers malicious RAT or infostealing payloads such as AsyncRAT and Vidar through phishing emails, targeting organizations in Europe (Spain, Italy, Poland, etc.). Written in JavaScript and PowerShell, MintsLoader operates through a multi-step infection process involving several URLs and domains, most of which use a domain generation algorithm (DGA) with .top TLD.
APT GROUP
MiniJS is a very simple JavaScript-based first-stage backdoor.
The backdoor is probably distributed via spearphishing email.
Due to infrastructure overlap, the malware can be attributed to the actor Turla. Comparable JavaScript-based backdoor families of the actor are KopiLuwak and IcedCoffee.
APT GROUP
MegaMedusa is NodeJS DDoS Machine Layer-7 provided by RipperSec Team.
APT GROUP
Magecart is a malware framework intended to steal credit card information from compromised eCommerce websites. Used in criminal activities, it's a sophisticated implant built on top of relays, command and controls and anonymizers used to steal eCommerce customers' credit card information. The first stage is typically implemented in Javascript included into a compromised checkout page. It copies data from "input fields" and send them to a relay which collects credit cards coming from a subset of compromised eCommerces and forwards them to Command and Control servers.
LNKR
Technical ID: js.lnkr
APT GROUP
The LNKR trojan is a malicious browser extension that will monitor the websites visited by the user, looking for pages with administrative privileges such as blog sites or web-based virtual learning environments. When the administrative user posts to the page, the infected extension will execute stored cross-site scripting attack and injects malicious JavaScript into the legitimate HTML of the page. This is used to redirect the second-party visitors of the site to both benign and malicious domains.
APT GROUP
Malware family identifying js.kopiluwak. Origin and technical characteristics tracked via Malpedia.
KongTuke
Technical ID: js.kongtuke
APT GROUPespionageadvanced
Kongtuke is a sophisticated TDS system that was initially discovered around May 2024. Making use of compromised CMS Websites, Kongtuke redirects website visitors through a multi-stage infection process ultimately leading to device infection. Initially using fake Update lures, it started to use FakeCaptcha lures at the beginning of 2025. It is likely an initial access service, selling infections to both Ransomware affiliates and other IA vendors like SocGholish.
Also known as: TAG-124 • js.LandUpdate808
jspRAT
Technical ID: js.jsprat
APT GROUP
Malware family identifying js.jsprat. Origin and technical characteristics tracked via Malpedia.
Jetriz
Technical ID: js.jetriz
APT GROUP
Malware family identifying js.jetriz. Origin and technical characteristics tracked via Malpedia.
Jeniva
Technical ID: js.jeniva
APT GROUP
Malware family identifying js.jeniva. Origin and technical characteristics tracked via Malpedia.
JADESNOW
Technical ID: js.jadesnow
APT GROUP
JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342. JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted. The final payload in the JADESNOW infection chain is usually a more persistent backdoor like INVISIBLEFERRET.JAVASCRIPT.
Also known as: ChainedDown
inter
Technical ID: js.inter
APT GROUP
Malware family identifying js.inter. Origin and technical characteristics tracked via Malpedia.
IClickFix
Technical ID: js.iclickfix
APT GROUPespionageadvanced
IClickFix is a malicious JavaScript framework deployed on compromised WordPress sites to deliver further malware using the ClickFix social engineering tactic and fake Cloudflare Turnstile CAPTCHA challenge.
APT GROUP
GRIFFON is a lightweight JavaScript validator-style implant without any persistence mechanism. The malware is designed for receiving modules to be executed in-memory and sending the results to C2s. The first module downloaded by the GRIFFON malware to the victim’s computer is an information-gathering JavaScript, which allows the cybercriminals to understand the context of the infected workstation.
Also known as: Harpy
grelos
Technical ID: js.grelos
APT GROUP
grelos is a skimmer used for magecart-style attacks.
APT GROUP
According to PCrisk, they discovered GootLoader malware while examining legitimate but compromised websites (mainly websites managed using WordPress). It was found that GootLoader is used to infect computers with additional malware. Cybercriminals using GootLoader seek to trick users into unknowingly downloading and executing the malware by disguising it as a document or other file.
Also known as: SLOWPOUR
GlassWorm
Technical ID: js.glassworm
APT GROUP
According to Koi Security, this malware harvests NPM, GitHub, and Git credentials for supply chain propagation. It targets 49 different cryptocurrency wallet extensions to drain funds. It uses stolen credentials to compromise additional packages and extensions, spreading the worm further. Furthermore, it deploys SOCKS proxy servers, turning developer machines into criminal infrastructure and installs hidden VNC servers for complete remote access.
APT GROUPfinancialhigh
FAKEUPDATES is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. It writes the payloads to disk prior to launching them. FAKEUPDATES has led to further compromise via additional malware families that include CHTHONIC, DRIDEX, EMPIRE, KOADIC, DOPPELPAYMER, and AZORULT.
FAKEUPDATES has been heavily used by UNC1543, a financially motivated group.
Also known as: FakeUpdate • GhoLoader • SocGholish
FakeUpdateRU
Technical ID: js.fakeupdateru
APT GROUP
FakeUpdateRU is a malicious JavaScript code injected into compromised websites to deliver further malware using the drive-by download technique. The malicious code displays a copy of the Google Chrome web browser download page and redirects the user to the download of a next-stage payload.
EVILNUM
Technical ID: js.evilnum
APT GROUP
According proofpoint, EvilNum is a backdoor that can be used for data theft or to load additional payloads. The malware includes multiple interesting components to evade detection and modify infection paths based on identified antivirus software.