Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,746 entities
EtherRAT
Technical ID: js.ether_rat
APT GROUP
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).
Updated: 2025-12-17
View profile →
Enrume
Technical ID: js.enrume
APT GROUP
Malware family identifying js.enrume. Origin and technical characteristics tracked via Malpedia.
Also known as: Ransom32
Updated: 2020-03-06
View profile →
doenerium
Technical ID: js.doenerium
APT GROUP
Open sourced javascript info stealer, with the capabilities of stealing crypto wallets, password, cookies and modify discord clients https://github.com/doener2323/doenerium
Updated: 2022-09-30
View profile →
DNSRat
Technical ID: js.dnsrat
Anunak
APT GROUP
Malware family identifying js.dnsrat. Origin and technical characteristics tracked via Malpedia.
Also known as: DNSbot
Updated: 2020-02-27
View profile →
DarkWatchman
Technical ID: js.darkwatchman
APT GROUP
Prevailion found this RAT written in JavaScript, which dynamically compiles an accompanying keylogger written in C# and uses a DGA for C&C.
Updated: 2025-11-28
View profile →
CukieGrab
Technical ID: js.cukiegrab_crx
APT GROUP
Malware family identifying js.cukiegrab_crx. Origin and technical characteristics tracked via Malpedia.
Also known as: Roblox Trade Assist
Updated: 2017-09-14
View profile →
CryptoNight
Technical ID: js.cryptonight
APT GROUP
WebAssembly-based crpyto miner.
Updated: 2018-04-24
View profile →
ContagiousDrop
Technical ID: js.contagious_drop
APT GROUP
According to SentinelOne, these applications, typically implemented in app.js files, are deployed on ClickFix malware distribution servers. These applications run servers that listen on configured ports to handle incoming HTTP GET and POST requests, executing different functions based on the specific request path. The ContagiousDrop applications deliver malware disguised as software updates or essential utilities. They distribute a tailored payload based on the victim’s operating system (Windows, macOS, or Linux), system architecture, and method of interaction with the server, such as the use of the curl command. In addition to delivering malware, the ContagiousDrop applications feature an integrated email notification system. These notifications, sent from a configured email address, provide the Contagious Interview threat actors with insights into victim engagement and interaction patterns and are delivered to their configured recipient addresses.
Updated: 2025-09-16
View profile →
ClearFake
Technical ID: js.clearfake
APT GROUP
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download technique. The malware leverages social engineering to trick the user into running a fake web browser update.
Updated: 2025-01-26
View profile →
ChromeBack
Technical ID: js.chromeback
APT GROUP
GoSecure describes ChromeBack as a browser hijacker, redirecting traffic and serving advertisements to users.
Updated: 2022-07-13
View profile →
CACTUSTORCH
Technical ID: js.cactustorch
APT32Leviathan
APT GROUP
According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher. It will spawn a 32 bit version of the binary specified and inject shellcode into it.
Updated: 2022-01-25
View profile →
BELLHOP
Technical ID: js.bellhop
Anunak
APT GROUP
• BELLHOP is a JavaScript backdoor interpreted using the native Windows Scripting Host(WSH). After performing some basic host information gathering, the BELLHOP dropper downloads a base64-encoded blob of JavaScript to disk and sets up persistence in three ways: • Creating a Run key in the Registry • Creating a RunOnce key in the Registry • Creating a persistent named scheduled task • BELLHOP communicates using HTTP and HTTPS with primarily benign sites such as Google Docs and PasteBin.
Updated: 2022-05-05
View profile →
BeaverTail
Technical ID: js.beavertail
WageMole
APT GROUP
BeaverTail is a JavaScript malware primarily distributed through NPM packages. It is designed for information theft and to load further stages of malware, specifically a multi-stage Python-based backdoor known as InvisibleFerret. BeaverTail targets cryptocurrency wallets and credit card information stored in the victim's web browsers. Its code is heavily obfuscated to evade detection. Threat actors can either upload malicious NPM packages containing BeaverTail to GitHub or inject BeaverTail code into legitimate NPM projects. Researchers have identified additional Windows and macOS variants, indicating that the BeaverTail malware family is likely still under development.
Updated: 2026-01-21
View profile →
Bateleur
Technical ID: js.bateleur
Anunak
APT GROUP
Malware family identifying js.bateleur. Origin and technical characteristics tracked via Malpedia.
Updated: 2022-05-05
View profile →
AIRBREAK
Technical ID: js.airbreak
Leviathan
APT GROUP
AIRBREAK, a JavaScript-based backdoor which retrieves commands from hidden strings in compromised webpages.
Also known as: Orz
Updated: 2020-05-23
View profile →
VersaMem
Technical ID: jar.versamem
Volt Typhoon
APT GROUP
According to Lumen, a web shell used by Volt Typhoon.
Updated: 2024-09-13
View profile →
Verblecon
Technical ID: jar.verblecon
APT GROUP
This malware seems to be used for attacks installing cryptocurrency miners on infected machines. Other indicators leads to the assumption that attackers may also use this malware for other purposes (e.g. stealing access tokens for Discord chat app). Symantec describes this malware as complex and powerful: The malware is loaded as a server-side polymorphic JAR file.
Updated: 2024-05-17
View profile →
SupremeBot
Technical ID: jar.supremebot
APT GROUP
Malware family identifying jar.supremebot. Origin and technical characteristics tracked via Malpedia.
Also known as: BlazeBot
Updated: 2019-03-07
View profile →
STRRAT
Technical ID: jar.strrat
APT GROUPfinancialhigh
STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins. The RAT has a focus on stealing credentials of browsers and email clients, and passwords via keylogging. It supports the following browsers and email clients: Firefox, Internet Explorer, Chrome, Foxmail, Outlook, Thunderbird. Since Version 1.2 and above, STRRAT was infamous for its ransomware-like behavior of appending the file name extension .crimson to files. Version 1.5 is notably more obfuscated and modular than previous versions, but the backdoor functions mostly remain the same: collect browser passwords, run remote commands and PowerShell, log keystrokes, among others. Version 1.5 of STRRAT Malware includes a proper encryption routine, though currently pretty simple to revert.
Updated: 2025-07-17
View profile →
Sorillus RAT
Technical ID: jar.sorillus
APT GROUPespionageadvanced
Sorillus is a Java-based multifunctional remote access trojan (RAT) that targets Linux, macOS, and Windows operating systems. First created in 2019, the tool gained significant attention in 2022 when various obfuscated client versions began appearing on VirusTotal starting January 18, 2022. The RAT's features were detailed on its now-defunct website (hxxps://sorillus[.]com), where it was marketed for lifetime access at 59.99€, with a discounted price of 19.99€ at the time. Payments were conveniently accepted via various cryptocurrencies. The creator and distributor of Sorillus, a YouTube user known as "Tapt," claimed the tool could collect sensitive information from infected systems, including: HardwareID Username Country Language Webcam footage Headless status Operating system details Client version However, Sorillus was shut down in 2025 following the FBI's Operation "Talent," which targeted alot of the Cracking infrastucture which included Sellix, the payment portal used by Sorillus for transactions. This operation disrupted the financial infrastructure supporting the RAT, leading to its cessation of operations 5 days later.
Updated: 2025-06-23
View profile →
SLAYSTYLE
Technical ID: jar.slaystyle
APT GROUP
According to Mandiant, SLAYSTYLE is a webshell written in Java.
Ratty
Technical ID: jar.ratty
APT GROUP
Ratty is an open source Java RAT, made available on GitHub and promoted heavily on HackForums. At some point in 2016 / 2017 the original author deleted his repository, but several clones exist.
Updated: 2025-05-20
View profile →
QRat
Technical ID: jar.qrat
APT GROUP
QRat, also known as Quaverse RAT, was introduced in May 2015 as undetectable (because of multiple layers of obfuscation). It offers the usual functionality (password dumper, file browser, keylogger, screen shots/streaming, ...), and it comes as a SaaS. For additional historical context, please see jar.qarallax.
Also known as: Quaverse RAT
Updated: 2021-01-11
View profile →
Qealler
Technical ID: jar.qealler
APT GROUP
Malware family identifying jar.qealler. Origin and technical characteristics tracked via Malpedia.
Also known as: Pyrogenic Infostealer
Updated: 2020-05-18
View profile →
Qarallax RAT
Technical ID: jar.qarallax_rat
APT GROUP
According to SpiderLabs, in May 2015 the "company" Quaverse offered a RAT known as Quaverse RAT or QRAT. At around May 2016, this QRAT evolved into another RAT which became known as Qarallax RAT, because its C2 is at qarallax.com. Quaverse also offers a service to encrypt Java payloads (Qrypter), and thus qrypted payloads are sometimes confused with Quaverse RATs (QRAT / Qarallax RAT).
Updated: 2018-02-08
View profile →
Pronsis Loader
Technical ID: jar.pronsis_loader
APT GROUP
According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.
Updated: 2025-02-03
View profile →
Octopus Scanner
Technical ID: jar.octopus_scanner
APT GROUP
Malware family identifying jar.octopus_scanner. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-06-08
View profile →
Mineping
Technical ID: jar.mineping
APT GROUP
DDoS for Minecraft servers.
Updated: 2024-10-21
View profile →
jSpy
Technical ID: jar.jspy
APT GROUP
Malware family identifying jar.jspy. Origin and technical characteristics tracked via Malpedia.
Updated: 2018-05-14
View profile →
jRAT
Technical ID: jar.jrat
APT GROUP
jRAT, also known as Jacksbot, is a RAT with history, written in Java. It has support for macOS, Linux, Windows and various BSD. It also has functionality to participate in DDoS-attacks as well as to perform click fraud. Note that the Adwind family often is mistakenly labeled as jRAT, because of of a red hering reference to jrat.io.
Also known as: Jacksbot
Updated: 2020-06-08
View profile →
JavaLocker
Technical ID: jar.javalocker
APT GROUP
Malware family identifying jar.javalocker. Origin and technical characteristics tracked via Malpedia.
Also known as: JavaEncrypt Ransomware
Updated: 2020-03-27
View profile →
JavaDispCash
Technical ID: jar.javadispcash
APT GROUP
JavaDispCash is a piece of malware designed for ATMs. The compromise happens by using the JVM attach-API on the ATM's local application and the goal is to remotely control its operation. The malware's primary feature is the ability to dispense cash. The malware also spawns a local port (65413) listening for commands from the attacker which needs to be located in the same internal network.
Updated: 2020-01-06
View profile →
IceRat
Technical ID: jar.icerat
APT GROUP
According to Karsten Hahn, this malware is actually written in JPHP, but can be treated similar to .class files produced by Java. IceRat has been observed to carry out information stealing and mining.
Updated: 2020-12-03
View profile →
FEimea RAT
Technical ID: jar.feimea_rat
APT GROUP
Malware family identifying jar.feimea_rat. Origin and technical characteristics tracked via Malpedia.
Updated: 2019-03-07
View profile →
EpicSplit RAT
Technical ID: jar.epicsplit
APT GROUP
EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files, manipulating the file system, establishing persistence, taking screenshots, and manipulating keyboard and mouse events. EpicSplit is typically obfuscated with the commercial Allatori Obfuscator software. One unique feature of the malware is that TCP messages sent by EpicSplit RAT to its C2 are terminated with the string "_packet_" as a packet delimiter.
Updated: 2021-06-22
View profile →
DynamicRAT
Technical ID: jar.dynamicrat
APT GROUP
DynamicRAT is a malware that is spread via email attachments and compromises the security of computer systems. Once running on a device, DynamicRAT establishes a persistent presence and gives attackers complete remote control. Its features include sensitive data exfiltration, hardware control, remote action, and the ability to perform DDoS attacks. In addition, DynamicRAT uses evasion and persistence techniques to evade detection and analysis by security solutions.
Also known as: DYNARAT
Updated: 2023-06-23
View profile →
CrossRAT
Technical ID: jar.crossrat
Dark Caracal
APT GROUP
Malware family identifying jar.crossrat. Origin and technical characteristics tracked via Malpedia.
Also known as: Trupto
Updated: 2020-06-08
View profile →
Blue Banana RAT
Technical ID: jar.bluebanana
APT GROUP
Malware family identifying jar.bluebanana. Origin and technical characteristics tracked via Malpedia.
Updated: 2020-10-13
View profile →
Banload
Technical ID: jar.banload
APT GROUP
F-Secure observed Banload variants silently downloading malicious files from a remote server, then installing and executing the files.
Updated: 2022-06-09
View profile →
Akemi
Technical ID: jar.akemi
APT GROUP
According to VMRay, this malware family uses in interesting obfuscation technique: a trailing slash in its archive to confuse analysis tools. It abuses #GitHub as a #C2 and exfiltrates stolen data, such as browser cookies, via Discord webhooks. The GitHub repositories are quite active and exist since mid to late 2024. The malware also monitors keyboard and mouse input, takes screenshots.
Updated: 2025-05-22
View profile →
← PreviousPage 197 / 269Next →