Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
EtherRAT
Technical ID: js.ether_rat
APT GROUP
According to sysdig, EtherRAT uses Ethereum smart contracts for C2 URL resolution. It establishes persistence through five independent mechanisms, ensuring survival across reboots and system maintenance (systemd, xdg, cron, bashrc, profile).
Enrume
Technical ID: js.enrume
APT GROUP
Malware family identifying js.enrume. Origin and technical characteristics tracked via Malpedia.
Also known as: Ransom32
doenerium
Technical ID: js.doenerium
APT GROUP
Open sourced javascript info stealer, with the capabilities of stealing crypto wallets, password, cookies and modify discord clients https://github.com/doener2323/doenerium
APT GROUP
Malware family identifying js.dnsrat. Origin and technical characteristics tracked via Malpedia.
Also known as: DNSbot
DarkWatchman
Technical ID: js.darkwatchman
APT GROUP
Prevailion found this RAT written in JavaScript, which dynamically compiles an accompanying keylogger written in C# and uses a DGA for C&C.
CukieGrab
Technical ID: js.cukiegrab_crx
APT GROUP
Malware family identifying js.cukiegrab_crx. Origin and technical characteristics tracked via Malpedia.
Also known as: Roblox Trade Assist
CryptoNight
Technical ID: js.cryptonight
APT GROUP
WebAssembly-based crpyto miner.
ContagiousDrop
Technical ID: js.contagious_drop
APT GROUP
According to SentinelOne, these applications, typically implemented in app.js files, are deployed on ClickFix malware distribution servers. These applications run servers that listen on configured ports to handle incoming HTTP GET and POST requests, executing different functions based on the specific request path.
The ContagiousDrop applications deliver malware disguised as software updates or essential utilities. They distribute a tailored payload based on the victim’s operating system (Windows, macOS, or Linux), system architecture, and method of interaction with the server, such as the use of the curl command.
In addition to delivering malware, the ContagiousDrop applications feature an integrated email notification system. These notifications, sent from a configured email address, provide the Contagious Interview threat actors with insights into victim engagement and interaction patterns and are delivered to their configured recipient addresses.
ClearFake
Technical ID: js.clearfake
APT GROUP
ClearFake is a malicious JavaScript framework deployed on compromised websites to deliver further malware using the drive-by download technique. The malware leverages social engineering to trick the user into running a fake web browser update.
ChromeBack
Technical ID: js.chromeback
APT GROUP
GoSecure describes ChromeBack as a browser hijacker, redirecting traffic and serving advertisements to users.
APT GROUP
According to the GitHub repo, CACTUSTORCH is a JavaScript and VBScript shellcode launcher. It will spawn a 32 bit version of the binary specified and inject shellcode into it.
APT GROUP
• BELLHOP is a JavaScript backdoor interpreted using the native Windows Scripting Host(WSH).
After performing some basic host information gathering, the BELLHOP dropper downloads a base64-encoded blob of JavaScript to disk and sets up persistence in three ways:
• Creating a Run key in the Registry
• Creating a RunOnce key in the Registry
• Creating a persistent named scheduled task
• BELLHOP communicates using HTTP and HTTPS with primarily benign sites such as Google Docs and PasteBin.
APT GROUP
BeaverTail is a JavaScript malware primarily distributed through NPM packages. It is designed for information theft and to load further stages of malware, specifically a multi-stage Python-based backdoor known as InvisibleFerret. BeaverTail targets cryptocurrency wallets and credit card information stored in the victim's web browsers. Its code is heavily obfuscated to evade detection. Threat actors can either upload malicious NPM packages containing BeaverTail to GitHub or inject BeaverTail code into legitimate NPM projects. Researchers have identified additional Windows and macOS variants, indicating that the BeaverTail malware family is likely still under development.
APT GROUP
Malware family identifying js.bateleur. Origin and technical characteristics tracked via Malpedia.
APT GROUP
AIRBREAK, a JavaScript-based backdoor which retrieves commands from hidden strings in compromised webpages.
Also known as: Orz
APT GROUP
According to Lumen, a web shell used by Volt Typhoon.
Verblecon
Technical ID: jar.verblecon
APT GROUP
This malware seems to be used for attacks installing cryptocurrency miners on infected machines. Other indicators leads to the assumption that attackers may also use this malware for other purposes (e.g. stealing access tokens for Discord chat app). Symantec describes this malware as complex and powerful: The malware is loaded as a server-side polymorphic JAR file.
SupremeBot
Technical ID: jar.supremebot
APT GROUP
Malware family identifying jar.supremebot. Origin and technical characteristics tracked via Malpedia.
Also known as: BlazeBot
STRRAT
Technical ID: jar.strrat
APT GROUPfinancialhigh
STRRAT is a Java-based RAT, which makes extensive use of plugins to provide full remote access to an attacker, as well as credential stealing, key logging and additional plugins. The RAT has a focus on stealing credentials of browsers and email clients, and passwords via keylogging. It supports the following browsers and email clients: Firefox, Internet Explorer, Chrome, Foxmail, Outlook, Thunderbird.
Since Version 1.2 and above, STRRAT was infamous for its ransomware-like behavior of appending the file name extension .crimson to files. Version 1.5 is notably more obfuscated and modular than previous versions, but the backdoor functions mostly remain the same: collect browser passwords, run remote commands and PowerShell, log keystrokes, among others. Version 1.5 of STRRAT Malware includes a proper encryption routine, though currently pretty simple to revert.
Sorillus RAT
Technical ID: jar.sorillus
APT GROUPespionageadvanced
Sorillus is a Java-based multifunctional remote access trojan (RAT) that targets Linux, macOS, and Windows operating systems. First created in 2019, the tool gained significant attention in 2022 when various obfuscated client versions began appearing on VirusTotal starting January 18, 2022. The RAT's features were detailed on its now-defunct website (hxxps://sorillus[.]com), where it was marketed for lifetime access at 59.99€, with a discounted price of 19.99€ at the time. Payments were conveniently accepted via various cryptocurrencies.
The creator and distributor of Sorillus, a YouTube user known as "Tapt," claimed the tool could collect sensitive information from infected systems, including:
HardwareID
Username
Country
Language
Webcam footage
Headless status
Operating system details
Client version
However, Sorillus was shut down in 2025 following the FBI's Operation "Talent," which targeted alot of the Cracking infrastucture which included Sellix, the payment portal used by Sorillus for transactions. This operation disrupted the financial infrastructure supporting the RAT, leading to its cessation of operations 5 days later.
SLAYSTYLE
Technical ID: jar.slaystyle
APT GROUP
According to Mandiant, SLAYSTYLE is a webshell written in Java.
Ratty
Technical ID: jar.ratty
APT GROUP
Ratty is an open source Java RAT, made available on GitHub and promoted heavily on HackForums. At some point in 2016 / 2017 the original author deleted his repository, but several clones exist.
QRat
Technical ID: jar.qrat
APT GROUP
QRat, also known as Quaverse RAT, was introduced in May 2015 as undetectable (because of multiple layers of obfuscation). It offers the usual functionality (password dumper, file browser, keylogger, screen shots/streaming, ...), and it comes as a SaaS. For additional historical context, please see jar.qarallax.
Also known as: Quaverse RAT
Qealler
Technical ID: jar.qealler
APT GROUP
Malware family identifying jar.qealler. Origin and technical characteristics tracked via Malpedia.
Also known as: Pyrogenic Infostealer
Qarallax RAT
Technical ID: jar.qarallax_rat
APT GROUP
According to SpiderLabs, in May 2015 the "company" Quaverse offered a RAT known as Quaverse RAT or QRAT. At around May 2016, this QRAT evolved into another RAT which became known as Qarallax RAT, because its C2 is at qarallax.com. Quaverse also offers a service to encrypt Java payloads (Qrypter), and thus qrypted payloads are sometimes confused with Quaverse RATs (QRAT / Qarallax RAT).
Pronsis Loader
Technical ID: jar.pronsis_loader
APT GROUP
According to TrustWave, this is a loader leveraging JPHP, which was observed fetching Latrodectus and Lumma.
Octopus Scanner
Technical ID: jar.octopus_scanner
APT GROUP
Malware family identifying jar.octopus_scanner. Origin and technical characteristics tracked via Malpedia.
Mineping
Technical ID: jar.mineping
APT GROUP
DDoS for Minecraft servers.
jSpy
Technical ID: jar.jspy
APT GROUP
Malware family identifying jar.jspy. Origin and technical characteristics tracked via Malpedia.
jRAT
Technical ID: jar.jrat
APT GROUP
jRAT, also known as Jacksbot, is a RAT with history, written in Java. It has support for macOS, Linux, Windows and various BSD. It also has functionality to participate in DDoS-attacks as well as to perform click fraud. Note that the Adwind family often is mistakenly labeled as jRAT, because of of a red hering reference to jrat.io.
Also known as: Jacksbot
JavaLocker
Technical ID: jar.javalocker
APT GROUP
Malware family identifying jar.javalocker. Origin and technical characteristics tracked via Malpedia.
Also known as: JavaEncrypt Ransomware
JavaDispCash
Technical ID: jar.javadispcash
APT GROUP
JavaDispCash is a piece of malware designed for ATMs. The compromise happens by using the JVM attach-API on the ATM's local application and the goal is to remotely control its operation. The malware's primary feature is the ability to dispense cash. The malware also spawns a local port (65413) listening for commands from the attacker which needs to be located in the same internal network.
IceRat
Technical ID: jar.icerat
APT GROUP
According to Karsten Hahn, this malware is actually written in JPHP, but can be treated similar to .class files produced by Java. IceRat has been observed to carry out information stealing and mining.
FEimea RAT
Technical ID: jar.feimea_rat
APT GROUP
Malware family identifying jar.feimea_rat. Origin and technical characteristics tracked via Malpedia.
EpicSplit RAT
Technical ID: jar.epicsplit
APT GROUP
EpicSplit RAT is a multiplatform Java RAT that is capable of running shell commands, downloading, uploading, and executing files, manipulating the file system, establishing persistence, taking screenshots, and manipulating keyboard and mouse events. EpicSplit is typically obfuscated with the commercial Allatori Obfuscator software. One unique feature of the malware is that TCP messages sent by EpicSplit RAT to its C2 are terminated with the string "_packet_" as a packet delimiter.
DynamicRAT
Technical ID: jar.dynamicrat
APT GROUP
DynamicRAT is a malware that is spread via email attachments and compromises the security of computer systems. Once running on a device, DynamicRAT establishes a persistent presence and gives attackers complete remote control. Its features include sensitive data exfiltration, hardware control, remote action, and the ability to perform DDoS attacks. In addition, DynamicRAT uses evasion and persistence techniques to evade detection and analysis by security solutions.
Also known as: DYNARAT
APT GROUP
Malware family identifying jar.crossrat. Origin and technical characteristics tracked via Malpedia.
Also known as: Trupto
Blue Banana RAT
Technical ID: jar.bluebanana
APT GROUP
Malware family identifying jar.bluebanana. Origin and technical characteristics tracked via Malpedia.
Banload
Technical ID: jar.banload
APT GROUP
F-Secure observed Banload variants silently downloading malicious files from a remote server, then installing and executing the files.
Akemi
Technical ID: jar.akemi
APT GROUP
According to VMRay, this malware family uses in interesting obfuscation technique: a trailing slash in its archive to confuse analysis tools. It abuses #GitHub as a #C2 and exfiltrates stolen data, such as browser cookies, via Discord webhooks. The GitHub repositories are quite active and exist since mid to late 2024. The malware also monitors keyboard and mouse input, takes screenshots.