Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,746 entities
BUSHWALK
Technical ID: elf.bushwalk
MALWARE
According to Mandiant, this is a webshell, written in Perl.
brute_ratel
Technical ID: elf.brute_ratel
MALWARE
Malware family identifying elf.brute_ratel. Origin and technical characteristics tracked via Malpedia.
MALWARE
According to Google, BRICKSTORM is used to consistently target appliances, among them primarily VMware vCenter and ESXi hosts.
BQTlock
Technical ID: elf.bqtlock
MALWARE
Malware family identifying elf.bqtlock. Origin and technical characteristics tracked via Malpedia.
MALWARE
BPFDoor is a passive backdoor used by a China-based threat actor. This backdoor supports multiple protocols for communicating with a C2 including TCP, UDP, and ICMP allowing the threat actor a variety of mechanisms to interact with the implant.
Also known as: JustForFun
BotenaGo
Technical ID: elf.botenago
MALWARE
According to Alien Labs, this malware targets embedded devices including routers with more than 30 exploits.
SourceCode: https://github.com/Egida/kek/blob/19991ef983f838287aa9362b78b4ed8da0929184/loader_multi.go (2021-10-16)
Break out the Box
Technical ID: elf.botb
MALWARE
This is a pentesting tool and according to the author, "BOtB is a container analysis and exploitation tool designed to be used by pentesters and engineers while also being CI/CD friendly with common CI/CD technologies.".
It has been observed being used by TeamTNT in their activities for spreading crypto-mining malware.
Also known as: BOtB
Bootkitty
Technical ID: elf.bootkitty
MALWARE
Malware family identifying elf.bootkitty. Origin and technical characteristics tracked via Malpedia.
BOLDMOVE
Technical ID: elf.boldmove
MALWARE
According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of Fortinet's SSL-VPN (CVE-2022-42475). There is also a Windows variant.
BlackSuit
Technical ID: elf.blacksuit
MALWAREfinancialhigh
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
Blackrota
Technical ID: elf.blackrota
MALWARE
Malware family identifying elf.blackrota. Origin and technical characteristics tracked via Malpedia.
BlackMatter
Technical ID: elf.blackmatter
MALWARE
Malware family identifying elf.blackmatter. Origin and technical characteristics tracked via Malpedia.
MALWAREfinancialhigh
ALPHV, also known as BlackCat or Noberus, is a ransomware family that is deployed as part of Ransomware as a Service (RaaS) operations. ALPHV is written in the Rust programming language and supports execution on Windows, Linux-based operating systems (Debian, Ubuntu, ReadyNAS, Synology), and VMWare ESXi. ALPHV is marketed as ALPHV on cybercrime forums, but is commonly called BlackCat by security researchers due to an icon of a black cat appearing on its leak site. ALPHV has been observed being deployed in ransomware attacks since November 18, 2021.
ALPHV can be configured to encrypt files using either the AES or ChaCha20 algorithms. In order to maximize the amount of ransomed data, ALPHV can delete volume shadow copies, stop processes and services, and stop virtual machines on ESXi servers. ALPHV can self-propagate by using PsExec to remote execute itself on other hosts on the local network.
Also known as: ALPHV • Noberus
Black Basta
Technical ID: elf.blackbasta
MALWAREfinancialhigh
ESXi encrypting ransomware, using a combination of the stream cipher ChaCha20 and RSA.
BioSet
Technical ID: elf.bioset
MALWARE
Malware family identifying elf.bioset. Origin and technical characteristics tracked via Malpedia.
BigViktor
Technical ID: elf.bigviktor
MALWARE
A DDoS bot abusing CVE-2020-8515 to target DrayTek Vigor routers. It uses a wordlist-based DGA to generate its C&C domains.
MALWARE
Linux version of the bifrose malware that originally targeted Windows platform only. The backdoor has the ability to perform file management, start or end a process, or start a remote shell. The connection is encrypted using a modified RC4 algorithm.
Also known as: elf.bifrose
MALWARE
According to Security Joes, this malware is an x64 ELF executable, lacking obfuscation or protective measures. It allows attackers to specify target folders and can potentially destroy an entire operating system if run with root permissions. During execution, it produces extensive output, which can be mitigated using the "nohup" command. It also leverages multiple threads and a queue to corrupt files concurrently, enhancing its speed and reach. Its actions include overwriting files, renaming them with a random string containing "BiBi," and excluding certain file types from corruption.
BianLian
Technical ID: elf.bianlian
MALWARE
Malware family identifying elf.bianlian. Origin and technical characteristics tracked via Malpedia.
BCMPUPnP_Hunter
Technical ID: elf.bcmpupnp_hunter
MALWARE
Malware family identifying elf.bcmpupnp_hunter. Origin and technical characteristics tracked via Malpedia.
Bashlite
Technical ID: elf.bashlite
MALWARE
Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.
Also known as: gayfgt • Gafgyt • qbot • torlus • lizkebab
Ballista
Technical ID: elf.ballista
MALWARE
Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers. It spreads through automatic exploitation of CVE-2023-1389. Its capabilities include remote code execution and DDoS attacks.
MALWARE
BADCALL is a Trojan malware variant used by the group Lazarus Group.
Irc16
Technical ID: elf.backdoor_irc16
MALWARE
Malware family identifying elf.backdoor_irc16. Origin and technical characteristics tracked via Malpedia.
Backdoorit
Technical ID: elf.backdoorit
MALWARE
According to Avast Decoded, Backdoorit is a multiplatform RAT written in Go programming language and supporting both Windows and Linux/Unix operating systems. In many places in the code it is also referred to as backd00rit.
Also known as: backd00rit
Babuk
Technical ID: elf.babuk
MALWAREfinancialhigh
ESX and NAS modules for Babuk ransomware.
B1txor20
Technical ID: elf.b1txor20
MALWARE
B1txor20 is a malware that was discovered by 360 Netlab along others exploiting Log4J. the name is derived from using the file name "b1t", the XOR encrpytion algorithm, and the RC4 algorithm key length of 20 bytes. According to 360 Netlab this Backdoor for Linux platform uses DNS Tunnel to build a C2 communication channel. They also had the assumption that the malware is still in development, because of some bugs and not fully implemented features.
azazel
Technical ID: elf.azazel
MALWARE
Azazel is a Linux user-mode rootkit based off of a technique from the Jynx rootkit (LD_PRELOAD technique). Azazel is purportedly more robust than Jynx and has many more anti-analysis features
AVrecon
Technical ID: elf.avrecon
MALWARE
AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices. The malware is distributed via exploitation of unpatched vulnerabilities or common misconfiguration of the targeted devices. Once deployed, AVreckon will collect some information about the infected device, open a session to pre-configured C&C server, and spawn a remote shell for command execution. It might also download additional arbitrary files and run them. The malware has recently been used in campaigns aimed at ad-fraud activities, password spraying and data exfiltration.
Avoslocker
Technical ID: elf.avoslocker
MALWARE
Malware family identifying elf.avoslocker. Origin and technical characteristics tracked via Malpedia.
Auto-Color
Technical ID: elf.auto_color
MALWARE
According to Unit 42, Auto-Color was discovered in November 2024 named based on the file name of the initial payload. It hides its C2 communication similarly to Symbiote, including the use of proprietary encryption algorithms.
MALWARE
Malware family identifying elf.angryrebel. Origin and technical characteristics tracked via Malpedia.
Also known as: Ghost RAT
AnchorDNS
Technical ID: elf.anchor_dns
MALWARE
Backdoor deployed by the TrickBot actors. It uses DNS as the command and control channel as well as for exfiltration of data.
MALWAREfinancialhigh
Ransomware
Also known as: REDBIKE
Aisuru
Technical ID: elf.aisuru
MALWARE
Honeypot-aware variant of Mirai.
AirDropBot
Technical ID: elf.airdrop
MALWARE
AirDropBot is used to create a DDoS botnet. It spreads as a worm, currently targeting Linksys routers. Backdoor and other bot functionality is present in this family. Development seems to be ongoing.
Also known as: CloudBot
AIRASHI
Technical ID: elf.airashi
MALWARE
According to Xlab, this is a DDoS bot.
AgeLocker
Technical ID: elf.age_locker
MALWARE
Malware family identifying elf.age_locker. Origin and technical characteristics tracked via Malpedia.
AcidRain
Technical ID: elf.acidrain
MALWARE
A MIPS ELF binary with wiper functionality used against Viasat KA-SAT modems.
AcidPour
Technical ID: elf.acidpour
MALWARE
Malware family identifying elf.acidpour. Origin and technical characteristics tracked via Malpedia.