Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.rozena
APT GROUPfinancialhigh
According to Trendmicro, Royal ransomware was first observed in September 2022, and the threat actors behind it are believed to be seasoned cybercriminals who used to be part of Conti Team One.
APT GROUPespionageadvanced
RoyalDNS is a DNS based backdoor used by APT15 that persistences on a system through a service called 'Nwsapagent'.
APT GROUP
RoyalCli is a backdoor which appears to be an evolution of BS2005 and uses familiar encryption and encoding routines. The name RoyalCli was chosen by us due to a debugging path left in the binary. RoyalCli and BS2005 both communicate with the attacker's command and control (C2) through Internet Explorer (IE) by using the COM interface IWebBrowser2.
APT GROUP
Rovnix is a bootkit and consists of a driver loader (in the VBR) and the drivers (32bit, 64bit) themselves. It is part of the Carberp source code leak (https://github.com/nyx0/Rovnix). Rovnix has been used to protect Gozi ISFB, ReactorBot and Rerdom (at least).
APT GROUP
Malware family tracked by Malpedia. ID: win.rover
APT GROUPfinancialhigh
Ransomware that was discovered over the last months of 2016 and likely based on Gomasom, another ransomware family.
APT GROUP
A DLL backdoor distributed by Raspberry Robin. According to Avast Decoded, Roshtyak belongs to one of the best-protected malware strains they have ever seen.
APT GROUP
Malware family tracked by Malpedia. ID: win.roseam
Malware family tracked by Malpedia. ID: win.rorschach
APT GROUP
Malware family tracked by Malpedia. ID: win.roopy
APT GROUP
Malware family tracked by Malpedia. ID: win.roopirs
Updated: 2018-07-24
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.roningloader
Malware family tracked by Malpedia. ID: win.romeos
Updated: 2017-05-17
View profile →
APT GROUPfinancialhigh
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.
APT GROUP
Malware family tracked by Malpedia. ID: win.rombertik
APT GROUP
Malware family tracked by Malpedia. ID: win.roll_sling
APT GROUPespionageadvanced
ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system. ROLLCOAST is a Dynamic Linked Library (DLL) with no named exports. When observed by Mandiant it uniquely had only one ordinal export 0x01. This suggested the sample was designed to avoid detection and be invoked within memory, possibly through BEACON provided to affiliates. Incident responders working on similar intrusions should capture memory for analysis.
APT GROUPespionageadvanced
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. DOGCALL is capable of capturing screenshots, logging keystrokes, evading analysis with anti-virtual machine detections, and leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex.
APT GROUP
A .NET variant of ps1.roguerobin
APT GROUP
Malware family tracked by Malpedia. ID: win.rofin
Updated: 2016-04-20
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rockloader
APT GROUP
Malware family tracked by Malpedia. ID: win.rock
Updated: 2018-09-19
View profile →
APT GROUP
According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.
APT GROUP
Malware family tracked by Malpedia. ID: win.roadsweep
APT GROUP
CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices.
APT GROUP
Created from the codebase of Gozi/ISFB.
APT GROUP
Malware family tracked by Malpedia. ID: win.rising_sun
APT GROUP
RisePro is a stealer that is spread through downloaders like win.privateloader. Once executed on a system, the malware can steal credit card information, passwords, and personal data.
APT GROUP
RiseLoader is a new malware loader family first observed in October 2024. It uses a custom TCP-based binary network protocol similar to, but distinct from, that used by the PrivateLoader and RisePro malware families. RiseLoader often drops other malware families, such as Vidar, Lumma Stealer, and XMRig, as secondary payloads. It collects information about installed applications and browser extensions, likely related to cryptocurrency. Key technical characteristics of RiseLoader include: Anti-analysis Techniques: Samples are often packed with VMProtect and obfuscate strings related to malware analysis and debugging tools. Behavioural Analysis: Creates a mutex with a hardcoded prefix and randomly generated suffixes. Communicates with a C2 server over TCP using a custom protocol involving specific message types for tasks such as transferring system information, receiving payloads, and confirming execution. Downloads and executes payloads from URLs provided by the C2 server. Creates registry keys as infection markers. Network Communication: Uses a custom TCP-based protocol with message types like SEND_VICTIM_INFO, SYS_INFO, PAYLOADS, KEEPALIVE, and others. Data is XOR encoded using keys exchanged via a SET_XORKEYS message. The protocol includes a three-way handshake and mechanisms for re-establishing connections. Similarities to RisePro/PrivateLoader: Shares similar network communication protocols and message structures with RisePro and PrivateLoader suggesting a potential link between their developers, though RiseLoader's protocol appears simplified. It currently lacks RisePro/PrivateLoader's information-stealing features but may be under development.
APT GROUP
Malware family tracked by Malpedia. ID: win.ripper_atm
APT GROUP
Malware family tracked by Malpedia. ID: win.rincux
APT GROUP
Malware family tracked by Malpedia. ID: win.rikamanu
APT GROUP
Malware family tracked by Malpedia. ID: win.rifdoor
APT GROUP
Rietspoof is malware that mainly acts as a dropper and downloader, however, it also sports bot capabilities and appears to be in active development.
APT GROUP
Malware family tracked by Malpedia. ID: win.rhttpctrl
APT GROUP
According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines. At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.
APT GROUP
Malware family tracked by Malpedia. ID: win.rgdoor
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.reverse_rat