Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,719 entities
APT GROUPespionageadvanced
Unit 42 notes that they identified a new version of SolarMarker, a malware family known for its infostealing and backdoor capabilities, mainly delivered through search engine optimization (SEO) manipulation to convince users to download malicious documents.
Some of SolarMarker’s capabilities include the exfiltration of auto-fill data, saved passwords and saved credit card information from victims’ web browsers. Besides capabilities typical for infostealers, SolarMarker has additional capabilities such as file transfer and execution of commands received from a C2 server.
The malware invests significant effort into defense evasion, which consists of techniques like signed files, huge files, impersonation of legitimate software installations and obfuscated PowerShell scripts.
APT GROUP
Malware family tracked by Malpedia. ID: win.solarbot
APT GROUP
Malware family tracked by Malpedia. ID: win.solar
APT GROUP
This is a RAT that is usually loaded with one or more shellcode and/or reflective DLL injection techniques. The RAT uses RC4 or a hardcoded RSA key for traffic encryption/decryption. Its communication can either happen via a raw TCP socket or a HTTP POST request. Depending on the version, the RAT may remotely execute DLLs or shellcode.
APT GROUP
Malware family tracked by Malpedia. ID: win.socksbot
APT GROUP
Sockbot is a customized and in Go written fork of the Ligolo reverse tunneling open-source
tool. Several modification were performed by the threat actors who rewrote that code, e.g. execution checks, hardcoded values.
Ligolo: https://github.com/sysdream/ligolo
APT GROUP
Socelars is an infostealer with main focus on:
* Facebook Stealer (ads/manager)
* Cookie Stealer | AdsCreditCard {Amazon}
APT GROUP
Malware family tracked by Malpedia. ID: win.sobig
APT GROUP
According to ESET, this RAT was derived from (the open-source) Quasar RAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.snslocker
APT GROUP
Information stealer, written in Rust.
APT GROUP
Malware family tracked by Malpedia. ID: win.snojan
APT GROUP
SnipVex is a virus that infects files with .exe extension via prepending itself to the host. It is written in .NET. It has a clipbanker as payload.
APT GROUP
Malware family tracked by Malpedia. ID: win.snifula
APT GROUP
Malware family tracked by Malpedia. ID: win.sneepy
APT GROUP
A downloader trojan with some infostealer capabilities focused on the browser. Previously observed as part of RigEK campaigns.
APT GROUP
Malware observed in the SnatchCrypto campaign, attributed by Kaspersky Labs to BlueNoroff with high confidence.
APT GROUPfinancial
Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.
Infra: 🔗 hl66646wtlp2naoqnhat…🔗 snatch.press…🔗 snatchteam.cc…+8 more
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.snappybee
APT GROUP
According to X-Force, SnakeDisk is a USB worm, dropping further payloads
APT GROUP
Malware family tracked by Malpedia. ID: win.sn0wslogger
APT GROUP
Malware family tracked by Malpedia. ID: win.smominru
APT GROUP
The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body.
APT GROUP
According to Mandiant, SMOKEDHAM is dropped through a powershell script that contains the (C#) source code for this backdoor, which is stored in an encrypted variable. The dropper dynamically defines a cmdlet and .NET class for the backdoor, meaning the compiled code is only found in memory.
APT GROUPfinancialhigh
According to PCrisk, Smaug ransomware is available for download on the dark web: it is for sale as Ransomware as a Service (RaaS). Therefore, cyber criminals who purchase it can perform ransomware attacks without having to develop malware of this type. Smaug is designed to encrypt files, rename them and create a ransom message.
APT GROUP
Malware family tracked by Malpedia. ID: win.smartloader
APT GROUP
Malware family tracked by Malpedia. ID: win.smarteyes
APT GROUP
Malware family tracked by Malpedia. ID: win.smanager
APT GROUP
Malware family tracked by Malpedia. ID: win.smackdown
APT GROUP
Malware family tracked by Malpedia. ID: win.smac
APT GROUP
Malware family tracked by Malpedia. ID: win.slub
APT GROUP
According to ESET, SlowStepper is a feature-rich backdoor with a toolkit of more than 30 components, programmed in C++, Python, and Go.
APT GROUP
According to MITRE, SLOTHFULMEDIA is a remote access Trojan written in C++ that has been used by an unidentified "sophisticated cyber actor" since at least January 2017. It has been used to target government organizations, defense contractors, universities, and energy companies in Russia, India, Kazakhstan, Kyrgyzstan, Malaysia, Ukraine, and Eastern Europe.
APT GROUP
According to HarfangLab, SloppyMIO is written in C#. It retrieves its configuration steganographically from images whose URLs are obtained via a Dead Drop Resolver (DDR) backed by GitHub. From these images, it extracts a XOR key, Telegram bot token and chat ID, and module URLs from an LSB-hidden payload. The malware can fetch and cache multiple modules from remote storage, run arbitrary commands, collect and exfiltrate files and deploy further malware with persistence via scheduled tasks. SloppyMIO beacons status messages, polls for commands and sends exfiltrated files over to a specified operator leveraging the Telegram Bot API for command-and-control.
APT GROUP
Malware family tracked by Malpedia. ID: win.slnrat
APT GROUP
According to VK9 Seecurity, Sliver is a Command and Control (C2) system made for penetration testers, red teams, and advanced persistent threats. It generates implants (slivers) that can run on virtually every architecture out there, and securely manage these connections through a central server. Sliver supports multiple callback protocols including DNS, TCP, and HTTP(S) to make egress simple, even when those pesky blue teams block your domains. You can even have multiple operators (players) simultaneously commanding your sliver army.
APT GROUP
According to Proofpoint, SlipScreen is a first stage loader and has variants written in Rust and in C++. Its crypter is updated for each campaign, making static detection difficult.
APT GROUPespionageadvanced
While analysing an incident which involved a suspected keylogger, we identified a malicious library able to interact with a virtual file system, which is usually the sign of an advanced APT actor. This turned out to be a malicious loader internally named ‘Slingshot’, part of a new, and highly sophisticated attack platform that rivals Project Sauron and Regin in complexity.
While for most victims the infection vector for Slingshot remains unknown, we were able to find several cases where the attackers got access to MikroTik routers and placed a component downloaded by Winbox Loader, a management suite for MikroTik routers. In turn, this infected the administrator of the router.
We believe this cluster of activity started in at least 2012 and was still active at the time of this analysis (February 2018).
APT GROUP
According to CERT-UA, this is a malware developed using the C++ programming language. The main functional purpose is the production of screenshots.