Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
According to Cofense, Revenge RAT is a simple and freely available Remote Access Trojan that automatically gathers system information before allowing threat actors to remotely access system components such as webcams, microphones, and various other utilities.
APT GROUP
According to its author, Revenant is a 3rd party agent for Havoc written in C, and based on Talon. This implant is meant to expand on the Talon implant by implementing covert methods of execution, robust capabilities, and more customization.
APT GROUP
Malware family tracked by Malpedia. ID: win.revc2
APT GROUP
Malware family tracked by Malpedia. ID: win.retro
APT GROUPfinancialhigh
The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor. Further is a bank logo added to the specific Android app to trick users into thinking this is a legitimate app. Moreover, if the victim is not a real victim, the link to download the APK is not the malicious APK, but the real 'Signal Private Messenger' tool, hence the victim's phone doesn't get infected.
APT GROUP
Malware family tracked by Malpedia. ID: win.retadup
APT GROUP
According to Cisco Talos, Resident is a backdoor likely developed by the same author as win.warmcookie, and it was observed being delivered in intrusions they attribute to TA866.
APT GROUP
Malware family tracked by Malpedia. ID: win.reshell
APT GROUP
Malware family tracked by Malpedia. ID: win.rerdom
APT GROUP
Malware family tracked by Malpedia. ID: win.remy
APT GROUP
Malware family tracked by Malpedia. ID: win.remsec_strider
APT GROUP
Malware family tracked by Malpedia. ID: win.remotecontrolclient
APT GROUP
Malware family tracked by Malpedia. ID: win.remoteadmin
APT GROUPespionageadvanced
Remexi is a highly advanced and stealthy malware discovered in recent times. It employs sophisticated evasion techniques to infiltrate target systems and networks undetected. This malware utilizes various propagation vectors, including exploit kits, social engineering tactics, and compromised websites. Once inside a system, Remexi establishes persistence through rootkit capabilities and leverages coAmmand-and-control infrastructure to receive and execute malicious commands. It possesses keylogging and data exfiltration capabilities, enabling it to steal sensitive information such as login credentials and financial data. Additionally, Remexi can download and execute additional payloads, making it adaptable and capable of evolving its malicious activities over time.
APT GROUP
Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers. Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns. Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user. Remcos is developed by the cybersecurity company BreakingSecurity.
APT GROUP
Malware family tracked by Malpedia. ID: win.remcom
APT GROUP
Malware family tracked by Malpedia. ID: win.relic_race
APT GROUP
Malware family tracked by Malpedia. ID: win.rektloader
rekoobe
Technical ID: win.rekoobe
MALWARE
A Trojan for Winows with the same code structure and functionalities of elf.rekoobe, for Linux environment instead.
APT GROUPespionageadvanced
Regin is a sophisticated malware and hacking toolkit attributed to United States' National Security Agency (NSA) for government spying operations. It was first publicly revealed by Kaspersky Lab, Symantec, and The Intercept in November 2014. Regin malware targeted victims in a range of industries, telecom, government, and financial institutions. It was engineered to be modular and over time dozens of modules have been found and attributed to this family. Symantec observed around 100 infections in 10 different countries across a variety of organisations including private companies, government entities, and research institutes.
APT GROUP
Malware family tracked by Malpedia. ID: win.regeorg
APT GROUPespionageadvanced
ReedBed, identified as a malware proxy backdoor, is suspected to be developed by QAKBOT devs, and was deployed by the threat actor Storm-1811 in campaigns observed during late October and early November 2024. These campaigns are typically initiated with email bombing, a tactic involving mass email distribution, followed by social engineering strategies where the actor impersonates help desk personnel to gain access to victim systems. Upon execution, ReedBed ensures single-instance operation via the mutex "JhishdiI2Uhsvoc94keiojn7ns19m0do" and hooks critical system APIs (NtCreateUserProcess, RtlExitUserProcess) for defense evasion, process interference, and anti-termination. It reads its Command and Control (C2) configuration, typically from the "Software\TitanPlus" registry key, establishes a persistent SSL/TLS encrypted connection, and transmits an initial system information beacon. Subsequently, ReedBed enters its main operational loop, acting as a versatile network proxy based on C2 commands; this includes initiating outgoing TCP connections, relaying data bi-directionally, and establishing reverse SOCKS5 (with authentication) or direct TCP port mapping services via locally opened listening ports. If commanded or upon connection failure, it transitions into a restart/wait cycle guided by registry values, leveraging its hooked exit function to hinder termination before attempting to reconnect to the C2.
APT GROUP
Malware family tracked by Malpedia. ID: win.red_gambler
APT GROUP
Malware family tracked by Malpedia. ID: win.redyms
APT GROUP
REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.
APT GROUP
Malware family tracked by Malpedia. ID: win.redsalt
APT GROUP
Malware family tracked by Malpedia. ID: win.redpepper
APT GROUP
Redosdru is a malware family that primarily acts as a downloader. Upon execution, it may drop downloaded DLLs in the "%ProgramFiles%\AppPatch" directory. The malware modifies the Windows registry to ensure its persistence, adding entries to run automatically at system startup.
RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer.
APT GROUP
Malware family tracked by Malpedia. ID: win.redleaves
APT GROUPfinancialhigh
According to Zscaler ThreatLabz, RedEnergy stealer uses a fake update campaign to target multiple industry verticals and possesses the ability to steal information from various browsers, enabling the exfiltration of sensitive data, while also incorporating different modules for carrying out ransomware activities.The name of the malware was kept due to the common method names observed during the analysis.
APT GROUP
According to Trend Micro, this backdoor receives valid domain credentials as an argument and uses it to log on to the Exchange Server and use it for data exfiltration purposes. The main function of this stage is to take the stolen password from the argument and send it to the attackers as an attachment in an email. We also observed that the threat actors relay these emails via government Exchange Servers using vaild accounts with stolen passwords.
APT GROUP
This malware is a successor to Raccoon Stealer (also referred to as Raccoon Stealer 2.0), which is however a full rewrite in C/C++.
APT GROUP
Reaver is a type of malware discovered by researchers at Palo Alto Networks in November 2017, but its activity dates back to at least late 2016. Researchers identified only ten unique samples of the malware, indicating limited use, and three different variants, noted as versions 1, 2, and 3. The malware is unique as its final payload masquerades as a control panel link (CPL) file. The intended targets of this activity are unknown as of this writing; however, it was used concurrently with the SunOrcal malware and the same C2 infrastructure used by threat actors who primarily target based on the "Five Poisons" - five perceived threats deemed dangerous to, and working against the interests of, the Chinese government.
APT GROUP
Please note: ReactorBot in its naming is often mistakenly labeled as Rovnix. ReactorBot is a full blown bot with modules, whereas Rovnix is just a bootkit / driver component (originating from Carberp), occasionally delivered alongside ReactorBot.
APT GROUP
Malware family tracked by Malpedia. ID: win.rdat
APT GROUP
Malware family tracked by Malpedia. ID: win.rdasrv
APT GROUP
Malware family tracked by Malpedia. ID: win.rctrl
APT GROUP
Malware family tracked by Malpedia. ID: win.rcs
APT GROUP
A family identified by ESET Research in the InvisiMole campaign.