Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
Malware family tracked by Malpedia. ID: win.razr
APT GROUP
Malware family tracked by Malpedia. ID: win.rawpos
APT GROUP
Malware family tracked by Malpedia. ID: win.rawdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.ravenstealer
APT GROUP
Malware family tracked by Malpedia. ID: win.ratsnif
APT GROUP
Malware family tracked by Malpedia. ID: win.raton_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.ratel
APT GROUP
Malware family tracked by Malpedia. ID: win.ratankbapos
APT GROUP
This is a backdoor that establishes persistence using the Startup folder. It communicates to its C&C server using HTTPS and a static HTTP User-Agent string. QUICKRIDE is capable of gathering information about the system, downloading and loading executables, and uninstalling itself. It was leveraged against banks in Poland.
Worm spread by external drives that leverages Windows Installer to reach out to QNAP-associated domains and download a malicious DLL.
APT GROUPfinancialhigh
This ransomware encrypts all user’s data on the PC (photos, documents, excel tables, music, videos, etc), adds its specific extension to every file, and creates the HOW_TO_DECYPHER_FILES.txt files in every folder which contains encrypted files.
APT GROUP
Malware family tracked by Malpedia. ID: win.rarog
APT GROUP
A spy trojan is a type of malware that has the capability to gather information from the infected system without consent from the user. This information is then sent to a remote attacker.
APT GROUPfinancialhigh
InfinityGroup notes that Rapid Ransomware, unlike regular Ransomware, stays active on the computer after initially encrypting the systems and also encrypts any new files that are created. It does this by creating auto-runs that are designed to launch the ransomware and display the ransom note every time the infected system is started.
APT GROUPfinancialhigh
Ransomware SNC is a ransomware who encrypts files and asks for a variable amount of Bitcoin before releasing the decryption key to your files. The threat actor asks to be contacted for negotiating the right ransom fee.
APT GROUP
Malware family tracked by Malpedia. ID: win.ransomlock
APT GROUP
Malware family tracked by Malpedia. ID: win.ranscam
APT GROUP
Malware family tracked by Malpedia. ID: win.ranbyus
APT GROUP
Malware family tracked by Malpedia. ID: win.ramsay
APT GROUPfinancialhigh
According to Check Point, Ramnit is primarily a banking trojan, meaning that its purpose is to steal login credentials for online banking, which cybercriminals can sell or use in future attacks. For this reason, Ramnit primarily targets individuals rather than focusing on particular industries. Ramnit campaigns have been observed to target organizations in particular industries. For example, a 2019 campaign targeted financial organizations in the United Kingdom, Italy, and Canada.
APT GROUP
Malware family tracked by Malpedia. ID: win.ramdo
Updated: 2016-04-20
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rambo
APT GROUP
Raindrop is a loader for Cobalt Strike that was observed in the SolarWinds attack.
APT GROUP
According to Trend Micro, RAILSETTER is a persistence installer component designed to work with RAILLOAD. Its main functions include: Copying and renaming RAILLOAD’s intended host from System32 to the intended target directory; Timestomping RAILLOAD and its host’s create, access, and modify time; Creating a scheduled task for persistence.
APT GROUP
Malware family tracked by Malpedia. ID: win.radrat
APT GROUP
Malware family tracked by Malpedia. ID: win.rad
Racket Downloader is an HTTP(S) downloader. It uses a custom substitution cipher for decryption of its character strings, and RC5 with a 256-bit key for encryption and decryption of network traffic. It sends an HTTP POST request containing a particular value that inspired its name, like "?product_field=racket" or "prd_fld=racket". Racket Downloader was deployed against South Korean targets running the Initech INISAFE CrossWeb EX software in Q2 2021 and Q1 2022.
APT GROUP
Raccoon Stealer is a malware reportedly sold for $75 a week or $200 a month. It gathers personal information including passwords, browser cookies and autofill data, as well as cryptowallet details. Additionally, Raccoon Stealer records system information such as IP addresses and geo-location data.
APT GROUP
Malware family tracked by Malpedia. ID: win.r980
APT GROUP
According to the author, r77 is a ring 3 rootkit that hides everything: * Files, directories * Processes & CPU usage * Registry keys & values * Services * TCP & UDP connections * Junctions, named pipes, scheduled tasks
APT GROUP
Malware family tracked by Malpedia. ID: win.qvoidstealer
APT GROUP
Qulab is an AutoIT Malware focusing on stealing & clipping content from victim's machines.
APT GROUP
QuiteRAT is a simple remote access trojan written with the help of Qt libraries. After sending preliminary system information to its C&C server, it expects a response containing either a supported command code or an actual Windows command (like systeminfo or ipconfig with parameters) to execute. It was deployed in a campaign exploiting a ManageEngine ServiceDesk vulnerability (CVE-2022-47966).
APT GROUP
According to X-Force, this is a loader module written in .NET languages for which ahead-of-time (AOT) compilation is used.
APT GROUP
According to Microsoft, this is a heavily obfuscated .NET malware, primarily geared towards the exfiltration of data from the compromised host. But it can also receive and execute a remote payload from the operator.
APT GROUP
Malware family tracked by Malpedia. ID: win.quietcanary
APT GROUP
QuickMute is a malware developed using the C/C++ programming language. Functionally provides download, RC4 decryption, and in-memory launch of the payload (waiting for a PE file with the export function "HttpsVictimMain"). To communicate with the management server, a number of protocols are provided, in particular: TCP, UDP, HTTP, HTTPS.
APT GROUP
Malware family tracked by Malpedia. ID: win.quickheal
APT GROUP
Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.
APT GROUPespionageadvanced
A stager used by APT29 to download and run CobaltStrike. Here, MUSKYBEAT refers to the in-memory dropper component, while STATICNOISE is the final payload / downloader.