Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016. It has all the features that would be expected from a RAT and probably more. The long list of the commands is documented on their website. But what separates Orcus from the others is its capability to load custom plugins developed by users, as well as plugins that are readily available from the Orcus repository. In addition to that, users can also execute C# and VB.net code on the remote machine in real-time.
APT GROUP
A malware generating DGA domains seeded by the Bitcoin Genesis Block. This family has strong code overlap with win.victorygate.
APT GROUP
OrcaRAT is a Backdoor that targets the Windows platform. It has been reported that a variant of this malware has been used in a targeted attack. It contacts a remote server, sending system information. Moreover, it receives control commands to execute shell commands, and download/upload a file, among other actions.
APT GROUP
FireEye details ORANGEADE as a dropper for the CREAMSICLE malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.op_blockbuster
APT GROUP
This entry serves as a placeholder of malware observed during Operation Ghoul. The samples will likely be assigned to their respective families. Some families involved and identified were Alina POS (Katrina variant) and TreasureHunter POS.
APT GROUP
Malware family tracked by Malpedia. ID: win.open_carrot
APT GROUP
Malware family tracked by Malpedia. ID: win.opensupdater
APT GROUP
Malware family tracked by Malpedia. ID: win.opcjacker
APT GROUP
Malware family tracked by Malpedia. ID: win.opachki
APT GROUP
Malware family tracked by Malpedia. ID: win.oopsie
APT GROUP
A spambot that has been observed being used for spreading Ursnif, Zeus Panda, Andromeda or Netflix phishing against Italy and Canada.
APT GROUP
OnionDuke is a new sophisticated piece of malware distributed by threat actors through a malicious exit node on the Tor anonymity network appears to be related to the notorious MiniDuke, researchers at F-Secure discovered. According to experts, since at least February 2014, the threat actors have also distributed the threat through malicious versions of pirated software hosted on torrent websites.
APT GROUP
Malware family tracked by Malpedia. ID: win.onhat
APT GROUP
According to Symantec, this malware has been deployed against IT services companies in the U.S. and Europe. A multi-stage backdoor, the first stage is a downloader that authenticates to Microsoft Graph API and downloads the second stage payload from OneDrive and executes it. The main payload will download a publicly available file from GitHub. It will then create a folder in OneDrive named deviceId_n_<ip address> for each infected machine and upload a file to OneDrive to signal the attackers the status of a new infection.
APT GROUP
Malware which seems to have no function other than to disrupt computer systems related to the 2018 Winter Olympic event.
APT GROUPespionageadvanced
According to FireEye, OLDBAIT is a credential stealer that has been observed to be used by APT28.
It targets Internet Explorer, Mozilla Firefox, Eudora, The Bat! (an email client by a Moldovan company), and Becky! (an email client made by a Japanese company). It can use both HTTP or SMTP to exfiltrate data.
In some places it is mistakenly named "Sasfis", which however seems to be a completely different and unrelated malware family.
APT GROUP
a new, previously unknown backdoor that we named Okrum. The malicious actors behind the Okrum malware were focused on the same targets in Slovakia that were previously targeted by Ketrican 2015 backdoors.
APT GROUP
Malware family tracked by Malpedia. ID: win.odinaff
APT GROUP
Spam bot that was active around 2007 and after, one of the first malware families to use a domain generation algorithm.
APT GROUP
Malware family tracked by Malpedia. ID: win.oddjob
APT GROUPespionageadvanced
Octowave Loader is a malware loader used to run other families of malware. This is often made up of an MSI or Inno Setup installer for a legitimate piece of software that has been trojanised to include a number of malicious DLLs which inevitably load and run malicious code often stored within a WAV file that is also delivered to an endpoint. In the wild this has been seen delivered through fake software installers and ClickFix / Fake Captcha campaigns. Families of malware deployed often include information stealers, NetSupport RAT, and potentially bots like Danabot.
APT GROUP
Malware family tracked by Malpedia. ID: win.octorat
APT GROUP
The author describes Octopus as an "open source, pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S."
It is different from the malware win.octopus written in Delphi and attributed to DustSquad by Kaspersky Labs.
APT GROUP
Emanuele De Lucia summarizes that this wiper was sent to potential targets in phishing mails that impersonated ESET as a follow up to a breach of its Israeli distributor Comsecure.
APT GROUP
Malware family tracked by Malpedia. ID: win.oceansalt
APT GROUP
Malware family tracked by Malpedia. ID: win.oceanmap
APT GROUP
Malware family tracked by Malpedia. ID: win.observer_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.obscene
APT GROUP
Malware family tracked by Malpedia. ID: win.oblique_rat
APT GROUP
OATBOAT is a loader that loads and executes shellcode payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.nyxem
APT GROUP
According to bin.re, in April 2018 a new version of Nymaim appeared, that has dropped previous obfuscation, and uses a new wordlist based DGA (Domain Generation Algorithm).
APT GROUP
Nymaim is a trojan downloader. It downloads (and runs) other malware on affected systems and was one of the primary malware families hosted on Avalanche. Nymaim is different in that it displays a localized lockscreen while it downloads additional malware. Nymaim is usually delivered by exploit kits and malvertising.
APT GROUP
Malware family tracked by Malpedia. ID: win.nworm
APT GROUP
Malware family tracked by Malpedia. ID: win.nvisospit
APT GROUPfinancialhigh
According to PCrisk, Numando is a banking trojan written in the Delphi programming language. As the malicious program's classification implies, it is designed to steal banking information. Numando primarily targets Brazil, with seldom campaigns occurring in Mexico and Spain.
APT GROUP
Nullmixer is a dropper/loader for additional malware. It is known to drop a vast amount of different malware, such as info stealers, rats and additional loaders. Samples observed contained up to 8 additional payloads.
APT GROUP
NSFOCUS describes PhantomNugget as a modularized malware toolkit, that was spread using EternalBlue. Payloads included a RAT and a XMRig miner.