Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,719 entities
APT GROUPfinancialhigh
According to Arbor, Forcepoint and Proofpoint, Panda is a variant of the well-known Zeus banking trojan(*). Fox IT discovered it in February 2016.
This banking trojan uses the infamous ATS (Automatic Transfer System/Scripts) to automate online bank portal actions.
The baseconfig (c2, crypto material, botnet name, version) is embedded in the malware itself. It then obtains a dynamic config from the c2, with further information about how to grab the webinjects and additional modules, such as vnc, backsocks and grabber.
Panda does have some DGA implemented, but according to Arbor, a bug prevents it from using it.
APT GROUP
Paladin RAT is a variant of Gh0st RAT used by PittyPanda active since at least 2011.
APT GROUP
Malware family tracked by Malpedia. ID: win.padcrypt
APT GROUP
Malware family tracked by Malpedia. ID: win.ozone
APT GROUP
Malware family tracked by Malpedia. ID: win.ozh_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.oxtarat
APT GROUP
Kaspersky describes this as a OWA add-on that has credential stealing capabilities.
APT GROUP
Malware family tracked by Malpedia. ID: win.owlproxy
APT GROUP
Malware family tracked by Malpedia. ID: win.owaauth
APT GROUP
Malware family tracked by Malpedia. ID: win.ovidiystealer
APT GROUP
Malware family tracked by Malpedia. ID: win.overlay_rat
APT GROUP
According to MITRE, OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Ember Bear since at least March 2021.
APT GROUP
Malware family tracked by Malpedia. ID: win.outlook_backdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.ousaban
APT GROUP
Malware family tracked by Malpedia. ID: win.osno
APT GROUP
Oski is a stealer written in C++ that appeared around November 2019 and is being sold for between 70$ to 100$ on Russian-speaking forums. It collects different types of data (cryptocurrency wallets, saved passwords, files matching an attacker-defined pattern etc) and it exfiltrates it in a zip file uploaded to the attacker's panel.
APT GROUP
Malware family tracked by Malpedia. ID: win.orpcbackdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.originlogger
APT GROUP
OriginBot is a modular information stealer which can also download and execute other malicious payloads.
APT GROUPfinancialhigh
This malware claims to be a ransomware, but it's actually a wiper. After execution, this malware terminates a number of processes such as database processes, likely to allow access to any files that these programs may have held open. Ordinypt will avoid wiping certain files and folders in order to prevent the infected machine from becoming unusable. Affected files are overwritten with null character and receive a random 5 character file extension. Finally, shadow copies are removed and Windows startup repair is disabled to complicate recovery of data from the affected system. The desktop background is changed and a ransom note is dropped for the victim. A C2 check-in occurs to keep track of the file extension used on that specific machine, as well as which BitCoin address was randomly provided for payment to the victim (drawn from a long list stored in the ransomware configuration).
APT GROUP
Orcus has been advertised as a Remote Administration Tool (RAT) since early 2016. It has all the features that would be expected from a RAT and probably more. The long list of the commands is documented on their website. But what separates Orcus from the others is its capability to load custom plugins developed by users, as well as plugins that are readily available from the Orcus repository. In addition to that, users can also execute C# and VB.net code on the remote machine in real-time.
APT GROUP
A malware generating DGA domains seeded by the Bitcoin Genesis Block. This family has strong code overlap with win.victorygate.
APT GROUP
OrcaRAT is a Backdoor that targets the Windows platform. It has been reported that a variant of this malware has been used in a targeted attack. It contacts a remote server, sending system information. Moreover, it receives control commands to execute shell commands, and download/upload a file, among other actions.
APT GROUP
FireEye details ORANGEADE as a dropper for the CREAMSICLE malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.op_blockbuster
APT GROUP
This entry serves as a placeholder of malware observed during Operation Ghoul. The samples will likely be assigned to their respective families. Some families involved and identified were Alina POS (Katrina variant) and TreasureHunter POS.
APT GROUP
Malware family tracked by Malpedia. ID: win.open_carrot
APT GROUP
Malware family tracked by Malpedia. ID: win.opensupdater
APT GROUP
Malware family tracked by Malpedia. ID: win.opcjacker
APT GROUP
Malware family tracked by Malpedia. ID: win.opachki
APT GROUP
Malware family tracked by Malpedia. ID: win.oopsie
APT GROUP
A spambot that has been observed being used for spreading Ursnif, Zeus Panda, Andromeda or Netflix phishing against Italy and Canada.
APT GROUP
OnionDuke is a new sophisticated piece of malware distributed by threat actors through a malicious exit node on the Tor anonymity network appears to be related to the notorious MiniDuke, researchers at F-Secure discovered. According to experts, since at least February 2014, the threat actors have also distributed the threat through malicious versions of pirated software hosted on torrent websites.
APT GROUP
Malware family tracked by Malpedia. ID: win.onhat
APT GROUP
According to Symantec, this malware has been deployed against IT services companies in the U.S. and Europe. A multi-stage backdoor, the first stage is a downloader that authenticates to Microsoft Graph API and downloads the second stage payload from OneDrive and executes it. The main payload will download a publicly available file from GitHub. It will then create a folder in OneDrive named deviceId_n_<ip address> for each infected machine and upload a file to OneDrive to signal the attackers the status of a new infection.
APT GROUP
Malware which seems to have no function other than to disrupt computer systems related to the 2018 Winter Olympic event.
APT GROUPespionageadvanced
According to FireEye, OLDBAIT is a credential stealer that has been observed to be used by APT28.
It targets Internet Explorer, Mozilla Firefox, Eudora, The Bat! (an email client by a Moldovan company), and Becky! (an email client made by a Japanese company). It can use both HTTP or SMTP to exfiltrate data.
In some places it is mistakenly named "Sasfis", which however seems to be a completely different and unrelated malware family.
APT GROUP
a new, previously unknown backdoor that we named Okrum. The malicious actors behind the Okrum malware were focused on the same targets in Slovakia that were previously targeted by Ketrican 2015 backdoors.