Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.logedrut
APT GROUP
Malware family tracked by Malpedia. ID: win.lodeinfo
APT GROUP
Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims. Proofpoint first observed Loda in September of 2016 and it has since grown in popularity. The name Loda is derived from a directory to which the malware author chose to write keylogger logs. It should be noted that some antivirus products currently detect Loda as “Trojan.Nymeria”, although the connection is not well-documented.
APT GROUP
Malware family tracked by Malpedia. ID: win.lock_pos
APT GROUP
For the lack of a better name, this is a VBS-based loader that was used in beginning of 2018 to deliver win.locky.
APT GROUP
Malware family tracked by Malpedia. ID: win.locky_decryptor
APT GROUPfinancialhigh
A ransomware first observed in July 2021.
APT GROUPfinancialhigh
According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to access a victim's computer without being noticed. The hVNC component is effective in evading fraud detection systems. Also, LOBSHOT is being used to carry out financial crimes through the use of banking trojan and information-stealing functionalities.
APT GROUP
According to AlienVault, LiteHTTP bot is a new HTTP bot programmed in C#. The bot has the ability to collect system information, download and execute programs, and update and kill other bots present on the system.
The source is on GitHub: https://github.com/zettabithf/LiteHTTP
APT GROUP
According to CarbonBlack, LiteDuke is a third stage backdoor. It appears to use the same dropper as PolyglotDuke. Its payload makes use of an AES encrypted SQLite database to store its configuration. LiteDuke supports a large number of individual commands including host information retrieval, file upload and download, and the ability to execute other code. LiteDuke C2 servers appear to be compromised servers, and the malware communicates with them using normal HTTP requests. It attempts to use a realistic User-Agent string to blend in better with normal HTTP traffic.
ESET have dubbed it LiteDuke because it uses SQLite to store information such as its configuration.
APT GROUP
Malware family tracked by Malpedia. ID: win.listrix
APT GROUP
Malware family tracked by Malpedia. ID: win.liontail
APT GROUP
Malware family tracked by Malpedia. ID: win.linseningsvr
APT GROUP
Malware family tracked by Malpedia. ID: win.limitail
APT GROUPfinancialhigh
## Description
Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, It should give you a general knowledge about dotNET malwares and how it behaves.
---
## Main Features
- **.NET**
- Coded in Visual Basic .NET, Client required framework 2.0 or 4.0 dependency, And server is 4.0
- **Connection**
- Using pastebin.com as ip:port , Instead of noip.com DNS. And Also using multi-ports
- **Plugin**
- Using plugin system to decrease stub's size and lower the AV detection
- **Encryption**
- The communication between server & client is encrypted with AES
- **Spreading**
- Infecting all files and folders on USB drivers
- **Bypass**
- Low AV detection and undetected startup method
- **Lightweight**
- Payload size is about 25 KB
- **Anti Virtual Machines**
- Uninstall itself if the machine is virtual to avoid scanning or analyzing
- **Ransomware**
- Encrypting files on all HHD and USB with .Lime extension
- **XMR Miner**
- High performance Monero CPU miner with user idle\active optimizations
- **DDoS**
- Creating a powerful DDOS attack to make an online service unavailable
- **Crypto Stealer**
- Stealing Cryptocurrency sensitive data
- **Screen-Locker**
- Prevents user from accessing their Windows GUI
- **And more**
- On Connect Auto Task
- Force enable Windows RDP
- Persistence
- File manager
- Passowrds stealer
- Remote desktop
- Bitcoin grabber
- Downloader
- Keylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.limepad
APT GROUP
Malware family tracked by Malpedia. ID: win.limeminer
APT GROUP
Malware family tracked by Malpedia. ID: win.limedownloader
APT GROUP
Malware family tracked by Malpedia. ID: win.ligsterac
APT GROUP
According to Mandiant, LIGHTWORK is a disruption tool written in C++ that implements the IEC-104 protocol to modify the state of RTUs over TCP. It crafts configurable IEC-104 ASDU messages, to change the state of RTU IOAs to ON or OFF. This sample works in tandem with PIEHOP, which sets up the execution.
APT GROUP
According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
APT GROUP
Lightning stealer can target 30+ Firefox and Chromium-based browsers and steal crypto wallets, Telegram data, Discord tokens, and Steam user’s data. Unlike other info stealers, Lightning Stealer stores all the stolen data in the JSON format for exfiltration.
APT GROUP
Malware family tracked by Malpedia. ID: win.lightneuron
APT GROUP
LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan.
In Q2 2022 and Q1 2023, it was deployed in targeted attacks against an aerospace company in Spain and a technology company in India.
Besides the support for commands already present in BlindingCan, its most significant update is mimicked functionality of many native Windows commands:
• ipconfig
• net
• netsh advfirewall firewall
• netstat
• reg
• sc
• ping (for both IPv4 and IPv6 protocols)
• wmic process call create
• nslookup
• schstasks
• systeminfo
• arp
These native commands are often abused by the attackers after they have gotten a foothold in the target’s system. Lightless is able to execute them discreetly within the RAT itself, rather than being executed visibly in the system console. This provides stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools.
LightlessCan use RC6 for decryption of its configuration, and also for encryption and decryption of network traffic.
APT GROUP
Malware family tracked by Malpedia. ID: win.lightbunny
APT GROUP
Malware family tracked by Malpedia. ID: win.liderc
APT GROUP
LgoogLoader is an installer that drops three files: a batch file, an AutoIt interpreter, and an AutoIt script. After downloading, it executes the batch file.
APT GROUP
Malware family tracked by Malpedia. ID: win.letmeout
APT GROUP
Lethic is a spambot dating back to 2008. It is known to be distributing low-level pharmaceutical spam.
APT GROUP
Leslieloader is a loader written in Golang, named after the observed AES decryption key referencing deceased actor, Leslie Cheung. The loader assists in the initial infection and deployment of the malicious payload, enabling execution on a system. The loader achieves its goal by decoding and decrypting a secondary payload binary, then injecting it into another process.
APT GROUP
Malware family tracked by Malpedia. ID: win.leouncia
APT GROUP
Lemon Duck is a monerocrypto-mining malware with capabilitiy to spread rapidly across the entire network. The malware runs its payload mainly in memory. Internal network spreading is performed by SMB RCE Vulnerability (CVE-2017-0144), or brute-force attacks.
APT GROUP
Malware family tracked by Malpedia. ID: win.lechiket
APT GROUP
Malware family tracked by Malpedia. ID: win.leash
APT GROUPfinancialhigh
A further branch of the URSNIF collection of malware families. According to Mandiant, it no longer has focus on banking fraud but generic backdoor capabilities instead.
APT GROUP
Malware family tracked by Malpedia. ID: win.lcpdot
APT GROUP
Malware family tracked by Malpedia. ID: win.lazycat
APT GROUP
Malware family tracked by Malpedia. ID: win.laziok
APT GROUP
Malware family tracked by Malpedia. ID: win.lazarus_killdisk
APT GROUP
Malware family tracked by Malpedia. ID: win.lazarloader