Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.lazardoor
APT GROUP
Malware family tracked by Malpedia. ID: win.laturo
APT GROUP
First discovered in October 2023, BLACKWIDOW is a backdoor written in C that communicates over HTTP using RC4 encrypted requests. The malware has the capability to execute discovery commands, query information about the victim's machine, update itself, as well as download and execute an EXE, DLL, or shellcode. The malware is believed to have been developed by LUNAR SPIDER, the creators of IcedID (aka BokBot) Malware.
APT GROUPfinancialhigh
FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless.
Using Dynamic Threat Intelligence, they have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which they named LATENTBOT – caught attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations.
APT GROUP
According to Seqrite, this is a TLS-based reverse shell.
APT GROUP
Malware family tracked by Malpedia. ID: win.lamdelin
APT GROUP
According to Microsoft, this is a downloader used in a supply chain attack involving a malicious variant of an application developed by CyberLink. It is centered around a legitimate CyberLink application installer that has been modified to include malicious code that downloads, decrypts, and loads a second-stage payload. The file, which was signed using a valid certificate issued to CyberLink Corp., is hosted on legitimate update infrastructure owned by CyberLink and includes checks to limit the time window for execution and evade detection by security products.
APT GROUP
Malware family tracked by Malpedia. ID: osx.lambert
APT GROUP
Malware family tracked by Malpedia. ID: win.lalala_stealer
APT GROUP
Kwampirs is a family of malware which uses SMB to spread. It typically will not execute or deploy in environments in which there is no publicly available admin$ share. It is a fully featured backdoor which can download additional modules. Typical C2 traffic is over HTTP and includes "q=[ENCRYPTED DATA]" in the URI.
APT GROUP
Cofense characterizes Kutaki as a data stealer that uses old-school techniques to detect sandboxes and debugging. Kutaki however works quite well against unhardened virtual machines and other analysis devices. By backdooring a legitimate application, it can fool unsophisticated detection methodologies.
APT GROUP
Malware family tracked by Malpedia. ID: win.kurton
APT GROUP
Malware family tracked by Malpedia. ID: win.kuluoz
APT GROUP
According to Threatray, KugelBlitz is a shellcode loader discovered in late 2024. It loads shellcode into memory from a file specified via command line. If no file is specified, it defaults to run.bin.
APT GROUP
Malware family tracked by Malpedia. ID: win.kuaibu8
APT GROUP
According to Trend Micro, KTLVdoor is a highly obfuscated malware that masquerades as different system utilities, allowing attackers to carry out a variety of tasks including file manipulation, command execution, and remote port scanning.
APT GROUP
Malware family tracked by Malpedia. ID: win.kryptocibule
APT GROUPespionageadvanced
Kronos malware is a sophisticated banking Trojan that first emerged in 2014. It is designed to target financial institutions and steal sensitive banking information. The malware is primarily spread through phishing campaigns and exploit kits. Once installed on a victim's computer, Kronos can capture login credentials, credit card details, and other personal information by keylogging and form grabbing techniques. It can also bypass security measures such as two-factor authentication. Kronos employs advanced evasion techniques to avoid detection by antivirus software and actively updates itself to evade security patches. It has been known to target a wide range of banking systems and has affected numerous organizations worldwide. The malware continues to evolve, making it a significant threat to online banking security.
APT GROUP
According to Trend Micro, this is a rootkit with capabilities of a full-featured backdoor with various capabilities, including process manipulation, file hiding, shellcode execution, traffic concealment, and C&C communication. It is controlled through a range of IOCTL codes.
APT GROUP
Malware family tracked by Malpedia. ID: win.krdownloader
APT GROUPfinancialhigh
ThreatPost describes KRBanker (Blackmoon) as a banking Trojan designed to steal user credentials from various South Korean banking institutions. It was discovered in early 2014 and since then has adopted a variety of infection and credential stealing techniques.
APT GROUP
KrakenKeylogger is a .NET based Infostealer malware sold in Underground hacking forums
APT GROUPfinancialhigh
According to ESET, this malware family is a banking trojan and was active in Brazil until the middle of 2019. Its most noticeable characteristic was its usage of well-known cryptographic methods to encrypt strings, as opposed to the majority of Latin American banking trojans that mainly use custom encryption schemes.
APT GROUP
KPOT is an information-stealing Trojan horse that can steal information from infected computers. It is distributed through phishing emails and malicious websites. Once executed on a computer, KPOT can steal passwords, credit card numbers, and other personal information.
APT GROUP
Malware family tracked by Malpedia. ID: win.korlia
APT GROUP
Malware family tracked by Malpedia. ID: win.koobface
APT GROUPespionageadvanced
KOMPROGO is a signature backdoor used by APT32 that is capable of process, file, and registry management, Creating a reverse shell, running WMI queries, retrieving information about the infected system.
APT GROUP
Malware family tracked by Malpedia. ID: win.kokokrypt
APT GROUP
Malware family tracked by Malpedia. ID: win.koistealer
APT GROUP
Malware family tracked by Malpedia. ID: win.koiloader
APT GROUP
Koadic is an open-source post-exploitation framework for Windows, created by zerosum0x0 and available on GitHub. The framework is written in Python and can generate JScript and VBScript payloads which can be written to disk or mapped directly into memory. Its capabilities include remote desktop access, command execution, lateral movement via SMB, file transfer, credential theft using Mimikatz, port scanning, and system information collection. It can also collect specific system information and targeted files based on their name or extension.
APT GROUP
Malware family tracked by Malpedia. ID: win.klrd
APT GROUP
Malware family tracked by Malpedia. ID: win.klogexe
APT GROUP
Malware family tracked by Malpedia. ID: win.klingon_rat
APT GROUP
KleptoParasite Stealer is advertised on Hackforums as a noob-friendly stealer. It is modular and comes with a IP retriever module, a Outlook stealer (32bit/64bit) and a Chrome/Firefox stealer (32bit/64bit). Earlier versions come bundled (loader plus modules), newer versions come with a loader (167k) that grabs the modules.
PDB-strings suggest a relationship to JogLog v6 and v7.
APT GROUP
Microsoft describes that threat actor ZINC is using Klackring as a malware dropped by ComeBacker, both being used to target security researchers.
APT GROUP
According to Zscaler, a malware sharing similarities with GhostRAT and Big Bad Wolf. The RAT’s features include clipboard manipulation to replace cryptocurrency addresses and the deployment of remote monitoring tools (i.e. Sunlogin, GotoHTTP).