Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
According to Threatray, KiwiStealer is a simple file stealer first discovered in late 2024. It starts by gathering the computer name and username. It also retrieves the current system time, which will be used later to check the last modification time of files on the machine. KiwiStealer searches through a predefined list of directories to gather files and only exfiltrates files that are smaller than 50MB and have been modified within the past year. It targets these extensions: z7, .txt, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .jpg, .zip, .rar, .apk, .neat, .err, .eln, .ppi, .er9, .azr, .pfx, .ovpn.
APT GROUP
Malware family tracked by Malpedia. ID: elf.kivars
APT GROUP
Malware family tracked by Malpedia. ID: win.kins
APT GROUP
According to Sophis, the botnet has been active since 2018, initially, the botmasters operated DDoS tools and backdoors, but later moved on to cryptocurrency miners. They use a DGA to automatically change the hosting domains every week.
APT GROUP
Malware family tracked by Malpedia. ID: win.kimjongrat
APT GROUP
Malware family tracked by Malpedia. ID: win.killsomeone
APT GROUP
KillDisk is a generic detection name used by ESET to refer to destructive malware with disk wiping capabilities, such as damaging boot sectors and overwriting then deleting (system) files, followed by a reboot to render the machine unusable. Although all KillDisk malware has similar functionality, as a generic detection, individual samples do not necessarily have strong code similarities or relationships. Such generic malware detections usually have many “sub-families”, distinguished by the detection suffix (e.g. KillDisk.NBO, KillDisk.NCV, and KillDisk.NCX). Sub-family variants that do have strong code similarities, are sometimes seen in separate cyberattacks and thus can help researchers make connections between them.
APT GROUP
Malware family tracked by Malpedia. ID: win.killav
APT GROUP
Malware family tracked by Malpedia. ID: win.kikothac
APT GROUP
According to Unit42, KHRAT is a Trojan that registers victims using their infected machine’s username, system language and local IP address. KHRAT provides the threat actors typical RAT features and access to the victim system, including keylogging, screenshot capabilities, remote shell access and so on.
APT GROUPfinancialhigh
A compact ransomware written in .NET and delivered as follow-up to Log4J exploitation, targeting Windows servers.
KGH SPY
Technical ID: KGH_SPY
APT GROUP
Malware family tracked by Malpedia. ID: win.kgh_spy
APT GROUP
Malware family tracked by Malpedia. ID: win.keymarble
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: win.keylogger_apt3
APT GROUP
According to Walmart Global Tech, Keyhole is a multi-functional VNC/Backconnect component used extensively by IcedID/Anubis. While the malware contains functionality that has been previously reported on as typical VNC and HDESK capabilities, a general lack of technical information appears to exist around some of the expanded functionality currently present.
APT GROUP
KeyBase is a .NET credential stealer and keylogger that first emerged in February 2015. It often incorporates Nirsoft tools such as MailPassView and WebBrowserPassView for additional credential grabbing.
APT GROUP
Intezer found this family mid May 2020, which appears to be a merger of the family Ketrican and Okrum.
APT GROUPespionageadvanced
Ketrican is a backdoor trojan used by APT 15.
APT GROUP
Malware family tracked by Malpedia. ID: win.kerrdown
APT GROUP
Malware family tracked by Malpedia. ID: win.keona
Stealer written in Python, available as open source on Github.
APT GROUP
Malware family tracked by Malpedia. ID: win.kelihos
APT GROUP
Malware family tracked by Malpedia. ID: win.kegotip
APT GROUP
Malware family tracked by Malpedia. ID: win.kdcsponge
APT GROUP
According to Karsten Hahn, a straightforward loader that runs assemblies from images.
APT GROUP
Malware family tracked by Malpedia. ID: win.kazuar
APT GROUP
Malware family tracked by Malpedia. ID: win.katz_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.kasperagent
APT GROUP
Malware family tracked by Malpedia. ID: win.karsto_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.karkoff
APT GROUPfinancialhigh
According to checkpoint, Karius is a banking trojan in development, borrowing code from Ramnit, Vawtrack as well as Trickbot, currently implementing webinject attacks only. It comes with an injector that loads an intermediate "proxy" component, which in turn loads the actual banker component. Communication with the c2 are in json format and encrypted with RC4 with a hardcoded key. In the initial version, observed in March 2018, the webinjects were hardcoded in the binary, while in subsequent versions, they were received by the c2.
APT GROUPfinancialhigh
According to ASERT, Kardon Loader is a fully featured downloader, enabling the download and installation of other malware, eg. banking trojans/credential theft etc.This malware has been on sale by an actor under the username Yattaze, starting in late April. The actor offers the sale of the malware as a standalone build with charges for each additional rebuild, or the ability to set up a botshop in which case any customer can establish their own operation and further sell access to a new customer base.
APT GROUP
Malware family tracked by Malpedia. ID: win.karagany
APT GROUP
Malware family tracked by Malpedia. ID: win.kapeka
APT GROUP
Kaolin RAT is a complex modular RAT, with Release_TMain_x64.dll as its internal DLL name. The malware provides standard backdoor functionality, including manipulation and listing of files and processes, exchanging the configuration, collecting the victim’s system info, opening a TCP connection, and executing local commands and collecting their outputs. Also, it is designed to execute additional DLL payloads in memory via specific exported functions: - _DoMyFunc, - _DoMyFunc2, - _DoMyThread, - _DoMyCommandWork. Functionally, Kaolin RAT relies on an accompanying trojanized curl library to handle network and exfiltration operations, by importing functions such as: - SendDataFromURL, - ZipFolder, - UnzipStr, - curl wrappers. For C&C communication, it employs AES encryption and attempts to evade network detection by randomly selecting words from a hardcoded custom dictionary to populate POST request parameters. The malware's name is derived from one of these dictionary words ("kaolin"). The Kaolin RAT has been observed in Lazarus campaigns as a late-stage payload — typically following loaders like RollFling, RollSling, and RollMid — and serves also as a delivery vector for the FudModule rootkit with a 0-day exploit.
APT GROUP
A Telegram bot with browser stealing capabilities, written using the .NET framework.
APT GROUP
Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to download files, receive commands, and execute files, allowing it to perform HTTP and DNS flooding attacks. The bot is also used to access sensitive files. The bot has been seen to be communicating with third-party platforms such as Telegram, Discord, and GitHub, using these platforms as backup C2 servers.
APT GROUP
Malware family tracked by Malpedia. ID: win.kagent
APT GROUP
Malware family tracked by Malpedia. ID: win.jupiter
APT GROUP
According to FireEye, JUMPALL is a malware dropper that has been observed dropping HIGHNOON/ZXSHELL/SOGU.