Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
As described on the Github repository page, "A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM".
APT GROUP
Malware family tracked by Malpedia. ID: win.jssloader
APT GROUP
JSOutProx is a sophisticated attack framework built using both Javascript and .NET. It uses the .NET (de)serialization feature to interact with a Javascript file which is the core module running on a victim machine. Once the malware is run on the victim, the framework can load several plugins performing additional malicious activities on the target.
APT GROUP
Malware family tracked by Malpedia. ID: win.jripbot
APT GROUP
Malware family tracked by Malpedia. ID: win.jqjsnicker
APT GROUP
Malware family tracked by Malpedia. ID: win.jolob
APT GROUP
Malware family tracked by Malpedia. ID: win.joao
APT GROUP
Malware family tracked by Malpedia. ID: win.joanap
APT GROUP
Malware family tracked by Malpedia. ID: win.jlorat
APT GROUP
Malware family tracked by Malpedia. ID: win.jinxloader
APT GROUP
Malware family tracked by Malpedia. ID: win.jimmy
APT GROUP
Cisco Talos identified JhoneRAT in January 2020. The RAT is delivered through cloud services (Google Drive) and also submits stolen data to them (Google Drive, Twitter, ImgBB, GoogleForms). The actors using JhoneRAT target Saudi Arabia, Iraq, Egypt, Libya, Algeria, Morocco, Tunisia, Oman, Yemen, Syria, UAE, Kuwait, Bahrain and Lebanon.
APT GROUP
JessieConTea is a remote access trojan that uses HTTP(S) for communication. It supports around 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration (both plain and zipped), and the download and execution of additional tools from the attacker’s arsenal. The commands are indexed by 32-bit integers, starting with the value 0x60D49D97.
The malware was delivered in-the-wild via trojanized applications like DeFi Wallet or Citrix Workspace.
JessieConTea generates POST parameters with a specific parameter name, jsessid, from which the initial part of its name is derived. Also, it contains a specific RTTI symbol ".?AVCHttpConn@@", which inspired the second part of the name. It uses RC4 for C&C traffic encryption.
APT GROUP
Malware family tracked by Malpedia. ID: win.jelus_rat
APT GROUPfinancialhigh
Ransomware written in Go.
APT GROUP
Malware family tracked by Malpedia. ID: win.jasus
APT GROUP
Jason is a graphic tool implemented to perform Microsoft exchange account brute-force in order to “harvest” the highest possible emails and accounts information. Distributed in a ZIP container the interface is quite intuitive: the Microsoft exchange address and its version shall be provided. Three brute-force methods could be selected: EWS (Exchange Web Service), OAB (Offline Address Book) or both (All). Username and password list can be selected and threads number should be provided in order to optimize the attack balance.
APT GROUP
Malware family tracked by Malpedia. ID: win.janeleiro
APT GROUPespionageadvanced
According to Zscaler, JanelaRAT is a heavily modified variant of BX RAT. Its focus is set on harvesting LATAM financial data and its method of extracting window titles for transmission underscores its targeted and stealthy nature. With an adaptive approach utilizing dynamic socket configuration and exploiting DLL side-loading from trusted sources, JanelaRAT poses a significant threat.
APT GROUP
Malware family tracked by Malpedia. ID: win.jaku
APT GROUP
Malware family tracked by Malpedia. ID: win.jager_decryptor
APT GROUP
Malware family tracked by Malpedia. ID: win.jackpos
APT GROUPespionageadvanced
According to Kaspersky Labs, this malware tool set has been used by APT group GoldenJackal, which has been observed since 2019 and which usually targets government and diplomatic entities in the Middle East and South Asia with espionage. It consists of multiple components and is written in .NET.
APT GROUP
Malware family tracked by Malpedia. ID: win.ixware
APT GROUP
Malware family tracked by Malpedia. ID: win.isspace
APT GROUP
ISR Stealer is a modified version of the Hackhound Stealer. It is written in VB and often comes in a .NET-wrapper.
ISR Stealer makes use of two Nirsoft tools: Mail PassView and WebBrowserPassView.
Incredibly, it uses an hard-coded user agent string: HardCore Software For : Public
APT GROUP
Malware family tracked by Malpedia. ID: win.ispy_keylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.ismdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.ismagent
APT GROUPespionageadvanced
2006 Gozi v1.0, Gozi CRM, CRM, Papras
2010 Gozi v2.0, Gozi ISFB, ISFB, Pandemyia(*)
In September 2010, the source code of a particular Gozi CRM dll version was leaked. This led to two main branches: one became known as Gozi Prinimalka, which was merge with Pony and became Vawtrak/Neverquest.
The other branch became known as Gozi ISFB, or ISFB in short. Webinject functionality was added to this version.
There is one panel which often was used in combination with ISFB: IAP. The panel's login page comes with the title 'Login - IAP'. The body contains 'AUTHORIZATION', 'Name:', 'Password:' and a single button 'Sign in' in a minimal design. Often, the panel is directly accessible by entering the C2 IP address in a browser. But there are ISFB versions which are not directly using IAP. The bot accesses a gate, which is called the 'Dreambot' gate. See win.dreambot for further information.
ISFB often was protected by Rovnix. This led to a further complication in the naming scheme - many companies started to call ISFB Rovnix. Because the signatures started to look for Rovnix, other trojans protected by Rovnix (in particular ReactorBot and Rerdom) sometimes got wrongly labelled.
In April 2016 a combination of Gozi ISFB and Nymaim was detected. This breed became known as GozNym. The merge uses a shellcode-like version of Gozi ISFB, that needs Nymaim to run. The C2 communication is performed by Nymaim.
See win.gozi for additional historical information.
APT GROUP
According to Recorded Future, IsaacWiper is a destructive malware that overwrites all physical disks and logical volumes on a victim’s machine.
APT GROUP
Malware family tracked by Malpedia. ID: win.ironzero
APT GROUP
Malware family tracked by Malpedia. ID: win.ironwind
APT GROUP
According to Mitre, IronNetInjector is a Turla toolchain that utilizes scripts from the open-source IronPython implementation of Python with a .NET injector to drop one or more payloads including ComRAT.
APT GROUP
IRONHALO is a downloader that uses the HTTP protocol to retrieve a Base64 encoded payload from a hard-coded command-and-control (CnC) server and uniform resource locator (URL) path.
The encoded payload is written to a temporary file, decoded and executed in a hidden window. The encoded and decoded payloads are written to files named igfxHK[%rand%].dat and igfxHK[%rand%].exe respectively, where [%rand%] is a 4-byte hexadecimal number based on the current timestamp. It persists by copying itself to the current user’s Startup folder.
APT GROUP
Android variant of IPStorm (InterPlanetary Storm).
APT GROUP
A maliciously abused open source tool for port forwarding & intranet proxy.
APT GROUP
According to Cyble, The Invicta Stealer can collect system information, system hardware details, wallet data, and browser data and extract information from applications like Steam and Discord.
APT GROUP
Malware family tracked by Malpedia. ID: osx.interception