Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,720 entities
APT GROUPfinancialhigh
LooCipher is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank to the term “Cipher”) and to the popular mythological figure, Lucifer. Despite its evocative nickname, the functionalities of this malware are pretty straight forward, not very different from those belonging to many other ransomware families.
Updated: 2026-08-05
View profile →
APT GROUPfinancialhigh
LooChiper is a Ransomware. It uses a nice but scary name: LooCipher. The name is at the same time an allusion to its capabilities (thank to the term “Cipher”) and to the popular mythological figure, Lucifer. Despite its evocative nickname, the functionalities of this malware are pretty straight forward, not very different from those belonging to many other ransomware families.
Updated: 2023-09-11
View profile →
APT GROUP
The primary function of LONGWATCH is a keylogger that outputs keystrokes to a log.txt file in the Windows temp folder.
APT GROUP
Malware family tracked by Malpedia. ID: win.lolsnif
APT GROUPfinancialhigh
According to ESET, this is a banking trojan that was active mainly in Mexico until the beginning of 2020, with builds for Brazil, Chile, and Colombia also having been identified.
APT GROUPespionageadvanced
"Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMe Loki-Bot employs function hashing to obfuscate the libraries utilized. While not all functions are hashed, a vast majority of them are. Loki-Bot accepts a single argument/switch of ‘-u’ that simply delays execution (sleeps) for 10 seconds. This is used when Loki-Bot is upgrading itself. The Mutex generated is the result of MD5 hashing the Machine GUID and trimming to 24-characters. For example: “B7E1C2CC98066B250DDB2123“. Loki-Bot creates a hidden folder within the %APPDATA% directory whose name is supplied by the 8th thru 13th characters of the Mutex. For example: “%APPDATA%\ C98066\”. There can be four files within the hidden %APPDATA% directory at any given time: “.exe,” “.lck,” “.hdb” and “.kdb.” They will be named after characters 13 thru 18 of the Mutex. For example: “6B250D.” Below is the explanation of their purpose: FILE EXTENSION FILE DESCRIPTION .exe A copy of the malware that will execute every time the user account is logged into .lck A lock file created when either decrypting Windows Credentials or Keylogging to prevent resource conflicts .hdb A database of hashes for data that has already been exfiltrated to the C2 server .kdb A database of keylogger data that has yet to be sent to the C2 server If the user is privileged, Loki-Bot sets up persistence within the registry under HKEY_LOCAL_MACHINE. If not, it sets up persistence under HKEY_CURRENT_USER. The first packet transmitted by Loki-Bot contains application data. The second packet transmitted by Loki-Bot contains decrypted Windows credentials. The third packet transmitted by Loki-Bot is the malware requesting C2 commands from the C2 server. By default, Loki-Bot will send this request out every 10 minutes after the initial packet it sent. Communications to the C2 server from the compromised host contain information about the user and system including the username, hostname, domain, screen resolution, privilege level, system architecture, and Operating System. The first WORD of the HTTP Payload represents the Loki-Bot version. The second WORD of the HTTP Payload is the Payload Type. Below is the table of identified payload types: BYTE PAYLOAD TYPE 0x26 Stolen Cryptocurrency Wallet 0x27 Stolen Application Data 0x28 Get C2 Commands from C2 Server 0x29 Stolen File 0x2A POS (Point of Sale?) 0x2B Keylogger Data 0x2C Screenshot The 11th byte of the HTTP Payload begins the Binary ID. This might be useful in tracking campaigns or specific threat actors. This value value is typically “ckav.ru”. If you come across a Binary ID that is different from this, take note! Loki-Bot encrypts both the URL and the registry key used for persistence using Triple DES encryption. The Content-Key HTTP Header value is the result of hashing the HTTP Header values that precede it. This is likely used as a protection against researchers who wish to poke and prod at Loki-Bot’s C2 infrastructure. Loki-Bot can accept the following instructions from the C2 Server: BYTE INSTRUCTION DESCRIPTION 0x00 Download EXE & Execute 0x01 Download DLL & Load #1 0x02 Download DLL & Load #2 0x08 Delete HDB File 0x09 Start Keylogger 0x0A Mine & Steal Data 0x0E Exit Loki-Bot 0x0F Upgrade Loki-Bot 0x10 Change C2 Polling Frequency 0x11 Delete Executables & Exit Suricata Signatures RULE SID RULE NAME 2024311 ET TROJAN Loki Bot Cryptocurrency Wallet Exfiltration Detected 2024312 ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M1 2024313 ET TROJAN Loki Bot Request for C2 Commands Detected M1 2024314 ET TROJAN Loki Bot File Exfiltration Detected 2024315 ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M1 2024316 ET TROJAN Loki Bot Screenshot Exfiltration Detected 2024317 ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M2 2024318 ET TROJAN Loki Bot Request for C2 Commands Detected M2 2024319 ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M2
APT GROUPfinancial
lokilocker — tracked by MISP Galaxy (ransomware).
Updated: 2026-08-05
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.lojax
APT GROUP
Malware family tracked by Malpedia. ID: win.logtu
APT GROUP
Malware family tracked by Malpedia. ID: win.logpos
APT GROUP
Malware family tracked by Malpedia. ID: win.logedrut
APT GROUP
Malware family tracked by Malpedia. ID: win.lodeinfo
APT GROUP
Loda is a previously undocumented AutoIT malware with a variety of capabilities for spying on victims. Proofpoint first observed Loda in September of 2016 and it has since grown in popularity. The name Loda is derived from a directory to which the malware author chose to write keylogger logs. It should be noted that some antivirus products currently detect Loda as “Trojan.Nymeria”, although the connection is not well-documented.
APT GROUP
Malware family tracked by Malpedia. ID: win.lock_pos
APT GROUP
For the lack of a better name, this is a VBS-based loader that was used in beginning of 2018 to deliver win.locky.
Updated: 2018-01-11
View profile →
Malware family tracked by Malpedia. ID: win.locky_decryptor
Updated: 2016-04-19
View profile →
APT GROUPfinancialhigh
Locky is a high profile ransomware family that first appeared in early 2016 and was observed being active until end of 2017. It encrypts files on the victim system and asks for ransom in order to have back original files. In its first version it added a .locky extension to the encrypted files, and in recent versions it added the .lukitus extension. The ransom amount is defined in BTC and depends on the actor.
APT GROUPfinancialhigh
A ransomware first observed in July 2021.
APT GROUPfinancialhigh
According to Trend Micro, LockerGoga is a ransomware that has been used in multiple attacks, most notably against Altran Technologies and Norsk Hydro. It encrypts a range of documents and source code files but certain versions had little to no whitelist that would protect import system files such as the Windows Boot Manager.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: elf.lockbit
T1486T1490T1489🎯 healthcare🎯 education
APT GROUPfinancialhigh
According to PCrisk, LOBSHOT is a type of malware with a feature called hVNC (Hidden Virtual Network Computing) that allows attackers to access a victim's computer without being noticed. The hVNC component is effective in evading fraud detection systems. Also, LOBSHOT is being used to carry out financial crimes through the use of banking trojan and information-stealing functionalities.
APT GROUP
According to AlienVault, LiteHTTP bot is a new HTTP bot programmed in C#. The bot has the ability to collect system information, download and execute programs, and update and kill other bots present on the system. The source is on GitHub: https://github.com/zettabithf/LiteHTTP
APT GROUP
According to CarbonBlack, LiteDuke is a third stage backdoor. It appears to use the same dropper as PolyglotDuke. Its payload makes use of an AES encrypted SQLite database to store its configuration. LiteDuke supports a large number of individual commands including host information retrieval, file upload and download, and the ability to execute other code. LiteDuke C2 servers appear to be compromised servers, and the malware communicates with them using normal HTTP requests. It attempts to use a realistic User-Agent string to blend in better with normal HTTP traffic. ESET have dubbed it LiteDuke because it uses SQLite to store information such as its configuration.
APT GROUP
Malware family tracked by Malpedia. ID: win.listrix
APT GROUP
Malware family tracked by Malpedia. ID: win.liontail
APT GROUP
Malware family tracked by Malpedia. ID: win.linseningsvr
APT GROUP
Malware family tracked by Malpedia. ID: win.limitail
Updated: 2017-04-29
View profile →
APT GROUPfinancialhigh
## Description Simple yet powerful RAT for Windows machines. This project is simple and easy to understand, It should give you a general knowledge about dotNET malwares and how it behaves. --- ## Main Features - **.NET** - Coded in Visual Basic .NET, Client required framework 2.0 or 4.0 dependency, And server is 4.0 - **Connection** - Using pastebin.com as ip:port , Instead of noip.com DNS. And Also using multi-ports - **Plugin** - Using plugin system to decrease stub's size and lower the AV detection - **Encryption** - The communication between server & client is encrypted with AES - **Spreading** - Infecting all files and folders on USB drivers - **Bypass** - Low AV detection and undetected startup method - **Lightweight** - Payload size is about 25 KB - **Anti Virtual Machines** - Uninstall itself if the machine is virtual to avoid scanning or analyzing - **Ransomware** - Encrypting files on all HHD and USB with .Lime extension - **XMR Miner** - High performance Monero CPU miner with user idle\active optimizations - **DDoS** - Creating a powerful DDOS attack to make an online service unavailable - **Crypto Stealer** - Stealing Cryptocurrency sensitive data - **Screen-Locker** - Prevents user from accessing their Windows GUI - **And more** - On Connect Auto Task - Force enable Windows RDP - Persistence - File manager - Passowrds stealer - Remote desktop - Bitcoin grabber - Downloader - Keylogger
APT GROUP
Malware family tracked by Malpedia. ID: win.limepad
APT GROUP
Malware family tracked by Malpedia. ID: win.limeminer
Malware family tracked by Malpedia. ID: win.limedownloader
APT GROUPfinancial
Lilith is a C/C++-based double-extortion ransomware that emerged in July 2022, targeting 64-bit Windows systems and sharing code with the Babuk ransomware family, with its first confirmed victim being a large South American construction firm.
Infra: 🔗 yeuajcizwytgmrntijhx
RLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.ligsterac
APT GROUP
According to Mandiant, LIGHTWORK is a disruption tool written in C++ that implements the IEC-104 protocol to modify the state of RTUs over TCP. It crafts configurable IEC-104 ASDU messages, to change the state of RTU IOAs to ON or OFF. This sample works in tandem with PIEHOP, which sets up the execution.
APT GROUP
According to Mandiant, this is a tunneler, likely based on an open-source Socks4a proxy, that communicates using Azure cloud infrastructure.
Lightning stealer can target 30+ Firefox and Chromium-based browsers and steal crypto wallets, Telegram data, Discord tokens, and Steam user’s data. Unlike other info stealers, Lightning Stealer stores all the stolen data in the JSON format for exfiltration.
APT GROUP
Malware family tracked by Malpedia. ID: win.lightneuron
APT GROUP
LightlessCan is a complex HTTP(S) RAT, that is a successor of the Lazarus RAT named BlindingCan. In Q2 2022 and Q1 2023, it was deployed in targeted attacks against an aerospace company in Spain and a technology company in India. Besides the support for commands already present in BlindingCan, its most significant update is mimicked functionality of many native Windows commands: • ipconfig • net • netsh advfirewall firewall • netstat • reg • sc • ping (for both IPv4 and IPv6 protocols) • wmic process call create • nslookup • schstasks • systeminfo • arp These native commands are often abused by the attackers after they have gotten a foothold in the target’s system. Lightless is able to execute them discreetly within the RAT itself, rather than being executed visibly in the system console. This provides stealthiness, both in evading real-time monitoring solutions like EDRs, and postmortem digital forensic tools. LightlessCan use RC6 for decryption of its configuration, and also for encryption and decryption of network traffic.
APT GROUP
Malware family tracked by Malpedia. ID: win.lightbunny
APT GROUP
Malware family tracked by Malpedia. ID: win.liderc