Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.doublepulsar
APT GROUP
Malware family tracked by Malpedia. ID: win.doubleloader
APT GROUP
Malware family tracked by Malpedia. ID: win.doublefinger
APT GROUP
Malware family tracked by Malpedia. ID: elf.doublefantasy
APT GROUP
DOUBLEBACK is a newly discovered fileless malware deployed as part of an attack campaign that took place in December 2020. The threat actors responsible for the operations are tracked as UNC2529 by researchers. According to their findings, DOUBLEBACK is the final payload delivered onto the compromised systems. Its task is to establish and maintain a backdoor on the victim's machine.
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.dot_ransomware
APT GROUP
According to Mandiant, DOSTEALER is a dataminer that mines browser login and cookie data. It is also capable of taking screenshots and logging keystrokes.
APT GROUP
Infrastructure and programs used for, as its name suggests, DDoSing. It used to be written in Python, nowadays it's written in Go. Clients: - Are written in Go. (Used to be written in Python.) - Do not seem to differ significantly across OS deployments. (Confirmed on Windows, MacOS, Linux, Android) - Seem to be partly run by NoName themselves. - Partly also run voluntarily, recruited via dedicated Telegram channels. Participants are rewarded with cryptocurrency. Prints a suggestion to use a VPN for Russia-based launches. (This yields IP-based blocking as rather ineffective, consider behavioral analysis instead.) Configuration: - Rotates near-daily. Can be browsed on https://witha.name/ (also reachable via http://withanamemwesdvodfhthjq25a5a3uas24cpgoa7qm6gchcerzpis6qd.onion/). - Is sent encrypted between C2 and Client. - Specifies target hostname, subpath, vector protocols, methods, ports, whether SSL is used, headers for HTTP, request bodies. - Any given config property can be randomly generated with per-use constraints. - Is provided by a multi-level hierarchy of C2 servers.
APT GROUP
Malware family tracked by Malpedia. ID: win.dorshel
APT GROUP
Malware family tracked by Malpedia. ID: win.dorkbot_ngrbot
APT GROUP
DoppelDridex is a fork of Indrik Spider's Dridex malware. DoppelDridex has been run as a parallel operation to Dridex with a different malware versioning system, different RSA key, and with different infrastructure.
APT GROUP
Malware family tracked by Malpedia. ID: win.doplugs
APT GROUP
Malware family tracked by Malpedia. ID: win.doorme
donut injector
Technical ID: donut_injector
APT GROUP
Donut is an open-source in-memory injector/loader, designed for execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It was used during attacks against U.S. organisations according to Threat Hunter Team (Symantec) and U.S. Defence contractors (Unit42). Github: https://github.com/TheWover/donut
APT GROUP
Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.
APT GROUP
Since late February 2023, Minodo Backdoor campaigns have been employed to deliver either the Project Nemesis information stealer or more sophisticated backdoors like Cobalt Strike. This backdoor collects basic system information, which it then transmits to the C2 server. In return, it receives an AES-encrypted payload. Notably, the Minodo Backdoor is designed to contact a different C2 address for domain-joined systems. This suggests that more capable backdoors, such as Cobalt Strike, are downloaded on higher-value targets instead of Project Nemesis.
APT GROUPfinancialhigh
DogHousePower is a PyInstaller-based ransomware targeting web and database servers. It is delivered through a PowerShell downloader and was hosted on Github.
APT GROUP
Malware family tracked by Malpedia. ID: win.dnwipe
APT GROUP
DNSMessenger makes use of DNS TXT record queries and responses to create a bidirectional Command and Control (C2) channel. This allows the attacker to use DNS communications to submit new commands to be run on infected machines and return the results of the command execution to the attacker.
APT GROUP
Malware family tracked by Malpedia. ID: win.dnschanger
APT GROUPespionageadvanced
DneSpy collects information, takes screenshots, and downloads and executes the latest version of other malicious components in the infected system. The malware is designed to receive a “policy” file in JSON format with all the commands to execute. The policy file sent by the C&C server can be changed and updated over time, making dneSpy flexible and well-designed. The output of each executed command is zipped, encrypted, and exfiltrated to the C&C server. These characteristics make dneSpy a fully functional espionage backdoor.
APT GROUP
DMSniff is a point-of-sale malware previously only privately sold. It has been used in breaches of small- and medium-sized businesses in the restaurant and entertainment industries. It uses a domain generation algorithm (DGA) to create lists of command-and-control domains on the fly.
APT GROUP
Malware family tracked by Malpedia. ID: win.dma_locker
APT GROUP
Malware family tracked by Malpedia. ID: win.dlrat
APT GROUP
Malware family tracked by Malpedia. ID: win.dizzyvoid
APT GROUP
Malware family tracked by Malpedia. ID: win.diztakun
APT GROUP
Malware family tracked by Malpedia. ID: win.divergent
APT GROUP
Malware family tracked by Malpedia. ID: win.disttrack
APT GROUP
Malware family tracked by Malpedia. ID: win.dispenserxfs
APT GROUP
Malware family tracked by Malpedia. ID: win.dispcashbr
APT GROUP
Malware family tracked by Malpedia. ID: win.disk_knight
APT GROUP
Malware family tracked by Malpedia. ID: win.dirtymoe
APT GROUP
Downloader.
APT GROUP
Malware family tracked by Malpedia. ID: win.dinodas_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.dimnie
APT GROUP
Downloader.
APT GROUPespionageadvanced
APT10's fork of the (open-source) Quasar RAT.
APT GROUP
A RAT written in .NET, used by FIN7 since 2021. In some instances dropped by ps1.powertrash.
APT GROUP
According to PCrisk, DiamondFox is highly modular malware offered as malware-as-a-service, and is for sale on various hacker forums. Therefore, cyber criminals who are willing to use DiamondFox do not necessarily require any technical knowledge to perform their attacks. Once purchased, this malware can be used to log keystrokes, steal credentials (e.g., usernames, email addresses, passwords), hijack cryptocurrency wallets, perform distributed denial of service (DDoS) attacks, and to carry out other malicious tasks. DiamondFox allows cyber criminals to choose which plug-ins to keep activated and see infection statistics in real-time.
APT GROUP
Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security firm Seculert, in December 2012. It infects PoS systems worldwide and steals sensitive information such as Credit Card and Debit Card information.