Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Dexphot is a cryptominer Malware attacking windows machines to gain profit from their resources. It implements many techniques to evade common security systems and a file-less technology to become inject malicious behavior. According to Microsoft the Dexphot It hijacked legitimate system processes to disguise malicious activity. If not stopped, Dexphot is equipped by monitoring services and scheduled tasks triggering re-infection when defenders attempt to remove the malware.
APT GROUP
Malware family tracked by Malpedia. ID: win.dexbia
APT GROUP
Malware family tracked by Malpedia. ID: win.devopt
APT GROUP
Malware family tracked by Malpedia. ID: win.devils_rat
APT GROUP
According to Microsoft, DevilsTongue is a complex modular multi-threaded piece of malware written in C and C++ with several novel capabilities.
For files on disk, PDB paths and PE timestamps are scrubbed, strings and configs are encrypted, and each file has a unique hash. The main functionality resides in DLLs that are encrypted on disk and only decrypted in memory, making detection more difficult. Configuration and tasking data is separate from the malware, which makes analysis harder. DevilsTongue has both user mode and kernel mode capabilities.
APT GROUP
According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity. DesertBlade is responsible for iteratively overwriting and then deleting overwritten files on all accessible drives (sparing the system if it is a domain controller).
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: elf.derusbi
APT GROUP
Malware family tracked by Malpedia. ID: win.deria_lock
APT GROUP
Malware family tracked by Malpedia. ID: win.deputydog
APT GROUP
According to IBM X-Force, this is a loader component for Sheriff.
APT GROUP
According to ESET Research, DePriMon is a malicious downloader, with several stages and using many non-traditional techniques. To achieve persistence, the malware registers a new local port monitor – a trick falling under the “Port Monitors” technique in the MITRE ATT&CK knowledgebase. For that, the malware uses the “Windows Default Print Monitor” name; that’s why we have named it DePriMon. Due to its complexity and modular architecture, researcher believe it to be a framework.
DePriMon has been active since at least March 2017. DePriMon was detected in a private company, based in Central Europe, and at dozens of computers in the Middle East.
APT GROUPfinancialhigh
Dented is a banking bot written in C. It supports IE, Firefox, Chrome, Opera and Edge and comes with a simple POS grabber. Due to its modularity, reverse socks 5, tor and vnc can be added.
APT GROUP
Malware family tracked by Malpedia. ID: win.deltas
APT GROUP
According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking. Its specificity is the presence of a server part, which is usually installed on compromised MS Exchange servers in the form of a MOF (Managed Object Format) file using the Desired State Configuration (DCS) PowerShell tool), effectively turning a legitimate server into a malware control center.
APT GROUP
Trend Micro describes DeimosC2 as an open-source C&C framework that was released in June 2020. It is a fully-functional framework that allows for multiple attackers to access, create payloads for, and interact with victim computers. As a post-exploitation C&C framework, DeimosC2 will generate the payloads that need to be manually executed on computer servers that have been compromised through other means such as social engineering, exploitation, or brute-force attacks. Once it is deployed, the threat actors will gain the same access to the systems as the user account that the payload was executed as, either as an administrator or a regular user. Note that DeimosC2 does not perform active or privilege escalation of any kind.
APT GROUP
Described by Elastic as being associated with win.jupyter, and being used in the context of initial access, persistence, and C&C capabilities.
APT GROUPfinancialhigh
Defray is ransomware that appeared in 2017, and is targeted ransomware, mainly on the healthcare vertical.
The distribution of Defray has several notable characteristics:
According to Proofpoint:
"
Defray is currently being spread via Microsoft Word document attachments in email
The campaigns are as small as several messages each
The lures are custom crafted to appeal to the intended set of potential victims
The recipients are individuals or distribution lists, e.g., group@ and websupport@
Geographic targeting is in the UK and US
Vertical targeting varies by campaign and is narrow and selective
"
APT GROUP
According to Broadcom, DeerStealer is an information stealer written in Delphi and targeting devices running an windows operating system. The malware has hidden VNC capabilities for stealthy remote desktop control, collecting crypto wallets from USB sticks and over 800 browser extensions. It exfiltrates the stolen data in form of a ZIP archive to a botnet C2 server.
APT GROUP
Malware family tracked by Malpedia. ID: win.deep_rat
APT GROUP
According to Volexity, DEEPPOST is a post-exploitation data exfiltration tool used to send files to a remote system.
APT GROUP
According to Volexity, DEEPDATA is a modular post-exploitation tool for Windows that facilitates collection of sensitive information from a compromised system. This tool must be run from the command line of a system by an attacker.
APT GROUP
Malware family tracked by Malpedia. ID: win.deepcreep
APT GROUP
Malware family tracked by Malpedia. ID: win.decebal
APT GROUPfinancialhigh
Ransomware written in Go.
APT GROUPfinancialhigh
According to PCrisk, DearCry ransomware has been observed infecting systems via ProxyLogon vulnerabilities of Microsoft Exchange servers - mail and calendaring servers developed by Microsoft. While a patch has been released addressing these vulnerabilities, thousands of Microsoft Exchange servers remained unpatched at the time of research.
APT GROUP
Malware family tracked by Malpedia. ID: win.dealply
APT GROUP
Malware family tracked by Malpedia. ID: win.ddkong
APT GROUP
Malware family tracked by Malpedia. ID: win.ddkeylogger
APT GROUPfinancialhigh
A ransomware as used by MosesStaff, built around the DiskCryptor tool.
APT GROUP
DCRat is a typical RAT that has been around since at least June 2019.
APT GROUPfinancialhigh
Ransomware written in .NET.
APT GROUP
This malware uses DropBox as C&C channel.
APT GROUP
This Delphi loader misuses Cloud storage services, such as Google Drive to download the Delphi stager component. The Delphi stager has the actual payload embedded as a resource and starts it.
APT GROUP
Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors. The malware has a custom TCP/IP stack and is capable of hijacking connections.
APT GROUP
Malware family tracked by Malpedia. ID: win.datper
APT GROUP
Malware family tracked by Malpedia. ID: win.data_exfiltrator
APT GROUP
Malware family tracked by Malpedia. ID: win.daserf
APT GROUP
According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online. it is can be used as a Virtual Network Computing service, which means that the attackers can get full access to the targeted system via this malware. However, unlike a genuine Virtual Network Computing utility, the DarkVNC threat operates in the background silently. Therefore, it is highly likely that the victims may not notice that their systems have been compromised.
APT GROUPespionageadvanced
DarkVision_RAT is a highly customizable Remote Access Trojan (RAT) first identified in 2020. Written in C/C++ and assembler, it has gained popularity due to its low cost and broad range of functionalities, including keylogging, screenshot capture, file manipulation, process injection, remote code execution, and password theft. In July 2024, a malware campaign was observed distributing DarkVision_RAT using PureCrypter as a loader. This RAT communicates with its command and control server through a custom network protocol via sockets. It also employs evasion and privilege escalation techniques such as DLL hijacking, self-elevation, and process injection. DarkVision_RAT supports a wide array of commands and plugins, enabling additional capabilities like keylogging, remote access, password theft, audio recording, and screenshot capture.