Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.csext
APT GROUP
Malware family tracked by Malpedia. ID: win.crystal_ransom
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptxxxx
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptowire
APT GROUPfinancialhigh
CryptoWall is a ransomware, is usually spread by spam and phishing emails, malicious ads, hacked websites, or other malware and uses a Trojan horse to deliver the malicious payload.
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoslay
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoshuffler
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoshield
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptorium
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoluck
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptodarkrubix
APT GROUP
Malware family tracked by Malpedia. ID: win.cryptoclippy
APT GROUP
CrypticConvo is a dropper trojan which appears to be embedded in an automatic generator framework to deliver the FakeM trojan. According to PaloaltoNetworks CrypticConvo and several additional trojans are believed to be included in a meta framework used by the "Scarlet Mimic" threat actor in order to quickly evade AV systems.
APT GROUP
A typical infostealer, capable of obtaining credentials for browsers, crypto currency wallets, browser cookies, credit cards, and creates screenshots of the infected system. All stolen data is bundled into a zip-file that is uploaded to the c2.
APT GROUP
Malware family tracked by Malpedia. ID: win.crypt0l0cker
APT GROUP
Malware family tracked by Malpedia. ID: win.crypmic
APT GROUP
Malware family tracked by Malpedia. ID: win.crutch
APT GROUP
Malware family tracked by Malpedia. ID: win.cruloader
APT GROUPespionageadvanced
According to Trend Micro, this is a custom loader for win.cobalt_strike, used by Earth Longzhi (a subgroup of APT41).
APT GROUP
According to FireEye, CROSSWALK is a skeletal, modular backdoor capable of system survey and adding modules in response to C&C replies.
APT GROUP
According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017. It enables operators to run command line tools, exfiltrate files, and upload files to the infected machine. CrimsonIAS is notable as it listens for incoming connections only; making it different from typical Windows backdoors that beacons out.
APT GROUP
It was first discovered in 2017 and has since been used to attack organizations around the world. The malware is often distributed through phishing emails or by exploiting vulnerabilities in outdated security software. Once Crimson RAT is installed on a computer, it can be used to steal data, spy on users, and even take control of the infected computers.
Some of the features of Crimson RAT include:
Remote control of infected computers
Data theft, such as passwords, files, and emails
User spying
Takeover of infected computers
Locking of infected computers
Extortion of payments
APT GROUP
Malware family tracked by Malpedia. ID: win.crenufs
APT GROUP
Malware family tracked by Malpedia. ID: win.creep_exfil
APT GROUP
Malware family tracked by Malpedia. ID: win.creepysnail
APT GROUPespionageadvanced
Malware family tracked by Malpedia. ID: win.credraptor
APT GROUP
Malware family tracked by Malpedia. ID: win.credomap
APT GROUP
A tool that implements the creation of a hidden account on Windows through cloning accounts via the Registry.
APT GROUP
Malware family tracked by Malpedia. ID: win.creamsicle
APT GROUP
According to Cisco Talos, CRAT is a remote access trojan with plugin capabilites, used by Lazarus since at least May 2020.
APT GROUP
Malware family tracked by Malpedia. ID: win.cradlecore
APT GROUP
CRACKSHOT is a downloader that can download files, including binaries, and run them from the hard disk or execute them directly in memory. It is also capable of placing itself into a dormant state.
APT GROUPfinancialhigh
According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware.
The families include more loaders, information stealers, cryptominers, a proxy bot, and ultimately also ransomware.
The execution order is orchestrated, e.g. as in data is stolen and exfiltrated before encryption.
It is distributed through advertized cracked software, e.g. IDA Pro.
APT GROUP
CozyDuke is not simply a malware toolset; rather, it is a modular malware platform formed around
a core backdoor component. This component can be instructed by the C&C server to download
and execute arbitrary modules, and it is these modules that provide CozyDuke with its vast array
of functionality. Known CozyDuke modules include:
• Command execution module for executing arbitrary Windows Command Prompt commands
• Password stealer module
• NT LAN Manager (NTLM) hash stealer module
• System information gathering module
• Screenshot module
APT GROUP
PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the pandemic. It operates by rewriting the system Master Boot Record (MBR). It does not delete the original, but rather creates a backup and replaces it with a custom MBR.
Typically, malicious software that modifies MBRs do so to prevent the Operating System (OS) from being booted (i.e., started). It also displays a screen-encompassing message, often containing a ransom message - this disables user access to the device.
APT GROUP
Destructive "joke" malware that ultimately deploys a wiper for the MBR.
APT GROUP
Covicli is a modified SSLeay32 dynamic library designated as a backdoor.
The dynamic library allows the attacker to communicate with the C2 over openSSL.
APT GROUP
Malware family tracked by Malpedia. ID: win.cova