Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line parameters. The backdoor is capable of enumerating files and processes, enumerating drivers, enumerating remote desktop sessions, uploading and downloading files, creating and terminating processes, deleting files, creating a reverse shell, acting as a proxy server, and hijacking processes among its other functionality. The backdoor communicates with its C&C server using a custom binary protocol over TCP with port specified as a command-line parameter.
APT GROUP
Malware family tracked by Malpedia. ID: win.chches
APT GROUPfinancialhigh
CHCH is a Ransomware spotted in the wild in December 2019. It encrypts victim files and adds the extension .chch to them while it drops a ransomware note named: READ_ME.TXT
APT GROUPfinancialhigh
According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.
APT GROUP
Malware family tracked by Malpedia. ID: win.chargeweapon
APT GROUPespionageadvanced
According to Kaspersky GReAT and AMR, TajMahal is a previously unknown and technically sophisticated APT framework discovered by Kaspersky Lab in the autumn of 2018. This full-blown spying framework consists of two packages named Tokyo and Yokohama. It includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents and cryptography key stealers, and even its own file indexer for the victim’s machine. We discovered up to 80 malicious modules stored in its encrypted Virtual File System, one of the highest numbers of plugins they have ever seen for an APT toolset.
APT GROUP
Malware family tracked by Malpedia. ID: win.chairsmack
APT GROUP
Malware family tracked by Malpedia. ID: win.chainshot
APT GROUP
This malware made its first appearance during the middle to end of 2020, it specifically targets Brazil and the largest e-commerce company in Latin America, Mercado Livre. It is a multistage malware deployment which uses several legitimate Windows processes and open source tools to remain undetected.
APT GROUP
Malware family tracked by Malpedia. ID: win.chachi
APT GROUP
Malware family tracked by Malpedia. ID: win.ceta_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.centerpos
APT GROUP
Mandiant characterizes this malware as a downloader and shellcode stager.
APT GROUP
According to CrowdStrike, this backdoor was discovered embedded in the legitimate, signed version of CCleaner 5.33, and thus constitutes a supply chain attack.
APT GROUP
Malware family tracked by Malpedia. ID: win.catchamas
APT GROUP
CastleLoader payloads are distributed as portable executables containing an embedded shellcode, which then invokes the main module of the loader that, in turn, connects to the C2 server in order to fetch and execute the next-stage malware.
APT GROUP
ESET describes Casper as a well-developed reconnaissance tool, making extensive efforts to remain unseen on targeted machines. Of particular note are the specific strategies adopted against anti-malware software. Casper was used against Syrian targets in April 2014, which makes it the most recent malware from this group publicly known at this time.
APT GROUP
Malware family tracked by Malpedia. ID: win.cashransom
APT GROUP
Malware family tracked by Malpedia. ID: win.carrotbat
APT GROUP
CARROTBALL is a simple FTP downloader built to deploy SYSCON, a Remote Access Trojan used by the same threat actor. Discovered by Unit 42 in late 2019, the downloader was adopted for use in spear phishing attacks against US government agencies.
APT GROUP
CargoBay is a newer malware family which was first observed in 2022 and is notable for being written in the Rust language. CargoBay is likely based on source code taken from 'Black Hat Rust' GitHub project (https://github.com/skerkour/black-hat-rust). CargoBay is usually distributed via phishing emails, and the malware binaries may be disguised as legitimate applications. Upon execution, the malware starts by performing environmental checks such as checking its execution path and the configured system language. If the tests pass, then the malware proceeds to gather basic system information and register with its C2 via HTTP from which it receives JSON-formatted jobs to carry out. CargoBay can execute commands via the command line and downloading additional malware binaries.
APT GROUPespionageadvanced
Cardinal RAT is a remote access Trojan capable of stealing username and credentials, cleaning out cookies from browsers, keylogging and capturing screenshots on targeted systems. It is delivered via a downloader dubbed “Carp” which uses malicious macros in Microsoft Excel documents to compile embedded source code into an executable, which then deploys the Cardinal RAT malware family.
APT GROUP
Malware family tracked by Malpedia. ID: win.carberp
APT GROUPespionageadvanced
[Carbanak](https://attack.mitre.org/groups/G0008) is a cybercriminal group that has used [Carbanak](https://attack.mitre.org/software/S0030) malware to target financial institutions since at least 2013. [Carbanak](https://attack.mitre.org/groups/G0008) may be linked to groups tracked separately as [Cobalt Group](https://attack.mitre.org/groups/G0080) and [FIN7](https://attack.mitre.org/groups/G0046) that have also used [Carbanak](https://attack.mitre.org/software/S0030) malware.(Citation: Kaspersky Carbanak)(Citation: FireEye FIN7 April 2017)(Citation: Europol Cobalt Mar 2018)(Citation: Secureworks GOLD NIAGARA Threat Profile)(Citation: Secureworks GOLD KINGSWOOD Threat Profile)
T1588.002T1543.003T1219
APT GROUP
Malware family tracked by Malpedia. ID: win.cannon
APT GROUP
Cannibal Rat is a python written remote access trojan with 4 versions as of March 2018. The RAT is reported to impact users of a Brazilian public sector management school. The RAT is distributed in a py2exe format, with the python27.dll and the python bytecode stored as a PE resource and the additional libraries zipped in the overlay of the executable.
APT GROUP
There is no lot of IOCs in this article so we take one sample and try to extract some interesting IOCs, our findings below :
CamuBot sample : 37ca2e37e1dc26d6b66ba041ed653dc8ee43e1db71a705df4546449dd7591479
Dropped Files on disk :
C:\Users\user~1\AppData\Local\Temp\protecao.exe : 0af612461174eedec813ce670ba35e74a9433361eacb3ceab6d79232a6fe13c1
C:\Users\user~1\AppData\Local\Temp\Renci.SshNet.dll : 3E3CD9E8D94FC45F811720F5E911B892A17EE00F971E498EAA8B5CAE44A6A8D8
C:\ProgramData\m.msi : AD90D4ADFED0BDCB2E56871B13CC7E857F64C906E2CF3283D30D6CFD24CD2190
Protecao.exe try to download hxxp://www.usb-over-network.com/usb-over-network-64bit.msi
A new driver is installed : C:\Windows\system32\drivers\ftusbload2.sys : 9255E8B64FB278BC5FFE5B8F70D68AF8
ftusbload2.sys set 28 IRP handlers.
APT GROUP
Malware family tracked by Malpedia. ID: win.campoloader
APT GROUP
PWC describes this malware as a backdoor, capable of file management, upload and download of files, and execution of commands.
APT GROUP
Malware family tracked by Malpedia. ID: win.calmthorn
APT GROUPespionageadvanced
CadelSpy is a spyware supposedly used by Iranian threat actors. It has several functions such as logging keystrokes, record audio, capture screenshots and webcam photos, and steal any documents that are sent to a printer.
APT GROUP
CaddyWiper is another destructive malware believed to be deployed to target Ukraine.
CaddyWiper wipes all files under C:\Users and all also all files under available drives from D: to Z: by overwriting the data with NULL value. If the target file is greater than 0xA00000 bytes in size (10MB), it will only wipe the first 0xA00000 bytes.
It also wipes disk partitions from \\.\PHYSICALDRIVE9 to \\.\PHYSICALDRIVE0 by overwriting the first 0x780 bytes with NULL.
APT GROUP
Malware family tracked by Malpedia. ID: win.cabart
APT GROUP
Malware family tracked by Malpedia. ID: win.c0d0so0
APT GROUP
Malware family tracked by Malpedia. ID: win.bypassboss
APT GROUP
Malware family tracked by Malpedia. ID: win.byeby
APT GROUP
Malware family tracked by Malpedia. ID: win.buzus
APT GROUP
Malware family tracked by Malpedia. ID: win.buterat
APT GROUP
According to Mandiant, BURNBOOK is a dropper for TEARPAGE.
APT GROUP
Malware family tracked by Malpedia. ID: win.bunnyloader