Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.bitter_rat
APT GROUPfinancialhigh
SHADYCAT is a dropper and spreader component for the HERMES 2.1 RANSOMWARE radical edition.
APT GROUP
Malware family tracked by Malpedia. ID: win.bitsloth
APT GROUP
Malware family tracked by Malpedia. ID: win.bistromath
APT GROUP
Malware family tracked by Malpedia. ID: win.biscuit
APT GROUP
BIOPASS RAT is a malware family which targets online gambling companies in China by leveraging a watering hole attack. This Remote Access Trojan (RAT) is unique in that it leverages the Open Broadcaster Software (OBS) framework to monitor the user's screen.
APT GROUP
Malware family tracked by Malpedia. ID: win.bioload
APT GROUP
Malware family tracked by Malpedia. ID: win.biodata
APT GROUP
Binanen is a dropper that drops and executes a section of itself into a hidden dummy process. According to F-Secure, it executes command line tools such as (for example) asipconfig, which is useful to retrieve the network configuration. The malware aims to steal information about the machine, the username, installed software and, more generally speaking, it potentially can carry out actions on the compromised machine.
APT GROUP
BillGates is a modularized malware, of supposedly Chinese origin. Its main functionality is to perform DDoS attacks, with support for DNS amplification. Often, BillGates is delivered with one or many backdoor modules.
BillGates is available for *nix-based systems as well as for Windows.
On Windows, the (Bill)Gates installer typically contains the various modules as linked resources.
APT GROUP
Malware family tracked by Malpedia. ID: win.bifrose
BI D Ransomware
Technical ID: BI_D Ransomware
APT GROUPespionageadvanced
Small and relatively simple ransomware for Windows. Gives files the .BI_D extension after encrypting them with a combination of RSA/AES. Persistence achieved via the Windows Registry. Kills all processes on the victim machine besides itself and a small whitelist of mostly Windows sytem processes and kills shadow copies.
APT GROUP
A Windows version of the BiBi wiper that was found by BlackBerry.
BH A006
Technical ID: BH_A006
APT GROUP
According to Volexity, a loader observed to be used with multiple malware families, among them LIGHTSPY.
APT GROUP
BHunt collects the crypto wallets of its victims. The malware consists of several functions/modules, e.g. a reporting module that reports the presence of crypto wallets on the target computers to the C2 server. It searches for many different cryptocurrencies (e.g. Atomic, Bitcoin, Electrum, Ethereum, Exodus, Jaxx and Litecoin). The Blackjack module is used to steal wallets, Sweet_Bonanza steals victims' browser passwords. There are also modules like the Golden7 or the Chaos_crew module.
APT GROUP
Malware family tracked by Malpedia. ID: win.bfbot
APT GROUP
Bezigate is a Trojan horse that opens a back door on the compromised computer. It may also download potentially malicious files.
The Trojan may perform the following actions:
List, move, and delete drives
List, move, and delete files
List processes and running Windows titles
List services
List registry values
Kill processes
Maximize, minimize, and close windows
Upload and download files
Execute shell commands
Uninstall itself
APT GROUPfinancialhigh
Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012. The malware began as a banking Trojan and is now packed with features that allow its operators to practically take over a victim’s machine and steal sensitive information.
APT GROUP
Malware family tracked by Malpedia. ID: win.bestkorea
APT GROUP
Malware family tracked by Malpedia. ID: win.berserk_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.bernhardpos
APT GROUP
Malware family tracked by Malpedia. ID: win.berbomthum
APT GROUP
Malware family tracked by Malpedia. ID: win.berbew
APT GROUP
Once set up in the system, Trojan.Belonard replaces the list of available game servers in the game client and creates proxies on the infected computer to spread the Trojan. As a rule, proxy servers show a lower ping, so other players will see them at the top of the list. By selecting one of them, a player gets redirected to a malicious server where their computer become infected with Trojan.Belonard.
APT GROUP
Malware family tracked by Malpedia. ID: win.bellaciao
APT GROUP
Malware family tracked by Malpedia. ID: win.beepservice
APT GROUP
BEENDOOR is a XMPP based trojan. It is capable of taking screenshots of the victim's desktop.
APT GROUP
Malware family observed in conjunction with PlugX infrastructure in 2013.
APT GROUP
Bedep has been mostly observed in ad-fraud campaigns, although it can also generally load modules for different tasks. It was dropped by the Angler Exploit Kit.
APT GROUP
BeaverTail is a JavaScript malware primarily distributed through NPM packages. It is designed for information theft and to load further stages of malware, specifically a multi-stage Python-based backdoor known as InvisibleFerret. BeaverTail targets cryptocurrency wallets and credit card information stored in the victim's web browsers. Its code is heavily obfuscated to evade detection. Threat actors can either upload malicious NPM packages containing BeaverTail to GitHub or inject BeaverTail code into legitimate NPM projects. Researchers have identified additional Windows and macOS variants, indicating that the BeaverTail malware family is likely still under development.
APT GROUP
According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C. BEATDROP uses Trello to store victim information and retrieve AES-encrypted shellcode payloads to be executed. BEATDROP then injects and executes downloaded payloads into a suspended process. Upon execution, BEATDROP maps a copy of ntdll.dll into memory to execute shellcode in its own process. The sample then creates a suspended thread with RtlCreateUserThread the thread points to NtCreateFile. The sample changes execution to shellcode and resumes the thread. The shellcode payload is retrieved from Trello and is targeted per victim. Once the payload has been retrieved, it is deleted from Trello.
APT GROUP
According to CERT-UA, this is a malware developed using the C++ programming language. It provides capabilities for downloading, decryption (chacha20-poly150) and performing PowerShell scripts, as well as uploading the command's results.
APT GROUP
According to Symantec, Beapy is a cryptojacking campaign impacting enterprises that uses the EternalBlue exploit and stolen and hardcoded credentials to spread rapidly across networks.
APT GROUP
According to Threatray, BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use until at least 2025.
APT GROUPfinancialhigh
360 Security Center describes BBtok as a banking trojan targeting Mexico.
APT GROUP
Malware family tracked by Malpedia. ID: win.bbsrat
APT GROUP
A rewrite of Bazarloader in the Nim programming language.
APT GROUP
BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor. Its called team9 backdoor (and the corresponding loader: team9 restart loader).
For now, it exclusively uses Emercoin domains (.bazar), thus the naming. FireEye uses KEGTAP as name for BazarLoader and BEERBOT for BazarBackdoor.
APT GROUP
According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise. This malware is used to execute payloads like Ursnif. Our team has discovered BATLOADER after executing installers for legitimate software (such as Zoom, TeamViewer Visual Studio) bundled with this malware. We have found those installers on compromised websites.
APT GROUP
Malware family tracked by Malpedia. ID: win.batel