Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.batchwiper
APT GROUP
Malware family tracked by Malpedia. ID: win.barkiofork
APT GROUP
Malware family tracked by Malpedia. ID: win.barbwire
Malware family tracked by Malpedia. ID: win.barbie
APT GROUP
According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.
APT GROUP
BanPolMex is a remote access trojan that uses TCP for communication. It uses an RC4-like stream cipher called Spritz for encryption of its configuration and network traffic. It sends detailed information about the victim's environment, like computer name, Windows version, free space of memory and all drives, processor identifier and architecture, system locale, system metrics, manufacturer, and network configuration. It supports almost 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration, and the download and execution of additional tools from the attacker’s C&C server. As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. However, in this case the indicis are convertible into a meaningful ASCII representation, that even suggests the functionality: SLEP, HIBN, DRIV, DIR, DIRP, CHDR, RUN, RUNX, DEL, WIPE, MOVE, FTIM, NEWF, DOWN, ZDWN, UPLD, PVEW, PKIL, CMDL, DIE, GCFG, SCFG, TCON, PEEX, PEIN. It has aclui.dll as the internal DLL name. It contains statically linked code from open-source libraries like libcurl (version 7.47.1) or zLib (version 0.15). BanPolMex RAT was delivered for victims of a watering hole campaign targeting employees of Polish and Mexican banks, that was discovered in February 2017. It is usually loaded by HOTWAX.
APT GROUP
Malware family tracked by Malpedia. ID: win.bankshot
APT GROUP
Malware family tracked by Malpedia. ID: win.banjori
APT GROUP
Malware family tracked by Malpedia. ID: win.bangat
APT GROUP
Bandook malware is a remote access trojan (RAT) first seen in 2007 and has been active for several years. Written in both Delphi and C++, it was first seen as a commercial RAT developed by a Lebanese creator named PrinceAli. Over the years, several variants of Bandook were leaked online, and the malware became available for public download.
Malware family tracked by Malpedia. ID: win.bandit
APT GROUP
Malware family tracked by Malpedia. ID: win.bancos
APT GROUP
Malware family tracked by Malpedia. ID: win.banatrix
APT GROUP
Malware family tracked by Malpedia. ID: win.bamital
APT GROUP
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf. BalkanDoor) is to deploy and leverage legitimate commercial software for remote administration. The malware has several additional components to help load, install and conceal the existence of the remote desktop software. A single long-term campaign involving BalkanRAT has been active at least from January 2016 and targeted accouting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina (considered that the contents of the emails, included links and decoy PDFs all were involving taxes). It was legitimaly signed and installed by an exploit of the WinRAR ACE vulnerability (CVE-2018-20250).
APT GROUP
According to ESET, BalkanDoor is a simple backdoor with a small number of commands (download and execute a file, create a remote shell, take a screenshot). It can be used to automate tasks on the compromised computer or to automatically control several affected computers at once. We have seen six versions of the backdoor, with a range of supported commands, evolve since 2016.
APT GROUP
Malware family tracked by Malpedia. ID: win.baldr
APT GROUP
Malware family tracked by Malpedia. ID: win.bagle
APT GROUP
Malware family tracked by Malpedia. ID: win.badpaw
APT GROUP
Malware family tracked by Malpedia. ID: win.badnews
APT GROUP
Malware family tracked by Malpedia. ID: win.badhatch
APT GROUP
BADFLICK, a backdoor that is capable of modifying the file system, generating a reverse shell, and modifying its command-and-control configuration.
APT GROUP
remote access tool (RAT) payload on Android devices
APT GROUP
According to Google, BADAUDIO is a custom first-stage downloader written in C++ that downloads, decrypts, and executes an AES-encrypted payload from a hard-coded command and control (C2) server. The malware collects basic system information, encrypts it using a hard-coded AES key, and sends it as a cookie value with the GET request to fetch the payload. The payload, in one case identified as Cobalt Strike Beacon, is decrypted with the same key and executed in memory.
APT GROUP
Malware family tracked by Malpedia. ID: win.backswap
APT GROUP
Malware family tracked by Malpedia. ID: win.backspace
APT GROUP
According to EclecticIQ, this is a downloader written in Go, able to exclude paths from Windows Defender in order to execute fetched payloads without raising alerts.
APT GROUP
Malware family tracked by Malpedia. ID: win.backoff
APT GROUP
Malware family tracked by Malpedia. ID: win.backnet
APT GROUP
Malware family tracked by Malpedia. ID: win.backconfig
APT GROUP
FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed. When executed, BACKBEND checks for the presence of the mutexes MicrosoftZj or MicrosoftZjBak (both associated with BACKSPACE variants). If either of the mutexes exist, the malware exits.
APT GROUP
Malware family tracked by Malpedia. ID: win.bachosens
APT GROUP
BabyShark is Microsoft Visual Basic (VB) script-based malware family first seen in November 2018. The malware is launched by executing the first stage HTA from a remote location, thus it can be delivered via different file types including PE files as well as malicious documents. It exfiltrates system information to C2 server, maintains persistence on the system, and waits for further instruction from the operator
APT GROUP
BABYMETAL is a command line network tunnel utility based on the TinyMet Meterpreter tool, primarily used to execute Meterpreter reverse shell payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.babylon_rat
APT GROUP
Malware family tracked by Malpedia. ID: win.babar
APT GROUP
According to PCrisk, Babadeda is a new sample in the crypters family, allowing threat actors to encrypt and obfuscate the malicious samples. The obfuscation allows malware to bypass the majority of antivirus protections without triggering any alerts. According to the researchers’ analysis, Babadeda leverages a sophisticated and complex obfuscation that shows a very low detection rate by anti-virus engines.
APT GROUPfinancialhigh
According to Porthas, this is a ransomware written in Golang, using a time-based kill switch to limit its execution.
APT GROUPfinancialhigh
According to Checkpoint, this malware is a wiper instead of ransomware as self-announced. It is manually written in FASM, unrecoverably overwriting data in blocks of 666 bytes, using multi-threading.
APT GROUP
AZORult is a credential and payment card information stealer. Among other things, version 2 added support for .bit-domains. It has been observed in conjunction with Chthonic as well as being dropped by Ramnit.