Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,725 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.creamsicle
APT GROUPfinancial
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
RLUpdated: N/A
View profile →
APT GROUP
According to Cisco Talos, CRAT is a remote access trojan with plugin capabilites, used by Lazarus since at least May 2020.
APT GROUP
Malware family tracked by Malpedia. ID: win.cradlecore
Updated: 2017-05-12
View profile →
APT GROUP
CRACKSHOT is a downloader that can download files, including binaries, and run them from the hard disk or execute them directly in memory. It is also capable of placing itself into a dormant state.
APT GROUPfinancialhigh
According to ANY.RUN, this is a dropper for win.privateloader and its execution will lead to a cascade of downloads with a large variety of additional malware. The families include more loaders, information stealers, cryptominers, a proxy bot, and ultimately also ransomware. The execution order is orchestrated, e.g. as in data is stolen and exfiltrated before encryption. It is distributed through advertized cracked software, e.g. IDA Pro.
APT GROUP
CozyDuke is not simply a malware toolset; rather, it is a modular malware platform formed around a core backdoor component. This component can be instructed by the C&C server to download and execute arbitrary modules, and it is these modules that provide CozyDuke with its vast array of functionality. Known CozyDuke modules include: • Command execution module for executing arbitrary Windows Command Prompt commands • Password stealer module • NT LAN Manager (NTLM) hash stealer module • System information gathering module • Screenshot module
APT GROUP
PCRisk notes that CoViper is yet another Coronavirus/COVID-19-themed malware infection, most likely proliferated as a file related to the pandemic. It operates by rewriting the system Master Boot Record (MBR). It does not delete the original, but rather creates a backup and replaces it with a custom MBR. Typically, malicious software that modifies MBRs do so to prevent the Operating System (OS) from being booted (i.e., started). It also displays a screen-encompassing message, often containing a ransom message - this disables user access to the device.
APT GROUP
Destructive "joke" malware that ultimately deploys a wiper for the MBR.
APT GROUP
Covicli is a modified SSLeay32 dynamic library designated as a backdoor. The dynamic library allows the attacker to communicate with the C2 over openSSL.
APT GROUP
Malware family tracked by Malpedia. ID: win.cova
APT GROUPfinancialhigh
According to Silent Push, this malware exists in multiple versions, including .NET, PowerShell, and JScript. They believe it is part of an IAB toolset or used by a affiliate with ties to LockBit, BlackBasta, and Qilin ransomware groups. CountLoader was also recently used in a PDF-based phishing lure targeting individuals in Ukraine, in a campaign that impersonated the Ukrainian police.
APT GROUP
Malware family tracked by Malpedia. ID: win.cotx
APT GROUP
Malware family tracked by Malpedia. ID: win.cosmicduke
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.coronavirus_ransomware
APT GROUP
Malware family tracked by Malpedia. ID: win.coreshell
APT GROUP
Malware family tracked by Malpedia. ID: win.coredn
APT GROUP
Malware family tracked by Malpedia. ID: win.corebot
APT GROUP
According to PCRIsk, CopperStealer, also known as Mingloa, is a malicious program designed to steal sensitive/personal information. It also has the capability to cause chain infections (i.e., download/install additional malware). Significant activity of CopperStealer has been observed in Brazil, India, Indonesia, Pakistan, and the Philippines. At the time of research, this malware had been noted being spread via websites offering illegal activation tools ("cracks") for licensed software products.
APT GROUP
According to Trend Micro, CopperStealth’s infection chain involves dropping and loading a rootkit, which later injects its payload into explorer.exe and another system process. These payloads are responsible for downloading and running additional tasks. The rootkit also blocks access to blocklisted registry keys and prevents certain executables and drivers from running. The task module is able to download and run additional payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.cookiebag
APT GROUP
FireEye described this malware as a proxy-aware backdoor that communicates using a custom-encrypted binary protocol. It may use the registry to store optional configuration data. The backdoor has been observed to support 26 commands that include directory traversal, file system manipulation, data archival and transmission, and command execution.
APT GROUPfinancial
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
Affiliates: Wazawaka
Infra: 🔗 continewsnv5otx5kaoj🔗 continews.click💬 m232fdxbfmbrcehbrj5i+6 more
🇷🇺 RU
RLUpdated: N/A
View profile →
APT GROUP
[Confucius](https://attack.mitre.org/groups/G0142) is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between [Confucius](https://attack.mitre.org/groups/G0142) and [Patchwork](https://attack.mitre.org/groups/G0040), particularly in their respective custom malware code and targets.(Citation: TrendMicro Confucius APT Feb 2018)(Citation: TrendMicro Confucius APT Aug 2021)(Citation: Uptycs Confucius APT Jan 2021)
T1566.002T1203T1566.001
APT GROUP
Malware family tracked by Malpedia. ID: win.conficker
concealment troy
Technical ID: concealment_troy
APT GROUP
Malware family tracked by Malpedia. ID: win.concealment_troy
APT GROUP
Malware family tracked by Malpedia. ID: win.comrade_circle
APT GROUP
Malware family tracked by Malpedia. ID: win.computrace
APT GROUP
Malware family tracked by Malpedia. ID: win.compfun
APT GROUP
Malware family tracked by Malpedia. ID: win.comodosec
APT GROUP
Malware family tracked by Malpedia. ID: win.common_magic
APT GROUPespionageadvanced
ComLook is a malicious plugin for the mail client "The Bat!", written in C++ and compiled with MSVC 10.0. It implements malicious commands like PutFile, GetFile, SetConfig, GetConfig, and Command. It contains hard-coded email addresses and other information, indicating a target in Azerbaijan. It was first uploaded to VirusTotal on January 12, 2022, and is associated with the APT group Turla. It appears to be a targeted deployment.
APT GROUP
Malware family tracked by Malpedia. ID: win.comfoo
APT GROUP
ComeBacker was found in a backdoored Visual Studio project that was used to target security researchers in Q4 2020 and early 2021. It is an HTTP(S) downloader. It uses the AES CBC cipher implemented through the OpenSSL's EVP interface for decryption of its configuration, and also for encryption and decryption of the client-server communication. The parameter names in HTTP POST requests of the client are generated randomly. As the initial connection, the client exchanges the keys with the server via the Diffie–Hellman key agreement protocol for the elliptic curve secp521r1. The client generates a random 32-bytes long private key, and the server responds with its public key in a buffer starting with the wide character "0". Next, the clients sends the current local time, and the server responds with a buffer containing multiple values separated with the pipe symbol. The typical values are the encrypted payload, the export to execute, and the MD5 hash of the decrypted DLL to verify the authenticity of the payload. There are variants of ComeBacker without statically linked OpenSSL. In that case, the key exchange is omitted and AES CBC is replaced with HC-256.
APT GROUP
Malware family tracked by Malpedia. ID: win.combos
APT GROUP
Malware family tracked by Malpedia. ID: win.combojack
APT GROUP
Malware family tracked by Malpedia. ID: win.colony
Malware family tracked by Malpedia. ID: win.collectorgoomba
Malware family tracked by Malpedia. ID: win.collection_rat
According to cloudsek, Colibri Loader is a form of malware designed to facilitate the installation of additional malware types on an already compromised system. This loader employs various techniques to evade detection, such as excluding the Import Address Table (IAT) and utilizing encrypted strings to complicate analysis. Similar to other loader malware, Colibri can be utilized to deploy information-stealing malware, potentially leading to significant loss of sensitive data. As a result, users should exercise caution when encountering unfamiliar files on their systems.