Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,726 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.bredolab
APT GROUPespionageadvanced
There is no reference available for this family and all known samples have version 1.0.0.
Pdb-strings in the samples suggest that this is an "exclusive" loader, known as "breakthrough" (maybe), e.g. C:\Users\Exclusiv\Desktop\хп-пробив\Release\build.pdb
The communication url parameters are pretty unique in this combination:
gate.php?hwid=<guid>&os=<OS>&build=1.0.0&cpu=8
<OS> is one of:
Windows95
Windows98
WindowsMe
Windows95family
WindowsNT3
WindowsNT4
Windows2000
WindowsXP
WindowsServer2003
WindowsNTfamily
WindowsVista
Windows7
Windows8
Windows10
APT GROUP
This is a backdoor which FireEye call the Breach Remote Administration Tool (BreachRAT), written in C++. The malware name is derived from the hardcoded PDB path found in the RAT: C:\Work\Breach Remote Administration Tool\Release\Client.pdb
APT GROUP
Malware family tracked by Malpedia. ID: win.brbbot
APT GROUP
Malware family tracked by Malpedia. ID: win.bravonc
APT GROUP
Brambul is a worm that spreads by using a list of hard-coded login credentials to launch a brute-force password attack against an SMB protocol for access to a victim’s networks.
APT GROUP
Malware family tracked by Malpedia. ID: win.brain
APT GROUPfinancial
BQTLock is a ransomware-as-a-service operation that emerged in 2025, using AES-256/RSA-4096 encryption with Monero payment demands, linked to pro-Palestinian hacktivist networks and targeting organizations with wave-based campaigns with 48-hour ransom deadlines.
Infra: 🔗 yywhylvqeqynzik6iboc…
RLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.bozok
APT GROUP
According to Checkpoint Research, this malware family has the ability to download and upload files, run commands and send the attackers the results. It has been observed being used by threat actor IndigoZebra.
APT GROUP
Malware family tracked by Malpedia. ID: win.bouncer
APT GROUP
Malware family tracked by Malpedia. ID: win.bottomloader
APT GROUP
Malware family tracked by Malpedia. ID: win.borr
APT GROUPespionageadvanced
The Borat RAT comes bundled with its components (e.g. binary builder, supporting modules, server certificates). According to Cyble this malware is an unique combination of RAT, Spyware, and ransomware.
The supporting modules are included; a few of the capabilities: Keylogger, Ransomware, Audio/Webcam Recording, Process Hollowing, Browser Credential/Discord Token Stealing, etc.
APT GROUP
BOOTWRECK is a master boot record wiper malware.
APT GROUP
FireEye describes BOOSTWRITE as a loader crafted to be launched via abuse of the DLL search order of applications which load the legitimate ‘Dwrite.dll’ provided by the Microsoft DirectX Typography Services. The application loads the ‘gdi’ library, which loads the ‘gdiplus’ library, which ultimately loads ‘Dwrite’. Mandiant identified instances where BOOSTWRITE was placed on the file system alongside the RDFClient binary to force the application to import DWriteCreateFactory from it rather than the legitimate DWrite.dll.
APT GROUP
Malware family tracked by Malpedia. ID: win.boombox
APT GROUP
Malware family tracked by Malpedia. ID: win.bookworm
APT GROUPespionageadvanced
This in .Net written malware is a classic information stealer. It can collect various information and can be depoyed in different configurations: "The full-featured version of the malware can log keystrokes, collect profile files of Mozilla Firefox and Google Chrome browsers, record sound from the microphone, grab desktop screenshots, capture photo from the webcam, and collect information about the version of the operation system and installed anti-virus software." (ESET)
This malware has been active since at least 2012.
APT GROUP
BookCodesRAT is a remote access trojan that uses HTTP(S) for communication. It supports around 25 commands that include operations on the victim’s filesystem, basic process management and the download and execution of additional tools from the attacker’s arsenal. They are indexed by 32-bit integers, starting with the value 0x97853646.
BookCodesRAT uses mostly compromised South Korean web servers for the C&C traffic and is usually deployed against South Korean targets.
APT GROUP
Malware family tracked by Malpedia. ID: win.bolek
APT GROUP
According to Mandiant, this malware family is attributed to potential chinese background and directly related to observed exploitation of Fortinet's SSL-VPN (CVE-2022-42475). There is also a Windows variant.
APT GROUP
Malware family tracked by Malpedia. ID: win.bohmini
APT GROUP
Bofamet Stealer is an infostealer managed through a web-based Command and Control (C2) panel, allowing attackers to configure operations, monitor infected hosts, and retrieve stolen data in real time.
APT GROUPfinancialhigh
According to Trend Micro, this is a ransomware written in Go, targeting Windows and MacOS environments that tries to disguise as LockBit by changing the wallpaper into a LockBit 2 screen. Most of the samples contained hard-coded AWS credentials, and the stolen data were uploaded to an Amazon S3 bucket controlled by the threat actor.
APT GROUP
This malware offers remote access capabilities but also has a DDoS module that was used against supporters of Ukraine.
APT GROUP
Malware family tracked by Malpedia. ID: win.boaxxe
APT GROUP
FIN7 uses this malware as helper module during intrusion operations. BOATLAUNCH is continuously looking for PowerShell processes on infected systems and patches them to bypuss Windows AntiMalware Scan Interface (AMSI).
APT GROUP
Malware family tracked by Malpedia. ID: win.bmanager
APT GROUPespionageadvanced
Avast describe this malware as a recombination of other malware including SpyEx, ThunderFox, ChromeRecovery, StormKitty, and firepwd.
APT GROUP
Malware family tracked by Malpedia. ID: win.bluether
APT GROUPfinancial
BlueSky is a financially motivated ransomware group active from mid-2022 into early 2023, using multi-threaded ChaCha20/Curve25519 encryption for fast file locking on Windows hosts, with code sharing significant overlap with Conti v2/v3 and Babuk, attributed with high confidence to Russian-origin threat actors.
Infra: 🔗 ccpyeuptrlatb2piua4u…
RLUpdated: N/A
View profile →APT GROUP
According to AhnLab, BlueShell is a backdoor malware developed in Go language, published on Github, and it supports Windows, Linux, and Mac operating systems. Currently, the original Github repository is presumed to have been deleted, but the BlueShell source code can still be obtained from other repositories. It features an explanatory ReadMe file in Chinese, indicating the possibility that the creator is a Chinese user.
APT GROUP
This family contains the BlueNoroff toolkit used for SWIFT manipulation, as used by the Lazarus activity cluster also referred to as BlueNoroff.
APT GROUP
Malware family used to deliver follow up payloads, variants using Microsoft Graph API and Google Web Apps have been observed.
APT GROUP
Mandiant associates this with UNC4191, this malware is a launcher for NCAT to establish a reverse tunnel.
APT GROUP
BlueFox is a .NET infostealer sold on forums as a Maware-as-a-Service. Its capabilities are those of a classic information stealer, with a focus on cryptocurrency wallets, and file grabber and loader capabilities.
APT GROUP
Malware family tracked by Malpedia. ID: win.bloodystealer
APT GROUP
This malware family is the suspected successor to ShadowPad and Deed rat.
APT GROUP
Elastic observed this loader coming with valid code signatures, being used to deploy secondary payloads in-memory.