Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUPespionageadvanced
According to brandefense, Zebrocy is malware that falls into the Trojan category, which the threat actor group APT28/Sofacy has used since 2015. Zebrocy malware consists of 3 main components; Backdoor, Downloader, and Dropper. The Downloader and Dropper take responsibility for discovery processes and downloading the main malware on the systems. At the same time, Backdoor undertakes the duties such as persistence in the system, espionage, and data extraction. This malware, which is not considered new, has variants in many languages from the past to the present. These include programming languages such as Delphi, C#, Visual C++, VB.net, and Golang. Furthermore, we know advanced threat actors and groups revise their malicious software among their toolkits at certain time intervals using different languages and technologies.
APT GROUP
Malware family tracked by Malpedia. ID: win.zardoor
APT GROUP
Bitdefender describes the primary features of the family as follows: Presence of a rootkit driver that protects itself as well as its other components, presence of man-in-the-browser capabilities that intercepts and decrypts SSL communications, and presence of an adware cleanup routine used to remove potential competition in the adware space. It also communicates with its C&C server, sending environment information such as installed AV and other applications. The malware also takes screenshots and does browser redirects, potentially manipulating the DOM tree. It also creates traffic in hidden windows, likely causing adfraud. The malware is generally very configurable and internally makes use of Lua scripts.
APT GROUP
W32/Yunsip!tr.pws is classified as a password stealing trojan. Password Stealing Trojan searches the infected system for passwords and send them to the hacker.
APT GROUP
Malware family tracked by Malpedia. ID: win.yty
APT GROUP
According to Intezer, YTStealer is a malware whose objective is to steal YouTube authentication cookies. As a stealer, it operates like many other stealers. The first thing it does when it’s executed is to perform some environment checks. This is to detect if the malware is being analyzed in a sandbox.
APT GROUPfinancialhigh
According to Trend Micro, this is a ransomware written as a Windows commandline script, with obfuscation applied.
APT GROUP
Simple malware with proxy/RDP and download capabilities. It often comes bundled with installers, in particular in the Chinese realm. PE timestamps suggest that it came into existence in the second half of 2014. Some versions perform checks of the status of the internet connection (InternetGetConnectedState: MODEM, LAN, PROXY), some versions perform simple AV process-checks (CreateToolhelp32Snapshot).
APT GROUP
Malware family tracked by Malpedia. ID: win.yorekey
APT GROUP
Malware family tracked by Malpedia. ID: win.yokai
APT GROUP
Malware family tracked by Malpedia. ID: win.yoddos
APT GROUP
Malware family tracked by Malpedia. ID: win.yibackdoor
APT GROUP
Malware family tracked by Malpedia. ID: win.yesrobot
Malware family tracked by Malpedia. ID: win.yellow_cockatoo
APT GROUP
Malware family tracked by Malpedia. ID: win.yayih
APT GROUP
According to Palo Alto Networks, Yasso is an open source multi-platform intranet-assisted penetration toolset that brings together a number of features such as scanning, brute forcing, remote interactive shell, and running arbitrary commands. It is authored by a Mandarin-speaking pentester nicknamed Sairson.
APT GROUPfinancialhigh
Yarraq is a ransomware that encrypts files by using asymmetric keys and adding '.yarraq' as extension to the end of filenames. At the time of writing the attacker asks for $2000 ransom in order to provide a decryptor, to enable victims to restore their original files back. To communicate with the attacker the email: cyborgyarraq@protonmail.ch is provided.
APT GROUP
According to PTSecurity, this RAT uses Yandex Disk as a C2.
APT GROUP
Malware family tracked by Malpedia. ID: win.yamabot
APT GROUPfinancialhigh
Ransomware.
APT GROUP
The author of X-ZIGZAG claims that it is a lightweight and stealthy Windows Remote Access Trojan (RAT) designed for educational purposes.
APT GROUP
Malware family tracked by Malpedia. ID: win.xxmm
APT GROUPfinancialhigh
Malware with wide range of capabilities ranging from RAT to ransomware.
APT GROUP
In March 2019, AT&T Alien Labs identified a new malware family that is actively scanning for exposed web services and default passwords. Based on our findings we are calling it “Xwo” - taken from its primary module name. It is likely related to the previously reported malware families Xbash and MongoLock.
This is a rewrite of win.xtunnel using the .NET framework that surfaced late 2017.
APT GROUP
X-Tunnel is a network proxy tool that implements a custom network protocol encapsulated in the TLS protocol.
APT GROUP
Simple Loader used to download and install stealers, clippers and other malwares.
APT GROUP
Malware family tracked by Malpedia. ID: win.xsplus
APT GROUP
Malware family tracked by Malpedia. ID: win.xserver
APT GROUPespionageadvanced
According to eSentire, XRed, also known as Synaptics worm, is a backdoor that has been circulating since at least 2019. This malware was initially spread through drivers bundled with USB-C hub adapters, which served as its primary distribution vector. Once executed, the backdoor self-replicates and to maintain persistence, it creates a Windows Registry Run key. Additionally, it uses a mutex named Synaptics2X to ensure that only one instance of the malware runs at a time. XRed includes several advanced features that enable remote control and data exfiltration. It can download additional payloads from hardcoded URLs embedded within its binary. The malware exfiltrates sensitive system information—such as the MAC address, username, and computer name—which is sent via SMTP to hardcoded email addresses. It also incorporates keylogging functionality through keyboard hooking techniques. Furthermore, XRed supports a variety of remote commands that allow the attacker to gain command prompt access, capture screenshots, list available disks and directories, download files from remote sources, and delete files from the infected system. XRed also exhibits worm-like behavior: It spreads through USB drives by creating an autorun.inf file. Additionally, the malware infects Excel files with macros (.xlsm) by injecting a malicious VBA macro into them. The malware uses a hardcoded dynamic DNS domain (xred.mooo.com) to communicate with its command and control server. This domain serves as an identifying feature of the malware. According to researchers at eSentire, linguistic evidence found in the malware's code suggests that the developer is a native Turkish speaker.
Malware family tracked by Malpedia. ID: win.xp_privesc
APT GROUP
According to PCrisk, XpertRAT is a Remote Administration Trojan, a malicious program that allows cyber criminals to remotely access and control infected computers. Typically, users download and install this software inadvertently because they are tricked. By having computers infected with malware such as XpertRAT, users can experience serious problems.
APT GROUP
Incorporates code of Quasar RAT.
APT GROUP
Malware family tracked by Malpedia. ID: win.xpan
APT GROUP
Symantec describes this as a decryptor/loader used by Chinese threat actor Antlion in campaigns targeting Taiwan.
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.xoriumstealer
APT GROUP
Malware family tracked by Malpedia. ID: elf.xmrig
Malware family tracked by Malpedia. ID: win.xillen_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.xiebroc2