Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,726 entities
APT GROUP
According to Cyderes, this is a tool to clear kernel callbacks registered by a range of security solutions.
APT GROUP
BLINDTOAD is 64-bit Service DLL that loads an encrypted file from disk and executes it in memory.
APT GROUP
BLINDINGCAN is a remote access trojan that communicates with its C&C server via HTTP(S).
It uses a (custom) RC4 or AES for encryption and decryption of its configuration and network traffic.
It sends information about the victim's environment, like computer name, IP, Windows product name and processor name.
It supports around 30 commands that include operations on the victim’s filesystem, basic process management, command line execution, file exfiltration, configuration update, and the download and execution of additional payloads from the attackers' C&C. The commands are indexed by 16-bit integers, starting with the index 0x2009 and going incrementally up to 0x2057, with some indicis being skipped.
It uses various parameter names in its HTTP POST requests, mostly associated with web servers running bulletin board systems, like bbs, article, boardid, s_board, page, idx_num, etc.
It contains specific RTTI symbols like ".?AVCHTTP_Protocol@@", ".?AVCFileRW@@" or ".?AVCSinSocket@@".
BLINDINGCAN RAT is a flagship payload deployed in many Lazarus attacks, especially in the Operation DreamJob campaigns happening in 2020-2022.
APT GROUP
Malware family tracked by Malpedia. ID: win.bleachgap
APT GROUP
Malware family tracked by Malpedia. ID: win.blackworm_rat
APT GROUPfinancial
According to Trend Micro, this ransomware has significant code overlap with Royal Ransomware.
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.blacksoul
APT GROUPfinancial
BlackSnake is a Ransomware-as-a-Service (RaaS) operation that first appeared in August 2022, when its operators began recruiting affiliates on underground forums with an unusually low revenue share of 15%. It primarily targets home users rather than large enterprises and does not maintain a public leak site. Built on the Chaos ransomware code base, it features both file encryption and a cryptocurrency clipper module to steal funds from victims. The ransomware is developed in .NET and includes safeguards to avoid execution in Turkish or Azerbaijani environments, suggesting geographic targeting preferences. Infections result in encrypted files and ransom notes instructing victims to make contact via email for payment negotiations. The group’s operational scale and visibility remain limited compared to major RaaS families.
RSLUpdated: 2026-08-05
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.blackshades
APT GROUP
Malware family tracked by Malpedia. ID: win.blackrouter
APT GROUP
Malware family tracked by Malpedia. ID: win.blackrevolution
APT GROUP
Malware family tracked by Malpedia. ID: win.blackremote
APT GROUP
BlackPOS infects computers running on Windows that have credit card readers connected to them and are part of a POS system. POS system computers can be easily infected if they do not have the most up to date operating systems and antivirus programs to prevent security breaches or if the computer database systems have weak administration login credentials.
APT GROUP
Malware family tracked by Malpedia. ID: win.blacknix_rat
APT GROUP
Advanced and modern Windows botnet with PHP panel developed using VB.NET. It has a lot of functionalities including: stealing/grabbing files and passwords, keylogging, cryptojacking, loading files, executing commands, etc. It is open source and emerged at the end of 2019.
APT GROUPfinancial
Ransomware-as-a-Service
Infra: 🔗 blackmax7su6mbwtcyo3…💬 supp24yy6a66hwszu2pi…💬 supp24maprinktc7uizg…
RLUpdated: N/A
View profile →APT GROUP
Malware family tracked by Malpedia. ID: win.blacklotus
APT GROUPfinancialhigh
Malware family tracked by Malpedia. ID: win.blackkingdom_ransomware
APT GROUP
According to Zscaler, BlackGuard has the capability to steal all types of information related to Crypto wallets, VPN, Messengers, FTP credentials, saved browser credentials, and email clients.
APT GROUPfinancialhigh
BlackEnergy, its first version shortened as BE1, started as a crimeware being sold in the Russian cyber underground as early as 2007. Initially, it was designed as a toolkit for creating botnets for conducting DDoS attacks. It supported a variety of flooding commands including protocols like ICMP, TCP SYN, UDP, HTTP and DNS. Among the high profile targets of cyber attacks utilising BE1 were a Norwegian bank and government websites in Georgia three weeks before Russo-Georgian War.
Version 2 of BlackEnergy, BE2, came in 2008 with a complete code rewrite that introduced a protective layer, a kernel-mode rootkit and a modular architecture. Plugins included mostly DDoS attacks, a spam plugin and two banking authentication plugins to steal from Russian nad Ukrainian banks. The banking plugin was paired with a module designed to destroy the filesystem. Moreover, BE2 was able to
- download and execute a remote file;
- execute a local file on the infected computer;
- update the bot and its plugins;
The Industrial Control Systems Cyber Emergency Response Team issued an alert warning that BE2 was leveraging the human-machine interfaces of industrial control systems like GE CIMPLICITY, Advantech/Broadwin WebAccess, and Siemens WinCC to gain access to critical infrastructure networks.
In 2014, the BlackEnergy toolkit, BE3, switched to a lighter footprint with no kernel-mode driver component. Its plugins included:
- operations with victim's filesystem
- spreading with a parasitic infector
- spying features like keylogging, screenshoots or a robust password stealer
- Team viewer and a simple pseudo “remote desktop”
- listing Windows accounts and scanning network
- destroying the system
Typical for distribution of BE3 was heavy use of spear-phishing emails containing Microsoft Word or Excel documents with a malicious VBA macro, Rich Text Format (RTF) documents embedding exploits or a PowerPoint presentation with zero-day exploit CVE-2014-4114.
On 23 December 2015, attackers behind the BlackEnergy malware successfully caused power outages for several hours in different regions of Ukraine. This cyber sabotage against three energy companies has been confirmed by the Ukrainian government. The power grid compromise has become known as the first-of-its-kind cyber warfare attack affecting civilians.
APT GROUP
a backdoor that obfuscates its communications as normal traffic to legitimate websites such as Github and Microsoft's Technet portal.
APT GROUPfinancialhigh
ALPHV, also known as BlackCat or Noberus, is a ransomware family that is deployed as part of Ransomware as a Service (RaaS) operations. ALPHV is written in the Rust programming language and supports execution on Windows, Linux-based operating systems (Debian, Ubuntu, ReadyNAS, Synology), and VMWare ESXi. ALPHV is marketed as ALPHV on cybercrime forums, but is commonly called BlackCat by security researchers due to an icon of a black cat appearing on its leak site. ALPHV has been observed being deployed in ransomware attacks since November 18, 2021.
ALPHV can be configured to encrypt files using either the AES or ChaCha20 algorithms. In order to maximize the amount of ransomed data, ALPHV can delete volume shadow copies, stop processes and services, and stop virtual machines on ESXi servers. ALPHV can self-propagate by using PsExec to remote execute itself on other hosts on the local network.
T1486T1021.001T1059.001🎯 healthcare🎯 manufacturing
APT GROUPfinancial
Ransomware. Uses dropper written in JavaScript to deploy a .NET payload.
Infra: 🔗 6iaj3efye3q62xjgfxye…🔗 f5uzduboq4fa2xkjlopr…🔗 dlyo7r3n4qy5fzv4645n…+10 more
T1112T1053.005T1055.012
RLUpdated: N/A
View profile →APT GROUPfinancial
"Black Basta" is a new ransomware strain discovered during April 2022 - looks in dev since at least early February 2022 - and due to their ability to quickly amass new victims and the style of their negotiations, this is likely not a new operation but rather a rebrand of a previous top-tier ransomware gang that brought along their affiliates.
Infra: 🔗 stniiomyjliimcgkvdsz…💬 bastad5huzwkepdixedg…📁 6y2qjrzzt4inluxzygdf…+14 more
RLUpdated: N/A
View profile →APT GROUPfinancialhigh
BKA Trojaner is a screenlocker ransomware that was active in 2011, displaying a police-themed message in German language.
APT GROUPfinancialhigh
Kaspersky Labs characterizes Bizarro as yet another banking Trojan family originating from Brazil that is now found in other regions of the world. They have seen users being targeted in Spain, Portugal, France and Italy. Attempts have now been made to steal credentials from customers of 70 banks from different European and South American countries.
APT GROUP
According to Bitdefender, BitRAT is a notorious remote access trojan (RAT) marketed on underground cybercriminal web markets and forums. Its price tag of $20 for lifetime access makes it irresistible to cybercriminals and helps the malicious payload spread.
Furthermore, each buyer’s modus operandi makes BitRAT even harder to stop, considering it can be employed in various operations, such as trojanized software, phishing and watering hole attacks.
BitRAT’s popularity arises from its versatility. The malicious tool can perform a wide range of operations, including data exfiltration, UAC bypass, DDoS attacks, clipboard monitoring, gaining unauthorized webcam access, credential theft, audio recording, XMRig coin mining and generic keylogging.
APT GROUP
Malware family tracked by Malpedia. ID: win.bitter_rat
APT GROUPfinancialhigh
SHADYCAT is a dropper and spreader component for the HERMES 2.1 RANSOMWARE radical edition.
APT GROUP
Malware family tracked by Malpedia. ID: win.bitsloth
APT GROUPfinancialhigh
Bitpylock is a ransomware that encrypts files by using asymmetric keys and puts '.bitpy' as suffix once the encryption phase ended. The ransom note appears on the affected user's Desktop with the following name: "# # HELP_TO_DECRYPT_YOUR_FILES # .html". At the time of writing the ransom request is 0.8 BTC and the communication email is: helpbitpy@cock.li.
APT GROUP
Malware family tracked by Malpedia. ID: win.bistromath
APT GROUP
Malware family tracked by Malpedia. ID: win.biscuit
APT GROUP
BIOPASS RAT is a malware family which targets online gambling companies in China by leveraging a watering hole attack. This Remote Access Trojan (RAT) is unique in that it leverages the Open Broadcaster Software (OBS) framework to monitor the user's screen.
APT GROUP
Malware family tracked by Malpedia. ID: win.bioload
APT GROUP
Malware family tracked by Malpedia. ID: win.biodata
APT GROUP
Binanen is a dropper that drops and executes a section of itself into a hidden dummy process. According to F-Secure, it executes command line tools such as (for example) asipconfig, which is useful to retrieve the network configuration. The malware aims to steal information about the machine, the username, installed software and, more generally speaking, it potentially can carry out actions on the compromised machine.
APT GROUP
BillGates is a modularized malware, of supposedly Chinese origin. Its main functionality is to perform DDoS attacks, with support for DNS amplification. Often, BillGates is delivered with one or many backdoor modules.
BillGates is available for *nix-based systems as well as for Windows.
On Windows, the (Bill)Gates installer typically contains the various modules as linked resources.