Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.bifrose
BI D Ransomware
Technical ID: BI_D Ransomware
APT GROUPespionageadvanced
Small and relatively simple ransomware for Windows. Gives files the .BI_D extension after encrypting them with a combination of RSA/AES. Persistence achieved via the Windows Registry. Kills all processes on the victim machine besides itself and a small whitelist of mostly Windows sytem processes and kills shadow copies.
APT GROUP
A Windows version of the BiBi wiper that was found by BlackBerry.
APT GROUPfinancial
BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.
Infra: 🔗 bianlianlbc5an4kgnay🔗 bianlivemqbawcco4cx4🔗 bianliaoxoeriowgqohc+1 more
RLUpdated: N/A
View profile →
BH A006
Technical ID: BH_A006
APT GROUP
According to Volexity, a loader observed to be used with multiple malware families, among them LIGHTSPY.
APT GROUP
BHunt collects the crypto wallets of its victims. The malware consists of several functions/modules, e.g. a reporting module that reports the presence of crypto wallets on the target computers to the C2 server. It searches for many different cryptocurrencies (e.g. Atomic, Bitcoin, Electrum, Ethereum, Exodus, Jaxx and Litecoin). The Blackjack module is used to steal wallets, Sweet_Bonanza steals victims' browser passwords. There are also modules like the Golden7 or the Chaos_crew module.
APT GROUP
Malware family tracked by Malpedia. ID: win.bfbot
Updated: 2017-04-29
View profile →
APT GROUP
Bezigate is a Trojan horse that opens a back door on the compromised computer. It may also download potentially malicious files. The Trojan may perform the following actions: List, move, and delete drives List, move, and delete files List processes and running Windows titles List services List registry values Kill processes Maximize, minimize, and close windows Upload and download files Execute shell commands Uninstall itself
APT GROUPfinancialhigh
Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012. The malware began as a banking Trojan and is now packed with features that allow its operators to practically take over a victim’s machine and steal sensitive information.
APT GROUP
Malware family tracked by Malpedia. ID: win.bestkorea
APT GROUPfinancial
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
Infra: 🔗 bertblogsoqmm4ow7nqy📁 wtwdv3ss4d637dka7iaf
RLUpdated: 2026-08-05
View profile →
Malware family tracked by Malpedia. ID: win.berserk_stealer
APT GROUP
Malware family tracked by Malpedia. ID: win.bernhardpos
APT GROUP
Malware family tracked by Malpedia. ID: win.berbomthum
APT GROUP
Malware family tracked by Malpedia. ID: win.berbew
APT GROUP
Once set up in the system, Trojan.Belonard replaces the list of available game servers in the game client and creates proxies on the infected computer to spread the Trojan. As a rule, proxy servers show a lower ping, so other players will see them at the top of the list. By selecting one of them, a player gets redirected to a malicious server where their computer become infected with Trojan.Belonard.
APT GROUP
Malware family tracked by Malpedia. ID: win.bellaciao
APT GROUP
Malware family tracked by Malpedia. ID: win.beepservice
APT GROUP
BEENDOOR is a XMPP based trojan. It is capable of taking screenshots of the victim's desktop.
APT GROUP
Malware family observed in conjunction with PlugX infrastructure in 2013.
APT GROUP
Bedep has been mostly observed in ad-fraud campaigns, although it can also generally load modules for different tasks. It was dropped by the Angler Exploit Kit.
APT GROUP
BeaverTail is a JavaScript malware primarily distributed through NPM packages. It is designed for information theft and to load further stages of malware, specifically a multi-stage Python-based backdoor known as InvisibleFerret. BeaverTail targets cryptocurrency wallets and credit card information stored in the victim's web browsers. Its code is heavily obfuscated to evade detection. Threat actors can either upload malicious NPM packages containing BeaverTail to GitHub or inject BeaverTail code into legitimate NPM projects. Researchers have identified additional Windows and macOS variants, indicating that the BeaverTail malware family is likely still under development.
APT GROUP
According to Mandiant, BEATDROP is a downloader written in C that uses Atlassian's project management service Trello for C&C. BEATDROP uses Trello to store victim information and retrieve AES-encrypted shellcode payloads to be executed. BEATDROP then injects and executes downloaded payloads into a suspended process. Upon execution, BEATDROP maps a copy of ntdll.dll into memory to execute shellcode in its own process. The sample then creates a suspended thread with RtlCreateUserThread the thread points to NtCreateFile. The sample changes execution to shellcode and resumes the thread. The shellcode payload is retrieved from Trello and is targeted per victim. Once the payload has been retrieved, it is deleted from Trello.
APT GROUP
According to CERT-UA, this is a malware developed using the C++ programming language. It provides capabilities for downloading, decryption (chacha20-poly150) and performing PowerShell scripts, as well as uploading the command's results.
APT GROUP
According to Symantec, Beapy is a cryptojacking campaign impacting enterprises that uses the EternalBlue exploit and stolen and hardcoded credentials to spread rapidly across networks.
APT GROUP
According to Threatray, BDarkRAT is a .NET RAT first discovered in 2019 that Bitter group continues to use until at least 2025.
APT GROUPfinancialhigh
360 Security Center describes BBtok as a banking trojan targeting Mexico.
APT GROUP
Malware family tracked by Malpedia. ID: win.bbsrat
APT GROUP
A rewrite of Bazarloader in the Nim programming language.
APT GROUP
BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor. Its called team9 backdoor (and the corresponding loader: team9 restart loader). For now, it exclusively uses Emercoin domains (.bazar), thus the naming. FireEye uses KEGTAP as name for BazarLoader and BEERBOT for BazarBackdoor.
APT GROUP
According to PCrisk, BATLOADER is part of the infection chain where it is used to perform the initial compromise. This malware is used to execute payloads like Ursnif. Our team has discovered BATLOADER after executing installers for legitimate software (such as Zoom, TeamViewer Visual Studio) bundled with this malware. We have found those installers on compromised websites.
APT GROUP
Malware family tracked by Malpedia. ID: win.batel
APT GROUP
Malware family tracked by Malpedia. ID: win.batchwiper
APT GROUP
Malware family tracked by Malpedia. ID: win.bart
APT GROUP
Malware family tracked by Malpedia. ID: win.barkiofork
APT GROUP
Malware family tracked by Malpedia. ID: win.barbwire
Malware family tracked by Malpedia. ID: win.barbie
APT GROUP
According to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.
APT GROUP
BanPolMex is a remote access trojan that uses TCP for communication. It uses an RC4-like stream cipher called Spritz for encryption of its configuration and network traffic. It sends detailed information about the victim's environment, like computer name, Windows version, free space of memory and all drives, processor identifier and architecture, system locale, system metrics, manufacturer, and network configuration. It supports almost 30 commands that include operations on the victim’s filesystem, basic process management, file exfiltration, and the download and execution of additional tools from the attacker’s C&C server. As in many RATs from Lazarus arsenal, the commands are indexed by 32-bit integers. However, in this case the indicis are convertible into a meaningful ASCII representation, that even suggests the functionality: SLEP, HIBN, DRIV, DIR, DIRP, CHDR, RUN, RUNX, DEL, WIPE, MOVE, FTIM, NEWF, DOWN, ZDWN, UPLD, PVEW, PKIL, CMDL, DIE, GCFG, SCFG, TCON, PEEX, PEIN. It has aclui.dll as the internal DLL name. It contains statically linked code from open-source libraries like libcurl (version 7.47.1) or zLib (version 0.15). BanPolMex RAT was delivered for victims of a watering hole campaign targeting employees of Polish and Mexican banks, that was discovered in February 2017. It is usually loaded by HOTWAX.
APT GROUP
Malware family tracked by Malpedia. ID: win.bankshot