Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,727 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.banjori
APT GROUP
Malware family tracked by Malpedia. ID: win.bangat
APT GROUP
Bandook malware is a remote access trojan (RAT) first seen in 2007 and has been active for several years. Written in both Delphi and C++, it was first seen as a commercial RAT developed by a Lebanese creator named PrinceAli. Over the years, several variants of Bandook were leaked online, and the malware became available for public download.
Malware family tracked by Malpedia. ID: win.bandit
APT GROUP
Malware family tracked by Malpedia. ID: win.bancos
APT GROUP
Malware family tracked by Malpedia. ID: win.banatrix
APT GROUP
Malware family tracked by Malpedia. ID: win.bamital
APT GROUP
The goal of BalkanRAT which is a more complex part of the malicious Balkan-toolset (cf. BalkanDoor) is to deploy and leverage legitimate commercial software for remote administration. The malware has several additional components to help load, install and conceal the existence of the remote desktop software. A single long-term campaign involving BalkanRAT has been active at least from January 2016 and targeted accouting departments of organizations in Croatia, Serbia, Montenegro, and Bosnia and Herzegovina (considered that the contents of the emails, included links and decoy PDFs all were involving taxes). It was legitimaly signed and installed by an exploit of the WinRAR ACE vulnerability (CVE-2018-20250).
APT GROUP
According to ESET, BalkanDoor is a simple backdoor with a small number of commands (download and execute a file, create a remote shell, take a screenshot). It can be used to automate tasks on the compromised computer or to automatically control several affected computers at once. We have seen six versions of the backdoor, with a range of supported commands, evolve since 2016.
APT GROUP
Malware family tracked by Malpedia. ID: win.baldr
APT GROUP
[Windshift](https://attack.mitre.org/groups/G0112) is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.(Citation: SANS Windshift August 2018)(Citation: objective-see windtail1 dec 2018)(Citation: objective-see windtail2 jan 2019)
T1204.001T1059.005T1057
APT GROUP
Malware family tracked by Malpedia. ID: win.bagle
APT GROUP
Malware family tracked by Malpedia. ID: win.badpaw
APT GROUP
Malware family tracked by Malpedia. ID: win.badnews
APT GROUP
Malware family tracked by Malpedia. ID: win.badhatch
APT GROUP
BADFLICK, a backdoor that is capable of modifying the file system, generating a reverse shell, and modifying its command-and-control configuration.
APT GROUP
Malware family tracked by Malpedia. ID: win.badencript
APT GROUP
remote access tool (RAT) payload on Android devices
APT GROUP
According to Google, BADAUDIO is a custom first-stage downloader written in C++ that downloads, decrypts, and executes an AES-encrypted payload from a hard-coded command and control (C2) server. The malware collects basic system information, encrypts it using a hard-coded AES key, and sends it as a cookie value with the GET request to fetch the payload. The payload, in one case identified as Cobalt Strike Beacon, is decrypted with the same key and executed in memory.
APT GROUP
Malware family tracked by Malpedia. ID: win.backswap
APT GROUP
Malware family tracked by Malpedia. ID: win.backspace
APT GROUP
According to EclecticIQ, this is a downloader written in Go, able to exclude paths from Windows Defender in order to execute fetched payloads without raising alerts.
APT GROUP
Malware family tracked by Malpedia. ID: win.backoff
APT GROUP
Malware family tracked by Malpedia. ID: win.backnet
APT GROUP
Malware family tracked by Malpedia. ID: win.backconfig
APT GROUP
FireEye describes BACKBEND as a secondary downloader used as a backup mechanism in the case the primary backdoor is removed. When executed, BACKBEND checks for the presence of the mutexes MicrosoftZj or MicrosoftZjBak (both associated with BACKSPACE variants). If either of the mutexes exist, the malware exits.
APT GROUP
Malware family tracked by Malpedia. ID: win.bachosens
APT GROUP
BabyShark is Microsoft Visual Basic (VB) script-based malware family first seen in November 2018. The malware is launched by executing the first stage HTA from a remote location, thus it can be delivered via different file types including PE files as well as malicious documents. It exfiltrates system information to C2 server, maintains persistence on the system, and waits for further instruction from the operator
APT GROUP
BABYMETAL is a command line network tunnel utility based on the TinyMet Meterpreter tool, primarily used to execute Meterpreter reverse shell payloads.
APT GROUP
Malware family tracked by Malpedia. ID: win.babylon_rat
APT GROUPfinancial
Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys.
RLUpdated: N/A
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.babar
APT GROUP
According to PCrisk, Babadeda is a new sample in the crypters family, allowing threat actors to encrypt and obfuscate the malicious samples. The obfuscation allows malware to bypass the majority of antivirus protections without triggering any alerts. According to the researchers’ analysis, Babadeda leverages a sophisticated and complex obfuscation that shows a very low detection rate by anti-virus engines.
APT GROUPfinancialhigh
According to Porthas, this is a ransomware written in Golang, using a time-based kill switch to limit its execution.
APT GROUPfinancialhigh
According to Checkpoint, this malware is a wiper instead of ransomware as self-announced. It is manually written in FASM, unrecoverably overwriting data in blocks of 666 bytes, using multi-threading.
APT GROUP
AZORult is a credential and payment card information stealer. Among other things, version 2 added support for .bit-domains. It has been observed in conjunction with Chthonic as well as being dropped by Ramnit.
APT GROUP
Keylogger.
APT GROUP
Malware family tracked by Malpedia. ID: win.ayegent
Updated: 2016-12-28
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.axlocker
APT GROUP
Malware family tracked by Malpedia. ID: win.avzhan