Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: osx.evilosx
APT GROUP
According to PCrisk, ElectroRAT is a Remote Access Trojan (RAT) written in the Go programming language and designed to target Windows, MacOS, and Linux users. Cyber criminals behind ElectroRAT target mainly cryptocurrency users. This RAT is distributed via the trojanized Jamm, eTrader, and DaoPoker applications.
APT GROUPespionageadvanced
Eleanor comes as a drag-and-drop file utility called EasyDoc Converter. This application bundle wraps a shell script that uses Dropbox name as a disguise and installs three components: a hidden Tor service, a Pastebin agent and a web service with a PHP-based graphical interface.
The Tor service transforms the victim’s computer into a server that provides attackers with full anonymous access to the infected machine via Tor-generated address.
The Pastebin agent uploads the address in encrypted form to the Pastebin website where the attackers can obtain it.
The web service is the main malicious component that provides the attackers with the control over the infected machine. After successful authentication, the interface offers several control panels to the attackers, allowing them to do the following actions:
- Managing files
- Listing processes
- Connecting to various database management systems such as MySQL or SQLite
- Connecting via bind/reverse shell
- Executing shell command
- Capturing and browsing images and videos from the victim’s webcam
- Sending emails with an attachment
APT GROUP
Malware family tracked by Malpedia. ID: osx.eggshell_rat
APT GROUP
Malware family tracked by Malpedia. ID: osx.dummy
APT GROUP
Malware family tracked by Malpedia. ID: osx.dockster
APT GROUP
Malware family tracked by Malpedia. ID: osx.dazzle_spy
APT GROUP
Malware family tracked by Malpedia. ID: osx.darthminer
APT GROUP
Malware family tracked by Malpedia. ID: osx.cthulhu_stealer
APT GROUP
Malware family tracked by Malpedia. ID: osx.crossrider
APT GROUP
Malware family tracked by Malpedia. ID: osx.crisis
APT GROUP
Malware family tracked by Malpedia. ID: osx.creative_updater
APT GROUP
Malware family tracked by Malpedia. ID: osx.cpumeaner
APT GROUP
Malware family tracked by Malpedia. ID: osx.convuster
APT GROUP
Malware family tracked by Malpedia. ID: osx.coldroot_rat
APT GROUP
CoinThief was a malware package designed to steal Bitcoins from the victim, consisting of a binary patcher, browser extensions, and a backdoor component.
It was spreading in early 2014 from several different sources:
- on Github (where the trojanized compiled binary didn’t match the displayed source code), o
- on popular and trusted download sites line CNET's Download.com or MacUpdate.com, and
- as cracked applications via torrents camouflaged as Bitcoin Ticker TTM, BitVanity, StealthBit, Litecoin Ticker, BBEdit, Pixelmator, Angry Birds and Delicious Library.
The patcher‘s role was to locate and modify legitimate versions of the Bitcoin-Qt wallet application. The analyzed malware samples targeted versions of Bitcoin-Qt 0.8.1, 0.8.0 and 0.8.5. The earlier patch modified Bitcoin-Qt adding malicious code that would send nearly all the victim’s Bitcoins to one of the hard-coded addresses belonging to the attacker.
The browser extensions targeted Chrome and Firefox and are disguised as a “Pop-up blocker”. The extensions monitored visited websites, download malicious JavaScripts and injected them into various Bitcoin-related websites (mostly Bitcoin exchanges and online wallet sites). The injected JS scripts were able to modify transactions to redirect Bitcoin transfers to an attacker’s address or simply harvest login credentials to the targeted online service.
The backdoor enabled the attacker to take full control over the victim’s computer:
- collect information about the infected computer
- execute arbitrary shell scripts on the target computer
- upload an arbitrary file from the victim’s hard drive to a remote server
- update itself to a newer version
APT GROUP
Malware family tracked by Malpedia. ID: osx.cloud_mensis
APT GROUP
Google TAG has observed this malware being delivered via watering hole attacks using 0-day exploits, targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political group.
APT GROUP
Malware family tracked by Malpedia. ID: osx.casso
APT GROUP
Malware family tracked by Malpedia. ID: osx.bundlore
APT GROUP
Malware family tracked by Malpedia. ID: osx.bella
APT GROUP
Malware family tracked by Malpedia. ID: osx.banshee
APT GROUP
Malware family tracked by Malpedia. ID: osx.amos
APT GROUP
Malware family tracked by Malpedia. ID: jsp.godzilla_webshell
APT GROUP
Malware family tracked by Malpedia. ID: js.witchcoven
APT GROUP
WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS. The developer has put in concerted effort to develop the malware’s breadth of capabilities, including novel techniques not observed in any prior malware campaigns - to our knowledge. These new TTPs include methods to modify Windows Setup and Windows Recovery to enable long-term persistence, as well as methods to patch browser extensions ‘on the fly’.
APT GROUP
According to PCrisk, Valak is malicious software that downloads JScript files and executes them. What happens next depends on the actions performed by the executed JScript files. It is very likely that cyber criminals behind Valak attempt to use this malware to cause chain infections (i.e., using Valak to distribute other malware).
Research shows that Valak is distributed through spam campaigns, however, in some cases, it infiltrates systems when they are already infected with malicious program such as Ursnif (also known as Gozi).
APT GROUP
Malware family tracked by Malpedia. ID: js.unidentified_js_002
APT GROUP
A script able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server by making HTTP requests.
APT GROUP
Malware family tracked by Malpedia. ID: js.unidentified_005
APT GROUP
A simple loader written in JavaScript found by Marco Ramilli.
According to Max Kersten, Emotet is dropped by a procedure spanned over multiple stages. The first stage is an office file that contains a macro. This macro then loads the second stage, which is either a PowerShell script or a piece of JavaScript, which is this family entry.
APT GROUP
Malware family tracked by Malpedia. ID: js.unidentified_001
APT GROUP
Expects a parameter to run: needs to be started as 'maintools.js EzZETcSXyKAdF_e5I2i1'.
APT GROUP
Malware family tracked by Malpedia. ID: js.turla_ff_ext
APT GROUP
Malware family tracked by Malpedia. ID: js.tsundere
APT GROUP
Malware family tracked by Malpedia. ID: js.swid
APT GROUP
According to IBM X-Force, this is a simple reverse shell. Upon execution, the script generates a unique victim ID by combining the machine's product ID and computer name. It queries a hardcoded server and executes optional commands directly via cmd.exe. Command output is send back using a POST request after completion or a timeout.
APT GROUP
SQLRat campaigns typically involve a lure document that includes an image overlayed by a VB Form trigger. Once a user has double-clicked the embedded image, the form executes a VB setup script. The script writes files to the path %appdata%\Roaming\Microsoft\Templates\, then creates two task entries triggered to run daily. The scripts are responsible for deobfuscating and executing the main JavaScript file mspromo.dot. The file uses a character insertion obfuscation technique, making it appear to contain Chinese characters. After deobfuscating the file, the main JavaScript is easily recognizable. It contains a number of functions designed to drop files and execute scripts on a host system. The SQLRat script is designed to make a direct SQL connection to a Microsoft database controlled by the attackers and execute the contents of various tables.