Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

✕ Clear filters3,491 entities
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.xiangoop
APT GROUP
Malware family tracked by Malpedia. ID: win.xfscashncr
APT GROUP
Malware family tracked by Malpedia. ID: win.xfsadm
Malware family tracked by Malpedia. ID: win.xfilesstealer
APT GROUP
XenoRAT is an open source remote access trojan written in C#. It can monitor user activity including keystrokes, and provide remote control over the compromised system.
APT GROUP
Malware family tracked by Malpedia. ID: win.xenon
APT GROUP
XenArmor is a suite of password recovery tools for various applications that have been observed to be abused in attacks alongside malware.
APT GROUP
Xehook is a .NET-based malware targeting Windows systems. It collects data from Chromium and Gecko browsers, supporting over 110 cryptocurrencies and 2FA extensions. CRIL found a potential link between Xehook Stealer, Agniane, and the Cinoshi project, suggesting a progression from a free MaaS model to the development of Xehook Stealer. SmokeLoader binaries were identified as a common vector for distributing Xehook Stealer. Xehook Stealer shares code overlaps with Agniane Stealer, indicating an evolutionary relationship.
APT GROUP
Checkpoint Research found this backdoor, attributed to IndigoZebra, used to target Afghan and other Central-Asia countries, including Kyrgyzstan and Uzbekistan, since at least 2014.
APT GROUP
Malware family tracked by Malpedia. ID: win.xbtl
Updated: 2016-05-10
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.xbot_pos
APT GROUP
Malware family tracked by Malpedia. ID: apk.popr-d30
APT GROUP
Malware family tracked by Malpedia. ID: win.x4
APT GROUP
Malware family tracked by Malpedia. ID: win.wslink
APT GROUP
Malware family tracked by Malpedia. ID: win.wscspl
APT GROUP
Malware family tracked by Malpedia. ID: win.wpbrutebot
APT GROUP
Malware family tracked by Malpedia. ID: win.wormlocker
APT GROUP
WORMHOLE is a TCP tunneler that is dynamically configurable from a C&C server and can communicate with an additional remote machine endpoint for a relay.
APT GROUP
Information Stealer.
APT GROUP
Malware family tracked by Malpedia. ID: win.woolger
APT GROUP
Malware family tracked by Malpedia. ID: win.woodyrat
APT GROUP
Malware family tracked by Malpedia. ID: win.woody
APT GROUP
Malware family tracked by Malpedia. ID: win.wonknu
APT GROUP
Malware family tracked by Malpedia. ID: win.wndtest
APT GROUP
According to Proofpoint, WmRAT is a remote access trojan (RAT) written in C++ that uses sockets for communications and has standard RAT functionality. The RAT can gather basic host information, upload or download files, take screenshots, get geolocation data of the target machine, enumerate directories and files, and run arbitrary commands via cmd or PowerShell. The malware also generates a number of junk threads, potentially to mislead researchers or responders investigating the samples.
APT GROUP
Malware family tracked by Malpedia. ID: win.wmighost
APT GROUP
Malware family tracked by Malpedia. ID: win.wipbot
APT GROUP
Malware family tracked by Malpedia. ID: win.winsloader
APT GROUP
Backdoor used in the EvilPlayout campaign against Iran's State Broadcaster.
APT GROUP
WinPot is created to make ATMs by a popular ATM vendor to automatically dispense all cash from their most valuable cassettes.
APT GROUP
Malware family tracked by Malpedia. ID: win.winos
APT GROUP
According to ESET Research, this is a payload downloaded by win.wslink. They attribute it with low confidence to Lazarus.
APT GROUP
Malware family tracked by Malpedia. ID: elf.winnti
APT GROUP
Malware family tracked by Malpedia. ID: win.winmm
APT GROUP
Malware family tracked by Malpedia. ID: win.winlog
APT GROUP
Malware family tracked by Malpedia. ID: win.wininetloader
APT GROUP
Malware family tracked by Malpedia. ID: win.wineloader
APT GROUP
Information stealer used by threat actor LuoYu.
APT GROUP
Malware family tracked by Malpedia. ID: win.wildfire
Updated: 2016-12-28
View profile →