Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters3,491 entities
APT GROUP
Malware family tracked by Malpedia. ID: win.wikiloader
APT GROUP
WhiteSnake Stealer, discovered in February 2022, is a sophisticated .NET data-stealing malware that targets browsers, applications, and crypto wallets.
The builder can build payloads in different file formats such as EXE, SCR, COM, CMD, BAT, VBS, PIF, WSF, .hta, MSI, PY, DOC, DOCM, XLS, XLL, XLSM. Some of these (python, bash) allow the malware to run on Linux systems.
The stealer has two execution methods:
* Non-resident - the stealer auto-deletes itself after successful execution
* Resident - the stealer beacons out to the C2 (possibly in the TOR network)
WhiteSnake Stealer can gather system information, execute remote commands, spread through USB drives, and perform tasks like keylogging, file management, and webcam access.
APT GROUP
Malware family tracked by Malpedia. ID: win.whiteblackcrypt
APT GROUP
According to Dr.Web, WhiteBird is a backdoor written in C++ and designed to operate in both 32-bit and 64-bit Microsoft Windows operating systems. The configuration is encrypted with a single byte XOR key. An interesting feature is that the malware can be restricted to operate only within certain "working_hours" with a granularity of one minute.
APT GROUP
Malware family tracked by Malpedia. ID: win.whiskerspy
APT GROUP
Malware family tracked by Malpedia. ID: win.westeal
APT GROUP
WellMess is A Remote Access Trojan written in GoLang and .NET. It has hard-coded User-Agents. Attackers deploy WellMess using separate tools which also allow lateral movement, for example "gost". Command and Control traffic is handled via HTTP using the Set-Cookie field and message body.
APT GROUP
Malware family tracked by Malpedia. ID: win.wecontrol
APT GROUP
On its website, Webmonitor RAT is described as 'a very powerful, user-friendly, easy-to-setup and state-of-the-art monitoring tool. Webmonitor is a fully native RAT, meaning it will run on all Windows versions and languages starting from Windows XP and up, and perfectly compatible with all crypters and protectors.'
Unit42 notes in their analysis that it is offered as C2-as-a-service and raises the controversial aspect that the builder allows to create client binaries that will not show any popup or dialogue during installation or while running on a target system.
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_yahoo
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_ugx
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_table
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_rave
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_qbp
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_kt3
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_head
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_greencat
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_div
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_cson
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_bolid
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_ausov
APT GROUP
Malware family tracked by Malpedia. ID: win.webc2_adspace
APT GROUP
WebbyTea is an HTTP(S) downloader that uses AES for C&C trafic encryption.
It sends detailed information about the victim's environment, like proxy settings, system instalation date, Windows product name and version, manufacturer, product name, system boot time, time zone, computer name, user name, current time and a list of currently running processes. Data sent to the C&C server consists of the prefix "ci", a 16-characters long hexadecimal string representing the victim ID and an encrypted data about the victim's system. After the payload is acquired from the server and successfully injected in a newly created explorer.exe process, the malware responds back with the same victim ID having the prefix changed to "cs".
The internal DLL name of the native WebbyTea is usually pe64.dll or webT64.dll (from which its name is derived).
The usual payload associated with WebbyTea is SnatchCrypto.
APT GROUP
Malware family tracked by Malpedia. ID: win.wavy_exfiller
APT GROUP
Wave Stealer is an infostealer offered as Malware-as-a-Service by a French-speaking actor called "Wave". The threat actor has strong relationships with Nova Stealer's and Epsilon Stealer's groups. It's capabilities include passwords and crypto-wallet stealing, discord and telegram injection, and backup codes finder.
APT GROUP
Malware family tracked by Malpedia. ID: win.waterspout
APT GROUP
Malware family tracked by Malpedia. ID: win.waterminer
APT GROUPespionageadvanced
Waterbear, also known as DbgPrint in its earlier export function, has been active since 2009. The malware is presumably developed by the BlackTech APT group and adopts advanced anti-analysis and forward-thinking design. These designs include a sophisticated shellcode stager, the ability to load plugins on-the-fly, and overall evasiveness should the C2 server fail to respond with a valid session key.
APT GROUPfinancialhigh
This malware looks similar to WastedLocker, but the ransomware component is missing.
APT GROUPfinancialhigh
Warsaw trojan is a new banking trojan based on the Hours Eyes RAT core engine.
APT GROUP
According to Seqrite, this is a fork of Stealerium that has high overlap with its originating codebase. Main changes include removal of Discord web hooks (for the sake of using Telegram) and rebranding away from Stealerium (string removal).
APT GROUPespionageadvanced
WarmCookie is backdoor that is capable of executing commands reading/writing files and capturing screenshots. It communicates with a command and control (C&C) server via HTTP to receive further instructions and exfiltrate stolen data. It is commonly distributed through phishing campaigns and malicious downloads, targeting unsuspecting users to infiltrate systems undetected.
APT GROUP
Malware family tracked by Malpedia. ID: win.warhawk
APT GROUP
Malware family tracked by Malpedia. ID: win.warezov
APT GROUPfinancialhigh
According to Mars, WannaHusky is a Nim-compiled ransomware malware sample, created for demonstration purposes and provided as part of the Practical Malware Analysis & Triage course provided by HuskyHacks.
APT GROUPfinancialhigh
WannaCry is ransomware that contains a worm component enabled by the EternalBlue exploit. It attempts to use vulnerabilities in the Windows SMBv1 server to remotely compromise systems, encrypt files, and spread to other hosts. Systems that have installed the MS17-010 patch are not vulnerable to the exploits used. The spreading was stopped about 8 hours after initial outbreak due to triggering a kill switch domain.
APT GROUP
Malware family tracked by Malpedia. ID: win.wallyshack
APT GROUP
Malware family tracked by Malpedia. ID: win.wainscot
APT GROUP
wAgentTea is an HTTP(S) downloader.
It was deployed mostly against South Korean targets like a pharmaceutical company (Q4 2020) or semiconductor industry (Q2 2023). In several cases, the initial access was obtained via exploitation of South Korean software like Initech's INISAFE CrossWeb EX or Dream Security’s MagicLine4NX.
It uses AES-128 for encryption and decryption of its network traffic, and for decryption of its binary configuration.
There is a hard-coded list of parameter names used in its HTTP POST request:
identy;tname;blogdata;content;thesis;method;bbs;level;maincode;tab;idx;tb;isbn;entry;doc;
category;articles;portal
It contains a specific RTTI symbol ".?AVCHttp_socket@@".