Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
10,728 entities
APT GROUP
This is a pentesting tool and according to the author, "BOtB is a container analysis and exploitation tool designed to be used by pentesters and engineers while also being CI/CD friendly with common CI/CD technologies.".
It has been observed being used by TeamTNT in their activities for spreading crypto-mining malware.
APT GROUP
Malware family tracked by Malpedia. ID: elf.bootkitty
APT GROUP
Malware family tracked by Malpedia. ID: elf.blackrota
APT GROUP
Malware family tracked by Malpedia. ID: elf.bioset
APT GROUP
A DDoS bot abusing CVE-2020-8515 to target DrayTek Vigor routers. It uses a wordlist-based DGA to generate its C&C domains.
APT GROUP
Linux version of the bifrose malware that originally targeted Windows platform only. The backdoor has the ability to perform file management, start or end a process, or start a remote shell. The connection is encrypted using a modified RC4 algorithm.
APT GROUP
According to Security Joes, this malware is an x64 ELF executable, lacking obfuscation or protective measures. It allows attackers to specify target folders and can potentially destroy an entire operating system if run with root permissions. During execution, it produces extensive output, which can be mitigated using the "nohup" command. It also leverages multiple threads and a queue to corrupt files concurrently, enhancing its speed and reach. Its actions include overwriting files, renaming them with a random string containing "BiBi," and excluding certain file types from corruption.
BCMPUPnP Hunter
Technical ID: BCMPUPnP_Hunter
APT GROUP
Malware family tracked by Malpedia. ID: elf.bcmpupnp_hunter
APT GROUP
Bashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.
APT GROUP
Ballista is an IoT botnet, infecting unpatched TP-Link Archer AX21 (AX1800) routers. It spreads through automatic exploitation of CVE-2023-1389. Its capabilities include remote code execution and DDoS attacks.
APT GROUP
Malware family tracked by Malpedia. ID: elf.backdoor_irc16
APT GROUP
According to Avast Decoded, Backdoorit is a multiplatform RAT written in Go programming language and supporting both Windows and Linux/Unix operating systems. In many places in the code it is also referred to as backd00rit.
APT GROUP
B1txor20 is a malware that was discovered by 360 Netlab along others exploiting Log4J. the name is derived from using the file name "b1t", the XOR encrpytion algorithm, and the RC4 algorithm key length of 20 bytes. According to 360 Netlab this Backdoor for Linux platform uses DNS Tunnel to build a C2 communication channel. They also had the assumption that the malware is still in development, because of some bugs and not fully implemented features.
APT GROUP
Azazel is a Linux user-mode rootkit based off of a technique from the Jynx rootkit (LD_PRELOAD technique). Azazel is purportedly more robust than Jynx and has many more anti-analysis features
APT GROUP
AVrecon is a Linux-based Remote Access Trojan (RAT) targeting small-office/home-office (SOHO) routers and other ARM-embedded devices. The malware is distributed via exploitation of unpatched vulnerabilities or common misconfiguration of the targeted devices. Once deployed, AVreckon will collect some information about the infected device, open a session to pre-configured C&C server, and spawn a remote shell for command execution. It might also download additional arbitrary files and run them. The malware has recently been used in campaigns aimed at ad-fraud activities, password spraying and data exfiltration.
APT GROUP
According to Unit 42, Auto-Color was discovered in November 2024 named based on the file name of the initial payload. It hides its C2 communication similarly to Symbiote, including the use of proprietary encryption algorithms.
APT GROUP
Malware family tracked by Malpedia. ID: elf.angryrebel
APT GROUP
Backdoor deployed by the TrickBot actors. It uses DNS as the command and control channel as well as for exfiltration of data.
APT GROUP
AirDropBot is used to create a DDoS botnet. It spreads as a worm, currently targeting Linksys routers. Backdoor and other bot functionality is present in this family. Development seems to be ongoing.
APT GROUP
According to Xlab, this is a DDoS bot.
APT GROUP
Malware family tracked by Malpedia. ID: elf.age_locker
APT GROUP
A MIPS ELF binary with wiper functionality used against Viasat KA-SAT modems.
APT GROUP
Malware family tracked by Malpedia. ID: elf.acidpour
APT GROUPfinancialhigh
Family based on HelloKitty Ransomware. Encryption algorithm changed from AES to ChaCha. Sample seems to be unpacked.
APT GROUP
Abcbot is a modular Go-based botnet and malware that propagates via exploits and brute force attempts. The botnet was observed launching DDoS attacks, perform internet scans, and serve web pages. It is probably linked to Xanthe-based clipjacking campaign.
APT GROUP
Malware family tracked by Malpedia. ID: asp.unidentified_001
APT GROUP
According to Unit42, TwoFace is a two-staged (loader+payload) webshell, written in C# and meant to run on webservers with ASP.NET. The author of the initial loader webshell included legitimate and expected content that will be displayed if a visitor accesses the shell in a browser, likely to remain undetected. The code in the loader webshell includes obfuscated variable names and the embedded payload is encoded and encrypted. To interact with the loader webshell, the threat actor uses HTTP POST requests to the compromised server.
The secondary webshell, which we call the payload, is embedded within the loader in encrypted form and contains additional functionality that we will discuss in further detail. When the threat actor wants to interact with the remote server, they provide data that the loader will use to modify a decryption key embedded within the loader that will be in turn used to decrypt the embedded TwoFace payload. Commands supported by the payload are execution of programs, up-, download and deletion of files and capability to manipulate MAC timestamps.
APT GROUP
According to Microsoft, this is a web shell, written in ASPX supporting C#, carrying sufficient yet rudimentary functionality to support the following secondary activities: uploading and downloading files, running shell commands, opening a port (default port is set to TCP 250).
APT GROUP
Malware family tracked by Malpedia. ID: apk.ztorg
APT GROUPespionageadvanced
ZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind ZooPark infect Android devices using several generations of malware we label from v1-v4, with v4 being the most recent version deployed in 2017.
APT GROUP
Malware family tracked by Malpedia. ID: apk.zen
APT GROUP
According to cyware, Zanubis malware pretends to be a malicious PDF application. The threat actor uses it as a key to decrypt responses received from the C2 server.
APT GROUP
Malware family tracked by Malpedia. ID: apk.yellyouth
APT GROUP
Malware family tracked by Malpedia. ID: apk.xrat
APT GROUP
Malware family tracked by Malpedia. ID: apk.xploitspy
APT GROUP
Xhelper is a very persistent malware that can reinstall itself after factory reset, Xhelper downloads malicious apps and displays annoying ads.
APT GROUPfinancialhigh
Xenomorph is a Android Banking RAT developed by the Hadoken.Security actor.