Threat Intelligence Feeds

Curated, continuously updated collections of Indicators of Compromise: command & control servers, phishing sites, malware distribution points and more. Every feed is downloadable in plain text, STIX2 or MISP format.

Feed Author Downloads Indicators
Command and Controls
This feed allocates all the alive Command & Controls from different RAT's and Botnets. It generates low noise when used with border log sources like firewalls.
agomez 20625408 106450
Malware Distribution
Collection IoCs that are actively distributing malware. These endpoints are contacted to download following stages after exploitation phase.
agomez 17477515 48408
TOR Nodes
Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It is intended use is to protect the personal privacy of its users, as well as their freedom and ability to conduct confidential communication by keeping their Internet activities unmonitored. This Feed contains a fresh list of active TOR Nodes
agomez 10433438 14874
T1566 - Phishing
Contains Phishing URLs that an adversary uses normally via email or other communication channels to trick a victim into providing sensitive information like passwords or to infect a host.
agomez 9099919 250000
Malicious IP
Set of IP addresses with context covering malicious hosts
agomez 7772015 247878
Advanced Persistent Threats
Maltiverse APT threat intelligence feed provides IoCs related to highly skilled, sophisticated and focused Attack Groups currenty active. That includes Nation-State Sponsored APTs, Corporate-Sponsored APTs, Cybercriminal Groups, Hacktivist Groups and Terrorist Groups
agomez 7372694 3342
Cybercrime
Covers most active and prolific threats used by active organized cybercrime. It contemplates IoCs from diverse malware families in its different stages.
agomez 5846405 81107
Malicious URL
Covers malicious URL's disregarding phishing
agomez 5069720 43214
Malicious Hostnames
Collection of malicious hostnames disregarding DGA
agomez 4359087 249990
Malware
Covering the most dangerous, prevalent and emerging malware
agomez 3740836 54358
S0367 - Emotet
Emotet is a Trojan that is primarily spread through spam emails (malspam). The infection may arrive either via malicious script, macro-enabled document files, or malicious link.
agomez 3560147 1686
Known Attackers
Contains a selection of active known attacker IPs. SSH Attackers, HTTP Attackers, Spammers and Bots, Mail Spammers, DDoS attackers, Bruteforcers, IMAP Attackers, Compromised Hosts and Low reputation IP's amongst others. This collection can generate so much unmeaningful noise when used against border log sources published to the internet like firewalls.
agomez 3482834 249150
S0154 - Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as "adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors". Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.
agomez 3381372 115134
Unreliable subdomains
This collection contains subdomains that are belonging to legit parent domains that are abused and used for non-legit purposes. Some examples are free web hosting sites or dynamic DNS services
agomez 1296523 1379
S0650 - Qakbot
QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor
agomez 860758 7601
S0561 - GuLoader
GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT.
agomez 701556 348
Industrial Control Systems
This feeds provides IOC's related to well known malware and threat actors that are normally interested in Industrial Sector plus specific malware families targeting these environments.
agomez 687962 6035
S0386 - Ursnif
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links. Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.
agomez 501633 967
IoT
Feed that contains a collection of alive IoCs relate to Internet of Things threats like Mozi or Mirai
agomez 496656 24283
G0099 - APT-C-36
APT-C-36 is a suspected South America espionage group that has been active since at least 2018. The group mainly targets Colombian government institutions as well as important corporations in the financial sector, petroleum industry, and professional manufacturing.
agomez 422691 47
S0332 - Remcos
Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.
agomez 414393 12699
S0453 - Pony
Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors.
agomez 404114 180
S0344 - Azorult
Azorult is a commercial Trojan that is used to steal information from compromised hosts. Azorult has been observed in the wild as early as 2016.In July 2018, Azorult was seen used in a spearphishing campaign against targets in North America. Azorult has been seen used for cryptocurrency theft.
agomez 398843 114
S0331 - AgentTesla
AgentTesla is a sophisticated and widely-used Remote Access Trojan (RAT) that has been active since 2014. It is a form of malware designed to infiltrate and steal sensitive information from victims' systems, such as login credentials, system information, and other critical data. This Trojan is often delivered through phishing emails with malicious attachments or embedded links.
agomez 393659 23762
AsyncRAT
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection
h 389014 15017
S0670 - WarzoneRAT
WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.
agomez 383690 13
S0002 - Mimikatz
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks.
agomez 376531 1067
S0385 - njRAT
njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East
agomez 375233 1732
S0334 - DarkComet
DarkComet is a Windows remote administration tool and backdoor.
agomez 375116 546
S0379 - Revenge RAT
Revenge RAT is a freely available remote access tool written in .NET (C#).
agomez 374679 425
S0262 - QuasarRAT
QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. QuasarRAT is developed in the C# language.
agomez 362627 1169
S0266 - TrickBot
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.
agomez 356246 490
S0226 - Smoke Loader
Smoke Loader is a malicious bot application that can be used to load other malware.Smoke Loader has been seen in the wild since at least 2011 and has included a number of different payloads. It is notorious for its use of deception and self-protection. It also comes with several plug-ins.
agomez 347557 254
G0032 - Lazarus Group
Lazarus Group is a North Korean state-sponsored cyber threat group that has been attributed to the Reconnaissance General Bureau. The group has been active since at least 2009 and was reportedly responsible for the November 2014 destructive wiper attack against Sony Pictures Entertainment as part of a campaign named Operation Blockbuster by Novetta. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.
agomez 333244 166
S0483 - IcedID
IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns.
agomez 332642 219
S0336 - NanoCore
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013
agomez 330167 2786
G0034 - Sandworm Team
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.This group has been active since at least 2009.
agomez 325232 14
S0220 - Chaos
Chaos is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets.
agomez 324142 360
S0455 - Metamorfo
Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.
agomez 323451 21
G0027 - Emissary Panda
Emissary Panda is a Chinese threat group that is believed to be sponsored by the Chinese Government. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors
agomez 322988 39
S0575 - Conti
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.
agomez 304419 110
S0534 - Bazar
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.
agomez 303359 112
G0129 - Mustang Panda
Mustang Panda is a China-based cyber espionage threat actor that was first observed in 2017 but may have been conducting operations since at least 2014. Mustang Panda has targeted government entities, nonprofits, religious, and other non-governmental organizations in the U.S., Europe, Mongolia, Myanmar, Pakistan, and Vietnam, among others.
agomez 298656 48
G1006 - Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.
agomez 295804 9
G0010 - Turla
Turla is a Russian-based threat group that has infected victims in over 45 countries, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies since 2004. Heightened activity was seen in mid-2015. Turla is known for conducting watering hole and spearphishing campaigns and leveraging in-house tools and malware. Turla’s espionage platform is mainly used against Windows machines, but has also been seen used against macOS and Linux machines.
agomez 291104 433
G0067 - APT37
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018
agomez 290731 258
G0135 - BackdoorDiplomacy
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.
agomez 289659 88
G1002 - BITTER
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has primarily targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
agomez 285601 32
S0115 - Crimson
Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016
agomez 281108 1
S0198 - Netwire
NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.
agomez 279069 4258
S0384 - Dridex
Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).
agomez 274893 1552
G0121 - Sidewinder
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan.
agomez 268866 225
S0253 - RunningRAT
RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and Brave Prince.
agomez 267433 27
G0004 - Ke3chang
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.
agomez 230812 14
G0049 - OilRig
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. FireEye assesses that the group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests.
agomez 222095 104
Anonymization IPs
agomez 48444 249962
Malicious Anonymization IPs
List of Malicious Anonymization IPs
h 42748 109473
S1213 - Lumma Stealer
Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer that targets Windows systems to steal sensitive data such as passwords, crypto wallets, and 2FA tokens. It spreads through phishing, fake downloads, and malicious websites, allowing attackers to collect and sell stolen information or use it to deploy other malware.
agomez 35884 2777
TEST FEED Prevent CrowdStrike
test11 33495 1