Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:48:48 UTC Home > List all groups > List all tools > List all groups using tool Licat Tool: Licat Names Licat Murofet Category Malware Type Banking trojan, Backdoor, Info stealer, Credential stealer, Botnet Description (johannesbader) Murofet, also called LICAT, is a member of the Zeus family. It uses a Domain Generation Algorithm (DGA) to determine the current C2 domain names. There exist at least three different versions of Murofet’s DGA, some of which I couldn’t find reimplementations online. In this short blog post I list the three variants that I looked at and discuss the properties of each. Although all versions share a similar algorithm, the resulting domains are very different. Information Malpedia Last change to this tool card: 24 May 2020 Download this tool card in JSON format All groups using tool Licat Changed Name Country Observed Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fc0c4e94-c35f-4245-80b1-6862ce4cd9fa https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fc0c4e94-c35f-4245-80b1-6862ce4cd9fa Page 1 of 1