{
	"id": "99e700fe-641b-41dd-b002-ee65e87c97ea",
	"created_at": "2026-04-06T00:21:10.996693Z",
	"updated_at": "2026-04-10T03:38:03.287574Z",
	"deleted_at": null,
	"sha1_hash": "e3d55782d67d6ad294f432f6b385bbf864d80ccc",
	"title": "Worm - Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 54549,
	"plain_text": "Worm - Threat Group Cards: A Threat Actor Encyclopedia\r\nArchived: 2026-04-05 14:05:41 UTC\r\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool H-Worm\r\n Tool: H-Worm\r\nNames\r\nH-Worm\r\nH-Worm RAT\r\nHoudini RAT\r\nHoudini\r\nHworm\r\nNjw0rm\r\nIniduoh\r\nJenxcus\r\nKognito\r\nWSHRAT\r\ndinihou\r\ndunihi\r\nCategory Malware\r\nType Backdoor, Info stealer\r\nDescription\r\n(FireEye) H-worm is a VBS (Visual Basic Script) based RAT written by an individual\r\ngoing by the name Houdini. We believe the author is based in Algeria and has connections\r\nto njq8, the author of njw0rm and njRAT/LV through means of a shared or common code\r\nbase. We have seen the H-worm RAT being employed in targeted attacks against the\r\ninternational energy industry; however, we also see it being employed in a wider context\r\nas run of the mill attacks through spammed email attachments and malicious links.\r\nInformation\r\n\u003chttps://www.fireeye.com/blog/threat-research/2013/09/now-you-see-me-h-worm-by-houdini.html\u003e\r\nMalpedia \u003chttps://malpedia.caad.fkie.fraunhofer.de/details/win.houdini\u003e\r\nAlienVault OTX \u003chttps://otx.alienvault.com/browse/pulses?q=tag:h-worm\u003e\r\nLast change to this tool card: 29 December 2022\r\nDownload this tool card in JSON format\r\nAll groups using tool H-Worm\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e\r\nPage 1 of 2\n\nChanged Name Country Observed\r\nAPT groups\r\n  Molerats, Extreme Jackal, Gaza Cybergang [Gaza] 2012-Jul 2023  \r\n      ↳ Subgroup: Pat Bear, APT-C-37 2015  \r\n  TA2541 [Unknown] 2017  \r\n  WIRTE Group [Middle East] 2018-Feb 2024  \r\n4 groups listed (4 APT, 0 other, 0 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e"
	],
	"report_names": [
		"listgroups.cgi?u=1f72516d-bbb2-465d-b747-94eb664cb96e"
	],
	"threat_actors": [
		{
			"id": "99468ac6-ccfd-4cd8-b726-791600e61431",
			"created_at": "2023-11-01T02:01:06.647272Z",
			"updated_at": "2026-04-10T02:00:05.313262Z",
			"deleted_at": null,
			"main_name": "TA2541",
			"aliases": [
				"TA2541"
			],
			"source_name": "MITRE:TA2541",
			"tools": [
				"Snip3",
				"Revenge RAT",
				"jRAT",
				"WarzoneRAT",
				"Imminent Monitor",
				"AsyncRAT",
				"NETWIRE",
				"Agent Tesla",
				"njRAT"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "97dc332f-2241-4755-ae33-54e5eff3990a",
			"created_at": "2023-01-06T13:46:39.307201Z",
			"updated_at": "2026-04-10T02:00:03.282272Z",
			"deleted_at": null,
			"main_name": "TA2541",
			"aliases": [],
			"source_name": "MISPGALAXY:TA2541",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "0c502f6d-640d-4e69-bfb8-328ba6540d4f",
			"created_at": "2022-10-25T15:50:23.756782Z",
			"updated_at": "2026-04-10T02:00:05.324924Z",
			"deleted_at": null,
			"main_name": "Molerats",
			"aliases": [
				"Molerats",
				"Operation Molerats",
				"Gaza Cybergang"
			],
			"source_name": "MITRE:Molerats",
			"tools": [
				"MoleNet",
				"DustySky",
				"DropBook",
				"SharpStage",
				"PoisonIvy"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "0769c188-62ce-44ee-8e9d-1067f3d3c083",
			"created_at": "2022-10-25T16:07:24.259063Z",
			"updated_at": "2026-04-10T02:00:04.913621Z",
			"deleted_at": null,
			"main_name": "Pat Bear",
			"aliases": [
				"APT-C-37",
				"Pat Bear",
				"Racquet Bear"
			],
			"source_name": "ETDA:Pat Bear",
			"tools": [
				"Bladabindi",
				"CypherRat",
				"DroidJack",
				"H-Worm",
				"H-Worm RAT",
				"Houdini",
				"Houdini RAT",
				"Hworm",
				"Iniduoh",
				"Jenxcus",
				"Jorik",
				"Kognito",
				"Njw0rm",
				"SSLove RAT",
				"SpyNote",
				"SpyNote RAT",
				"WSHRAT",
				"dinihou",
				"dunihi",
				"njRAT"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "b14cd6df-3108-4839-8a2d-52eb2f8ce9c8",
			"created_at": "2022-10-25T15:50:23.798666Z",
			"updated_at": "2026-04-10T02:00:05.255838Z",
			"deleted_at": null,
			"main_name": "WIRTE",
			"aliases": [
				"WIRTE"
			],
			"source_name": "MITRE:WIRTE",
			"tools": [
				"LitePower",
				"Ferocious"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "7800d05d-e713-4a4f-9b4f-0b960fb82c9d",
			"created_at": "2023-11-14T02:00:07.079123Z",
			"updated_at": "2026-04-10T02:00:03.444083Z",
			"deleted_at": null,
			"main_name": "WIRTE",
			"aliases": [
				"Ashen Lepus"
			],
			"source_name": "MISPGALAXY:WIRTE",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "e5cad6bf-fa91-4128-ba0d-2bf3ff3c6c6b",
			"created_at": "2025-08-07T02:03:24.53077Z",
			"updated_at": "2026-04-10T02:00:03.680525Z",
			"deleted_at": null,
			"main_name": "ALUMINUM SARATOGA",
			"aliases": [
				"APT-C-23",
				"Arid Viper",
				"Desert Falcon",
				"Extreme Jackal ",
				"Gaza Cybergang",
				"Molerats ",
				"Operation DustySky ",
				"TA402"
			],
			"source_name": "Secureworks:ALUMINUM SARATOGA",
			"tools": [
				"BlackShades",
				"BrittleBush",
				"DarkComet",
				"LastConn",
				"Micropsia",
				"NimbleMamba",
				"PoisonIvy",
				"QuasarRAT",
				"XtremeRat"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "6bad0c51-0d2b-4f04-b355-f88c960db813",
			"created_at": "2025-08-07T02:03:24.546734Z",
			"updated_at": "2026-04-10T02:00:03.691101Z",
			"deleted_at": null,
			"main_name": "ALUMINUM THORN",
			"aliases": [
				"Frankenstein ",
				"WIRTE "
			],
			"source_name": "Secureworks:ALUMINUM THORN",
			"tools": [
				"FruityC2",
				"PowerShell Empire"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "1162e0d4-b69c-423d-a4da-f3080d1d2b0c",
			"created_at": "2023-01-06T13:46:38.508262Z",
			"updated_at": "2026-04-10T02:00:03.006018Z",
			"deleted_at": null,
			"main_name": "Molerats",
			"aliases": [
				"Gaza Cybergang",
				"Operation Molerats",
				"Extreme Jackal",
				"ALUMINUM SARATOGA",
				"G0021",
				"BLACKSTEM",
				"Gaza Hackers Team",
				"Gaza cybergang"
			],
			"source_name": "MISPGALAXY:Molerats",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "878ce40c-9fbc-4cff-a5c4-771086979fa7",
			"created_at": "2022-10-25T16:07:24.264056Z",
			"updated_at": "2026-04-10T02:00:04.915395Z",
			"deleted_at": null,
			"main_name": "TA2541",
			"aliases": [],
			"source_name": "ETDA:TA2541",
			"tools": [
				"AVE_MARIA",
				"AgenTesla",
				"Agent Tesla",
				"AgentTesla",
				"AsyncRAT",
				"Ave Maria",
				"AveMariaRAT",
				"DarkRAT",
				"H-Worm",
				"H-Worm RAT",
				"Houdini",
				"Houdini RAT",
				"Hworm",
				"Imminent Monitor",
				"Imminent Monitor RAT",
				"Iniduoh",
				"Jenxcus",
				"Kognito",
				"Luminosity RAT",
				"LuminosityLink",
				"Negasteal",
				"NetWeird",
				"NetWire",
				"NetWire RAT",
				"NetWire RC",
				"NetWired RC",
				"Njw0rm",
				"Origin Logger",
				"Parallax",
				"Parallax RAT",
				"ParallaxRAT",
				"Recam",
				"Revenge RAT",
				"RevengeRAT",
				"Revetrat",
				"WSHRAT",
				"ZPAQ",
				"avemaria",
				"dinihou",
				"dunihi"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "aa5c2fa9-e018-484b-9f4a-0ef76ebbbf57",
			"created_at": "2022-10-25T16:07:24.41839Z",
			"updated_at": "2026-04-10T02:00:04.982315Z",
			"deleted_at": null,
			"main_name": "WIRTE Group",
			"aliases": [
				"G0090",
				"White Dev 21"
			],
			"source_name": "ETDA:WIRTE Group",
			"tools": [
				"EmPyre",
				"EmpireProject",
				"H-Worm",
				"H-Worm RAT",
				"Houdini",
				"Houdini RAT",
				"Hworm",
				"Iniduoh",
				"Jenxcus",
				"Kognito",
				"LOLBAS",
				"LOLBins",
				"Living off the Land",
				"Njw0rm",
				"PowerShell Empire",
				"SameCoin",
				"WSHRAT",
				"dinihou",
				"dunihi"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "847f600c-cf90-44c0-8b39-fb0d5adfcef4",
			"created_at": "2022-10-25T16:07:23.875541Z",
			"updated_at": "2026-04-10T02:00:04.768142Z",
			"deleted_at": null,
			"main_name": "Molerats",
			"aliases": [
				"ATK 89",
				"Aluminum Saratoga",
				"Extreme Jackal",
				"G0021",
				"Gaza Cybergang",
				"Gaza Hackers Team",
				"Molerats",
				"Operation DustySky",
				"Operation DustySky Part 2",
				"Operation Molerats",
				"Operation Moonlight",
				"Operation SneakyPastes",
				"Operation TopHat",
				"TA402",
				"TAG-CT5"
			],
			"source_name": "ETDA:Molerats",
			"tools": [
				"BadPatch",
				"Bladabindi",
				"BrittleBush",
				"Chymine",
				"CinaRAT",
				"Darkmoon",
				"Downeks",
				"DropBook",
				"DustySky",
				"ExtRat",
				"Gen:Trojan.Heur.PT",
				"H-Worm",
				"H-Worm RAT",
				"Houdini",
				"Houdini RAT",
				"Hworm",
				"Iniduoh",
				"IronWind",
				"Jenxcus",
				"JhoneRAT",
				"Jorik",
				"KasperAgent",
				"Kognito",
				"LastConn",
				"Micropsia",
				"MoleNet",
				"Molerat Loader",
				"NeD Worm",
				"NimbleMamba",
				"Njw0rm",
				"Pierogi",
				"Poison Ivy",
				"Quasar RAT",
				"QuasarRAT",
				"SPIVY",
				"Scote",
				"SharpSploit",
				"SharpStage",
				"WSHRAT",
				"WelcomeChat",
				"Xtreme RAT",
				"XtremeRAT",
				"Yggdrasil",
				"dinihou",
				"dunihi",
				"njRAT",
				"pivy",
				"poisonivy"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434870,
	"ts_updated_at": 1775792283,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/e3d55782d67d6ad294f432f6b385bbf864d80ccc.pdf",
		"text": "https://archive.orkl.eu/e3d55782d67d6ad294f432f6b385bbf864d80ccc.txt",
		"img": "https://archive.orkl.eu/e3d55782d67d6ad294f432f6b385bbf864d80ccc.jpg"
	}
}