Description

The Registry Access and Manager feature in malware allows attackers to interact with the Windows Registry, the hierarchical database that stores low-level settings for the operating system and installed applications. With capabilities to view, create, edit, or delete registry keys and data, this feature gives attackers a powerful tool to manipulate system configurations and behavior. Additionally, it can be used to steal sensitive information such as passwords and software licenses stored in registry entries. For instance, by modifying or creating registry entries, malware can ensure its own persistence, deactivate security measures, or even alter user permissions. The ability to steal passwords and licenses from the registry can also facilitate privilege escalation, making the compromised system even more vulnerable to further exploitation. This kind of access is particularly valuable for advanced attacks, where fine-grained control over the target system is required. By manipulating the registry, attackers can not only deepen their level of system compromise but also tailor the environment to suit their malicious objectives, making this feature a key asset in a sophisticated malware toolkit.


Categories Alteration, Exfiltration, Credentials, System Management, Disruption
Dangerousness High

Associated with Releases

Version Origins Authors Languages Release Date
Back Orifice 1.20 logoBack Orifice 1.20 United States ๐Ÿ‡บ๐Ÿ‡ธ Cult of the Dead Cow (cDc) C++ Jul, 1998
SubSeven 1.4 logoSubSeven 1.4 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Mar, 1999
SubSeven 1.5 logoSubSeven 1.5 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Apr, 1999
SubSeven 1.6 logoSubSeven 1.6 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Apr, 1999
SubSeven 1.7 logoSubSeven 1.7 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi May, 1999
SubSeven 1.8 logoSubSeven 1.8 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi May, 1999
SubSeven 1.9 logoSubSeven 1.9 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Jun, 1999
Back Orifice 2000 (BO2K) 1.0 logoBack Orifice 2000 (BO2K) 1.0 United States ๐Ÿ‡บ๐Ÿ‡ธ Cult of the Dead Cow (cDc) C++ Jul, 1999
SubSeven 1.9 Apocalypse logoSubSeven 1.9 Apocalypse Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Aug, 1999
SubSeven 2.0 logoSubSeven 2.0 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Sep, 1999
SubSeven 2.1 logoSubSeven 2.1 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Nov, 1999
SubSeven 2.1.1 GOLD edition logoSubSeven 2.1.1 GOLD edition Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Feb, 2000
SubSeven 2.1.2 M.U.I.E logoSubSeven 2.1.2 M.U.I.E Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Apr, 2000
SubSeven 2.1.3 BONUS logoSubSeven 2.1.3 BONUS Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Jun, 2000
SubSeven 2.1.4 DEFCON 8 logoSubSeven 2.1.4 DEFCON 8 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Jul, 2000
Y3K rat 1.5 logoY3K rat 1.5 Greece ๐Ÿ‡ฌ๐Ÿ‡ท firelarm , Chucky Delphi Jan, 2001
SubSeven 2.2 logoSubSeven 2.2 Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Mar, 2001
Y3K rat 1.6 MS logoY3K rat 1.6 MS Greece ๐Ÿ‡ฌ๐Ÿ‡ท firelarm , Chucky Delphi Jul, 2001
Optix Pro 1.0 logoOptix Pro 1.0 Unknown ๐Ÿดโ€โ˜ ๏ธ s13az3 Delphi Apr, 2002
Net-Devil 1.5 logoNet-Devil 1.5 Unknown ๐Ÿดโ€โ˜ ๏ธ Nilez Delphi Jul, 2002
MoSucker 3.0b logoMoSucker 3.0b Germany ๐Ÿ‡ฉ๐Ÿ‡ช Superchachi Visual Basic 6 (VB6) Nov, 2002
Beast 1.91 logoBeast 1.91 Romania ๐Ÿ‡ท๐Ÿ‡ด Tataye Delphi Jan, 2003
SubSeven 2.1.5 Legends logoSubSeven 2.1.5 Legends Romania ๐Ÿ‡ท๐Ÿ‡ด, Canada ๐Ÿ‡จ๐Ÿ‡ฆ Mobman Delphi Feb, 2003
Beast 2.01 logoBeast 2.01 Romania ๐Ÿ‡ท๐Ÿ‡ด Tataye Delphi Jun, 2003
LanFiltrator 1.1 Fix 1 logoLanFiltrator 1.1 Fix 1 Australia ๐Ÿ‡ฆ๐Ÿ‡บ Read101 Delphi Aug, 2003
Optix Pro 1.32 logoOptix Pro 1.32 Unknown ๐Ÿดโ€โ˜ ๏ธ s13az3 , xMs Delphi Sep, 2003
CIA 1.2 logoCIA 1.2 England ๐Ÿด๓ ง๓ ข๓ ฅ๓ ฎ๓ ง๓ ฟ Alchemist Visual Basic 6 (VB6) Sep, 2003
Beast 2.02 logoBeast 2.02 Romania ๐Ÿ‡ท๐Ÿ‡ด Tataye Delphi Sep, 2003
Nuclear RAT 1.0 Beta 5 logoNuclear RAT 1.0 Beta 5 Brazil ๐Ÿ‡ง๐Ÿ‡ท Caesar2k Delphi Feb, 2004
ProRat 1.4 logoProRat 1.4 Turkey ๐Ÿ‡น๐Ÿ‡ท HighLander , ATmaCA Borland C++ Feb, 2004
LanFiltrator 1.5 Beta III logoLanFiltrator 1.5 Beta III Australia ๐Ÿ‡ฆ๐Ÿ‡บ Read101 Delphi Feb, 2004
ProRat 1.6 logoProRat 1.6 Turkey ๐Ÿ‡น๐Ÿ‡ท HighLander , ATmaCA Borland C++ Mar, 2004
ProRat 1.8 logoProRat 1.8 Turkey ๐Ÿ‡น๐Ÿ‡ท HighLander , ATmaCA Borland C++ Apr, 2004
Infector NG 2004 2.1.0 logoInfector NG 2004 2.1.0 Belgium ๐Ÿ‡ง๐Ÿ‡ช, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง fc , Infiltration Delphi May, 2004
Beast 2.07 logoBeast 2.07 Romania ๐Ÿ‡ท๐Ÿ‡ด Tataye Delphi Aug, 2004
Optix Pro 1.33 logoOptix Pro 1.33 Unknown ๐Ÿดโ€โ˜ ๏ธ s13az3 Delphi Aug, 2004
ProRat 1.9 logoProRat 1.9 Turkey ๐Ÿ‡น๐Ÿ‡ท HighLander , ATmaCA Borland C++ Aug, 2004
Institution 2004 0.4.0 logoInstitution 2004 0.4.0 United States ๐Ÿ‡บ๐Ÿ‡ธ Aphex Delphi Oct, 2004
CIA 1.3 logoCIA 1.3 England ๐Ÿด๓ ง๓ ข๓ ฅ๓ ฎ๓ ง๓ ฟ Alchemist Visual Basic 6 (VB6) Dec, 2004
DARKMOON 4.11 / 4.11 Private Edition logoDARKMOON 4.11 / 4.11 Private Edition Spain ๐Ÿ‡ช๐Ÿ‡ธ shukisnike Delphi Jun, 2005
Bifrost 1.2.1 logoBifrost 1.2.1 Sweden ๐Ÿ‡ธ๐Ÿ‡ช ksv C++ Jan, 2007
Bandook 1.35 logoBandook 1.35 Lebanon ๐Ÿ‡ฑ๐Ÿ‡ง PrinceAli Delphi, C++ Apr, 2007
Poison Ivy 2.3.0 logoPoison Ivy 2.3.0 Sweden ๐Ÿ‡ธ๐Ÿ‡ช Shapeless Delphi, MASM Jun, 2007
sharK 2.4.0 Fwb+ logosharK 2.4.0 Fwb+ Germany ๐Ÿ‡ฉ๐Ÿ‡ช sNiper109 , rockZ Visual Basic 6 (VB6) Aug, 2007
Nuclear RAT 2.1.0 logoNuclear RAT 2.1.0 Brazil ๐Ÿ‡ง๐Ÿ‡ท Caesar2k Delphi Sep, 2007
Poison Ivy 2.3.2 logoPoison Ivy 2.3.2 Sweden ๐Ÿ‡ธ๐Ÿ‡ช Shapeless Delphi, MASM Jan, 2008
Turkojan 4 logoTurkojan 4 Turkey ๐Ÿ‡น๐Ÿ‡ท FยตNGยตยง Delphi Feb, 2008
sharK 3.1 fwb++ logosharK 3.1 fwb++ Germany ๐Ÿ‡ฉ๐Ÿ‡ช sNiper109 , rockZ Visual Basic 6 (VB6) Mar, 2008
SynRAT 4.0.1 logoSynRAT 4.0.1 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Delphi May, 2009
Cerberus 1.0 Beta logoCerberus 1.0 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Cerberus 1.01 Beta logoCerberus 1.01 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Cerberus 1.02 Beta logoCerberus 1.02 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Apocalypse RAT 1.4 logoApocalypse RAT 1.4 Turkey ๐Ÿ‡น๐Ÿ‡ท ap0calypse Delphi Aug, 2009
Cerberus 1.03.4 logoCerberus 1.03.4 United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Sep, 2009
Spy-Net 2.6 logoSpy-Net 2.6 Brazil ๐Ÿ‡ง๐Ÿ‡ท Raphael Delphi Oct, 2009
DarkComet RAT 1.3 logoDarkComet RAT 1.3 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Nov, 2009
Cerberus 1.03.5 Beta logoCerberus 1.03.5 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Dec, 2009
DarkComet RAT 2.0 RC4 logoDarkComet RAT 2.0 RC4 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Delphi Mar, 2010
CyberGate 1.04.8 logoCyberGate 1.04.8 United States ๐Ÿ‡บ๐Ÿ‡ธ johnyk Delphi Apr, 2010
Lost Door 4.3.1 logoLost Door 4.3.1 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Apr, 2010
Lost Door 5.1 logoLost Door 5.1 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Oct, 2010
Coolvibes 1 Update 8 logoCoolvibes 1 Update 8 Spain ๐Ÿ‡ช๐Ÿ‡ธ Thor Delphi May, 2011
Xtreme RAT 2.9 logoXtreme RAT 2.9 Brazil ๐Ÿ‡ง๐Ÿ‡ท Raphael Delphi Jul, 2011
DarkComet RAT 5.3.1 logoDarkComet RAT 5.3.1 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Delphi Jun, 2012
NjRat 0.7d logoNjRat 0.7d Kuwait ๐Ÿ‡ฐ๐Ÿ‡ผ njq8 VB .net Dec, 2013