| | | BloodAlchemy | [] | win.bloodalchemy | [] | 2024-04-26 | | | |
| | | Rhadamanthys | [] | win.rhadamanthys | ['Sandworm'] | 2024-04-11 | | | |
| | | Unidentified 111 (Latrodectus) | ['BLACKWIDOW', 'IceNova', 'Latrodectus', 'Lotus'] | win.unidentified_111 | [] | 2024-04-10 | | | |
| | | DCRat | ['DarkCrystal RAT'] | win.dcrat | [] | 2024-04-23 | | | |
| | | Venom RAT | [] | win.venom | [] | 2024-04-23 | | | |
| | | AsyncRAT | [] | win.asyncrat | [] | 2024-04-23 | | | |
| | | CloudEyE | ['GuLoader', 'vbdropper'] | win.cloudeye | [] | 2024-04-23 | | | |
| | | LokiBot | [] | apk.lokibot | [] | 2024-04-23 | | | |
| | | Agent Tesla | ['AgenTesla', 'AgentTesla', 'Negasteal'] | win.agent_tesla | ['SWEED'] | 2024-04-23 | | | |
| | | Remcos | ['RemcosRAT', 'Remvio', 'Socmer'] | win.remcos | ['APT33', 'The Gorgon Group', 'UAC-0050'] | 2024-04-23 | | | |
| | | Formbook | ['win.xloader'] | win.formbook | ['SWEED', 'Cobalt'] | 2024-04-23 | | | |
| | | XWorm | [] | win.xworm | [] | 2024-04-23 | | | |
| | | 404 Keylogger | ['404KeyLogger', 'Snake Keylogger'] | win.404keylogger | [] | 2024-04-23 | | | |
| | | Broomstick | ['CleanUpLoader', 'Oyster'] | win.broomstick | [] | 2024-03-04 | | | |
| | | SmartLoader | [] | win.smartloader | [] | 2024-04-23 | | | |
| | | SSLoad | [] | win.ssload | [] | 2024-04-23 | | | |
| | | KrBanker | ['BlackMoon'] | win.krbanker | [] | 2024-04-23 | | | |
| | | solarmarker | ['Jupyter', 'Polazert', 'Yellow Cockatoo'] | win.solarmarker | [] | 2024-01-18 | | | |
| | | JSOutProx | [] | win.jsoutprox | ['SOLAR SPIDER'] | 2024-04-08 | | | |
| | | Alureon | ['Olmarik', 'Pihar', 'TDL', 'TDSS', 'wowlik'] | win.alureon | [] | 2024-04-23 | | | |
| | | SpyNote | ['CypherRat'] | apk.spynote | ['OilRig'] | 2024-04-23 | | | |
| | | CryptoClippy | [] | win.cryptoclippy | [] | 2024-04-23 | | | |
| | | Chaos | ['FakeRyuk', 'RyukJoke', 'Yashma'] | win.chaos | [] | 2024-04-23 | | | |
| | | RAWDOOR | [] | win.rawdoor | ['APT31'] | 2024-04-17 | | | |
| | | Industroyer | ['Crash', 'CrashOverride'] | win.industroyer | ['ELECTRUM'] | 2024-04-23 | | | |
| | | RoarBAT | [] | win.roar_bat | ['Sandworm'] | 2024-04-23 | | | |
| | | CaddyWiper | ['KillDisk.NCX'] | win.caddywiper | ['APT28'] | 2024-04-23 | | | |
| | | VPNFilter | [] | elf.vpnfilter | [] | 2024-04-23 | | | |
| | | BlackEnergy | [] | win.blackenergy | ['Sandworm'] | 2024-04-23 | | | |
| | | EternalPetya | ['ExPetr', 'Pnyetya', 'Petna', 'NotPetya', 'Nyetya', 'NonPetya', 'nPetya', 'Diskcoder.C', 'BadRabbit'] | win.eternal_petya | ['TeleBots', 'Sandworm'] | 2024-04-23 | | | |
| | | INDUSTROYER2 | [] | win.industroyer2 | ['Sandworm'] | 2024-04-23 | | | |
| | | PartyTicket | ['Elections GoRansom', 'HermeticRansom', 'SonicVote'] | win.partyticket | [] | 2024-04-23 | | | |
| | | Olympic Destroyer | ['SOURGRAPE'] | win.olympic_destroyer | [] | 2024-04-23 | | | |
| | | HermeticWiper | ['DriveSlayer', 'FoxBlade', 'KillDisk.NCV', 'NEARMISS'] | win.hermeticwiper | [] | 2024-04-23 | | | |
| | | MgBot | ['BLame', 'MgmBot'] | win.mgbot | [] | 2024-04-23 | | | |
| | | PlugX | ['Destroy RAT', 'Kaba', 'Korplug', 'Sogu', 'TIGERPLUG', 'RedDelta'] | win.plugx | ['APT 22', 'APT 26', 'APT31', 'APT41', 'Aurora Panda', 'Calypso group', 'DragonOK', 'EMISSARY PANDA', 'Hellsing', 'Hurricane Panda', 'Leviathan', 'Mirage', 'Mustang Panda', 'NetTraveler', 'Nightshade Panda', 'SLIME29', 'Samurai Panda', 'Stone Panda', 'UPS', 'Violin Panda'] | 2024-04-19 | | | |
| | | CHINACHOPPER | [] | win.chinachopper | ['APT41', 'EMISSARY PANDA', 'GALLIUM', 'HAFNIUM', 'Hurricane Panda', 'Leviathan'] | 2024-04-19 | | | |
| | | TinyTurlaNG | ['TTNG'] | win.tinyturla_ng | ['Turla'] | 2024-04-19 | | | |
| | | SoumniBot | [] | apk.soumnibot | [] | 2024-04-19 | | | |
| | | RedLine Stealer | ['RECORDSTEALER'] | win.redline_stealer | [] | 2024-04-18 | | | |
| | | Kapeka | [] | win.kapeka | ['Sandworm'] | 2024-04-17 | | | |
| | | Vultur | ['Vulture'] | apk.vultur | [] | 2024-04-15 | | | |
| | | Epsilon Stealer | [] | win.epsilon_stealer | [] | 2024-04-15 | | | |
| | | Nova Stealer | ['Malicord'] | win.nova | [] | 2024-04-11 | | | |
| | | Zloader | ['DELoader', 'SILENTNIGHT', 'Terdot'] | win.zloader | [] | 2024-02-16 | | | |
| | | Amadey | [] | win.amadey | [] | 2024-02-05 | | | |
| | | xzbot | ['xzorcist'] | sh.xzbot | [] | 2024-04-15 | | | |
| | | Vidar | [] | win.vidar | [] | 2024-04-15 | | | |
| | | Quasar RAT | ['CinaRAT', 'QuasarRAT', 'Yggdrasil'] | win.quasar_rat | ['APT33', 'Dropping Elephant', 'Stone Panda', 'The Gorgon Group'] | 2024-04-15 | | | |
| | | SystemBC | ['Coroxy', 'DroxiDat'] | win.systembc | [] | 2024-01-22 | | | |
| | | LaZagne | [] | py.lazagne | [] | 2024-04-15 | | | |
| | | Drokbk | [] | win.drokbk | ['APT35'] | 2024-04-15 | | | |
| | | PureLogs Stealer | [] | win.purelogs | [] | 2024-04-15 | | | |
| | | Donex | [] | win.donex | [] | 2024-04-15 | | | |
| | | Glupteba | [] | win.glupteba | [] | 2024-04-15 | | | |
| | | Simda | ['iBank'] | win.simda | [] | 2024-04-15 | | | |
| | | Dridex | [] | win.dridex | ['Evil Corp', 'INDRIK SPIDER', 'TA505'] | 2024-04-15 | | | |
| | | Emotet | ['Geodo', 'Heodo'] | win.emotet | ['GOLD CABIN', 'MUMMY SPIDER', 'Mealybug'] | 2024-04-15 | | | |
| | | UPSTYLE | [] | py.upstyle | [] | 2024-04-15 | | | |
| | | Conti | [] | win.conti | [] | 2024-04-15 | | | |
| | | Decoy Dog RAT | [] | elf.decoy_dog | [] | 2024-04-15 | | | |
| | | XploitSPY | [] | apk.xploitspy | [] | 2024-04-11 | | | |
| | | No-Justice | [] | win.no_justice | [] | 2024-04-11 | | | |
| | | LockBit | [] | osx.lockbit | [] | 2024-04-11 | | | |
| | | LockBit | [] | elf.lockbit | [] | 2024-04-11 | | | |
| | | LockBit | ['ABCD Ransomware'] | win.lockbit | [] | 2024-04-11 | | | |
| | | RandomQuery | [] | ps1.randomquery | ['Kimsuky'] | 2024-04-11 | | | |
| | | Linodas | ['XDealer', 'DinodasRAT'] | elf.linodas | [] | 2024-04-11 | | | |
| | | ARTFULPIE | [] | win.artfulpie | ['Lazarus Group'] | 2020-02-27 | | | |
| | | AthenaGo RAT | [] | win.athenago | [] | 2017-02-13 | | | |
| | | abantes | [] | win.abantes | [] | 2018-10-18 | | | |
| | | Artra Downloader | [] | win.artra | [] | 2022-07-13 | | | |
| | | AdamLocker | [] | win.adam_locker | [] | 2018-01-04 | | | |
| | | Project Alice | ['PrAlice', 'AliceATM'] | win.alice_atm | [] | 2020-02-27 | | | |
| | | HOTCROISSANT | [] | win.hotcroissant | ['Lazarus Group'] | 2020-04-17 | | | |
| | | Antilam | ['Latinus'] | win.antilam | [] | 2018-07-24 | | | |
| | | AgfSpy | [] | win.agfspy | [] | 2020-11-09 | | | |
| | | Agent.BTZ | ['ComRAT', 'Minit', 'Sun rootkit'] | win.agent_btz | ['Turla'] | 2023-05-10 | | | |
| | | Anatova Ransomware | [] | win.anatova_ransom | [] | 2019-05-09 | | | |
| | | Alphabet Ransomware | [] | win.alphabet_ransomware | [] | 2022-11-12 | | | |
| | | Arik Keylogger | ['Aaron Keylogger'] | win.arik_keylogger | [] | 2018-02-07 | | | |
| | | Abbath Banker | [] | win.abbath_banker | [] | 2016-12-28 | | | |
| | | Acronym | [] | win.acronym | [] | 2017-04-06 | | | |
| | | AppleJeus | [] | win.applejeus | ['Lazarus Group'] | 2023-11-30 | | | |
| | | Alma Communicator | [] | win.alma_communicator | ['OilRig'] | 2019-04-18 | | | |
| | | Reshell | [] | win.reshell | ['GALLIUM'] | 2024-04-11 | | | |
| | | ShadowPad | ['POISONPLUG.SHADOW', 'XShellGhost'] | win.shadowpad | ['APT23', 'APT41', 'APT17', 'DAGGER PANDA', 'Earth Lusca', 'Tonto Team', 'WET PANDA'] | 2024-04-11 | | | |
| | | DinodasRAT | ['XDealer'] | win.dinodas_rat | [] | 2024-04-11 | | | |
| | | Cobalt Strike | ['Agentemis', 'BEACON', 'CobaltStrike', 'cobeacon'] | win.cobalt_strike | ['APT 29', 'APT32', 'APT41', 'AQUATIC PANDA', 'Anunak', 'Cobalt', 'Codoso', 'CopyKittens', 'DarkHydrus', 'FIN6', 'FIN7', 'Leviathan', 'Mustang Panda', 'Shell Crew', 'Stone Panda', 'TianWu', 'UNC1878', 'UNC2452', 'Winnti Umbrella'] | 2024-04-11 | | | |
| | | TONESHELL | [] | win.toneshell | ['MUSTANG PANDA'] | 2024-04-11 | | | |
| | | RemCom | ['RemoteCommandExecution'] | win.remcom | [] | 2024-04-11 | | | |
| | | MimiKatz | [] | win.mimikatz | ['APT32', 'Anunak', 'GALLIUM'] | 2024-04-11 | | | |
| | | Winnti | ['BleDoor', 'JUMPALL', 'RbDoor', 'Pasteboy'] | win.winnti | ['APT17'] | 2024-04-11 | | | |
| | | HyperBro | [] | win.hyperbro | ['EMISSARY PANDA'] | 2024-04-11 | | | |
| | | Poison Ivy | ['SPIVY', 'pivy', 'poisonivy'] | win.poison_ivy | ['GALLIUM', 'Molerats', 'Mustang Panda', 'Nightshade Panda', 'Pirate Panda', 'Stone Panda', 'TA428', 'Temper Panda'] | 2024-04-11 | | | |
| | | Derusbi | ['PHOTO'] | win.derusbi | ['APT41', 'APT17', 'Leviathan', 'Stone Panda'] | 2024-04-11 | | | |
| | | Matanbuchus | [] | win.matanbuchus | [] | 2024-04-10 | | | |
| | | Bashlite | ['gayfgt', 'Gafgyt', 'qbot', 'torlus', 'lizkebab'] | elf.bashlite | [] | 2024-04-10 | | | |
| | | CryptNET | [] | win.cryptnet | [] | 2024-04-10 | | | |
| | | SideWinder | [] | win.sidewinder | ['RAZOR TIGER'] | 2024-04-10 | | | |