| | | Gentlemen | [] | win.gentlemen | ['The Gentlemen'] | 2026-05-11 | | | |
| | | AppleChris | [] | win.apple_chris | ['CL-STA-1087'] | 2026-05-11 | | | |
| | | DohDoor | [] | win.dohdoor | [] | 2026-05-11 | | | |
| | | BoryptGrab | [] | win.boryptgrab | [] | 2026-05-11 | | | |
| | | TernDoor | [] | win.terndoor | ['UAT-9244'] | 2026-05-11 | | | |
| | | PeerTime | [] | elf.peer_time | ['UAT-9244'] | 2026-05-11 | | | |
| | | BruteEntry | [] | elf.brute_entry | ['UAT-9244'] | 2026-05-11 | | | |
| | | GRIDTIDE | [] | elf.gridtide | ['UNC2814'] | 2026-05-11 | | | |
| | | OtterCookie | [] | js.otter_cookie | ['WageMole'] | 2026-05-11 | | | |
| | | BeaverTail | [] | js.beavertail | ['WageMole'] | 2026-05-11 | | | |
| | | SquidLoader | [] | win.squidloader | [] | 2026-05-11 | | | |
| | | Coruna | [] | ios.coruna | [] | 2026-05-08 | | | |
| | | Tsundere | ['DinDoor'] | js.tsundere | ['MuddyWater'] | 2026-05-08 | | | |
| | | Loki (Mythic) | [] | win.loki_mythic | ['Mythic Likho'] | 2026-05-08 | | | |
| | | MicroStealer | [] | jar.microstealer | [] | 2026-05-08 | | | |
| | | LucidRook | [] | win.lucidrook | [] | 2026-05-08 | | | |
| | | LucidKnight | [] | win.lucidknight | [] | 2026-05-08 | | | |
| | | LucidPawn | [] | win.lucidpawn | [] | 2026-05-08 | | | |
| | | SpyFRPTunnel | ['fvncBot'] | apk.spyfrptunnel | [] | 2026-05-08 | | | |
| | | PlugX | ['Destroy RAT', 'Kaba', 'Korplug', 'Sogu', 'TIGERPLUG', 'RedDelta'] | win.plugx | ['APT 22', 'APT 26', 'APT31', 'APT41', 'Aurora Panda', 'Calypso group', 'DragonOK', 'EMISSARY PANDA', 'Hellsing', 'Hurricane Panda', 'Leviathan', 'Mirage', 'Mustang Panda', 'NetTraveler', 'Nightshade Panda', 'SLIME29', 'Samurai Panda', 'Stone Panda', 'UPS', 'Violin Panda'] | 2026-05-08 | | | |
| | | TONESHELL | [] | win.toneshell | ['MUSTANG PANDA'] | 2026-05-08 | | | |
| | | SafePay | [] | win.safepay | [] | 2026-05-08 | | | |
| | | Babuk | [] | elf.babuk | [] | 2026-05-08 | | | |
| | | LockBit | ['ABCD Ransomware'] | win.lockbit | [] | 2026-05-08 | | | |
| | | Havoc | ['Havokiz'] | win.havoc | [] | 2026-05-08 | | | |
| | | DracuLoader | [] | win.dracu_loader | ['Earth Estries'] | 2026-05-08 | | | |
| | | FINALDRAFT | [] | win.finaldraft | [] | 2026-05-08 | | | |
| | | SNAPPYBEE | ['Deed RAT', 'POISONPLUG.DEED'] | win.snappybee | ['Earth Estries'] | 2026-05-08 | | | |
| | | VShell | [] | win.vshell | [] | 2026-05-08 | | | |
| | | STOWAWAY | [] | win.stowaway | [] | 2026-05-08 | | | |
| | | SNOWLIGHT | [] | elf.snowlight | ['UNC5174'] | 2026-05-08 | | | |
| | | Phantom Stealer | [] | win.phantom_stealer | [] | 2026-05-08 | | | |
| | | Xloader | ['Formbook'] | osx.xloader | [] | 2026-05-08 | | | |
| | | PylangGhost | ['WeaselStore'] | py.pylangghost | ['WageMole'] | 2026-05-08 | | | |
| | | InvisibleFerret | [] | py.invisibleferret | ['WageMole'] | 2026-05-06 | | | |
| | | EternalPetya | ['ExPetr', 'Pnyetya', 'Petna', 'NotPetya', 'Nyetya', 'NonPetya', 'nPetya', 'Diskcoder.C', 'BadRabbit'] | win.eternal_petya | ['TeleBots', 'Sandworm'] | 2026-05-07 | | | |
| | | GeckoStealer | [] | win.geckostealer | [] | 2026-05-06 | | | |
| | | fast16 | [] | win.fast16 | [] | 2026-05-06 | | | |
| | | ProSpy | [] | apk.prospy | ['HAZY TIGER'] | 2026-05-06 | | | |
| | | LedgerChecker Stealer | [] | win.ledgerchecker | [] | 2026-05-06 | | | |
| | | VoltStealer | [] | win.voltstealer | [] | 2026-05-06 | | | |
| | | SpankRAT | [] | win.spank_rat | [] | 2026-05-06 | | | |
| | | HanGhost | [] | win.hanghost | [] | 2026-05-06 | | | |
| | | AGEWHEEZE | [] | win.agewheeze | ['Cyber Serp'] | 2026-05-06 | | | |
| | | ABCDoor | [] | win.abcdoor | [] | 2026-05-06 | | | |
| | | Gandcrab | ['GrandCrab'] | win.gandcrab | ['Pinchy Spider'] | 2026-05-05 | | | |
| | | Phorpiex | ['Tldr', 'Trik', 'TwizT', 'phorphiex'] | win.phorpiex | [] | 2026-05-05 | | | |
| | | NetSupportManager RAT | ['NetSupport'] | win.netsupportmanager_rat | [] | 2026-05-05 | | | |
| | | SmartApeSG | ['HANEYMANEY', 'ZPHP'] | js.smartapesg | [] | 2026-05-05 | | | |
| | | SectopRAT | ['1xxbot', 'ArechClient'] | win.sectop_rat | [] | 2026-05-05 | | | |
| | | QLNX | ['Quasar Linux RAT'] | elf.qlnx | [] | 2026-05-05 | | | |
| | | Dridex | [] | win.dridex | ['Evil Corp', 'INDRIK SPIDER', 'TA505'] | 2026-05-05 | | | |
| | | Macaw | [] | win.macaw | [] | 2026-05-05 | | | |
| | | WastedLocker | [] | win.wastedlocker | [] | 2026-05-05 | | | |
| | | SNOWBASIN | [] | py.snowbasin | ['UNC6692'] | 2026-05-05 | | | |
| | | ZionSiphon | [] | win.zionsiphon | [] | 2026-05-05 | | | |
| | | DistTrack | ['Shamoon'] | win.disttrack | ['Shamoon', 'Magic Hound', 'Timberworm', 'COBALT GIPSY'] | 2026-05-05 | | | |
| | | GRAMDOOR | ['Small Sieve'] | win.gramdoor | ['MuddyWater'] | 2026-05-05 | | | |
| | | POWERSTATS | ['Valyria'] | ps1.powerstats | ['MuddyWater'] | 2026-05-05 | | | |
| | | STARWHALE | ['Canopy', 'SloughRAT'] | vbs.starwhale | ['MuddyWater'] | 2026-05-05 | | | |
| | | PowGoop | [] | ps1.powgoop | ['MuddyWater'] | 2026-05-05 | | | |
| | | WannaCryptor | ['Wana Decrypt0r', 'WannaCry', 'WannaCrypt', 'Wcry'] | win.wannacryptor | ['Lazarus Group'] | 2026-05-05 | | | |
| | | RandomQuery | [] | vbs.randomquery | ['Kimsuky'] | 2026-05-05 | | | |
| | | RandomQuery | [] | ps1.randomquery | ['Kimsuky'] | 2026-05-05 | | | |
| | | CloudEyE | ['GuLoader', 'vbdropper'] | win.cloudeye | [] | 2026-05-05 | | | |
| | | Lumma Stealer | ['LummaC2 Stealer'] | win.lumma | ['Angry Likho'] | 2026-05-05 | | | |
| | | SmokeLoader | ['Dofoil', 'Sharik', 'Smoke', 'Smoke Loader'] | win.smokeloader | ['SMOKY SPIDER', 'UAC-0006'] | 2026-05-05 | | | |
| | | SMOKEDHAM | [] | win.smokedham | [] | 2026-05-05 | | | |
| | | AgendaCrypt | ['Agenda', 'Qilin'] | win.agendacrypt | [] | 2026-05-05 | | | |
| | | Qilin | [] | elf.qilin | [] | 2026-05-05 | | | |
| | | JADESNOW | ['ChainedDown'] | js.jadesnow | ['WageMole'] | 2026-05-05 | | | |
| | | Bedep | [] | win.bedep | [] | 2026-05-05 | | | |
| | | killada | [] | win.killada | [] | 2026-05-05 | | | |
| | | GhostSocks | [] | win.ghostsocks | [] | 2026-05-05 | | | |
| | | Vidar | [] | win.vidar | [] | 2026-05-05 | | | |
| | | SmartLoader | [] | win.smartloader | [] | 2026-05-05 | | | |
| | | Stealc | [] | win.stealc | [] | 2026-05-05 | | | |
| | | PicassoLoader | [] | win.picasso_loader | ['Ghostwriter'] | 2026-05-05 | | | |
| | | Stealerium | [] | win.stealerium | [] | 2026-05-05 | | | |
| | | Supper | ['SocksShell', 'ZAPCAT'] | win.supper | ['Vanilla Tempest'] | 2026-02-25 | | | |
| | | HijackLoader | ['DOILoader', 'GHOSTPULSE', 'IDAT Loader', 'SHADOWLADDER'] | win.hijackloader | [] | 2026-05-05 | | | |
| | | 3snake | [] | elf.3snake | [] | 2026-05-04 | | | |
| | | SHEETCREEP | [] | win.sheetcreep | [] | 2026-01-29 | | | |
| | | Albiriox | [] | apk.albiriox | [] | 2026-04-22 | | | |
| | | FriendlyFerret | [] | osx.friendlyferret | ['WageMole'] | 2025-02-04 | | | |
| | | Remcos | ['RemcosRAT', 'Remvio', 'Socmer'] | win.remcos | ['APT33', 'The Gorgon Group', 'UAC-0050'] | 2026-04-22 | | | |
| | | AmodalTea | [] | osx.amodaltea | ['UNC1069'] | 2026-04-22 | | | |
| | | BetaBot | ['Neurevt'] | win.betabot | [] | 2026-04-22 | | | |
| | | RTM | ['Redaman'] | win.rtm | [] | 2026-04-22 | | | |
| | | SpyEye | [] | win.spyeye | [] | 2026-04-22 | | | |
| | | Zeus | ['Zbot'] | win.zeus | [] | 2026-04-22 | | | |
| | | TrickBot | ['Trickster', 'TheTrick', 'TrickLoader'] | win.trickbot | ['TA505', 'UNC1878', 'WIZARD SPIDER'] | 2026-04-22 | | | |
| | | Gozi | ['CRM', 'Gozi CRM', 'Papras', 'Snifula', 'Ursnif'] | win.gozi | [] | 2026-04-22 | | | |
| | | Ramnit | ['Nimnul'] | win.ramnit | [] | 2026-04-22 | | | |
| | | DanaBot | ['DanaTools'] | win.danabot | ['SCULLY SPIDER'] | 2026-04-22 | | | |
| | | Emotet | ['Geodo', 'Heodo'] | win.emotet | ['GOLD CABIN', 'MUMMY SPIDER', 'Mealybug'] | 2026-04-22 | | | |
| | | Mirax | ['MiraxRAT', 'Mirax Bot'] | apk.mirax | [] | 2026-04-22 | | | |
| | | Tenzor | [] | win.tenzor | [] | 2026-04-09 | | | |
| | | Remus | [] | win.remus | [] | 2026-04-09 | | | |
| | | Payload | [] | elf.payload | [] | 2026-04-09 | | | |