| | | Vidar | [] | win.vidar | [] | 2026-03-04 | | | |
| | | BadPaw | [] | win.badpaw | ['APT28'] | 2026-03-04 | | | |
| | | TrustConnect RAT | [] | win.trustconnect | [] | 2026-03-04 | | | |
| | | Aura Stealer | ['AURA Stealer', 'AURASTEAL'] | win.aurastealer | [] | 2026-03-04 | | | |
| | | PXA Stealer | ['PXAStealer', 'PXA'] | py.pxa_stealer | ['CoralRaider'] | 2026-03-03 | | | |
| | | IronZero | [] | win.ironzero | [] | 2026-03-03 | | | |
| | | RMS | ['Gussdoor', 'Remote Manipulator System', 'RuRAT'] | win.rms | ['TA505'] | 2026-03-03 | | | |
| | | GONEPOSTAL | ['Cordyceps', 'NOTDOOR'] | win.gonepostal | ['APT28'] | 2026-03-03 | | | |
| | | GRUNT | ['Covenant'] | win.grunt | [] | 2026-03-03 | | | |
| | | InsidiousGh0st | [] | osx.insidiousgh0st | ['Unfading Sea Haze'] | 2026-02-26 | | | |
| | | InsidiousGh0st | [] | elf.insidiousgh0st | ['Unfading Sea Haze'] | 2026-02-26 | | | |
| | | Stealc | [] | win.stealc | [] | 2026-02-25 | | | |
| | | ArcaneStealer | [] | win.arcane_stealer | [] | 2026-03-03 | | | |
| | | BlackByte | [] | win.blackbyte | [] | 2026-03-02 | | | |
| | | Nokoyawa Ransomware | [] | win.nokoyawa | [] | 2026-03-02 | | | |
| | | FudModule | ['LIGHTSHOW'] | win.fudmodule | ['Lazarus Group'] | 2026-03-02 | | | |
| | | JADESNOW | ['ChainedDown'] | js.jadesnow | [] | 2026-01-19 | | | |
| | | BADAUDIO | [] | win.badaudio | ['APT24'] | 2026-03-02 | | | |
| | | WAVESHAPER | [] | osx.waveshaper | ['UNC1069'] | 2026-02-27 | | | |
| | | SUGARLOADER | [] | osx.sugarloader | ['Lazarus Group'] | 2026-02-27 | | | |
| | | ComeBacker | [] | win.comebacker | ['Lazarus Group'] | 2026-02-27 | | | |
| | | Medusa | [] | win.medusa | [] | 2026-02-27 | | | |
| | | GRIMBOLT | [] | elf.grimbolt | [] | 2026-02-27 | | | |
| | | SLAYSTYLE | [] | jar.slaystyle | [] | 2026-02-27 | | | |
| | | BRICKSTORM | [] | elf.brickstorm | ['UTA0178'] | 2026-02-27 | | | |
| | | Agent Tesla | ['AgenTesla', 'AgentTesla', 'Negasteal'] | win.agent_tesla | ['SWEED'] | 2026-02-27 | | | |
| | | KarstoRAT | [] | win.karsto_rat | [] | 2026-02-26 | | | |
| | | GolangGhost | ['BitStep RAT', 'WeaselStore'] | win.golangghost | ['WageMole'] | 2026-02-26 | | | |
| | | BeaverTail | [] | js.beavertail | ['WageMole'] | 2026-02-26 | | | |
| | | PylangGhost | [] | py.pylangghost | ['WageMole'] | 2026-02-26 | | | |
| | | Broomstick | ['CLEANBOOST', 'CleanUp', 'CleanUpLoader', 'Oyster'] | win.broomstick | [] | 2026-02-25 | | | |
| | | AstarionRAT | ['MIMICRAT'] | win.astarion_rat | [] | 2026-02-25 | | | |
| | | Matanbuchus | [] | win.matanbuchus | [] | 2026-02-25 | | | |
| | | Airstalk | [] | win.airstalk | ['CL-STA-1009'] | 2026-02-25 | | | |
| | | DRAT | [] | win.drat | ['TAG-140'] | 2026-02-25 | | | |
| | | Ashen | ['AshTag'] | win.ashen | ['WIRTE'] | 2026-02-25 | | | |
| | | PortStarter | ['SocksProxyGo'] | win.portstarter | ['Vanilla Tempest'] | 2026-02-25 | | | |
| | | WalkLoader | [] | elf.walkloader | [] | 2026-02-25 | | | |
| | | GoldenSpy | [] | win.goldenspy | [] | 2026-02-25 | | | |
| | | GoldenHelper | [] | win.goldenhelper | [] | 2026-02-25 | | | |
| | | LockerGoga | [] | win.lockergoga | ['FIN6'] | 2026-02-25 | | | |
| | | Ryuk | [] | win.ryuk | ['FIN6', 'GRIM SPIDER', 'UNC1878', 'WIZARD SPIDER'] | 2026-02-25 | | | |
| | | FriedEx | ['BitPaymer', 'DoppelPaymer', 'IEncrypt'] | win.friedex | ['INDRIK SPIDER'] | 2026-02-25 | | | |
| | | Clop | ['Cl0p'] | elf.clop | [] | 2026-02-25 | | | |
| | | Mespinoza | ['pysa'] | win.mespinoza | [] | 2026-02-25 | | | |
| | | Egregor | [] | win.egregor | [] | 2026-02-25 | | | |
| | | TONERJAM | [] | win.tonerjam | [] | 2026-02-25 | | | |
| | | Cobalt Strike | ['Agentemis', 'BEACON', 'CobaltStrike', 'cobeacon'] | win.cobalt_strike | ['APT 29', 'APT29', 'APT32', 'APT41', 'AQUATIC PANDA', 'Anunak', 'Cobalt', 'Codoso', 'CopyKittens', 'DarkHydrus', 'Earth Baxia', 'FIN6', 'FIN7', 'Leviathan', 'Mustang Panda', 'Shell Crew', 'Stone Panda', 'TianWu', 'UNC1878', 'UNC2452', 'Winnti Umbrella'] | 2026-02-25 | | | |
| | | IISpy | ['BadIIS'] | win.iispy | [] | 2026-02-25 | | | |
| | | DynoWiper | [] | win.dynowiper | [] | 2026-02-25 | | | |
| | | reptile | [] | elf.reptile | [] | 2026-02-25 | | | |
| | | tsh | ['TINYSHELL'] | elf.tsh | [] | 2026-02-25 | | | |
| | | StormKittyRAT | [] | win.stormkitty_rat | [] | 2026-02-25 | | | |
| | | Infy | ['Foudre'] | win.infy | [] | 2026-02-25 | | | |
| | | Rorschach Ransomware | ['BabLock'] | win.rorschach | [] | 2026-02-25 | | | |
| | | VoidLink | [] | elf.voidlink | [] | 2026-02-25 | | | |
| | | IClickFix | [] | js.iclickfix | [] | 2026-02-25 | | | |
| | | Hamweq | [] | win.hamweq | [] | 2026-02-25 | | | |
| | | Latrodectus | ['BLACKWIDOW', 'IceNova', 'Latrodectus', 'Lotus'] | win.latrodectus | [] | 2026-02-25 | | | |
| | | Supper | ['SocksShell', 'ZAPCAT'] | win.supper | ['Vanilla Tempest'] | 2026-02-25 | | | |
| | | Void | ['VoidCrypt'] | win.void | [] | 2026-02-25 | | | |
| | | PureRAT | ['PureHVNC', 'ResolverRAT'] | win.pure_rat | [] | 2026-02-25 | | | |
| | | NonEuclid RAT | ['LiberiumRAT', 'ShadowRoot', 'SheetRAT'] | win.noneuclid_rat | [] | 2026-02-24 | | | |
| | | RatonRAT | [] | win.raton_rat | [] | 2026-02-24 | | | |
| | | XWorm | [] | win.xworm | ['Hive0137'] | 2026-02-24 | | | |
| | | OtterCookie | [] | js.otter_cookie | ['WageMole'] | 2026-02-24 | | | |
| | | ACR Stealer | [] | win.acr_stealer | [] | 2026-01-27 | | | |
| | | Astaroth | ['Guildma'] | win.astaroth | [] | 2026-02-17 | | | |
| | | CASTLELOADER | [] | win.castleloader | [] | 2026-02-17 | | | |
| | | Lumma Stealer | ['LummaC2 Stealer'] | win.lumma | ['Angry Likho'] | 2026-02-17 | | | |
| | | Aisuru | [] | elf.aisuru | [] | 2026-02-17 | | | |
| | | Kimwolf | [] | apk.kimwolf | [] | 2026-02-17 | | | |
| | | Razr ransomware | [] | win.razr | [] | 2026-02-15 | | | |
| | | InvisibleFerret | [] | py.invisibleferret | ['WageMole'] | 2026-01-21 | | | |
| | | NodeCordRAT | [] | js.nodecordrat | [] | 2026-02-17 | | | |
| | | JSOutProx | [] | win.jsoutprox | ['SOLAR SPIDER'] | 2024-04-08 | | | |
| | | OctoRAT | [] | win.octorat | [] | 2026-02-05 | | | |
| | | DragonForce | [] | win.dragonforce | [] | 2026-02-05 | | | |
| | | Black Basta | ['no_name_software'] | win.blackbasta | ['GOLD REBELLION', 'STAC5143', 'Storm-0506', 'Storm-0826', 'TA2101', 'UNC3973', 'UNC4393'] | 2026-02-05 | | | |
| | | Chrysalis | [] | win.chrysalis | ['LOTUS PANDA'] | 2026-02-03 | | | |
| | | AsyncRAT | [] | win.asyncrat | [] | 2026-02-03 | | | |
| | | TelePowerBot | [] | win.telepowerbot | [] | 2026-02-03 | | | |
| | | Lynx | [] | win.lynx | [] | 2026-02-03 | | | |
| | | PromptLock | [] | win.prompt_lock | [] | 2026-02-03 | | | |
| | | NjRAT | ['Bladabindi', 'Lime-Worm'] | win.njrat | ['AQUATIC PANDA', 'Earth Lusca', 'Operation C-Major', 'The Gorgon Group'] | 2026-02-03 | | | |
| | | MASS Logger | [] | win.masslogger | [] | 2026-02-03 | | | |
| | | LockBit | ['ABCD Ransomware'] | win.lockbit | [] | 2026-02-03 | | | |
| | | LockBit | [] | elf.lockbit | [] | 2026-02-03 | | | |
| | | Xillen Stealer | [] | win.xillen_stealer | [] | 2026-01-31 | | | |
| | | LazyWiper | [] | ps1.lazywiper | [] | 2026-01-30 | | | |
| | | Interlock | [] | win.interlock | [] | 2026-01-30 | | | |
| | | SloppyMIO | [] | win.sloppy_mio | [] | 2026-01-29 | | | |
| | | GhostChat | [] | apk.ghost_chat | [] | 2026-01-29 | | | |
| | | SHEETCREEP | [] | win.sheetcreep | [] | 2026-01-29 | | | |
| | | MAILCREEP | [] | win.mailcreep | [] | 2026-01-29 | | | |
| | | GRAYRABBIT | [] | win.grayrabbit | ['UNC3569'] | 2026-01-28 | | | |
| | | HelloBot | [] | win.hellobot | ['Earth Berberoka'] | 2026-01-28 | | | |
| | | HUI Loader | ['SIDESTEP'] | win.hui_loader | [] | 2026-01-28 | | | |
| | | PlugX | ['Destroy RAT', 'Kaba', 'Korplug', 'Sogu', 'TIGERPLUG', 'RedDelta'] | win.plugx | ['APT 22', 'APT 26', 'APT31', 'APT41', 'Aurora Panda', 'Calypso group', 'DragonOK', 'EMISSARY PANDA', 'Hellsing', 'Hurricane Panda', 'Leviathan', 'Mirage', 'Mustang Panda', 'NetTraveler', 'Nightshade Panda', 'SLIME29', 'Samurai Panda', 'Stone Panda', 'UPS', 'Violin Panda'] | 2026-01-28 | | | |
| | | SiestaGraph | ['DRAFTGRAPH'] | win.siesta_graph | [] | 2026-01-28 | | | |