| | | Pteranodon | ['Pterodo'] | win.pteranodon | ['Gamaredon Group', 'Operation Armageddon'] | 2025-09-09 | | | |
| | | CastleRAT | [] | win.castle_rat | [] | 2025-09-09 | | | |
| | | MostereRAT | [] | win.mostere_rat | [] | 2025-09-09 | | | |
| | | RatOn | [] | apk.rat_on | [] | 2025-09-09 | | | |
| | | Rhysida | [] | win.rhysida | ['Vanilla Tempest'] | 2025-09-09 | | | |
| | | Merlin | [] | win.merlin | [] | 2025-09-09 | | | |
| | | Cobalt Strike | ['Agentemis', 'BEACON', 'CobaltStrike', 'cobeacon'] | win.cobalt_strike | ['APT 29', 'APT29', 'APT32', 'APT41', 'AQUATIC PANDA', 'Anunak', 'Cobalt', 'Codoso', 'CopyKittens', 'DarkHydrus', 'Earth Baxia', 'FIN6', 'FIN7', 'Leviathan', 'Mustang Panda', 'Shell Crew', 'Stone Panda', 'TianWu', 'UNC1878', 'UNC2452', 'Winnti Umbrella'] | 2025-09-09 | | | |
| | | TimbreStealer | [] | win.timbre_stealer | [] | 2025-09-09 | | | |
| | | NightshadeC2 | [] | win.nightshade_c2 | [] | 2025-09-09 | | | |
| | | NightshadeC2 | [] | py.nightshade_c2 | [] | 2025-09-09 | | | |
| | | Rustonotto | ['CHILLYCHINO'] | win.rustonotto | ['APT37'] | 2025-09-09 | | | |
| | | RunForestRun | ['Blackhole', 'Sutra'] | js.runforestrun | [] | 2025-09-09 | | | |
| | | FireWood | [] | elf.firewood | ['Gelsemium'] | 2025-09-09 | | | |
| | | LAMEHUG | [] | py.lamehug | ['APT28'] | 2025-09-09 | | | |
| | | GONEPOSTAL | ['Cordyceps', 'NOTDOOR'] | win.gonepostal | ['APT28'] | 2025-09-09 | | | |
| | | Stealerium | [] | win.stealerium | [] | 2025-09-09 | | | |
| | | ValleyRAT | ['Winos'] | win.valley_rat | [] | 2025-09-09 | | | |
| | | Broomstick | ['CLEANBOOST', 'CleanUp', 'CleanUpLoader', 'Oyster'] | win.broomstick | [] | 2025-08-27 | | | |
| | | BeaverTail | [] | js.beavertail | ['WageMole'] | 2025-08-29 | | | |
| | | InvisibleFerret | [] | py.invisibleferret | ['WageMole'] | 2025-08-29 | | | |
| | | Latrodectus | ['BLACKWIDOW', 'IceNova', 'Latrodectus', 'Lotus'] | win.latrodectus | [] | 2025-07-14 | | | |
| | | Supper | ['SocksShell', 'ZAPCAT'] | win.supper | ['Vanilla Tempest'] | 2025-07-01 | | | |
| | | DEVMAN | [] | win.devman | ['DragonForce', '[Unnamed group]'] | 2025-09-09 | | | |
| | | Konni | [] | win.konni | ['APT37'] | 2025-09-09 | | | |
| | | Loki Password Stealer (PWS) | ['Burkina', 'Loki', 'LokiBot', 'LokiPWS'] | win.lokipws | ['SWEED', 'The Gorgon Group', 'Cobalt'] | 2025-09-09 | | | |
| | | Maze | ['ChaCha'] | win.maze | ['FIN6', 'TA2101'] | 2025-09-09 | | | |
| | | Felixroot | [] | win.felixroot | ['GreyEnergy'] | 2025-09-09 | | | |
| | | AnchorMTea | [] | win.anchormtea | ['Lazarus Group'] | 2025-09-09 | | | |
| | | Anchor | [] | win.anchor | ['WIZARD SPIDER'] | 2025-09-09 | | | |
| | | Amadey | [] | win.amadey | [] | 2025-09-09 | | | |
| | | Agent Tesla | ['AgenTesla', 'AgentTesla', 'Negasteal'] | win.agent_tesla | ['SWEED'] | 2025-09-09 | | | |
| | | Carbanak | ['Anunak', 'Sekur RAT'] | win.carbanak | ['FIN7'] | 2025-09-09 | | | |
| | | Carberp | [] | win.carberp | [] | 2025-09-09 | | | |
| | | Cardinal RAT | [] | win.cardinal_rat | [] | 2025-09-09 | | | |
| | | Meterpreter | [] | win.meterpreter | [] | 2025-09-09 | | | |
| | | XTinyLoader | [] | win.xtinyloader | [] | 2025-09-09 | | | |
| | | RapperBot | [] | elf.rapper_bot | [] | 2025-09-09 | | | |
| | | Vidar | [] | win.vidar | [] | 2025-09-09 | | | |
| | | TamperedChef | [] | win.tampered_chef | [] | 2025-09-08 | | | |
| | | SalatStealer | [] | win.salatstealer | [] | 2025-08-28 | | | |
| | | Sindoor | [] | elf.sindoor | ['Operation C-Major'] | 2025-09-01 | | | |
| | | XWorm | [] | win.xworm | ['Hive0137'] | 2025-09-01 | | | |
| | | PylangGhost | [] | py.pylangghost | ['WageMole'] | 2025-08-18 | | | |
| | | Hook | [] | apk.hook | [] | 2025-08-29 | | | |
| | | s1ngularity Stealer | [] | js.s1ngularity | [] | 2025-08-29 | | | |
| | | AsyncRAT | [] | win.asyncrat | [] | 2025-08-29 | | | |
| | | BitRAT | [] | win.bit_rat | [] | 2025-08-29 | | | |
| | | NjRAT | ['Bladabindi', 'Lime-Worm'] | win.njrat | ['AQUATIC PANDA', 'Earth Lusca', 'Operation C-Major', 'The Gorgon Group'] | 2025-08-29 | | | |
| | | DCRat | ['DarkCrystal RAT'] | win.dcrat | [] | 2025-08-29 | | | |
| | | LimeRAT | [] | win.limerat | ['APT-C-36'] | 2025-08-29 | | | |
| | | PureCrypter | [] | win.purecrypter | [] | 2025-08-29 | | | |
| | | Remcos | ['RemcosRAT', 'Remvio', 'Socmer'] | win.remcos | ['APT33', 'The Gorgon Group', 'UAC-0050'] | 2025-08-29 | | | |
| | | Quasar RAT | ['CinaRAT', 'QuasarRAT', 'Yggdrasil'] | win.quasar_rat | ['APT33', 'Dropping Elephant', 'Stone Panda', 'The Gorgon Group'] | 2025-08-29 | | | |
| | | GolangGhost | ['BitStep RAT', 'WeaselStore'] | win.golangghost | ['WageMole'] | 2025-08-29 | | | |
| | | GolangGhost | [] | osx.golangghost | ['WageMole'] | 2025-08-29 | | | |
| | | OtterCookie | [] | js.otter_cookie | ['WageMole'] | 2025-08-29 | | | |
| | | Godfather | [] | apk.godfather | [] | 2025-08-29 | | | |
| | | Ghost RAT | ['Farfli', 'Gh0st RAT', 'PCRat'] | win.ghost_rat | ['EMISSARY PANDA', 'Hurricane Panda', 'Lazarus Group', 'Leviathan', 'Red Menshen', 'Stone Panda'] | 2025-08-28 | | | |
| | | Lumma Stealer | ['LummaC2 Stealer'] | win.lumma | ['Angry Likho'] | 2025-08-28 | | | |
| | | BlackCat | ['ALPHV', 'Noberus'] | win.blackcat | ['Alpha Spider', 'RansomHub', 'Vanilla Tempest'] | 2025-08-28 | | | |
| | | BlackCat | ['ALPHV', 'Noberus'] | elf.blackcat | ['Vanilla Tempest'] | 2025-08-28 | | | |
| | | MetaStealer | [] | win.metastealer | ['UNC5537'] | 2025-09-01 | | | |
| | | Anatsa | ['ReBot', 'TeaBot', 'Toddler'] | apk.anatsa | [] | 2025-08-28 | | | |
| | | Akira Stealer | [] | py.akira_stealer | [] | 2025-08-28 | | | |
| | | PromptLock | [] | win.prompt_lock | [] | 2025-08-27 | | | |
| | | RokRAT | ['DOGCALL'] | win.rokrat | ['APT37'] | 2025-08-15 | | | |
| | | p0sT5n1F3r | [] | elf.p0st5n1f3r | [] | 2025-08-27 | | | |
| | | LunaSpy | ['Backdoor.916'] | apk.luna_spy | [] | 2025-08-26 | | | |
| | | STATICPLUGIN | [] | win.staticplugin | ['MUSTANG PANDA'] | 2025-08-26 | | | |
| | | Vshell | [] | win.vshell | [] | 2025-08-25 | | | |
| | | TgToxic | [] | apk.tgtoxic | [] | 2025-08-25 | | | |
| | | ToxicPanda | [] | apk.toxic_panda | [] | 2025-08-25 | | | |
| | | SilentPrism | [] | ps1.silent_prism | ['Larva-208'] | 2025-08-25 | | | |
| | | Fickle Stealer | [] | win.fickle | [] | 2025-08-25 | | | |
| | | XenArmor | ['XenArmor Suite'] | win.xenarmor | [] | 2023-05-10 | | | |
| | | BQTlock | [] | win.bqtlock | [] | 2025-08-25 | | | |
| | | donut_injector | ['Donut'] | win.donut_injector | [] | 2025-08-25 | | | |
| | | JSOutProx | [] | win.jsoutprox | ['SOLAR SPIDER'] | 2024-04-08 | | | |
| | | Luna Grabber | [] | py.lunagrabber | [] | 2025-08-22 | | | |
| | | ApolloShadow | [] | win.apollo_shadow | ['Turla'] | 2025-08-22 | | | |
| | | QuirkyLoader | [] | win.quirkyloader | [] | 2025-08-22 | | | |
| | | Dridex | [] | win.dridex | ['Evil Corp', 'INDRIK SPIDER', 'TA505'] | 2024-04-15 | | | |
| | | SoundBill | [] | win.soundbill | [] | 2025-08-21 | | | |
| | | PicassoLoader | [] | win.picasso_loader | ['Ghostwriter'] | 2025-08-26 | | | |
| | | XenoRAT | [] | win.xenorat | [] | 2025-08-20 | | | |
| | | Akira | ['REDBIKE'] | win.akira | ['Storm-1567'] | 2025-08-20 | | | |
| | | AdaptixC2 | [] | win.adaptix_c2 | [] | 2025-08-20 | | | |
| | | BumbleBee | ['COLDTRAIN', 'SHELLSTING', 'Shindig'] | win.bumblebee | ['EXOTIC LILY', 'GOLD CABIN', 'TA578', 'TA579'] | 2025-08-20 | | | |
| | | WarLock | [] | win.warlock | [] | 2025-08-20 | | | |
| | | HawkEye Keylogger | ['HawkEye', 'HawkEye Reborn', 'Predator Pain'] | win.hawkeye_keylogger | [] | 2025-08-20 | | | |
| | | VELETRIX | [] | win.veletrix | [] | 2025-08-19 | | | |
| | | AgendaCrypt | ['Agenda', 'Qilin'] | win.agendacrypt | [] | 2025-08-19 | | | |
| | | Qilin | [] | elf.qilin | [] | 2025-08-19 | | | |
| | | Morpheus Loader | [] | win.morpheus | [] | 2025-08-19 | | | |
| | | Aurotun Stealer | [] | win.aurotun_stealer | [] | 2025-08-18 | | | |
| | | PS1Bot | [] | php.ps1bot | [] | 2025-08-18 | | | |
| | | Nitrogen Ransomware | [] | win.nitrogen_ransomware | [] | 2025-08-18 | | | |
| | | PureLogs Stealer | [] | win.purelogs | [] | 2025-08-18 | | | |
| | | PureRAT | ['PureHVNC', 'ResolverRAT'] | win.pure_rat | [] | 2025-08-18 | | | |
| | | PolarEdge | [] | elf.polaredge | [] | 2025-08-18 | | | |