| | | MAYBEROBOT | ['', 'SIMPLEFIX'] | win.mayberobot | ['Callisto'] | 2025-11-10 | | | |
| | | FudModule | ['LIGHTSHOW'] | win.fudmodule | ['Lazarus Group'] | 2025-11-10 | | | |
| | | LANDFALL | [] | apk.landfall | [] | 2025-11-09 | | | |
| | | BlackCat | ['ALPHV', 'Noberus'] | win.blackcat | ['Alpha Spider', 'RansomHub', 'Vanilla Tempest'] | 2025-11-09 | | | |
| | | Cactus | [] | win.cactus | [] | 2025-11-09 | | | |
| | | Cicada3301 | [] | win.cicada3301 | [] | 2025-11-09 | | | |
| | | Clop | [] | win.clop | ['TA505'] | 2025-11-09 | | | |
| | | Royal Ransom | [] | win.royal_ransom | [] | 2025-11-09 | | | |
| | | Silence | ['TrueBot'] | win.silence | ['Silence group', 'TA505'] | 2025-11-09 | | | |
| | | LockBit | ['ABCD Ransomware'] | win.lockbit | [] | 2025-11-09 | | | |
| | | RansomHub | [] | win.ransomhub | ['RansomHub'] | 2025-11-09 | | | |
| | | PLAY | ['PlayCrypt'] | win.play | [] | 2025-11-09 | | | |
| | | Aisuru | [] | elf.aisuru | [] | 2025-11-08 | | | |
| | | Lumma Stealer | ['LummaC2 Stealer'] | win.lumma | ['Angry Likho'] | 2025-11-05 | | | |
| | | VShell | [] | win.vshell | [] | 2025-11-05 | | | |
| | | Agent Tesla | ['AgenTesla', 'AgentTesla', 'Negasteal'] | win.agent_tesla | ['SWEED'] | 2025-11-05 | | | |
| | | Dante | [] | win.dante | [] | 2025-11-05 | | | |
| | | Aura Stealer | ['AURA Stealer', 'AURASTEAL'] | win.aurastealer | [] | 2025-09-16 | | | |
| | | BQTlock | [] | elf.bqtlock | [] | 2025-11-05 | | | |
| | | PolarEdge | [] | elf.polaredge | [] | 2025-11-05 | | | |
| | | MetaStealer | [] | win.metastealer | ['UNC5537'] | 2025-11-05 | | | |
| | | LinkPro | [] | elf.linkpro | [] | 2025-11-03 | | | |
| | | JADESNOW | ['ChainedDown'] | js.jadesnow | [] | 2025-11-03 | | | |
| | | Kamasers | [] | win.kamasers | [] | 2025-10-31 | | | |
| | | PostNapTea | ['SIGNBT'] | win.postnaptea | ['Lazarus Group'] | 2025-10-31 | | | |
| | | wAgentTea | ['wAgent'] | win.wagenttea | ['Lazarus Group'] | 2025-10-31 | | | |
| | | Bankshot | ['COPPERHEDGE', 'FoggyBrass'] | win.bankshot | ['Lazarus Group'] | 2025-10-31 | | | |
| | | EntryShell | [] | win.entryshell | [] | 2025-10-29 | | | |
| | | SparrowDoor | [] | win.sparrow_door | ['GhostEmperor'] | 2025-10-29 | | | |
| | | ShadowPad | ['POISONPLUG.SHADOW', 'XShellGhost'] | win.shadowpad | ['APT23', 'APT41', 'APT17', 'DAGGER PANDA', 'Earth Lusca', 'Tonto Team', 'WET PANDA'] | 2025-10-29 | | | |
| | | DracuLoader | [] | win.dracu_loader | ['Earth Estries'] | 2025-10-29 | | | |
| | | SNAPPYBEE | ['Deed RAT', 'POISONPLUG.DEED'] | win.snappybee | ['Earth Estries'] | 2025-10-29 | | | |
| | | BUSHWALK | [] | elf.bushwalk | [] | 2025-10-28 | | | |
| | | PITFUEL | [] | elf.pitfuel | [] | 2025-10-28 | | | |
| | | PITSOCK | [] | elf.pitsock | [] | 2025-10-28 | | | |
| | | PITHOOK | [] | elf.pithook | [] | 2025-10-28 | | | |
| | | PulsarTea | [] | win.pulsartea | ['Lazarus Group'] | 2025-10-28 | | | |
| | | Kubo Injector | [] | elf.kubo_injector | [] | 2025-10-28 | | | |
| | | PylangGhost | [] | py.pylangghost | ['WageMole'] | 2025-10-20 | | | |
| | | LockBit | [] | elf.lockbit | [] | 2025-10-22 | | | |
| | | Princess | [] | apk.princess | [] | 2025-10-24 | | | |
| | | BlindEDR | [] | win.blind_edr | [] | 2025-10-23 | | | |
| | | NOROBOT | ['BAITSWITCH'] | win.norobot | ['Callisto'] | 2025-10-22 | | | |
| | | MedusaLocker | ['AKO Ransomware', 'AKO Doxware', 'MedusaReborn'] | win.medusalocker | [] | 2025-10-22 | | | |
| | | YESROBOT | [] | win.yesrobot | ['Callisto'] | 2025-10-22 | | | |
| | | GlassWorm | [] | js.glassworm | [] | 2025-10-21 | | | |
| | | BRICKSTORM | [] | elf.brickstorm | ['UTA0178'] | 2025-10-22 | | | |
| | | TOLLBOOTH | ['HijackServer IIS'] | win.tollbooth | [] | 2025-10-22 | | | |
| | | PureLogs Stealer | [] | win.purelogs | [] | 2025-10-20 | | | |
| | | vGet | [] | elf.vget | [] | 2025-10-20 | | | |
| | | OtterCandy | ['HardHatRAT', 'UNSEENMINK'] | js.ottercandy | [] | 2025-10-22 | | | |
| | | Bofamet | [] | win.bofamet | [] | 2025-10-21 | | | |
| | | ACR Stealer | [] | win.acr_stealer | [] | 2025-10-21 | | | |
| | | TONESHELL | [] | win.toneshell | ['MUSTANG PANDA'] | 2025-09-23 | | | |
| | | Tendyron | [] | win.tendyron_dropper | ['TA410'] | 2025-10-15 | | | |
| | | NightshadeC2 | ['CastleRAT'] | win.nightshade_c2 | [] | 2025-10-20 | | | |
| | | DanderSpritz | ['Dsz'] | win.danderspritz | [] | 2025-10-20 | | | |
| | | vxRat | [] | win.vx_rat | [] | 2025-10-20 | | | |
| | | JSOutProx | [] | win.jsoutprox | ['SOLAR SPIDER'] | 2024-04-08 | | | |
| | | GolangGhost | ['BitStep RAT', 'WeaselStore'] | win.golangghost | ['WageMole'] | 2025-10-20 | | | |
| | | Tropidoor | [] | win.tropidoor | ['WageMole'] | 2025-10-20 | | | |
| | | AkdoorTea | [] | win.akdoortea | ['WageMole'] | 2025-10-20 | | | |
| | | ClipBanker | [] | win.clipbanker | [] | 2025-10-20 | | | |
| | | CHINACHOPPER | [] | win.chinachopper | ['APT41', 'EMISSARY PANDA', 'GALLIUM', 'HAFNIUM', 'Hurricane Panda', 'Leviathan'] | 2025-10-20 | | | |
| | | MimiKatz | [] | win.mimikatz | ['APT10', 'APT32', 'Anunak', 'GALLIUM'] | 2025-10-20 | | | |
| | | Lookback | [] | win.lookback | ['TA410'] | 2025-10-20 | | | |
| | | Brute Ratel C4 | ['BOLDBADGER', 'BruteRatel'] | win.brute_ratel_c4 | [] | 2025-10-15 | | | |
| | | WRECKSTEEL | [] | ps1.wrecksteel | [] | 2025-10-15 | | | |
| | | HOMESTEEL | [] | vbs.homesteel | [] | 2025-10-15 | | | |
| | | Amatera | [] | win.amatera | [] | 2025-10-15 | | | |
| | | GIFTEDCROOK | [] | win.giftedcrook | ['UAC-0226'] | 2025-10-15 | | | |
| | | StrelaStealer | [] | win.strelastealer | [] | 2025-10-15 | | | |
| | | BellaCiao | [] | win.bellaciao | [] | 2025-10-15 | | | |
| | | Pantegana | [] | win.pantegana | [] | 2025-10-15 | | | |
| | | Vampire Bot | [] | win.vampire_bot | [] | 2025-10-15 | | | |
| | | SparkRAT | [] | win.spark_rat | [] | 2025-10-15 | | | |
| | | Leslieloader | [] | win.leslieloader | [] | 2025-10-15 | | | |
| | | NET-STAR | [] | win.net_star | [] | 2025-10-15 | | | |
| | | Loki Password Stealer (PWS) | ['Burkina', 'Loki', 'LokiBot', 'LokiPWS'] | win.lokipws | ['SWEED', 'The Gorgon Group', 'Cobalt'] | 2025-10-15 | | | |
| | | MonsterV2 | ['Aurotun Stealer'] | win.monsterv2 | [] | 2025-10-15 | | | |
| | | PlugX | ['Destroy RAT', 'Kaba', 'Korplug', 'Sogu', 'TIGERPLUG', 'RedDelta'] | win.plugx | ['APT 22', 'APT 26', 'APT31', 'APT41', 'Aurora Panda', 'Calypso group', 'DragonOK', 'EMISSARY PANDA', 'Hellsing', 'Hurricane Panda', 'Leviathan', 'Mirage', 'Mustang Panda', 'NetTraveler', 'Nightshade Panda', 'SLIME29', 'Samurai Panda', 'Stone Panda', 'UPS', 'Violin Panda'] | 2025-10-15 | | | |
| | | FlowCloud | [] | win.flowcloud | ['Stone Panda'] | 2025-10-15 | | | |
| | | Unidentified 096 (Keylogger) | [] | win.unidentified_096 | ['TA410'] | 2025-10-15 | | | |
| | | x4 | [] | win.x4 | [] | 2025-10-15 | | | |
| | | Soul | ['SoulSearcher'] | win.soul | [] | 2025-10-15 | | | |
| | | SoulSearcher | [] | win.soulsearcher | ['SharpPanda'] | 2025-10-15 | | | |
| | | AdaptixC2 | [] | win.adaptix_c2 | [] | 2025-10-15 | | | |
| | | GhostSocks | [] | win.ghostsocks | [] | 2025-10-02 | | | |
| | | DHCSpy | [] | apk.dhcspy | ['MuddyWater'] | 2025-10-01 | | | |
| | | Akira | ['REDBIKE'] | elf.akira | ['Storm-1567'] | 2025-10-01 | | | |
| | | Akira | ['REDBIKE'] | win.akira | ['Storm-1567'] | 2025-10-01 | | | |
| | | AllaKore | [] | win.allakore | [] | 2025-09-30 | | | |
| | | BQTlock | [] | win.bqtlock | [] | 2025-09-30 | | | |
| | | WannaCryptor | ['Wana Decrypt0r', 'WannaCry', 'WannaCrypt', 'Wcry'] | win.wannacryptor | ['Lazarus Group'] | 2025-09-30 | | | |
| | | PseudoManuscrypt | [] | win.pseudo_manuscrypt | [] | 2025-09-25 | | | |
| | | TamperedChef | [] | win.tampered_chef | [] | 2025-09-25 | | | |
| | | YiBackdoor | [] | win.yibackdoor | [] | 2025-09-24 | | | |
| | | Bert | [] | win.bert | [] | 2025-09-23 | | | |
| | | Shai-Hulud | [] | js.shai_hulud | [] | 2025-09-23 | | | |
| | | BaoLoader | [] | win.baoloader | [] | 2025-09-23 | | | |