| | | PhantomCore | [] | win.phantomcore | [] | 2025-03-21 | | | |
| | | PlugX | ['Destroy RAT', 'Kaba', 'Korplug', 'Sogu', 'TIGERPLUG', 'RedDelta'] | win.plugx | ['APT 22', 'APT 26', 'APT31', 'APT41', 'Aurora Panda', 'Calypso group', 'DragonOK', 'EMISSARY PANDA', 'Hellsing', 'Hurricane Panda', 'Leviathan', 'Mirage', 'Mustang Panda', 'NetTraveler', 'Nightshade Panda', 'SLIME29', 'Samurai Panda', 'Stone Panda', 'UPS', 'Violin Panda'] | 2025-03-21 | | | |
| | | JuicyPotato | [] | win.juicy_potato | [] | 2025-03-21 | | | |
| | | Meterpreter | [] | win.meterpreter | [] | 2025-03-21 | | | |
| | | MimiKatz | [] | win.mimikatz | ['APT32', 'Anunak', 'GALLIUM'] | 2025-03-21 | | | |
| | | LaZagne | [] | py.lazagne | [] | 2025-03-21 | | | |
| | | Lethic | [] | win.lethic | [] | 2025-03-21 | | | |
| | | AMOS | ['Atomic macOS Stealer'] | osx.amos | [] | 2025-03-21 | | | |
| | | BlackMatter | [] | win.blackmatter | [] | 2025-03-21 | | | |
| | | LockBit | ['ABCD Ransomware'] | win.lockbit | [] | 2025-03-21 | | | |
| | | Anel | ['UPPERCUT', 'lena'] | win.anel | ['Stone Panda'] | 2025-03-21 | | | |
| | | Akira | [] | elf.akira | [] | 2025-03-14 | | | |
| | | tsh | ['TINYSHELL'] | elf.tsh | [] | 2025-03-14 | | | |
| | | SectopRAT | ['1xxbot', 'ArechClient'] | win.sectop_rat | [] | 2025-03-14 | | | |
| | | KoSpy | [] | apk.kospy | ['APT37'] | 2025-03-13 | | | |
| | | NjRAT | ['Bladabindi', 'Lime-Worm'] | win.njrat | ['AQUATIC PANDA', 'Earth Lusca', 'Operation C-Major', 'The Gorgon Group'] | 2025-03-12 | | | |
| | | SmartLoader | [] | win.smartloader | [] | 2025-03-12 | | | |
| | | DCRat | ['DarkCrystal RAT'] | win.dcrat | [] | 2025-03-12 | | | |
| | | DragonForce | [] | win.dragonforce | [] | 2025-03-12 | | | |
| | | BumbleBee | ['COLDTRAIN', 'SHELLSTING', 'Shindig'] | win.bumblebee | ['EXOTIC LILY', 'GOLD CABIN', 'TA578', 'TA579'] | 2025-01-14 | | | |
| | | ERMAC | [] | apk.ermac | [] | 2025-03-12 | | | |
| | | STOP | ['KeyPass', 'Djvu'] | win.stop | [] | 2025-03-12 | | | |
| | | Akira | [] | win.akira | [] | 2025-03-12 | | | |
| | | Anatsa | ['ReBot', 'TeaBot', 'Toddler'] | apk.anatsa | [] | 2025-03-11 | | | |
| | | RandomQuery | [] | ps1.randomquery | ['Kimsuky'] | 2025-03-11 | | | |
| | | vo1d | [] | apk.vo1d | [] | 2025-03-06 | | | |
| | | Moose | [] | elf.moose | [] | 2025-03-10 | | | |
| | | QakBot | ['Oakboat', 'Pinkslipbot', 'Qbot', 'Quakbot'] | win.qakbot | ['GOLD CABIN'] | 2025-03-10 | | | |
| | | Hunters International | [] | win.hunters_international | ['Storm-0501'] | 2025-03-06 | | | |
| | | Fickle Stealer | [] | win.fickle | [] | 2025-03-10 | | | |
| | | Abyss Locker | ['elf.hellokitty'] | elf.abyss | [] | 2025-03-10 | | | |
| | | RokRAT | ['DOGCALL'] | win.rokrat | ['APT37'] | 2025-03-10 | | | |
| | | Joker | ['Bread'] | apk.joker | [] | 2025-03-07 | | | |
| | | lightSpy | [] | ios.lightspy | [] | 2025-03-07 | | | |
| | | Qilin | [] | elf.qilin | [] | 2025-03-07 | | | |
| | | Pyramid | [] | py.pyramid | [] | 2025-03-07 | | | |
| | | Simda | ['iBank'] | win.simda | [] | 2025-03-07 | | | |
| | | SparkRAT | [] | win.spark_rat | [] | 2025-03-07 | | | |
| | | Revenge RAT | ['Revetrat'] | win.revenge_rat | ['The Gorgon Group'] | 2025-03-07 | | | |
| | | Babuk | [] | elf.babuk | [] | 2025-03-07 | | | |
| | | EvilExtractor | [] | win.evilextractor | [] | 2025-03-07 | | | |
| | | Phoenix Locker | [] | win.phoenix_locker | [] | 2025-03-07 | | | |
| | | Hades | [] | win.hades | ['GOLD WINTER'] | 2025-03-07 | | | |
| | | Conti | [] | win.conti | ['WIZARD SPIDER'] | 2025-03-07 | | | |
| | | Unidentified 103 (FIN8) | ['Ragnar Loader', 'Sardonic'] | win.unidentified_103 | [] | 2025-03-06 | | | |
| | | XWorm | [] | win.xworm | [] | 2025-03-06 | | | |
| | | NailaoLocker | [] | win.nailao_locker | [] | 2025-03-05 | | | |
| | | Loki RAT | [] | py.lokirat | ['El Machete'] | 2025-03-05 | | | |
| | | I2PRAT | ['I2Parcae'] | win.i2prat | [] | 2025-03-05 | | | |
| | | Unidentified 118 | [] | win.unidentified_118 | [] | 2025-03-05 | | | |
| | | MintStealer | [] | win.mintstealer | [] | 2025-03-05 | | | |
| | | Cactus | [] | win.cactus | [] | 2025-03-05 | | | |
| | | DanaBot | [] | win.danabot | ['SCULLY SPIDER'] | 2025-03-05 | | | |
| | | IcedID | ['BokBot', 'IceID'] | win.icedid | ['GOLD CABIN', 'Lunar Spider'] | 2025-03-05 | | | |
| | | DarkGate | ['Meh', 'MehCrypter'] | win.darkgate | [] | 2025-03-05 | | | |
| | | Cuba | ['COLDDRAW'] | win.cuba | [] | 2025-03-05 | | | |
| | | FINALDRAFT | [] | elf.finaldraft | [] | 2025-02-28 | | | |
| | | FINALDRAFT | [] | win.finaldraft | [] | 2025-02-28 | | | |
| | | PolarEdge | [] | elf.polaredge | [] | 2025-02-28 | | | |
| | | PANIX | [] | sh.panix | [] | 2025-02-28 | | | |
| | | Winos | [] | win.winos | ['Void Arachne'] | 2025-02-28 | | | |
| | | TgToxic | [] | apk.tgtoxic | [] | 2025-02-28 | | | |
| | | Cyclops | [] | win.cyclops | [] | 2025-02-28 | | | |
| | | AllaSenha | [] | win.allasenha | [] | 2025-02-28 | | | |
| | | EvilGnome | [] | elf.evilgnome | ['Gamaredon Group'] | 2025-02-28 | | | |
| | | HiddenWasp | [] | elf.hiddenwasp | [] | 2025-02-28 | | | |
| | | Turla RAT | [] | elf.turla_rat | [] | 2025-02-28 | | | |
| | | OceanLotus | [] | osx.oceanlotus | ['APT32'] | 2025-02-28 | | | |
| | | BitRAT | [] | win.bit_rat | [] | 2025-02-28 | | | |
| | | RecordBreaker | [] | win.recordbreaker | [] | 2025-02-28 | | | |
| | | DuQu | [] | win.duqu | ['Unit 8200'] | 2025-02-28 | | | |
| | | StegoLoader | [] | win.stegoloader | [] | 2025-02-28 | | | |
| | | Nanocore RAT | ['Nancrat', 'NanoCore'] | win.nanocore | ['APT33', 'The Gorgon Group'] | 2025-02-28 | | | |
| | | RedTail | [] | elf.redtail | [] | 2025-02-28 | | | |
| | | Winnti | ['BleDoor', 'JUMPALL', 'RbDoor', 'Pasteboy'] | win.winnti | ['APT17'] | 2025-02-28 | | | |
| | | RAWDOOR | [] | win.rawdoor | ['APT31'] | 2025-02-28 | | | |
| | | AllaKore | [] | win.allakore | [] | 2025-02-28 | | | |
| | | donut_injector | ['Donut'] | win.donut_injector | [] | 2025-02-28 | | | |
| | | Sliver | [] | win.sliver | [] | 2025-02-28 | | | |
| | | BellaCiao | [] | win.bellaciao | [] | 2025-02-28 | | | |
| | | xmrig | [] | win.xmrig | [] | 2025-02-28 | | | |
| | | Behinder | [] | php.behinder | [] | 2025-02-28 | | | |
| | | LCRYX | [] | vbs.lcryx | [] | 2025-02-26 | | | |
| | | MarraCrypt | [] | win.marracrypt | [] | 2025-02-26 | | | |
| | | Hermes | [] | win.hermes | ['Lazarus Group'] | 2025-02-26 | | | |
| | | ToxicEye | [] | win.toxiceye | [] | 2025-02-25 | | | |
| | | CashRansomware | [] | win.cashransom | [] | 2025-02-25 | | | |
| | | TAMECAT | [] | vbs.tamecat | ['APT42'] | 2025-02-25 | | | |
| | | ShrinkLocker | [] | win.shrinklocker | [] | 2025-02-25 | | | |
| | | Darktrack RAT | [] | win.darktrack_rat | [] | 2025-02-25 | | | |
| | | MoqHao | ['Shaoye', 'Wroba', 'XLoader'] | apk.moqhao | ['Yanbian Gang'] | 2025-02-25 | | | |
| | | xHelper | [] | apk.xhelper | [] | 2025-02-25 | | | |
| | | BlackSuit | [] | win.blacksuit | [] | 2025-02-25 | | | |
| | | Slocker | ['Jisut', 'Simple Locker'] | apk.slocker | [] | 2025-02-28 | | | |
| | | Zloader | ['DELoader', 'SILENTNIGHT', 'Terdot'] | win.zloader | [] | 2025-02-25 | | | |
| | | KV | [] | sh.kv | ['Volt Typhoon'] | 2025-01-23 | | | |
| | | KrustyLoader | [] | elf.krustyloader | [] | 2025-02-21 | | | |
| | | Cring | [] | win.cring | [] | 2025-02-20 | | | |
| | | ElizaRAT | [] | win.eliza_rat | ['Operation C-Major'] | 2025-02-19 | | | |
| | | LODEINFO | [] | win.lodeinfo | ['MirrorFace'] | 2025-02-19 | | | |