| | | BPFDoor | ['JustForFun'] | elf.bpfdoor | ['Red Menshen'] | 2026-03-27 | | | |
| | | Kamasers | [] | win.kamasers | [] | 2026-03-27 | | | |
| | | PixyNetLoader | [] | win.pixynet_loader | ['APT28'] | 2026-03-26 | | | |
| | | GHOSTBLADE | [] | js.ghostblade | ['UNC6353'] | 2026-03-24 | | | |
| | | Unidentified JS 007 (Zimbra Stealer) | [] | js.unidentified_007 | ['APT28'] | 2026-03-24 | | | |
| | | RegPhantom | [] | win.regphantom | [] | 2026-03-23 | | | |
| | | Reynolds | [] | win.reynolds | [] | 2026-03-23 | | | |
| | | GreenBlood | [] | win.greenblood | [] | 2026-03-23 | | | |
| | | MoonRise | [] | win.moonrise | [] | 2026-03-23 | | | |
| | | Black Basta | ['no_name_software'] | win.blackbasta | ['GOLD REBELLION', 'STAC5143', 'Storm-0506', 'Storm-0826', 'TA2101', 'UNC3973', 'UNC4393'] | 2026-03-23 | | | |
| | | VENON | [] | win.venon | [] | 2026-03-23 | | | |
| | | OtterCandy | ['HardHatRAT', 'UNSEENMINK'] | js.ottercandy | ['WageMole'] | 2026-03-13 | | | |
| | | ACR Stealer | [] | win.acr_stealer | [] | 2026-03-23 | | | |
| | | TOUGHPROGRESS | ['Calendarwalk'] | win.toughprogress | ['APT41'] | 2026-03-23 | | | |
| | | DustyHammock | [] | win.dusty_hammock | [] | 2026-03-12 | | | |
| | | MeltingClaw | [] | win.meltingclaw | [] | 2026-03-12 | | | |
| | | TransferLoader | [] | win.transferloader | [] | 2026-03-12 | | | |
| | | ROMCOM RAT | ['PEAPOD', 'SingleCamper', 'SnipBot'] | win.romcom_rat | [] | 2026-03-12 | | | |
| | | NightshadeC2 | ['CastleRAT'] | win.nightshade_c2 | [] | 2026-03-12 | | | |
| | | CASTLELOADER | [] | win.castleloader | [] | 2026-03-12 | | | |
| | | Rhadamanthys | [] | win.rhadamanthys | ['Sandworm'] | 2026-03-12 | | | |
| | | Matanbuchus | [] | win.matanbuchus | [] | 2026-03-12 | | | |
| | | KadNap | [] | elf.kadnap | [] | 2026-03-11 | | | |
| | | BEARDSHELL | [] | win.beardshell | ['APT28'] | 2026-03-11 | | | |
| | | GRUNT | ['Covenant'] | win.grunt | [] | 2026-03-11 | | | |
| | | X-Agent | ['splm', 'chopstick'] | win.xagent | ['APT28'] | 2026-03-11 | | | |
| | | XTunnel | ['Shunnael', 'X-Tunnel', 'xaps'] | win.xtunnel | ['APT28'] | 2026-03-11 | | | |
| | | SLIMAGENT | [] | win.slimagent | ['APT28'] | 2026-03-11 | | | |
| | | GolangGhost | [] | osx.golangghost | ['WageMole'] | 2026-03-11 | | | |
| | | Morpheus | ['HellCat'] | win.morpheus | [] | 2026-03-11 | | | |
| | | Morpheus Loader | [] | win.morpheus_loader | [] | 2025-08-19 | | | |
| | | TrustConnect RAT | [] | win.trustconnect | [] | 2026-03-04 | | | |
| | | AstarionRAT | ['MIMICRAT'] | win.astarion_rat | [] | 2026-03-11 | | | |
| | | PUBLOAD | ['ClaimLoader', 'PUBLOAD'] | win.pubload | [] | 2025-09-23 | | | |
| | | RustyRocket | [] | win.rustyrocket | [] | 2026-03-10 | | | |
| | | AdaptixC2 | [] | win.adaptix_c2 | [] | 2026-03-10 | | | |
| | | Akira | ['REDBIKE'] | win.akira | ['Storm-1567'] | 2026-03-10 | | | |
| | | BumbleBee | ['COLDTRAIN', 'SHELLSTING', 'Shindig'] | win.bumblebee | ['EXOTIC LILY', 'GOLD CABIN', 'TA578', 'TA579'] | 2026-03-10 | | | |
| | | AMOS | ['Atomic macOS Stealer'] | osx.amos | [] | 2026-03-10 | | | |
| | | OceanLotus | [] | osx.oceanlotus | ['APT32'] | 2026-03-10 | | | |
| | | MacSpy | [] | osx.macspy | [] | 2026-03-10 | | | |
| | | Brute Ratel C4 | ['BOLDBADGER', 'BruteRatel'] | win.brute_ratel_c4 | [] | 2026-03-10 | | | |
| | | Salvador Stealer | [] | apk.salvador | [] | 2026-03-10 | | | |
| | | BadPaw | [] | win.badpaw | ['APT28'] | 2026-03-04 | | | |
| | | PXA Stealer | ['PXAStealer', 'PXA'] | py.pxa_stealer | ['CoralRaider'] | 2026-03-03 | | | |
| | | IronZero | [] | win.ironzero | [] | 2026-03-03 | | | |
| | | RMS | ['Gussdoor', 'Remote Manipulator System', 'RuRAT'] | win.rms | ['TA505'] | 2026-03-03 | | | |
| | | GONEPOSTAL | ['Cordyceps', 'NOTDOOR'] | win.gonepostal | ['APT28'] | 2026-03-03 | | | |
| | | InsidiousGh0st | [] | osx.insidiousgh0st | ['Unfading Sea Haze'] | 2026-02-26 | | | |
| | | InsidiousGh0st | [] | elf.insidiousgh0st | ['Unfading Sea Haze'] | 2026-02-26 | | | |
| | | ArcaneStealer | [] | win.arcane_stealer | [] | 2026-03-03 | | | |
| | | BlackByte | [] | win.blackbyte | [] | 2026-03-02 | | | |
| | | Nokoyawa Ransomware | [] | win.nokoyawa | [] | 2026-03-02 | | | |
| | | FudModule | ['LIGHTSHOW'] | win.fudmodule | ['Lazarus Group'] | 2026-03-02 | | | |
| | | BADAUDIO | [] | win.badaudio | ['APT24'] | 2026-03-02 | | | |
| | | SUGARLOADER | [] | osx.sugarloader | ['Lazarus Group'] | 2026-02-27 | | | |
| | | ComeBacker | [] | win.comebacker | ['Lazarus Group'] | 2026-02-27 | | | |
| | | Medusa | [] | win.medusa | [] | 2026-02-27 | | | |
| | | GRIMBOLT | [] | elf.grimbolt | [] | 2026-02-27 | | | |
| | | SLAYSTYLE | [] | jar.slaystyle | [] | 2026-02-27 | | | |
| | | BRICKSTORM | [] | elf.brickstorm | ['UTA0178'] | 2026-02-27 | | | |
| | | Agent Tesla | ['AgenTesla', 'AgentTesla', 'Negasteal'] | win.agent_tesla | ['SWEED'] | 2026-02-27 | | | |
| | | KarstoRAT | [] | win.karsto_rat | [] | 2026-02-26 | | | |
| | | Broomstick | ['CLEANBOOST', 'CleanUp', 'CleanUpLoader', 'Oyster'] | win.broomstick | [] | 2026-02-25 | | | |
| | | Airstalk | [] | win.airstalk | ['CL-STA-1009'] | 2026-02-25 | | | |
| | | DRAT | [] | win.drat | ['TAG-140'] | 2026-02-25 | | | |
| | | Ashen | ['AshTag'] | win.ashen | ['WIRTE'] | 2026-02-25 | | | |
| | | PortStarter | ['SocksProxyGo'] | win.portstarter | ['Vanilla Tempest'] | 2026-02-25 | | | |
| | | WalkLoader | [] | elf.walkloader | [] | 2026-02-25 | | | |
| | | GoldenSpy | [] | win.goldenspy | [] | 2026-02-25 | | | |
| | | GoldenHelper | [] | win.goldenhelper | [] | 2026-02-25 | | | |
| | | LockerGoga | [] | win.lockergoga | ['FIN6'] | 2026-02-25 | | | |
| | | Ryuk | [] | win.ryuk | ['FIN6', 'GRIM SPIDER', 'UNC1878', 'WIZARD SPIDER'] | 2026-02-25 | | | |
| | | FriedEx | ['BitPaymer', 'DoppelPaymer', 'IEncrypt'] | win.friedex | ['INDRIK SPIDER'] | 2026-02-25 | | | |
| | | Clop | ['Cl0p'] | elf.clop | [] | 2026-02-25 | | | |
| | | Mespinoza | ['pysa'] | win.mespinoza | [] | 2026-02-25 | | | |
| | | Egregor | [] | win.egregor | [] | 2026-02-25 | | | |
| | | TONERJAM | [] | win.tonerjam | [] | 2026-02-25 | | | |
| | | IISpy | ['BadIIS'] | win.iispy | [] | 2026-02-25 | | | |
| | | Cobalt Strike | ['Agentemis', 'BEACON', 'CobaltStrike', 'cobeacon'] | win.cobalt_strike | ['APT 29', 'APT29', 'APT32', 'APT41', 'AQUATIC PANDA', 'Anunak', 'Cobalt', 'Codoso', 'CopyKittens', 'DarkHydrus', 'Earth Baxia', 'FIN6', 'FIN7', 'Leviathan', 'Mustang Panda', 'Shell Crew', 'Stone Panda', 'TianWu', 'UNC1878', 'UNC2452', 'Winnti Umbrella'] | 2026-02-25 | | | |
| | | DynoWiper | [] | win.dynowiper | [] | 2026-02-25 | | | |
| | | reptile | [] | elf.reptile | [] | 2026-02-25 | | | |
| | | StormKittyRAT | [] | win.stormkitty_rat | [] | 2026-02-25 | | | |
| | | Infy | ['Foudre'] | win.infy | [] | 2026-02-25 | | | |
| | | Rorschach Ransomware | ['BabLock'] | win.rorschach | [] | 2026-02-25 | | | |
| | | VoidLink | [] | elf.voidlink | [] | 2026-02-25 | | | |
| | | IClickFix | [] | js.iclickfix | [] | 2026-02-25 | | | |
| | | Hamweq | [] | win.hamweq | [] | 2026-02-25 | | | |
| | | Latrodectus | ['BLACKWIDOW', 'IceNova', 'Latrodectus', 'Lotus'] | win.latrodectus | [] | 2026-02-25 | | | |
| | | Void | ['VoidCrypt'] | win.void | [] | 2026-02-25 | | | |
| | | PureRAT | ['PureHVNC', 'ResolverRAT'] | win.pure_rat | [] | 2026-02-25 | | | |
| | | NonEuclid RAT | ['LiberiumRAT', 'ShadowRoot', 'SheetRAT'] | win.noneuclid_rat | [] | 2026-02-24 | | | |
| | | RatonRAT | [] | win.raton_rat | [] | 2026-02-24 | | | |
| | | XWorm | [] | win.xworm | ['Hive0137'] | 2026-02-24 | | | |
| | | Astaroth | ['Guildma'] | win.astaroth | [] | 2026-02-17 | | | |
| | | Kimwolf | [] | apk.kimwolf | [] | 2026-02-17 | | | |
| | | Aisuru | [] | elf.aisuru | [] | 2026-02-17 | | | |
| | | Razr ransomware | [] | win.razr | [] | 2026-02-15 | | | |
| | | NodeCordRAT | [] | js.nodecordrat | [] | 2026-02-17 | | | |
| | | OctoRAT | [] | win.octorat | [] | 2026-02-05 | | | |