| | | Empyrean | [] | py.empyrean | [] | 2023-04-25 | | | |
| | | OpcJacker | [] | win.opcjacker | [] | 2023-04-25 | | | |
| | | SwiftSlicer | ['JaguarBlade'] | win.swiftslicer | ['Sandworm'] | 2023-04-25 | | | |
| | | DesertBlade | [] | win.desertblade | [] | 2023-04-25 | | | |
| | | DoubleZero | ['FiberLake'] | win.doublezero | [] | 2023-04-25 | | | |
| | | DealPly | [] | win.dealply | [] | 2023-04-25 | | | |
| | | Gdrive | ['DoomDrive', 'GoogleDriveSucks'] | win.gdrive | ['APT 29', 'APT29'] | 2023-04-22 | | | |
| | | QUIETEXIT | [] | elf.quietexit | [] | 2023-04-18 | | | |
| | | CryptoJoker | ['PlutoCrypt'] | win.cryptojoker | [] | 2023-04-18 | | | |
| | | HelloBot | [] | elf.hellobot | [] | 2023-04-18 | | | |
| | | HelloBot | [] | win.hellobot | ['Earth Berberoka'] | 2023-04-18 | | | |
| | | ArguePatch | [] | win.arguepatch | ['APT28', 'Sandworm'] | 2022-09-26 | | | |
| | | Nexus | [] | apk.nexus | [] | 2023-04-12 | | | |
| | | WorldWind | [] | win.worldwind | [] | 2023-04-08 | | | |
| | | 3CX Backdoor | [] | osx.3cx_backdoor | ['Lazarus Group'] | 2023-04-06 | | | |
| | | ACBackdoor | [] | elf.acbackdoor | [] | 2023-04-06 | | | |
| | | Vjw0rm | [] | win.vjw0rm | [] | 2023-01-18 | | | |
| | | INCONTROLLER | [] | win.incontroller | [] | 2023-03-30 | | | |
| | | Darktrack RAT | [] | win.darktrack_rat | [] | 2023-03-30 | | | |
| | | RambleOn | [] | apk.rambleon | [] | 2023-03-27 | | | |
| | | Kaiten | ['STD'] | elf.kaiten | [] | 2023-03-27 | | | |
| | | FFDroider | [] | win.ffdroider | [] | 2023-03-27 | | | |
| | | Dracarys | [] | apk.dracarys | ['HAZY TIGER'] | 2022-08-15 | | | |
| | | CloudMensis | [] | osx.cloud_mensis | [] | 2023-03-24 | | | |
| | | PyAesLoader | [] | py.pyaesloader | [] | 2023-03-23 | | | |
| | | Entropy | [] | win.entropy | [] | 2023-03-23 | | | |
| | | Unidentified 025 (Clickfraud) | [] | win.unidentified_025_clickfraud | [] | 2023-03-23 | | | |
| | | Eternity Clipper | [] | win.eternity_clipper | [] | 2023-03-23 | | | |
| | | Cryakl | ['CryLock'] | win.cryakl | [] | 2023-03-20 | | | |
| | | Poet RAT | [] | py.poet_rat | [] | 2023-03-20 | | | |
| | | Orcus RAT | ['Schnorchel'] | win.orcus_rat | [] | 2023-03-20 | | | |
| | | XP PrivEsc (CVE-2014-4076) | [] | win.xp_privesc | ['APT28'] | 2017-02-15 | | | |
| | | X-Tunnel (.NET) | [] | win.xtunnel_net | ['APT28'] | 2018-10-24 | | | |
| | | NetFlash | [] | win.netflash | ['Turla'] | 2020-06-05 | | | |
| | | Neuron | [] | win.neuron | ['APT34', 'Turla'] | 2020-05-23 | | | |
| | | MiniJS | [] | js.minijs | ['Turla'] | 2021-07-05 | | | |
| | | HTML5 Encoding | [] | js.turla_ff_ext | ['Turla'] | 2021-07-20 | | | |
| | | Maintools.js | [] | js.turla_maintools | ['Turla'] | 2017-11-17 | | | |
| | | Komplex | ['SedUploader', 'JHUHUGIT', 'JKEYSKW'] | osx.komplex | ['APT28'] | 2017-02-15 | | | |
| | | Uroburos | [] | osx.uroburos | ['Turla'] | 2017-05-12 | | | |
| | | X-Agent | [] | osx.xagent | ['APT28'] | 2020-05-23 | | | |
| | | X-Agent | [] | ios.xagent | ['APT28'] | 2020-05-23 | | | |
| | | CyberAzov | [] | apk.cyber_azov | ['Turla'] | 2022-08-05 | | | |
| | | X-Agent | ['Popr-d30'] | apk.popr-d30 | ['APT28'] | 2017-01-09 | | | |
| | | Unidentified ASP 001 (Webshell) | [] | asp.unidentified_001 | ['Turla'] | 2019-04-18 | | | |
| | | Cannon | [] | win.cannon | ['APT28'] | 2022-07-29 | | | |
| | | Unidentified 003 (Gamaredon Downloader) | [] | vbs.unidentified_003 | ['Gamaredon Group'] | 2023-03-15 | | | |
| | | Unidentified VBS 005 (Telegram Loader) | [] | vbs.unidentified_005 | [] | 2023-03-15 | | | |
| | | Unidentified VBS 006 (Telegram Loader) | [] | vbs.unidentified_006 | ['Gamaredon Group'] | 2023-03-15 | | | |
| | | tDiscoverer | ['HAMMERTOSS', 'HammerDuke'] | win.tdiscoverer | ['APT29'] | 2023-03-14 | | | |
| | | TOUCHSHIFT | [] | win.touchshift | [] | 2023-03-13 | | | |
| | | BlackSnake | [] | win.blacksnake | [] | 2023-03-13 | | | |
| | | Xenomorph | [] | apk.xenomorph | [] | 2023-03-13 | | | |
| | | HyperSSL | ['SysUpdate'] | elf.hyperssl | ['APT27'] | 2023-03-13 | | | |
| | | Somnia | [] | win.somnia | [] | 2023-03-13 | | | |
| | | Stealerium | [] | win.stealerium | [] | 2023-02-13 | | | |
| | | Chisel | [] | elf.chisel | [] | 2022-04-25 | | | |
| | | Phonk | [] | win.phonk | [] | 2023-02-27 | | | |
| | | poweRAT | [] | py.powerat | [] | 2023-02-21 | | | |
| | | Venus Stealer | [] | py.venus_stealer | [] | 2023-02-21 | | | |
| | | win.beep | [] | win.beep | [] | | | | |
| | | Janicab | [] | osx.janicab | ['Evilnum'] | 2023-02-21 | | | |
| | | BLINDTOAD | [] | win.blindtoad | ['Lazarus Group'] | 2023-02-21 | | | |
| | | OxtaRAT | [] | win.oxtarat | [] | 2023-02-17 | | | |
| | | Bobik | [] | win.bobik | [] | 2023-02-17 | | | |
| | | Zeppelin | [] | win.zeppelin | [] | 2023-02-15 | | | |
| | | ESXiArgs | [] | elf.esxi_args | [] | 2023-02-13 | | | |
| | | Paradies Clipper | [] | win.paradies_clipper | [] | 2023-02-09 | | | |
| | | ColdStealer | [] | win.coldstealer | [] | 2023-02-06 | | | |
| | | AmpleBot | ['BlackRock'] | apk.amplebot | [] | 2022-03-14 | | | |
| | | Reveton | [] | win.reveton | [] | 2021-02-04 | | | |
| | | SEADADDY | ['SeaDuke', 'Seadask'] | win.seadaddy | ['APT29'] | 2022-03-14 | | | |
| | | LNKR | [] | js.lnkr | [] | 2023-02-06 | | | |
| | | Bifrost | ['elf.bifrose'] | elf.bifrost | ['BlackTech'] | 2023-02-06 | | | |
| | | Saitama Backdoor | ['AMATIAS', 'Saitama'] | win.saitama | ['OilRig'] | 2023-02-03 | | | |
| | | HelloKitty | [] | elf.hellokitty | [] | 2023-02-03 | | | |
| | | Hive (Vault 8) | [] | elf.vault8_hive | ['Longhorn'] | 2023-02-02 | | | |
| | | Cold$eal | ['ColdSeal'] | win.coldseal | [] | 2020-11-26 | | | |
| | | Alien | ['AlienBot'] | apk.alien | [] | 2023-01-05 | | | |
| | | Unidentified VBS 004 (RAT) | [] | vbs.unidentified_004 | ['MuddyWater'] | 2023-01-25 | | | |
| | | xdr33 | [] | elf.xdr33 | [] | 2023-01-25 | | | |
| | | IronNetInjector | [] | win.ironnetinjector | [] | 2023-01-25 | | | |
| | | TerraPreter | [] | win.terrapreter | [] | 2023-01-25 | | | |
| | | TerraLoader | [] | win.terra_loader | [] | 2023-01-25 | | | |
| | | VenomLNK | [] | win.venom_lnk | [] | 2023-01-25 | | | |
| | | Deimos | [] | win.deimos | [] | 2023-01-19 | | | |
| | | PRIVATELOG | [] | win.privatelog | [] | 2022-05-09 | | | |
| | | ROLLCOAST | ['Sabbath', 'S4bb47h', 'Arcane'] | win.rollcoast | [] | 2023-01-19 | | | |
| | | Triton | ['Trisis', 'HatMan'] | win.triton | ['XENOTIME'] | 2023-01-19 | | | |
| | | RapperBot | [] | elf.rapper_bot | [] | 2023-01-19 | | | |
| | | StoneDrill | [] | win.stonedrill | ['Charming Kitten'] | 2023-01-19 | | | |
| | | IsraBye | [] | win.israbye | [] | 2023-01-19 | | | |
| | | Meteor | [] | win.meteor | [] | 2023-01-19 | | | |
| | | Ordinypt | ['GermanWiper', 'HSDFSDCrypt'] | win.ordinypt | [] | 2023-01-19 | | | |
| | | BotenaGo | [] | elf.botenago | [] | 2023-01-19 | | | |
| | | Luna | [] | elf.luna | [] | 2023-01-13 | | | |
| | | DarkTortilla | [] | win.darktortilla | [] | 2023-01-05 | | | |
| | | Ekipa RAT | [] | win.ekipa | [] | 2023-01-05 | | | |
| | | win.sunnyday | [] | win.sunnyday | [] | | | | |
| | | MintStealer | [] | win.mintstealer | [] | 2023-01-04 | | | |