| | | CountLoader | [] | win.count_loader | [] | 2025-09-23 | | | |
| | | Global | ['GLOBAL GROUP'] | win.global | [] | 2025-09-23 | | | |
| | | BTMOB RAT | [] | apk.btmob | [] | 2025-09-23 | | | |
| | | PUBLOAD | ['ClaimLoader', 'PUBLOAD'] | win.pubload | [] | 2025-09-23 | | | |
| | | Yokai | [] | win.yokai | ['MUSTANG PANDA'] | 2025-09-23 | | | |
| | | SnakeDisk | [] | win.snake_disk | ['MUSTANG PANDA'] | 2025-09-23 | | | |
| | | SystemBC | ['Coroxy', 'DroxiDat'] | win.systembc | ['Vanilla Tempest'] | 2025-09-23 | | | |
| | | SystemBC | [] | elf.systembc | [] | 2025-09-23 | | | |
| | | Kazuar | [] | win.kazuar | ['Turla'] | 2024-12-11 | | | |
| | | BeaverTail | [] | osx.beavertail | [] | 2025-09-22 | | | |
| | | SmokeLoader | ['Dofoil', 'Sharik', 'Smoke', 'Smoke Loader'] | win.smokeloader | ['SMOKY SPIDER', 'UAC-0006'] | 2025-09-17 | | | |
| | | GRUNT | ['Covenant'] | win.grunt | [] | 2025-09-17 | | | |
| | | BEARDSHELL | [] | win.beardshell | ['APT28'] | 2025-09-17 | | | |
| | | SLIMAGENT | [] | win.slimagent | ['APT28'] | 2025-09-17 | | | |
| | | kkRAT | [] | win.kk_rat | [] | 2025-09-17 | | | |
| | | Raven Stealer | [] | win.ravenstealer | [] | 2025-09-17 | | | |
| | | ContagiousDrop | [] | js.contagious_drop | [] | 2025-09-16 | | | |
| | | RandomQuery | [] | ps1.randomquery | ['Kimsuky'] | 2025-09-16 | | | |
| | | 3CX Backdoor | ['SUDDENICON'] | win.3cx_backdoor | ['Lazarus Group'] | 2025-09-15 | | | |
| | | POOLRAT | ['SIMPLESEA', 'SIMPLETEA'] | osx.poolrat | ['Lazarus Group'] | 2025-09-15 | | | |
| | | SimpleTea | ['PondRAT', 'SimplexTea'] | elf.simpletea | ['Lazarus Group'] | 2025-09-15 | | | |
| | | BLINDINGCAN | ['AIRDRY', 'ZetaNile'] | win.blindingcan | ['Lazarus Group'] | 2025-09-15 | | | |
| | | CLOUDBURST | ['NickelLoader'] | win.cloudburst | ['Lazarus Group'] | 2025-09-15 | | | |
| | | SnatchCrypto | ['BackbitingTea', 'msoRAT'] | win.snatchcrypto | ['Lazarus Group'] | 2025-11-05 | | | |
| | | WinInetLoader | ['LIDSHOT'] | win.wininetloader | ['Lazarus Group'] | 2025-09-15 | | | |
| | | WebbyTea | [] | win.webbytea | ['Lazarus Group'] | 2025-09-15 | | | |
| | | SecondHandTea | [] | win.secondhandtea | ['Lazarus Group'] | 2025-09-15 | | | |
| | | miniBlindingCan | ['AIRDRY.V2', 'EventHorizon'] | win.miniblindingcan | ['Lazarus Group'] | 2025-09-15 | | | |
| | | LambLoad | ['OfficeCertTea'] | win.lambload | ['Lazarus Group'] | 2025-09-15 | | | |
| | | LightlessCan | ['SIDESHOW'] | win.lightlesscan | ['Lazarus Group'] | 2025-11-05 | | | |
| | | ImprudentCook | [] | win.imprudentcook | ['Lazarus Group'] | 2025-09-15 | | | |
| | | ForestTiger | ['ScoringMathTea'] | win.forest_tiger | ['Lazarus Group'] | 2025-09-15 | | | |
| | | EvilConwi | [] | win.evilconwi | [] | 2025-06-30 | | | |
| | | GONEPOSTAL | ['Cordyceps', 'NOTDOOR'] | win.gonepostal | ['APT28'] | 2025-09-12 | | | |
| | | Pykspa | [] | win.pykspa | [] | 2025-09-12 | | | |
| | | MostereRAT | [] | win.mostere_rat | [] | 2025-09-09 | | | |
| | | RatOn | [] | apk.rat_on | [] | 2025-09-09 | | | |
| | | Rhysida | [] | win.rhysida | ['Vanilla Tempest'] | 2025-09-09 | | | |
| | | Merlin | [] | win.merlin | [] | 2025-09-09 | | | |
| | | TimbreStealer | [] | win.timbre_stealer | [] | 2025-09-09 | | | |
| | | NightshadeC2 | [] | py.nightshade_c2 | [] | 2025-09-09 | | | |
| | | Rustonotto | ['CHILLYCHINO'] | win.rustonotto | ['APT37'] | 2025-09-09 | | | |
| | | FireWood | [] | elf.firewood | ['Gelsemium'] | 2025-09-09 | | | |
| | | LAMEHUG | [] | py.lamehug | ['APT28'] | 2025-09-09 | | | |
| | | Stealerium | [] | win.stealerium | [] | 2025-09-09 | | | |
| | | DEVMAN | [] | win.devman | ['DragonForce', '[Unnamed group]'] | 2025-09-09 | | | |
| | | Maze | ['ChaCha'] | win.maze | ['FIN6', 'TA2101'] | 2025-09-09 | | | |
| | | Felixroot | [] | win.felixroot | ['GreyEnergy'] | 2025-09-09 | | | |
| | | Konni | [] | win.konni | ['APT37'] | 2025-09-09 | | | |
| | | Carbanak | ['Anunak', 'Sekur RAT'] | win.carbanak | ['FIN7'] | 2025-09-09 | | | |
| | | Carberp | [] | win.carberp | [] | 2025-09-09 | | | |
| | | Cardinal RAT | [] | win.cardinal_rat | [] | 2025-09-09 | | | |
| | | Amadey | [] | win.amadey | [] | 2025-09-09 | | | |
| | | Anchor | [] | win.anchor | ['WIZARD SPIDER'] | 2025-09-09 | | | |
| | | AnchorMTea | [] | win.anchormtea | ['Lazarus Group'] | 2025-09-09 | | | |
| | | XTinyLoader | [] | win.xtinyloader | [] | 2025-09-09 | | | |
| | | RapperBot | [] | elf.rapper_bot | [] | 2025-09-09 | | | |
| | | SalatStealer | [] | win.salatstealer | [] | 2025-08-28 | | | |
| | | Sindoor | [] | elf.sindoor | ['Operation C-Major'] | 2025-09-01 | | | |
| | | s1ngularity Stealer | [] | js.s1ngularity | [] | 2025-08-29 | | | |
| | | BitRAT | [] | win.bit_rat | [] | 2025-08-29 | | | |
| | | LimeRAT | [] | win.limerat | ['APT-C-36'] | 2025-08-29 | | | |
| | | PureCrypter | [] | win.purecrypter | [] | 2025-08-29 | | | |
| | | GolangGhost | [] | osx.golangghost | ['WageMole'] | 2025-08-29 | | | |
| | | Godfather | [] | apk.godfather | [] | 2025-08-29 | | | |
| | | Ghost RAT | ['Farfli', 'Gh0st RAT', 'PCRat'] | win.ghost_rat | ['EMISSARY PANDA', 'Hurricane Panda', 'Lazarus Group', 'Leviathan', 'Red Menshen', 'Stone Panda'] | 2025-08-28 | | | |
| | | BlackCat | ['ALPHV', 'Noberus'] | elf.blackcat | ['Vanilla Tempest'] | 2025-08-28 | | | |
| | | Anatsa | ['ReBot', 'TeaBot', 'Toddler'] | apk.anatsa | [] | 2025-08-28 | | | |
| | | Akira Stealer | [] | py.akira_stealer | [] | 2025-08-28 | | | |
| | | PromptLock | [] | win.prompt_lock | [] | 2025-08-27 | | | |
| | | RokRAT | ['DOGCALL'] | win.rokrat | ['APT37'] | 2025-08-15 | | | |
| | | p0sT5n1F3r | [] | elf.p0st5n1f3r | [] | 2025-08-27 | | | |
| | | LunaSpy | ['Backdoor.916'] | apk.luna_spy | [] | 2025-08-26 | | | |
| | | STATICPLUGIN | [] | win.staticplugin | ['MUSTANG PANDA'] | 2025-08-26 | | | |
| | | TgToxic | [] | apk.tgtoxic | [] | 2025-08-25 | | | |
| | | ToxicPanda | [] | apk.toxic_panda | [] | 2025-08-25 | | | |
| | | SilentPrism | [] | ps1.silent_prism | ['Larva-208'] | 2025-08-25 | | | |
| | | Fickle Stealer | [] | win.fickle | [] | 2025-08-25 | | | |
| | | XenArmor | ['XenArmor Suite'] | win.xenarmor | [] | 2023-05-10 | | | |
| | | donut_injector | ['Donut'] | win.donut_injector | [] | 2025-08-25 | | | |
| | | Luna Grabber | [] | py.lunagrabber | [] | 2025-08-22 | | | |
| | | ApolloShadow | [] | win.apollo_shadow | ['Turla'] | 2025-08-22 | | | |
| | | QuirkyLoader | [] | win.quirkyloader | [] | 2025-08-22 | | | |
| | | Dridex | [] | win.dridex | ['Evil Corp', 'INDRIK SPIDER', 'TA505'] | 2024-04-15 | | | |
| | | SoundBill | [] | win.soundbill | [] | 2025-08-21 | | | |
| | | PicassoLoader | [] | win.picasso_loader | ['Ghostwriter'] | 2025-08-26 | | | |
| | | XenoRAT | [] | win.xenorat | [] | 2025-08-20 | | | |
| | | WarLock | [] | win.warlock | [] | 2025-08-20 | | | |
| | | HawkEye Keylogger | ['HawkEye', 'HawkEye Reborn', 'Predator Pain'] | win.hawkeye_keylogger | [] | 2025-08-20 | | | |
| | | VELETRIX | [] | win.veletrix | [] | 2025-08-19 | | | |
| | | AgendaCrypt | ['Agenda', 'Qilin'] | win.agendacrypt | [] | 2025-08-19 | | | |
| | | Qilin | [] | elf.qilin | [] | 2025-08-19 | | | |
| | | Morpheus Loader | [] | win.morpheus | [] | 2025-08-19 | | | |
| | | PS1Bot | [] | php.ps1bot | [] | 2025-08-18 | | | |
| | | Nitrogen Ransomware | [] | win.nitrogen_ransomware | [] | 2025-08-18 | | | |
| | | HijackLoader | ['DOILoader', 'GHOSTPULSE', 'IDAT Loader', 'SHADOWLADDER'] | win.hijackloader | [] | 2025-08-18 | | | |
| | | Plague | [] | elf.plague | [] | 2025-08-18 | | | |
| | | ERMAC | [] | apk.ermac | [] | 2025-08-18 | | | |
| | | Cmimai Stealer | [] | win.cmimai | [] | 2025-08-18 | | | |
| | | magecart | [] | js.magecart | ['FIN6', 'MageCart'] | 2025-08-18 | | | |