| OS | Common Name | Alternative Names | Name | Actors | Last Updated | Status | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| AvD Crypto Stealer | [] | win.avd | [] | |||||||
| AridHelper | [] | win.aridhelper | ['AridViper'] | |||||||
| Vigram | ['WizardUpdate'] | osx.vigram | [] | |||||||
| GIMMICK | [] | osx.gimmick | [] | |||||||
| Bella | [] | osx.bella | [] | |||||||
| Silver Sparrow | [] | osx.silver_sparrow | [] | |||||||
| Yellow Cockatoo RAT | ['Polazer'] | win.yellow_cockatoo | [] | |||||||
| RMOT | [] | ps1.rmot | ['DarkHotel'] | |||||||
| PeaceNotWar | [] | js.peacenotwar | [] | |||||||
| VegaLocker | ['Buran', 'Vega'] | win.vegalocker | [] | |||||||
| Snatch | [] | win.snatch | [] | |||||||
| BlackKingdom Ransomware | [] | win.blackkingdom_ransomware | [] | |||||||
| Gofing | ['Velocity Polymorphic Compression Malware'] | win.gofing | [] | |||||||
| SLAPSTICK | [] | elf.slapstick | [] | |||||||
| STEELCORGI | [] | elf.steelcorgi | [] | |||||||
| lsassDumper | [] | win.lsassdumper | [] | |||||||
| B1txor20 | [] | elf.b1txor20 | [] | |||||||
| GRAMDOOR | ['Small Sieve'] | win.gramdoor | ['MuddyWater'] | |||||||
| SBIDIOT | [] | elf.sbidiot | [] | |||||||
| Gh0stnet | ['Remosh'] | win.ghostnet | [] | |||||||
| Prometheus | [] | win.prometheus | [] | |||||||
| EvilPlayout | [] | win.evilplayout | [] | |||||||
| WinScreeny | [] | win.winscreeny | [] | |||||||
| Guerrilla | [] | apk.guerrilla | [] | |||||||
| Sugar | [] | win.sugar | [] | |||||||
| GlowSpark | [] | vbs.glowspark | [] | |||||||
| GoldenHelper | [] | win.goldenhelper | [] | |||||||
| Ploutus ATM | [] | win.ploutus_atm | [] | |||||||
| Book of Eli | [] | win.bookofeli | [] | |||||||
| Philadephia Ransom | [] | win.philadelphia_ransom | [] | |||||||
| Vermilion Strike | [] | elf.vermilion_strike | [] | |||||||
| Incubator | [] | win.incubator | [] | |||||||
| Erebus | [] | elf.erebus | [] | |||||||
| N-W0rm | ['nw0rm', 'NWorm'] | win.nworm | [] | |||||||
| NimbleMamba | [] | win.nimblemamba | ['Molerats'] | |||||||
| DropBook | [] | win.dropbook | ['Molerats'] | |||||||
| JhoneRAT | [] | win.jhone_rat | [] | |||||||
| SharpStage | ['LastConn'] | win.sharpstage | ['Molerats'] | |||||||
| Spark | [] | win.spark | ['Molerats'] | |||||||
| BrittleBush | [] | win.brittle_bush | ['Molerats'] | |||||||
| DazzleSpy | [] | osx.dazzle_spy | [] | |||||||
| Unidentified 007 (ARMAAN RAT) | [] | apk.unidentified_007 | [] | |||||||
| BlackSun | [] | ps1.blacksun | [] | |||||||
| WireLurker | [] | ios.wirelurker | [] | |||||||
| coldbrew | [] | win.coldbrew | [] | |||||||
| ChaChi | [] | win.chachi | [] | |||||||
| Kraken | [] | win.kraken | [] | |||||||
| Cloud Snooper | ['Snoopy'] | elf.cloud_snooper | [] | |||||||
| CACTUSTORCH | [] | js.cactustorch | ['APT32', 'Leviathan'] | |||||||
| PrivetSanya | [] | elf.privet_sanya | [] | |||||||
| CetaRAT | [] | win.ceta_rat | [] | |||||||
| QSnatch | [] | elf.qsnatch | [] | |||||||
| HiAsm | [] | win.hiasm | [] | |||||||
| Xanthe | [] | elf.xanthe | [] | |||||||
| BlackNET RAT | [] | win.blacknet_rat | [] | |||||||
| Gomorrah stealer | [] | win.gomorrah_stealer | [] | |||||||
| Krachulka | [] | win.krachulka | [] | |||||||
| Lokorrito | [] | win.lokorrito | [] | |||||||
| PeddleCheap | [] | win.peddlecheap | ['Equation Group'] | |||||||
| MISTYVEAL | [] | win.mistyveal | ['Equation Group'] | |||||||
| Dark Nexus | [] | elf.darknexus | [] | |||||||
| BioData | [] | win.biodata | [] | |||||||
| elf.wellmess | [] | elf.wellmess | ['APT 29'] | |||||||
| bancos | [] | win.bancos | [] | |||||||
| ZStealer | ['Z*Stealer'] | win.zstealer | [] | |||||||
| MercurialGrabber | [] | win.mercurialgrabber | [] | |||||||
| HabitsRAT | [] | win.habitsrat | [] | |||||||
| USBCulprit | [] | win.usbculprit | ['Hellsing'] | |||||||
| ESPecter | [] | win.especter | [] | |||||||
| Guard | [] | py.guard | [] | |||||||
| jspRAT | [] | js.jsprat | [] | |||||||
| Chinotto | [] | apk.chinotto | ['APT37'] | |||||||
| EwDoor | [] | elf.ewdoor | [] | |||||||
| PoorWeb | [] | win.poorweb | ['APT37'] | |||||||
| SharpMapExec | [] | win.sharpmapexec | [] | |||||||
| CronRAT | [] | elf.cronrat | [] | |||||||
| PowerShortShell | [] | ps1.powershortshell | [] | |||||||
| AdWind | ['AlienSpy', 'JSocket', 'Frutas', 'UNRECOM', 'JBifrost', 'Sockrat'] | jar.adwind | [] | |||||||
| ostap | [] | js.ostap | [] | |||||||
| Povlsomware | [] | win.povlsomware | [] | |||||||
| ShellClient RAT | ['GhostShell'] | win.shellclient | [] | |||||||
| Unidentified APK 006 | [] | apk.unidentified_006 | [] | |||||||
| Mevade | ['Sefnit', 'SBC'] | win.mevade | [] | |||||||
| PixStealer | ['BrazKing'] | apk.pixstealer | [] | |||||||
| PhoneSpy | [] | apk.phonespy | [] | |||||||
| DCSrv | ['DCrSrv'] | win.dcsrv | [] | |||||||
| Unidentified ELF 004 | [] | elf.unidentified_004 | ['APT31'] | |||||||
| SharpBeacon | [] | win.sharpbeacon | [] | |||||||
| Shark | [] | win.shark | [] | |||||||
| Milan | [] | win.milan | [] | |||||||
| Graphon | [] | win.graphon | [] | |||||||
| UltimaSMS | [] | apk.ultima_sms | [] | |||||||
| GriftHorse | [] | apk.grifthorse | [] | |||||||
| FoxSocket | [] | win.foxsocket | [] | |||||||
| Turkojan | [] | win.turkojan | [] | |||||||
| Ranion | [] | win.ranion | [] | |||||||
| Lambert | ['GreenLambert'] | osx.lambert | ['Longhorn'] | |||||||
| ZuRu | [] | osx.zuru | [] | |||||||
| WireX | [] | apk.wirex | [] | |||||||
| FontOnLake | [] | elf.fontonlake | [] | |||||||