| | | AMOS | ['Atomic macOS Stealer'] | osx.amos | [] | 2025-03-21 | | | |
| | | BlackMatter | [] | win.blackmatter | [] | 2025-03-21 | | | |
| | | Anel | ['UPPERCUT', 'lena'] | win.anel | ['Stone Panda'] | 2025-03-21 | | | |
| | | tsh | ['TINYSHELL'] | elf.tsh | [] | 2025-03-14 | | | |
| | | KoSpy | [] | apk.kospy | ['APT37'] | 2025-03-13 | | | |
| | | SmartLoader | [] | win.smartloader | [] | 2025-03-12 | | | |
| | | ERMAC | [] | apk.ermac | [] | 2025-03-12 | | | |
| | | Anatsa | ['ReBot', 'TeaBot', 'Toddler'] | apk.anatsa | [] | 2025-03-11 | | | |
| | | RandomQuery | [] | ps1.randomquery | ['Kimsuky'] | 2025-03-11 | | | |
| | | vo1d | [] | apk.vo1d | [] | 2025-03-06 | | | |
| | | Moose | [] | elf.moose | [] | 2025-03-10 | | | |
| | | QakBot | ['Oakboat', 'Pinkslipbot', 'Qbot', 'Quakbot'] | win.qakbot | ['GOLD CABIN'] | 2025-03-10 | | | |
| | | Fickle Stealer | [] | win.fickle | [] | 2025-03-10 | | | |
| | | Abyss Locker | ['elf.hellokitty'] | elf.abyss | [] | 2025-03-10 | | | |
| | | lightSpy | [] | ios.lightspy | [] | 2025-03-07 | | | |
| | | Qilin | [] | elf.qilin | [] | 2025-03-07 | | | |
| | | Simda | ['iBank'] | win.simda | [] | 2025-03-07 | | | |
| | | SparkRAT | [] | win.spark_rat | [] | 2025-03-07 | | | |
| | | Revenge RAT | ['Revetrat'] | win.revenge_rat | ['The Gorgon Group'] | 2025-03-07 | | | |
| | | Babuk | [] | elf.babuk | [] | 2025-03-07 | | | |
| | | EvilExtractor | [] | win.evilextractor | [] | 2025-03-07 | | | |
| | | Phoenix Locker | [] | win.phoenix_locker | [] | 2025-03-07 | | | |
| | | Hades | [] | win.hades | ['GOLD WINTER'] | 2025-03-07 | | | |
| | | Unidentified 103 (FIN8) | ['Ragnar Loader', 'Sardonic'] | win.unidentified_103 | [] | 2025-03-06 | | | |
| | | NailaoLocker | [] | win.nailao_locker | [] | 2025-03-05 | | | |
| | | Loki RAT | [] | py.lokirat | ['El Machete'] | 2025-03-05 | | | |
| | | I2PRAT | ['I2Parcae'] | win.i2prat | [] | 2025-03-05 | | | |
| | | Unidentified 118 | [] | win.unidentified_118 | [] | 2025-03-05 | | | |
| | | MintStealer | [] | win.mintstealer | [] | 2025-03-05 | | | |
| | | Cactus | [] | win.cactus | [] | 2025-03-05 | | | |
| | | IcedID | ['BokBot', 'IceID'] | win.icedid | ['GOLD CABIN', 'Lunar Spider'] | 2025-03-05 | | | |
| | | Cuba | ['COLDDRAW'] | win.cuba | [] | 2025-03-05 | | | |
| | | PolarEdge | [] | elf.polaredge | [] | 2025-02-28 | | | |
| | | PANIX | [] | sh.panix | [] | 2025-02-28 | | | |
| | | TgToxic | [] | apk.tgtoxic | [] | 2025-02-28 | | | |
| | | Cyclops | [] | win.cyclops | [] | 2025-02-28 | | | |
| | | AllaSenha | [] | win.allasenha | [] | 2025-02-28 | | | |
| | | EvilGnome | [] | elf.evilgnome | ['Gamaredon Group'] | 2025-02-28 | | | |
| | | HiddenWasp | [] | elf.hiddenwasp | [] | 2025-02-28 | | | |
| | | Turla RAT | [] | elf.turla_rat | [] | 2025-02-28 | | | |
| | | OceanLotus | [] | osx.oceanlotus | ['APT32'] | 2025-02-28 | | | |
| | | BitRAT | [] | win.bit_rat | [] | 2025-02-28 | | | |
| | | RecordBreaker | [] | win.recordbreaker | [] | 2025-02-28 | | | |
| | | DuQu | [] | win.duqu | ['Unit 8200'] | 2025-02-28 | | | |
| | | StegoLoader | [] | win.stegoloader | [] | 2025-02-28 | | | |
| | | Nanocore RAT | ['Nancrat', 'NanoCore'] | win.nanocore | ['APT33', 'The Gorgon Group'] | 2025-02-28 | | | |
| | | RedTail | [] | elf.redtail | [] | 2025-02-28 | | | |
| | | Winnti | ['BleDoor', 'JUMPALL', 'RbDoor', 'Pasteboy'] | win.winnti | ['APT17'] | 2025-02-28 | | | |
| | | RAWDOOR | [] | win.rawdoor | ['APT31'] | 2025-02-28 | | | |
| | | AllaKore | [] | win.allakore | [] | 2025-02-28 | | | |
| | | donut_injector | ['Donut'] | win.donut_injector | [] | 2025-02-28 | | | |
| | | BellaCiao | [] | win.bellaciao | [] | 2025-02-28 | | | |
| | | xmrig | [] | win.xmrig | [] | 2025-02-28 | | | |
| | | Behinder | [] | php.behinder | [] | 2025-02-28 | | | |
| | | LCRYX | [] | vbs.lcryx | [] | 2025-02-26 | | | |
| | | MarraCrypt | [] | win.marracrypt | [] | 2025-02-26 | | | |
| | | Hermes | [] | win.hermes | ['Lazarus Group'] | 2025-02-26 | | | |
| | | ToxicEye | [] | win.toxiceye | [] | 2025-02-25 | | | |
| | | CashRansomware | [] | win.cashransom | [] | 2025-02-25 | | | |
| | | TAMECAT | [] | vbs.tamecat | ['APT42'] | 2025-02-25 | | | |
| | | ShrinkLocker | [] | win.shrinklocker | [] | 2025-02-25 | | | |
| | | Darktrack RAT | [] | win.darktrack_rat | [] | 2025-02-25 | | | |
| | | MoqHao | ['Shaoye', 'Wroba', 'XLoader'] | apk.moqhao | ['Yanbian Gang'] | 2025-02-25 | | | |
| | | xHelper | [] | apk.xhelper | [] | 2025-02-25 | | | |
| | | BlackSuit | [] | win.blacksuit | [] | 2025-02-25 | | | |
| | | Slocker | ['Jisut', 'Simple Locker'] | apk.slocker | [] | 2025-02-28 | | | |
| | | Zloader | ['DELoader', 'SILENTNIGHT', 'Terdot'] | win.zloader | [] | 2025-02-25 | | | |
| | | KV | [] | sh.kv | ['Volt Typhoon'] | 2025-01-23 | | | |
| | | Cring | [] | win.cring | [] | 2025-02-20 | | | |
| | | ElizaRAT | [] | win.eliza_rat | ['Operation C-Major'] | 2025-02-19 | | | |
| | | NOOPDOOR | ['HiddenFace'] | win.noopdoor | ['MirrorFace'] | 2025-02-19 | | | |
| | | LODEINFO | [] | win.lodeinfo | ['MirrorFace'] | 2025-02-19 | | | |
| | | DarkSide | ['BlackMatter'] | win.darkside | [] | 2025-02-19 | | | |
| | | DarkSide | [] | elf.darkside | [] | 2025-02-19 | | | |
| | | SMOKEDHAM | [] | win.smokedham | [] | 2025-02-19 | | | |
| | | SECONDDATE | [] | elf.seconddate | [] | 2025-02-19 | | | |
| | | Marcher | ['ExoBot'] | apk.marcher | [] | 2025-02-19 | | | |
| | | FrigidStealer | [] | osx.frigid_stealer | [] | 2025-02-19 | | | |
| | | Unidentified 120 | [] | win.unidentified_120 | [] | 2025-02-19 | | | |
| | | magecart | [] | js.magecart | ['FIN6', 'MageCart'] | 2025-02-18 | | | |
| | | Moisha Ransomware | [] | win.moisha | [] | 2025-02-18 | | | |
| | | BlankGrabber | [] | py.blankgrabber | [] | 2025-02-18 | | | |
| | | Kalambur | [] | ps1.kalambur | ['Sandworm'] | 2025-02-17 | | | |
| | | BACKORDER | [] | win.backorder | ['Sandworm'] | 2025-02-17 | | | |
| | | MooBot | [] | elf.moobot | [] | 2025-02-17 | | | |
| | | CredoMap | [] | win.credomap | ['APT28'] | 2025-02-17 | | | |
| | | TelePowerBot | [] | win.telepowerbot | [] | 2025-02-13 | | | |
| | | KamiKakaBot | ['Kami'] | win.kami | [] | 2025-02-13 | | | |
| | | Luxy | [] | win.luxy | [] | 2025-02-13 | | | |
| | | GoRed | [] | win.go_red | ['ExCobalt'] | 2025-02-13 | | | |
| | | LocalOlive | [] | asp.localolive | ['Sandworm'] | 2025-02-13 | | | |
| | | CMS8000 Backdoor | [] | elf.cms8000_backdoor | [] | 2025-02-11 | | | |
| | | Parite | [] | win.parite | [] | 2025-02-10 | | | |
| | | php.shin_webshell | [] | php.shin_webshell | [] | 2025-02-10 | | | |
| | | Unidentified PS 005 (Telegram Bot) | [] | ps1.unidentified_005 | ['YoroTrooper'] | 2025-02-10 | | | |
| | | Creal Stealer | [] | py.creal_stealer | [] | 2025-02-10 | | | |
| | | Sshdinjector | [] | elf.sshdinjector | [] | 2025-02-10 | | | |
| | | FlexibleFerret | [] | osx.flexibleferret | ['WageMole'] | 2025-02-04 | | | |
| | | FriendlyFerret | [] | osx.friendlyferret | ['WageMole'] | 2025-02-04 | | | |
| | | Satacom | ['CurlyGate', 'LegionLoader', 'RobotDropper'] | win.satacom | [] | 2025-02-04 | | | |