Malware Families
Ransomware, RATs, loaders, and wipers — with hash IoCs and MITRE ATT&CK mappings.
FBot
MalwareKimwolf
MalwareKIMWOLF is an android based malware which uses compromised systems to relay malicious and abusive Internet traffic, as well as participating in distributed denial-of-service (DDoS). KIMWOLF primarily infects unofficial Android-TV set-top boxes and digital photo frames. The malware has frequently been noted to achieve infection spread via abusing Android Debug Bridge (ADB) and residential proxies. There are multiple reports suggesting a connection to the Aisuru botnet, with Kimwolf acting as the Android variant.
VoidLink
MalwareVoidLink is a cloud-native Linux malware family designed as a modular post-exploitation framework for modern cloud and containerized environments. It features a plugin-based architecture with dynamically loadable components that provide reconnaissance, credential harvesting, privilege escalation, lateral movement, persistence, and anti-forensic capabilities. The framework demonstrates strong operational security through runtime encryption, environment awareness (cloud provider and container detection), and the use of user-mode and kernel-level rootkit techniques to evade detection. VoidLink is not a repurposed legacy tool but a purpose-built framework optimized for cloud infrastructure, indicating a shift in advanced threat development toward Linux-based cloud workloads. Although no confirmed large-scale infections have been observed, its maturity and design suggest potential use by sophisticated threat actors for long-term, stealthy access to cloud environments.
LinkPro
MalwareAccording to Synacktiv, LinkPro targets the GNU/Linux systems and is developed in Golang. It is named after its main module and the corresponding (private) GitHub repository. LinkPro uses eBPF technology, to activate only when receiving a "magic package", and to hide on the compromised system.
404 Keylogger
Malwareaka 404KeyLogger, Snake Keylogger
Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victim’s sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.
Xloader
Malwareaka Formbook
Xloader is a Rebranding of Formbook malware (mainly a stealer), available for macOS as well. Formbook has a "magic"-value FBNG (FormBook-NG), while Xloader has a "magic"-value XLNG (XLoader-NG). This "magic"-value XLNG is platform-independent. Not to be confused with apk.xloader or ios.xloader.
XWorm
MalwareMalware with wide range of capabilities ranging from RAT to ransomware.
zgRAT
MalwarezgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets. Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on.
Agent Tesla
Malwareaka AgenTesla, AgentTesla, Negasteal
A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
DarkCloud Stealer
MalwareStealer is written in Visual Basic.
Formbook
Malwareaka win.xloader
FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware.
WEEVILPROXY
Malwareaka JSCEAL
WEEVILPROXY is a sophisticated and featureful stealer which has a payload primarily written in NodeJS. The developer has put in concerted effort to develop the malware’s breadth of capabilities, including novel techniques not observed in any prior malware campaigns - to our knowledge. These new TTPs include methods to modify Windows Setup and Windows Recovery to enable long-term persistence, as well as methods to patch browser extensions ‘on the fly’.
DEVMAN
MalwareDEVMAN is a ransomware which shares a large part of its codebase with DragonForce ransomware. It is highly probable that the group used a DragonForce ransomware build and simply changed the extension added to the encrypted files (from .dragonforce_encrypted to .devman). In one of the first observed samples, the ransom note still claimed to be part of the DragonForce Ransomware Cartel. The ransomware implements common features such as the deletion of ShadowCopies, and avoid encrypting files with some extensions present in a hard-coded list. The ransomware implements multiple encryption modes: - Full encryption - Header-only encryption - Custom encryption These modes allow the operator to choose between a quick or a strong encryption depending on the scenario. The ransomware also tries to connect to SMB folders. DEVMAN ransomware creates a temporary session under the following registry key: `HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000`. The use of the Restart Manager to bypass file locks and ensure encrypted access to active user session files. This capability seems to be a legacy of Conti ransomware, which inspired DragonForce and DEVMAN. As part of this legacy, the ransomware use a hard-coded mutex to prevent multiple instances from running in parallel.
Clop (ELF)
Malwareaka Cl0p
ELF version of clop ransomware.
Odyssey Stealer
MalwareBRICKSTORM
MalwareAccording to Google, BRICKSTORM is used to consistently target appliances, among them primarily VMware vCenter and ESXi hosts.
Quasar RAT
Malwareaka CinaRAT, QuasarRAT, Yggdrasil
Quasar RAT is a malware family written in .NET which is used by a variety of attackers. The malware is fully functional and open source, and is often packed to make analysis of the source more difficult.
FoalShell
MalwareAccording to BI.ZONE, FoalShell is a simple reverse shell used by Cavalry Werewolf, written in Go, C++, and C#. FoalShell allows attackers to execute arbitrary commands in the cmd.exe command line interpreter on a compromised host.
StallionRAT
MalwareAccording to BI.ZONE, StallionRAT allows attackers to execute arbitrary commands, load additional files, and exfiltrate collected data. The malware uses a Telegram bot as their C2 server.
PteroGraphin
MalwareKazuar
MalwareBaoLoader
MalwareAccording to Expel, the developers behind the recent AppSuite-PDF and PDF Editor campaigns have used at least 26 code-signing certificates over the last seven years to make their software appear legitimate. Due to different use of and certificate clustering, the malware is believed different from both Chromeloader and TamperedChef.
TamperedChef
MalwareInvisibleFerret
MalwarePylangGhost
Malwareaka WeaselStore
Python-version of GolangGhost RAT
SNAPPYBEE
Malwareaka Deed RAT, POISONPLUG.DEED
YESROBOT
MalwareMAYBEROBOT
Malwareaka SIMPLEFIX
LOSTKEYS
MalwareAccording to Google, LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.
NOROBOT
Malwareaka BAITSWITCH