Malware
Advanced Espionage Tool Adware AI Android APP APPX file ATM Malware Backdoor Banking Bookit Bot BotNet Code-injection CoinMiners Crypt Cryptocurrency Cryptojacking CyberSpy Data Wiper DDoS DEAMON Destructive Malware DNS Backdoor Downloader Driver Droper EDR and AV Killer ELF ENGINE Espionage Exploit Families Fileless FRAMEWORK FUD Engine Go GPT GPU GRU Malware HTML ICS InfoStealer Injector iOS IoT IRC ISS Java JavaScipt JSON Keylogger Killer Kit LINUX Loader Maas MacOS Macro Malware Military Malware Miner Mobil MultiOS nmp OS OSX OT malware P2P virus Password STEALER Pay-per-install (PPI) PoS Malware PowerShell Program PyPI Python QR trojan Ransom Raspberry RAT Roque Rootkit SMS Spy Spyware SQL Malware Stealer SymbOS Tool Trojan TV UEFI bootkit USB Utility VBA Macro VBE VBS VHD malware Virus Vishing toolset VMware ESXi Windows Wipper WM virus Worm Wrapper
| 18.08.26 | HOLLOWGRAPH | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels | MALWARE | MALWARE |
| 06.08.26 | ENDLESSDOORS | ENDLESSDOORS Is Phoning Home. Pick Up. | MALWARE | MALWARE |
| 12.04.26 | VENOM | Meet VENOM: The PhaaS Platform That Neutralizes MFA | MALWARE | MALWARE |
| 10.04.26 | PRISMEX | The Russian threat actor known as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine and its allies to deploy a previously undocumented malware suite codenamed PRISMEX. | MALWARE | MALWARE |
|
12.12.25 |
Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite |
MALWARE |
||
|
01.11.25 |
Suspected Nation-State Threat Actor Uses New Airstalk Malware in a Supply Chain Attack |
MALWARE |
||
|
21.10.25 |
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER |
Malware |
||
|
03.10.25 |
Self-Propagating Malware Spreading Via WhatsApp, Targets Brazilian Users |
Malware |
||
|
01.06.25 |
Dark Partners: The crypto heist adventure of Poseidon Stealer and Payday Loader |
MALWARE |
||
|
27.02.25 |
Winos 4.0 Spreads via Impersonation of Official Email to Target Users in Taiwan |
MALWARE |
||
|
10.02.25 |
From South America to Southeast Asia: The Fragile Web of REF7707 |
Malware |
||
|
10.02.25 |
NAPLISTENER: more bad dreams from developers of SIESTAGRAPH |
Malware |
||
|
10.02.25 |
This blog post details our analysis of an SEO manipulation campaign targeting Asia. |
Malware |
||
|
10.02.25 |
ASPXSpy is a Web shell. It has been modified by Threat Group-3390 actors to create the ASPXTool version. |
Malware |
||
|
26.12.24 |
BellaCPP: Discovering a new BellaCiao variant written in C++ |
Malware |
||
|
23.07.24 |
Fake Browser Updates Lead to BOINC Volunteer Computing Software |
Malware |
||
|
10.07.24 |
The Mechanics of ViperSoftX: Exploiting AutoIt and CLR for Stealthy PowerShell Execution |
Malware |
||
|
18.03.24 |
Scalable Vector Graphics (SVG) files are a popular format for web graphics because they can be resized without losing quality. |
Malware |
||
|
29.11.23 |
Deep Analysis of GCleaner |
Malware |
||
|
14.09.23 |
According to Elastic, BUGHATCH is an in-memory implant loaded by an
obfuscated PowerShell script that decodes and |
Malware |
||
|
06.09.23 |
According to Tony Lambert, this is a malware written in .NET. It was observed to be delivered using the .NET Single File deployment feature. |
Malware |
||
|
24.08.23 |
Analysis of Telegram bot that helps cybercriminals scam people on online marketplaces |
Malware |
||
|
11.08.23 |
Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors |
Malware |
||
|
11.08.23 |
Group Uses Custom Backdoor to Target Orgs in Government, Aviation, Other Sectors |
Malware |
||
|
11.08.23 |
RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale |
Malware |
||
|
11.08.23 |
Brute Ratel is a a Customized Command and Control Center for Red Team and Adversary Simulation |
Malware |
||
|
02.08.23 |
Known as HeadCrab, this advanced threat actor utilizes a
state-of-the-art, custom-made malware that is undetectable |
Malware |
||
|
03.07.23 |
According to PCrisk, SVCReady collects information about the infected
system such as username, computer name, time zone, |
Malware |
||
|
03.07.23 |
According to PCrisk, Matanbuchus is a loader-type malicious program offered by its developers as Malware-as-a-Service (MaaS). |
Malware |
||
|
03.07.23 |
CargoBay is a newer malware family which was first observed in 22 and is notable for being written in the Rust language. |
Malware |
||
|
01.07.23 |
Bluenoroff’s RustBucket campaign |
Malware |
||
|
24.06.23 |
Mandiant associates this with UNC4191, this malware spreads to removable drives. |
Malware |
||
|
24.06.23 |
Mandiant associates this with UNC4191, this malware is a launcher for NCAT to establish a reverse tunnel. |
Malware |
||
|
24.06.23 |
Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW. |
Malware |
||
|
24.06.23 |
Camaro Dragon is a Chinese-based espionage threat actor whose operations are actively focused on Southeast Asian |
Malware |
||
|
17.06.23 |
The malware, dubbed ChamelDoH by Stairwell, is a C++-based tool for communicating via DNS-over-HTTPS (DoH) tunneling. |
Malware |
||
|
14.06.23 |
Sneaky DoubleFinger loads GreetingGhoul targeting your cryptocurrency |
Malware |
||
|
13.06.23 |
Amadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. |
Malware |
||
|
08.06.23 |
PowerDrop: A New Insidious PowerShell Script for Command and Control Attacks Targets U.S. Aerospace Defense Industry |
Malware |
||
|
03.06.23 |
Cisco Talos has observed a threat actor deploying a previously unidentified botnet program Talos is calling “Horabot,”. |
Malware |
||
|
03.06.23 |
MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT |
Malware |
||
|
03.06.23 |
According to SentinelLabs, this is a VisualBasic-based malware that
gathers system and file information and exfiltrates the |
Malware |
||
|
03.06.23 |
BabyShark is Microsoft Visual Basic (VB) script-based malware family first seen in November 2018. |
Malware |
||
|
31.05.23 |
ASERT recently discovered Lojack agents containing malicious C2s. These
hijacked agents pointed to suspected Fancy Bear |
Malware |
||
|
17.05.23 |
According to Mandiant, POORTRY is a malware written as a driver, signed
with a Microsoft Windows Hardware |
Malware |
||
|
05.05.23 |
Elastic Security Labs discovers the LOBSHOT malware |
Malware |
||
|
28.04.23 |
The name used by malware developers is BellaCiao, a reference to the Italian folk song about resistance fighting. |
Malware |
||
|
26.04.23 |
Github Repository: RATel |
Malware |
||
|
26.04.23 |
Tomiris called, they want their Turla malware back |
Malware |
||
|
4.4.23 |
Amadey is a botnet that appeared around October 2018 and is being sold for about 500$ on Russian-speaking hacking forums. |
|||
|
4.4.23 |
BabyShark is Microsoft Visual Basic (VB) script-based malware family first seen in November 2018. |
|||
|
25.03.23 |
Mandiant associates this with UNC4191, this malware is a launcher for NCAT to establish a reverse tunnel. |
|||
|
25.03.23 |
Mandiant associates this with UNC4191, this malware decrypts and runs DARKDEW. |
|||
|
23.03.23 |
This unique malware sample contains a C# class called MsEXGHealthd that consists of three methods: Main, SetRespHeader, and Listener. |
|||
|
17.03.23 |
|
|||
|
13.03.23 |
In February 23, EclecticIQ researchers identified multiple KamiKakaBot
malwares which are very likely used to target |
|||
|
11.03.23 |
According to researchers with Palo Alto Networks' Unit 42, who first
spotted it in the wild and dubbed it GoBruteforcer, |
|||
|
10.03.23 |
In June 22, Mandiant Managed Defense detected and responded to an UNC2970 phishing campaign targeting a U.S.-based technology company. |
|||
|
10.03.23 |
In part one on North Korea's UNC2970, we covered UNC2970’s tactics,
techniques and procedures (TTPs) |
|||
|
10.03.23 |
PlugX malware through the Chinese remote control programs Sunlogin and Awesun’s remote code execution vulnerability. |
|||
|
02.03.23 |
Sideloader used by EmissaryPanda |
|||
|
02.03.23 |
Gootloader Malware Leads to Cobalt Strike and Hand-on-Keyboard Activity |
|||
|
02.03.23 |
FAKEUPDATES is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. |
|||
|
14.02.23 |
Tracking the entire iceberg: long-term APT malware C2 protocol emulation and scanning |
Malware |
||
|
14.02.23 |
QuickMute is a malware developed using the C/C++ programming language.
Functionally provides download, RC4 decryption, and in-memory |
Malware |
||
|
11.02.23 |
This malware is delivered by an ISO file, with an DLL inside with a custom loader. |
Malware |
||
|
09.02.23 |
THREAT ALERT: GootLoader - SEO Poisoning and Large Payloads Leading to Compromise |
|||
|
09.01.23 |
Cybersecurity researchers have exposed a wide variety of techniques adopted by an advanced malware downloader called GuLoader to evade security software. |
Malware |
||
|
28.06.22 |
In June 22, a new Android banking trojan was discovered by the Cleafy TIR team. |
Malware |
||
|
14.06.22 |
Unit 42 recently identified a new, difficult-to-detect remote access trojan named PingPull being used by GALLIUM, an advanced persistent threat (APT) group. |
Malware |
||
|
14.06.22 |
Open-source lightweight backdoor for C2 communication. |
Malware |
||
|
06.06.22 |
A previously unknown malware loader named SVCReady has been discovered
in phishing attacks, featuring an |
Malware |
||
|
04.06.22 |
FAKEUPDATES is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. |
Malware |
||
|
31.05.22 |
Rapidly evolving IoT malware EnemyBot now targeting Content Management System servers and Android devices |
Malware |
||
|
29.05.22 |
ChromeLoader might seem like a run-of-the-mill browser hijacker, but its peculiar use of PowerShell could spell deeper trouble. |
Malware |
||
|
29.05.22 |
Lowering the Barrier of Entry for Malicious Actors.Free-to-use browser automation framework creates thriving criminal community |
Malware |
||
|
20.05.22 |
The North Korea-backed Lazarus Group has been observed leveraging the
Log4Shell vulnerability in VMware Horizon servers to |
Malware |
||
|
20.05.22 |
In April 22, ThreatLabz discovered several newly registered domains,
which were created by a threat actor to spoof the official Microsoft
|
Malware |
||
|
11.05.22 |
Identified by Proofpoint as the threat actor behind the Contact Forms
campaign, TA578 also appears to be pushing ISO files for Bumblebee |
Malware |
||
|
08.05.22 |
Malware |
|||
|
08.05.22 |
Malware |
|||
|
08.05.22 |
Malware |
|||
|
08.05.22 |
We recently encountered a fairly sophisticated malware framework that we named NetDooka after the names of some of its components. |
Malware |
||
|
30.04.22 |
Starting in March 22, Proofpoint observed campaigns delivering a new downloader called Bumblebee. |
Malware |
||
|
30.04.22 |
The threat group’s targeting shift could reflect a change in China’s intelligence collection requirements due to the war in Ukraine. |
Malware |
||
|
30.04.22 |
Aqua’s Team Nautilus found a logical flaw in npm that allows threat
actors to masquerade a malicious package as legitimate and trick |
Malware |
||
|
27.04.22 |
GOLDBACKDOOR, an artifact that shares technical overlaps with another malware named BLUELIGHT, which has been previously linked to the group. |
Malware |
||
|
27.04.22 |
A rapidly expanding malware is entrapping routers, DVRs, and servers all
over the web in order to launch Distributed Denial-of-Service (DDoS)
|
Malware |
||
|
27.04.22 |
BotenaGo is a relatively new malware written in Golang, Google’s open-source programming language. |
Malware |
||
|
14.04.22 |
Malware |
|||
|
14.04.22 |
Malware |
|||
|
10.04.22 |
Malware |
|||
|
09.04.22 |
Malware |
|||
|
09.04.22 |
Malware |
|||
|
02.04.22 |
Malware |
|||
|
02.04.22 |
Malware |
|||
|
05.06.22 |
An "extremely sophisticated" Chinese-speaking advanced persistent threat
(APT) actor dubbed LuoYu has been observed using |
Malware espionage |
||
|
06.04.22 |
Malware espionage |
|||
|
09.01.23 |
The ASEC analysis team recently discovered that a Linux malware developed with Shc has been installing a CoinMiner. |
Malware Linux |
||
|
27.06.22 |
Recently, Cyble Research Labs came across a Twitter post where a researcher observed this malware spreading through spam campaigns. |
Malware loader |
||
|
08.05.22 |
Malware RAT |
|||
|
08.05.22 |
RedPacket Security describes NJRat as "a remote access trojan (RAT) has
capabilities to log keystrokes, access the victim's camera, |
Malware RAT |
||
|
05.05.22 |
I haven't really looked into Remcos RAT lately, but I found an email with a password-protected Excel file attached to it. |
Malware RAT |
||
|
10.04.22 |
Malware RAT |
|||
|
30.04.22 |
At the start of the year, Bitdefender noticed a RIG Exploit Kit campaign
using CVE-2021-26411 exploits found in Internet Explorer to deliver |
Malware Stealer |
||
|
16.04.22 |
Malware Stealer |
|||
|
14.04.22 |
Malware Stealer |
|||
|
14.04.22 |
Malware Stealer |
|||
|
06.04.22 |
Malware Stealer |
|||
|
02.04.22 |
Malware Stealer |
|||
|
02.04.22 |
Malware Stealer |
|||
|
21.11.24 |
Attacks on Ukraine’s Energy Infrastructure: Harm to the Civilian Population |
MALWARE |
||