Malware

Malware Families

Ransomware, RATs, loaders, and wipers — with hash IoCs and MITRE ATT&CK mappings.

30 on this page

SUCEFUL

Malware

ATMitch

Malware

GreenDispenser

Malware

Skimer

Malware

ATMii

Malware

DarkMe

Malware

Global

Malware

aka GLOBAL GROUP

The GLOBAL GROUP is a Ransomware-as-a-Service program which emerged in June 2025. It is suspected to have ties to BlackLock and Mamona, due to code and infrastructure similarities. It's negotiation panel offers AI-driven negotiations to help the operators to engage with the victims.

LAMEHUG

Malware

According to CERT-UA, LAMEHUG uses an LLM (Qwen) to dynamically generate commands to gather basic information about a computer and recursively exfiltrate Office documents from a set of folders, to be uploaded either by SFTP or HTTP POST requests.

Bifrost

Malware

aka elf.bifrose

Linux version of the bifrose malware that originally targeted Windows platform only. The backdoor has the ability to perform file management, start or end a process, or start a remote shell. The connection is encrypted using a modified RC4 algorithm.

ReverseRAT

Malware

FlexibleFerret

Malware

OtterCandy

Malware

aka HardHatRAT, UNSEENMINK

OtterCandy is a JavaScript backdoor that uses the Socket.IO WebSocket protocol over port 5000 for command and control and exfiltrates data via HTTP on port 3011. It focuses on credential theft from Chromium-based browsers (Chrome, Edge, Brave, Opera, Yandex) by decrypting SQLite login databases with Windows DPAPI, and it targets cryptocurrency wallets through both browser extension identification and desktop wallet directory collection. The malware conducts recursive filesystem searches to gather .env files, seed phrases, blockchain configuration data, shell history, and cloud credentials for AWS, Azure, and GCP. It fingerprints victims by combining hostname and machine UUID to prevent duplicate records and includes a secondary payload system that downloads, prepares, and executes platform-specific follow-on malware.

StoatWaffle

Malware

StoatWaffle Malware is a lightweight JavaScript-based backdoor trojan active since at least October 2025 that enables persistent, stealthy remote control over infected systems by continuously beaconing to a command-and-control server approximately every 5 seconds. The First-Stage Module performs host fingerprinting — collecting hostname, MAC address, operating system details, and the complete Node.js process environment (process.env), which frequently contains cloud credentials, API keys, and CI/CD secrets — and executes attacker-supplied payloads via eval(). The Second-Stage Module additionally collects the victim's public IP address, spawns attacker-supplied payloads as isolated detached child processes using the local Node.js runtime, and supports process ID tracking, remote agent UUID and session token updates, and an operator-controlled kill-switch that terminates all tracked child processes and self-exits on command. Both modules suppress SIGHUP signals and hide spawned process windows to reduce visibility, report errors to the C2 server via a dedicated telemetry endpoint, and together allow attackers to steal secrets, deliver additional payloads, execute arbitrary commands, and maintain ongoing process-level control with the privileges of the compromised user.

Metamorfo

Malware

aka Casbaneiro

According to BitDefender, Metamorfo is a family of banker Trojans that has been active since mid-2018. It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments. Metamorfo is a potent piece of malware, whose primary capability is theft of banking information and other personal data from the user and exfiltration of it to the C2 server.

PoisonCarp

Malware

aka INSOMNIA

ToxicPanda

Malware

ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.

SparrowDoor

Malware

Pulsar RAT

Malware

According to Broadcom, Pulsar RAT is a derivation of Quasar RAT, which has miscellaneous functionality including keylogging, cryptocurrency wallet clipping, infostealing, file management, remote shell and command execution, among others. The data theft capabilities of this malware include collection and exfiltration of sensitive information such as credentials, cookies, cryptowallets, session files and data stored in the system web browsers, etc.

GRAYRABBIT

Malware

According to Mandiant, GRAYRABBIT is a lightweight and simple backdoor that supports simple file operation, system information collection, running modularized plugins, and executing a remote command shell.

SharpHound

Malware

According to its Github repository, SharpHound is a C# Data Collector for BloodHound.

Rubeus

Malware

Rubeus is a C# toolset for raw Kerberos interaction and abuses.

Gigabud

Malware

Gigabud is the name of an Android Remote Access Trojan (RAT) Android that can record the victim's screen and steal banking credentials by abusing the Accessibility Service. Gigabud masquerades as banking, shopping, and other applications. Threat actors have been observed using deceptive websites to distribute Gigabud RAT.

Amatera

Malware

Amatera is a stealer written in C++. It conducts anti-sandbox analysis before enumerating browsers, exfiltrating found cryptocurrency files/wallets and possibly credentials.

Pink

Malware

A botnet with P2P and centralized C&C capabilities.

Tonnerre

Malware

BADBOX

Malware

According to BitSight, BADBOX is a large-scale cybercriminal operation selling off-brand Android TV boxes, smartphones, and other Android electronics with preinstalled malware.

oRAT

Malware

SentinelOne describes this as a malware written in Go, mixing own custom code with code from public repositories.

Sality

Malware

F-Secure states that the Sality virus family has been circulating in the wild as early as 2003. Over the years, the malware has been developed and improved with the addition of new features, such as rootkit or backdoor functionality, and so on, keeping it an active and relevant threat despite the relative age of the malware. Modern Sality variants also have the ability to communicate over a peer-to-peer (P2P) network, allowing an attacker to control a botnet of Sality-infected machines. The combined resources of the Sality botnet may also be used by its controller(s) to perform other malicious actions, such as attacking routers. Infection Sality viruses typically infect executable files on local, shared and removable drives. In earlier variants, the Sality virus simply added its own malicious code to the end of the infected (or host) file, a technique known as prepending. The viral code that Sality inserts is polymorphic, a form of complex code that is intended to make analysis more difficult. Earlier Sality variants were regarded as technically sophisticated in that they use an Entry Point Obscuration (EPO) technique to hide their presence on the system. This technique means that the virus inserts a command somewhere in the middle of an infected file's code, so that when the system is reading the file to execute it and comes to the command, it forces the system to 'jump' to the malware's code and execute that instead. This technique was used to make discovery and disinfection of the malicious code harder. Payload Once installed on the computer system, Sality viruses usually also execute a malicious payload. The specific actions performed depend on the specific variant in question, but generally Sality viruses will attempt to terminate processes, particularly those related to security programs. The virus may also attempt to open connections to remote sites, download and run additional malicious files, and steal data from the infected machine.

TeamSpy

Malware

aka TVRAT, TVSPY, TeamViewerENT

DarkVNC

Malware

According to Enigmasoft, DarkVNC malware is a hacking tool that is available for purchase online. it is can be used as a Virtual Network Computing service, which means that the attackers can get full access to the targeted system via this malware. However, unlike a genuine Virtual Network Computing utility, the DarkVNC threat operates in the background silently. Therefore, it is highly likely that the victims may not notice that their systems have been compromised.

Next →