3,697 indexed

SOFTWARESoftware & malware

3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 1–50 of 3,697 · page 1 of 74

IDTitleSummary
05250LOCK05250lockRansomware
0APT0aptThis group is newly observed and first observation suggest this is not a serious group, as most - if not all - of the claims cannot be validated and are for ra…
0KILOBYPT0kilobyptRansomware
0MEGA0Mega0mega, a new ransomware operation, has been observed targeting organizations around the world. The ransomware operators are launching double-extortion attacks …
1000110001Ransomware
1337-LOCKER1337-LockerRansomware
16X16x
2023LOCK2023lock2023Lock is a ransomware strain first observed in January 2024, believed to be an evolution of the Venus and Zeoticus families and a direct precursor to the la…
20DFS20dfsransomware
24H24HRansomware
32AA32aaransomware
3AM3am
3NCRY3nCRYRansomware
3PARA-RAT3PARA RAT
3VE3ve3ve, pronounced as “Eve”, was a botnet that was halted in late 2018. 3ve utilized the malware packages Boaxxe and Kovter to infect a network of PCs. They were …
4H-RAT4H RAT4H RAT is malware that has been used by Putter Panda since at least 2007.
4RW5W4rw5wRansomware
5P00F3R-N-RAT5p00f3r.N$ RAT
5SS5C-5SS5CCRYPT5ss5c(5ss5cCrypt)Ransomware
5SS5C-RANSOMWARE5ss5c RansomwareThe cybercrime group that brought us Satan, DBGer and Lucky ransomware and perhaps Iron ransomware, has now come up with a new version or rebranding named 5ss5…
63256-BOTNET63256 botnet
68-RANDOM-HEX68-Random-HEXransomware
777777Ransomware
777-LEGION777(Legion)Ransomware
7777-BOTNET7777-Botnet7777-Botnet has been observed brute forcing Microsoft Azure instances via Microsoft Azure PowerShell bruteforcing. The botnet has a unique pattern of opening p…
7EV3N7ev3nRansomware
7H9R7h9rRansomware
7Z-PORTUGUESE7z PortugueseRansomware
7ZIPPER-RANSOMWARE7Zipper RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
8BASE8base8Base emerged in early 2022 and rapidly escalated its ransomware operations by mid-2023, positioning itself as a “simple pen tester” while executing a relentle…
8LOCK88lock8Ransomware Based on HiddenTear
90029002
A1PROJECTa1projectThe locker is written in C/C++/ASM. <br/>It supports all systems starting from Windows 2003, has a separate binary for ESXi, and uses a unified encrypted file …
A32S-RATA32s RAT
A4ZETAA4Zeta
AACAACRansomware
ABCBOTAbcbotBotnet
ABCLOCKERABCLockerRansomware
ABRAHAM-S-AXAbraham's AxAbraham's Ax announced their existence and mission through social media channels such as Twitter posts on November 8, 2022. Abraham's Ax use a WordPress blog a…
ABYSS-DATAabyss-data
ACROWARE-CRYPTOLOCKER-RANSOMWAREAcroware Cryptolocker RansomwareLeo discovered a screenlocker that calls itself Acroware Cryptolocker Ransomware. It does not encrypt.
ADAMLOCKER-RANSOMWAREAdamLocker RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
ADB-MINERADB.minerA new botnet appeared over the weekend, and it's targeting Android devices by scanning for open debug ports so it can infect victims with malware that mines th…
ADMINLOCKERadminlockerAdminLocker was first observed around December 2021 and appears to be a lone operator or small group, with no clear Ransomware-as-a-Service (RaaS) model report…
ADONISAdonisRansomware
ADWINDAdwindAdwind is a backdoor written purely in Java that targets system supporting the Java runtime environment. Commands that can be used, among other things, to disp…
ADWIND-RATAdwind RATBackdoor:Java/Adwind is a Java archive (.JAR) file that drops a malicious component onto the machines and runs as a backdoor. When active, it is capable of ste…
ADZOKAdzokRemote Administrator
AEPCRYPTAepCryptRansomware
AEROADMINAeroAdminAeroAdmin is probably the easiest program to use for free remote access. There are hardly any settings, and everything is quick and to the point, which is perf…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.