3,697 indexed

SOFTWARESoftware & malware

3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 501–550 of 3,697 · page 11 of 74

IDTitleSummary
COMRADE-HTComrade HTRansomware
COMRATComRATComRAT is a remote access tool suspected of being a decedent of Agent.btz and used by Turla.
CONDICondiDDoS-as-a-service botnet calling itself Condi. This malware employs several techniques to keep itself running in an infected system. At the same time, it also …
CONFICKERConfickerConficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 200…
CONFUSEREXConfuserExConfuserEx is a common .NET packer/protector used to obfuscate .NET assemblies and confuse the decompilation process. According to the official site: ConfuserE…
CONSCIOUSNESSConsciousnessransomware
CONSOLEAPPLICATION1-RANSOMWAREConsoleApplication1 RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
CONTFRcontfrLaunched around September 2024, ContFR is a French-speaking RaaS that uses a Tor-hosted platform to provide ransomware embedded in PDF files (targeting both Wi…
CONTIContiConti ransomware is a RaaS and has been observed encrypting networks since mid-2020. Conti was developed by the “TrickBot” group, an organized Russian cybercri…
COOEECooeeCooee is a trojan pre-installed on some Phillips smartphones that displays annoying advertisements and downloads and installs different software without user k…
COOKIEBAGCOOKIEBAGhis family of malware is a backdoor capable of file upload and download as well as providing remote interactive shell access to the compromised machine. Commun…
COOMCoomRansomware
COOMINGCoomingprevious clearnet domain coomingproject.com
CORALDECKCORALDECKCORALDECK is an exfiltration tool that searches for specified files and exfiltrates them in password protected archives using hardcoded HTTP POST headers. CORA…
COREcoreCore ransomware surfaced in early 2025 as a new variant within the broader Makop family. It employs a single-extortion model, focusing on encrypting files and …
COREFLOODCorefloodCoreflood is a trojan horse and botnet created by a group of Russian hackers and released in 2010. The FBI included on its list of infected systems approximate…
CORESHELLCORESHELLdownloader - Newer version of SOURFACE
CORONAVIRUSCoronaVirusA new ransomware called CoronaVirus has been distributed through a fake web site pretending to promote the system optimization software and utilities from Wise…
CORRUPTCRYPTCorruptCryptRansomware
COVENANTCovenantCovenant is a .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve…
COVERTONCovertonRansomware
COVIDLOCKCovidLockMobile ransomware. The Zscaler ThreatLabZ team recently came across a URL named hxxp://coronavirusapp[.]site/mobile.html, which portrays itself as a download s…
COWBOYCowboyBased on our research, it appears the malware author calls the encoded secondary payload “Cowboy” regardless of what malware family is delivered.
COWERSNAILCowerSnailCowerSnail was compiled using Qt and linked with various libraries. This framework provides benefits such as cross-platform capability and transferability of t…
CPUMEANERCpuMeanerA macOS crypto-currency mining trojan.
CR1PTT0RCr1ptT0rCr1ptT0r Ransomware Targets NAS Devices with Old Firmware.
CRACKMAPEXECCrackMapExecA swiss army knife for pentesting networks. CRACKMAPEXEC is a post-exploitation tool against Microsoft Windows environments. It is recognized for its lateral m…
CRACKONOSHCrackonoshIn 2021 Crackonosh has been found in 222,000 compromised computers that were used to download illegal, torrented versions of popular video games. Crackonosh su…
CRAFTULCraftulransomware
CRAZYHUNTER-TEAMcrazyhunter team
CREAMPIE-RANSOMWARECreamPie RansomwareJakub Kroustek found what appears to be an in-dev version of the CreamPie Ransomware. It does not currently display a ransom note, but does encrypt files and a…
CREEPERCreeperRansomware
CREEPYCreepyRansomware
CRIMSONCrimson
CRIPTONCriptonRansomware
CRIPTON7ZPCripton7zpRansomware
CROMPTUICromptui
CRONIXCroniXThe researchers named this campaign CroniX, a moniker that derives from the malware's use of Cron to achieve persistence and Xhide to launch executables with f…
CROSSLOCKcrosslockCrossLock ransomware was first observed in April 2023, targeting an IT services firm in Brazil using a double‑extortion approach—encrypting data and threatenin…
CROSSRATCrossRatThe EFF/Lookout report describes CrossRat as a “newly discovered desktop surveillanceware tool…which is able to target Windows, OSX, and Linux.”
CRPTXXX-RANSOMWARECrptxxx RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
CRY0cry0
CRY36Cry36Ransomware
CRY9Cry9Ransomware
CRYAKICryakiRansomware
CRYAKLCryaklransomware
CRYBOLACrybolaRansomware
CRYBRAZILCryBrazilMostly Hidden Tear with some codes from Eda2 & seems compiled w/ Italian VS. Maybe related to OpsVenezuela?
CRYCIPHERCryCipherRansomware
CRYCRYPTORCryCryptorransomware
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.
Software & malware — full index | SQUR Knowledge Base