3,697 indexed

SOFTWARESoftware & malware

3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 51–100 of 3,697 · page 2 of 74

IDTitleSummary
AES-KEY-GEN-ASSIST-RANSOMWAREAES_KEY_GEN_ASSIST RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
AES-MATRIXAES-MatrixRansomware
AES-NI-APRIL-EDITIONAES-NI: April EditionRansomware
AES-NI-RANSOMWAREAES-NI Ransomware It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
AESDDOSAESDDoSOur honeypot sensors recently detected an AESDDoS botnet malware variant (detected by Trend Micro as Backdoor.Linux.AESDDOS.J) exploiting a server-side templat…
AESMEWAESMewransomware
AFRODITAAfroditaRansomware
AGENDA-RANSOMWAREAgenda RansomwareRansomware
AGENT-BTZAgent.BTZIn November 2014, the experts of the G DATA SecurityLabs published an article about ComRAT, the Agent.BTZ successor. We explained that this case is linked to t…
AGENT-DNEAgent.dne
AGENT-ORMAgent ORMAgent ORM began circulating alongside Skeur in campaigns throughout the second half of 2015. The malware collects basic system information and is able to take …
AGENT-TESLAAgent TeslaAgent Tesla is modern powerful keystroke logger. It provides monitoring your personel computer via keyboard and screenshot. Keyboard, screenshot and registered…
AGL0BGVYCGaGl0bGVyCgRansomware
AHK-BOTAHK BotAccording to Proofpoint, the A(uto)H(ot)K(key) Bot is a collection of separate AutoHotKey scripts. The bot's main component is an infinite loop that polls and …
AHNYTH-ANDROIDAhNyth AndroidAndroid Remote Administration Tool
AHTAPODAhtapod
AILOCKailockAiLock is a Ransomware-as-a-Service (RaaS) group first identified in March 2025. It employs a double-extortion approach—encrypting files and threatening to rep…
AIRACROPAiraCropRansomware related to TeamXRat
AIRACROP-RANSOMWAREAiraCrop RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
AIRASHIAirashiVariant of Aisuru.
AISURUaisuruAisuru is a Mirai-derivative DDoS botnet active since at least August 2024. The botnet has evolved through two distinct generations — transitioning from DNS A …
AKBOTAkbotAkbot was a computer virus that infected an estimated 1.3 million computers and added them to a botnet.
AKIRAAkira
AKOAkoOnce installed, Ako will attempt to delete Volume Shadow Copies and disable recovery services. It will then begin to encrypt all files that do not match a hard…
AL-NAMROODAl-NamroodRansomware
ALBERTINOalbertinoRemote Access Trojan
ALBERTINO-ADVANCED-RATAlbertino Advanced RAT
ALCATRAZ-LOCKER-RANSOMWAREAlcatraz Locker RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
ALCOAlcoRansomware
ALFA-RANSOMWAREALFA RansomwareRansomware Made by creators of Cerber
ALL-YOUR-DOCUMENTS-RANSOMWAREAll_Your_Documents RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
ALLCRYAllCryRansomware
ALLDATALOCKERAlldataLockerRansomware
ALMA-COMMUNICATORALMA CommunicatorThe ALMA Communicator Trojan is a backdoor Trojan that uses DNS tunneling exclusively to receive commands from the adversary and to exfiltrate data. This Troja…
ALMA-RANSOMWAREAlma RansomwareRansomware
ALP-001alp-001
ALPHA-RANSOMWAREAlpha RansomwareRansomware
ALPHABET-RANSOMWAREAlphabet RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
AMADEYAmadeyAmadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information abo…
AMAVALDOAmavaldoWe named the malware family described in the rest of this blog post Amavaldo. This family is still in active development – the latest version we have observed …
AMAVALDO-BANKING-TROJANAmavaldo Banking TrojanAmavaldo is banking trojan writen in Delphi and known to targeting Spanish or Portuguese speaking countries. It contains backdoor functionality and can work as…
AMBAAMBARansomware Websites only amba@riseup.net
AMJIXIUSAmjixiusransomware
AMMYADMINAmmyAdmin
AMMYY-ADMINAmmyy AdminAmmyy Admin is a completely portable remote access program that's extremely simple to setup. It works by connecting one computer to another via an ID supplied …
AMNESIAAmnesiaRansomware
AMNESIA-2Amnesia-2Ransomware
ANATOVAAnatovaRansomware
ANDROIDAnDROidRansomware
ANDROIDBAUTSAndroidBautsAndroidBauts botnet is a network of infected Android devices that are used for promoting advertisements to users online. At one point, the number of infected d…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.