3,773 indexed

SOFTWARESoftware & malware

3,773 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 1,201–1,250 of 3,773 · page 25 of 76

IDTitleSummary
GIBBERISHGibberishransomware
GIBONGibonransomware
GINGERBREADGingerbreadRansomware
GIYOTINGiyotinransomware
GLADIUSGladiusransomware
GLOBALglobalNot a RaaS yet.
GLOBAL-CYBERNETIC-COLLECTIVEglobal cybernetic collective
GLOBAL-SECRET-GROUPglobal secret group
GLOBEglobeGlobe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note te…
GLOBE-V1Globe v1Ransomware
GLOBE2-RANSOMWAREGlobe2 RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
GLOBE3-RANSOMWAREGlobe3 RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GLOBEIMPOSTERGlobeImposterDuring December 2017, a new variant of the GlobeImposter Ransomware was detected for the first time and reported on malware-traffic-analysis. At first sight th…
GLOOXMAILGLOOXMAILGLOOXMAIL communicates with Google's Jabber/XMPP servers and authenticates with a hard-coded username and password. The malware can accept commands over XMPP …
GLUPTEBAGluptebaA multi-component botnet targeting Windows Computer. Glupteba is known to steal user credentials and cookies, mine cryptocurrencies on infected hosts, deploy a…
GNL-LOCKERGNL LockerRansomware Only encrypts DE or NL country. Variants, from old to latest: Zyklon Locker, WildFire locker, Hades Locker
GOCRYPTOLOCKERGoCryptoLockerransomware
GOD-CRYPT-JOKE-RANSOMWAREGod Crypt Joke RansomwareMalwareHunterTeam found a new ransomware called God Crypt that does not appear to decrypt and appears to be a joke ransomware. Has an unlock code of 29b579fb81…
GODRAGodraransomware
GOG-RANSOMWAREGOG RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GOGGLESGOGGLESA family of downloader malware, that retrieves an encoded payload from a fixed location, usually in the form of a file with the .jpg extension. Some variants h…
GOGINRATGoginRATGoginRAT is a remote access trojan written in Go, used by the SilkParasite activity cluster and observed by Bitdefender in Central Asia. Bitdefender notes deve…
GOGOOGLEGoGoogleransomware
GOHACKGoHackransomware
GOLDDRAGONGOLDDRAGONGOLDDRAGON is a downloader written in C that retrieves a payload from a remote server via HTTP. The downloaded payload is written to disk and executed. GOLDDRA…
GOLDDROPGOLDDROPGOLDDROP is a C/C++ Windows dropper. It decrypts a resource file, saves it to the file system, and injects it into another process. Availability: Non-public
GOLDEN-AXEGolden Axeransomware
GOLDEN-PHOENIXGOlden Phoenix
GOLDENEYE-RANSOMWAREGoldenEye RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GOLDFINDERGoldFinderTool written in Go, GoldFinder was most likely used as a custom HTTP tracer tool that logs the route or hops that a packet takes to reach a hardcoded C2 server…
GOLDMAXGoldMaxWritten in Go, GoldMax acts as command-and-control backdoor for the actor. It uses several different techniques to obfuscate its actions and evade detection. T…
GOLDSMELTGOLDSMELTGOLDSMELT is a C/C++ utility used to close the rundll32.exe process and delete a file likely used for logs. Availability: Non-public
GOMASOMGomasomRansomware
GOMMEGommeransomware
GONNACRY-RANSMWAREGonnaCry Ransmwareransomware
GOOD-DAYgood dayGood Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to its reticent financial extortion model an…
GOOFED-HTGoofed HTransomware
GOOPICGoopicRansomware
GOOTKITGootKitAs was the case earlier, the bot Gootkit is written in NodeJS, and is downloaded to a victim computer via a chain of downloaders. The main purpose of the bot a…
GOOTLOADERGootLoaderGootLoader is a malware loader historically associated with the GootKit malware. As its developers updated its capabilities, GootLoader has evolved from a load…
GOPHERGopherRansomware OS X ransomware (PoC)
GORANSOM-POCGoRansom POCransomware
GORGONGorgonransomware
GOSCANSSHGoScanSSHDuring a recent Incident Response (IR) engagement, Talos identified a new malware family that was being used to compromise SSH servers exposed to the internet.…
GOSTGOSTA simple security tunnel written in Golang. Features: Listening on multiple ports, Multi-level forward proxy - proxy chain, Standard HTTP/HTTPS/HTTP2/SOCKS4(A)…
GOTCHAGotcharansomware
GOTTACRYGottaCryransomware
GOVRATGovRATGovRAT is an old cyberespionage tool, it has been in the wild since 2014 and it was used by various threat actors across the years.
GPAAGPAAransomware
GPGQWERTYGPGQwertyransomware
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.