3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 1,201–1,250 of 3,719 · page 25 of 75

IDTitleSummary
GOLDDRAGONGOLDDRAGONGOLDDRAGON is a downloader written in C that retrieves a payload from a remote server via HTTP. The downloaded payload is written to disk and executed. GOLDDRA…
GOLDDROPGOLDDROPGOLDDROP is a C/C++ Windows dropper. It decrypts a resource file, saves it to the file system, and injects it into another process. Availability: Non-public
GOLDEN-AXEGolden Axeransomware
GOLDEN-PHOENIXGOlden Phoenix
GOLDENEYE-RANSOMWAREGoldenEye RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GOLDFINDERGoldFinderTool written in Go, GoldFinder was most likely used as a custom HTTP tracer tool that logs the route or hops that a packet takes to reach a hardcoded C2 server…
GOLDMAXGoldMaxWritten in Go, GoldMax acts as command-and-control backdoor for the actor. It uses several different techniques to obfuscate its actions and evade detection. T…
GOLDSMELTGOLDSMELTGOLDSMELT is a C/C++ utility used to close the rundll32.exe process and delete a file likely used for logs. Availability: Non-public
GOMASOMGomasomRansomware
GOMMEGommeransomware
GONNACRY-RANSMWAREGonnaCry Ransmwareransomware
GOOD-DAYgood dayGood Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to its reticent financial extortion model an…
GOOFED-HTGoofed HTransomware
GOOPICGoopicRansomware
GOOTKITGootkitGootkit is a trojan that steals confidential information and allows criminals to take control of infected systems remotely. Gootkit can also be used to install…
GOOTLOADERGootLoaderGootLoader is a malware loader historically associated with the GootKit malware. As its developers updated its capabilities, GootLoader has evolved from a load…
GOPHERGopherRansomware OS X ransomware (PoC)
GORANSOM-POCGoRansom POCransomware
GORGONGorgonransomware
GOSCANSSHGoScanSSHDuring a recent Incident Response (IR) engagement, Talos identified a new malware family that was being used to compromise SSH servers exposed to the internet.…
GOSTGOSTA simple security tunnel written in Golang. Features: Listening on multiple ports, Multi-level forward proxy - proxy chain, Standard HTTP/HTTPS/HTTP2/SOCKS4(A)…
GOTCHAGotcharansomware
GOTTACRYGottaCryransomware
GOVRATGovRATGovRAT is an old cyberespionage tool, it has been in the wild since 2014 and it was used by various threat actors across the years.
GPAAGPAAransomware
GPGQWERTYGPGQwertyransomware
GRAPHICBOOTINGGraphicBooting
GRATEFULPOSGratefulPOSGratefulPOS has the following functions 1. Access arbitrary processes on the target POS system 2. Scrape track 1 and 2 payment card data from the process(es) 3…
GRAVITYRATGravityRATGravityRAT has been under ongoing development for at least 18 months, during which the developer has implemented new features. We've seen file exfiltration, re…
GRAYFISHGrayFish
GREAMEGreame
GREAT-CANNONGreat CannonThe Great Cannon of China is an Internet attack tool that is used by the Chinese government to launch distributed denial-of-service attacks on websites by perf…
GREEK-HACKERS-RATGreek Hackers RAT
GREENCATGREENCATMembers of this family are full featured backdoors that communicates with a Web-based Command & Control (C2) server over SSL. Features include interactive shel…
GREMIT-RANSOMWAREGremit RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
GREPgrep
GREYSTARSGreystarsransomware
GRIEFGriefcaptcha prevents indexing
GRINCHgrinch
GRODEXCRYPTGrodexCryptransomware
GROOVEGrooveGroove was a short-lived ransomware group and cybercrime gang that emerged in August 2021 and became notable for its aggressive, publicity-driven tactics. Unli…
GRUJARSORIUMGrujaRSoriumransomware
GRUMGrumThe Grum botnet, also known by its alias Tedroo and Reddyb, was a botnet mostly involved in sending pharmaceutical spam e-mails. Once the world's largest botne…
GRUXERGruxerransomware
GUILDMAGuildmaThe campaign spreads via phishing emails posing as invoices, tax reports, invitations and similar types of messages containing a ZIP archive attachment with a …
GUMBLARGumblarGumblar is a malicious JavaScript trojan horse file that redirects a user's Google searches, and then installs rogue security software. Also known as Troj/JSRe…
GUNRAgunra
GUSCRYPTERGusCrypterransomware
GUSTER-RANSOMWAREGuster RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
GWISINgwisinGwisin is a targeted ransomware group first publicly reported in July 2022, believed to operate primarily within South Korea. The group’s name means “ghost” in…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.
Software & malware — full index | SQUR Knowledge Base