3,773 indexed
SOFTWARESoftware & malware
3,773 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.
Showing 1,201–1,250 of 3,773 · page 25 of 76
| ID | Title | Summary |
|---|---|---|
| GIBBERISH | Gibberish | ransomware |
| GIBON | Gibon | ransomware |
| GINGERBREAD | Gingerbread | Ransomware |
| GIYOTIN | Giyotin | ransomware |
| GLADIUS | Gladius | ransomware |
| GLOBAL | global | Not a RaaS yet. |
| GLOBAL-CYBERNETIC-COLLECTIVE | global cybernetic collective | |
| GLOBAL-SECRET-GROUP | global secret group | |
| GLOBE | globe | Globe is a ransomware family that first appeared in August 2016, notable for its highly customizable codebase that allows operators to configure ransom note te… |
| GLOBE-V1 | Globe v1 | Ransomware |
| GLOBE2-RANSOMWARE | Globe2 Ransomware | This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac… |
| GLOBE3-RANSOMWARE | Globe3 Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp… |
| GLOBEIMPOSTER | GlobeImposter | During December 2017, a new variant of the GlobeImposter Ransomware was detected for the first time and reported on malware-traffic-analysis. At first sight th… |
| GLOOXMAIL | GLOOXMAIL | GLOOXMAIL communicates with Google's Jabber/XMPP servers and authenticates with a hard-coded username and password. The malware can accept commands over XMPP … |
| GLUPTEBA | Glupteba | A multi-component botnet targeting Windows Computer. Glupteba is known to steal user credentials and cookies, mine cryptocurrencies on infected hosts, deploy a… |
| GNL-LOCKER | GNL Locker | Ransomware Only encrypts DE or NL country. Variants, from old to latest: Zyklon Locker, WildFire locker, Hades Locker |
| GOCRYPTOLOCKER | GoCryptoLocker | ransomware |
| GOD-CRYPT-JOKE-RANSOMWARE | God Crypt Joke Ransomware | MalwareHunterTeam found a new ransomware called God Crypt that does not appear to decrypt and appears to be a joke ransomware. Has an unlock code of 29b579fb81… |
| GODRA | Godra | ransomware |
| GOG-RANSOMWARE | GOG Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp… |
| GOGGLES | GOGGLES | A family of downloader malware, that retrieves an encoded payload from a fixed location, usually in the form of a file with the .jpg extension. Some variants h… |
| GOGINRAT | GoginRAT | GoginRAT is a remote access trojan written in Go, used by the SilkParasite activity cluster and observed by Bitdefender in Central Asia. Bitdefender notes deve… |
| GOGOOGLE | GoGoogle | ransomware |
| GOHACK | GoHack | ransomware |
| GOLDDRAGON | GOLDDRAGON | GOLDDRAGON is a downloader written in C that retrieves a payload from a remote server via HTTP. The downloaded payload is written to disk and executed. GOLDDRA… |
| GOLDDROP | GOLDDROP | GOLDDROP is a C/C++ Windows dropper. It decrypts a resource file, saves it to the file system, and injects it into another process. Availability: Non-public |
| GOLDEN-AXE | Golden Axe | ransomware |
| GOLDEN-PHOENIX | GOlden Phoenix | |
| GOLDENEYE-RANSOMWARE | GoldenEye Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp… |
| GOLDFINDER | GoldFinder | Tool written in Go, GoldFinder was most likely used as a custom HTTP tracer tool that logs the route or hops that a packet takes to reach a hardcoded C2 server… |
| GOLDMAX | GoldMax | Written in Go, GoldMax acts as command-and-control backdoor for the actor. It uses several different techniques to obfuscate its actions and evade detection. T… |
| GOLDSMELT | GOLDSMELT | GOLDSMELT is a C/C++ utility used to close the rundll32.exe process and delete a file likely used for logs. Availability: Non-public |
| GOMASOM | Gomasom | Ransomware |
| GOMME | Gomme | ransomware |
| GONNACRY-RANSMWARE | GonnaCry Ransmware | ransomware |
| GOOD-DAY | good day | Good Day is a ransomware variant within the ARCrypter family, first observed in May 2023. It gained prominence due to its reticent financial extortion model an… |
| GOOFED-HT | Goofed HT | ransomware |
| GOOPIC | Goopic | Ransomware |
| GOOTKIT | GootKit | As was the case earlier, the bot Gootkit is written in NodeJS, and is downloaded to a victim computer via a chain of downloaders. The main purpose of the bot a… |
| GOOTLOADER | GootLoader | GootLoader is a malware loader historically associated with the GootKit malware. As its developers updated its capabilities, GootLoader has evolved from a load… |
| GOPHER | Gopher | Ransomware OS X ransomware (PoC) |
| GORANSOM-POC | GoRansom POC | ransomware |
| GORGON | Gorgon | ransomware |
| GOSCANSSH | GoScanSSH | During a recent Incident Response (IR) engagement, Talos identified a new malware family that was being used to compromise SSH servers exposed to the internet.… |
| GOST | GOST | A simple security tunnel written in Golang. Features: Listening on multiple ports, Multi-level forward proxy - proxy chain, Standard HTTP/HTTPS/HTTP2/SOCKS4(A)… |
| GOTCHA | Gotcha | ransomware |
| GOTTACRY | GottaCry | ransomware |
| GOVRAT | GovRAT | GovRAT is an old cyberespionage tool, it has been in the wild since 2014 and it was used by various threat actors across the years. |
| GPAA | GPAA | ransomware |
| GPGQWERTY | GPGQwerty | ransomware |