3,697 indexed

SOFTWARESoftware & malware

3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 1,451–1,500 of 3,697 · page 30 of 74

IDTitleSummary
KAMPRETKampretransomware
KANGAROO-RANSOMWAREKangaroo RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
KAPPAKappaMade with OXAR builder; decryptable
KARAEKARAEKarae backdoors are typically used as first-stage malware after an initial compromise. The backdoors can collect system information, upload and download files,…
KARKOFFKarkoffIn addition to increased reports of threat activity, we have also discovered new evidence that the threat actors behind the DNSpionage campaign continue to cha…
KARMAkarmaRansomware.
KARMA-RANSOMWAREKarma RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
KARMEN-RANSOMWAREKarmen RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
KAROKaroransomware
KASISKI-RANSOMWAREKasiski RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
KASSEIKAkasseikaKasseika is a ransomware variant first publicly reported in January 2024, identified as a new evolution of the BlackMatter/LockBit ransomware codebase. The mal…
KATAFRANKKatafrankransomware
KATANAkatanaMirai variant with on-device compiled rootkit, targeting Android TV set-top boxes
KATYUSHAKatyusharansomware
KAWAkawa
KAWAIILOCKERKawaiiLockerRansomware
KAZUARKazuarKazuar is a fully featured backdoor written using the .NET Framework and obfuscated using the open source packer called ConfuserEx. Unit 42 researchers have un…
KAZYBOTKazybot
KBOTKBOTKBOT penetrates users’ computers via the Internet or a local network, or from infected external media. After the infected file is launched, the malware gains a…
KCTF-LOCKERKCTF Lockerransomware
KCWKCWransomware
KEEKeeransomware
KEKWKEKWransomware
KELIHOSKelihosThe Kelihos botnet, also known as Hlux, is a botnet mainly involved in spamming and the theft of bitcoins.
KELVIN-SECURITYKelvin SecurityKelvin Security is a cybercrime group active since at least 2013, primarily known for hacktivism, data breaches, and website defacements rather than traditiona…
KERANGERKeRangerRansomware OS X Ransomware
KERKOPORTAKerkoportaransomware
KEY-GROUPkey group
KEYBASEKeyBaseIn the wild since February 2015. The malware comes equipped with a variety of features and can be purchased for $50 directly from the author. It has been deplo…
KEYBOYKeyBoyThe actors used a new version of “KeyBoy,” a custom backdoor first disclosed by researchers at Rapid7 in June 2013. Their work outlined the capabilities of the…
KEYBTCKeyBTCRansomware
KEYHOLDERKEYHolderRansomware via remote attacker. tuyuljahat@hotmail.com contact address
KEYMAKERKeyMakerransomware
KEYMARBLEKEYMARBLEThis Malware Analysis Report (MAR) is the result of analytic efforts between Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI…
KEYPASSKEYPASSA new distribution campaign is underway for a STOP Ransomware variant called KeyPass based on the amount of victims that have been seen. Unfortunately, how the…
KHRATKhRATSo called because the Command and Control (C2) infrastructure from previous variants of the malware was located in Cambodia, as discussed by Roland Dela Paz at…
KILER-RATKiler RATThis remote access trojan (RAT) has capabilities ranging from manipulating the registry to opening a reverse shell. From stealing credentials stored in browser…
KILLADAkillada
KILLBOT-VIRUSKillBot_Virusransomware
KILLDISK-DIMENSKillDisk-Dimensransomware
KILLDISK-RANSOMWAREKillDisk RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
KILLDISK-WIPERKillDisk WiperKillDisk, along with the multipurpose, cyberespionage-related BlackEnergy, was used in cyberattacks in late December 2015 against Ukraine’s energy sector as we…
KILLER-RATKiller RAT
KILLERLOCKERKillerLockerRansomware Possibly Portuguese dev
KILLRABBITKillRabbitransomware
KILLSECkillsec
KILLSEC3killsec3
KILLSWITCHKillSwitchransomware
KIMCILWAREKimcilWareRansomware websites only
KIMJONGRATKimJongRATWe conclude that this RAT/stealeris efficient and was also really interesting to analyse.Furthermore, the creator made effortsto look Korean, for example the a…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.