3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 2,351–2,400 of 3,719 · page 48 of 75

IDTitleSummary
RSAUTILRSAUtilRSAUtil is distributed by the developer hacking into remote desktop services and uploading a package of files. This package contains a variety of tools, a conf…
RTM-LOCKERrtm locker
RUBELLA-MACRO-BUILDERRubella Macro BuilderA crimeware kit dubbed the Rubella Macro Builder has recently been gaining popularity among members of a top-tier Russian hacking forum. Despite being relative…
RUBYRubyransomware
RUCKGUVRuckguv
RUHAPPYRUHAPPYRUHAPPY is a destructive wiper tool seen on systems targeted by DOGCALL. It attempts to overwrite the MBR, causing the system not to boot. When victims' system…
RUN-SOME-WARESrun some wares
RUNEXEMEMORYRunExeMemoryransomware
RUNSOMEWERERunsomewereRansomware Based on HT/EDA2 Utilizes the Jigsaw Ransomware background
RURKTARRurktarDubbed Rurktar, the tool hasn’t had all of its functionality implemented yet, but G DATA says “it is relatively safe to say [it] is intended for use in targete…
RUSHRushransomware
RUSSENGERRussengerransomware
RUSSIAN-EDA2Russian EDA2ransomware
RUSSIAN-GLOBE-RANSOMWARERussian Globe RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
RUSSIANROULETTERussianRouletteRansomware Variant of the Philadelphia ransomware
RUSTOCKRustock
RUSTYLOCKERrustylocker
RWX-RATRWX RAT
RYUK-RANSOMWARERyuk ransomwareSimilar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments. Code comparison between versions of Ryuk and Hermes ransomware ind…
S0001Trojan.Mebromi
Windows
[Trojan.Mebromi](https://attack.mitre.org/software/S0001) is BIOS-level malware that takes control of the victim before MBR. (Citation: Ge 2011) Documented pl…
S0002Mimikatz
Windows
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many…
S0003RIPTIDE
Windows
[RIPTIDE](https://attack.mitre.org/software/S0003) is a proxy-aware backdoor used by [APT12](https://attack.mitre.org/groups/G0005). (Citation: Moran 2014) Do…
S0004TinyZBot
Windows
[TinyZBot](https://attack.mitre.org/software/S0004) is a bot written in C# that was developed by [Cleaver](https://attack.mitre.org/groups/G0003). (Citation: C…
S0005Windows Credential Editor
Windows
[Windows Credential Editor](https://attack.mitre.org/software/S0005) is a password dumping tool. (Citation: Amplia WCE) Documented platforms: Windows. Catalog…
S0006pwdump
Windows
[pwdump](https://attack.mitre.org/software/S0006) is a credential dumper. (Citation: Wikipedia pwdump) Documented platforms: Windows. Catalogued in ATT&CK 14.…
S0007Skeleton Key
Windows
[Skeleton Key](https://attack.mitre.org/software/S0007) is malware used to inject false credentials into domain controllers with the intent of creating a backd…
S0008gsecdump
Windows
[gsecdump](https://attack.mitre.org/software/S0008) is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows opera…
S0009Hikit
Windows
[Hikit](https://attack.mitre.org/software/S0009) is malware that has been used by [Axiom](https://attack.mitre.org/groups/G0001) for late-stage persistence and…
S0010Lurid
Windows
[Lurid](https://attack.mitre.org/software/S0010) is a malware family that has been used by several groups, including [PittyTiger](https://attack.mitre.org/grou…
S0011Taidoor
Windows
[Taidoor](https://attack.mitre.org/software/S0011) is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on …
S0012PoisonIvy
Windows
[PoisonIvy](https://attack.mitre.org/software/S0012) is a popular remote access tool (RAT) that has been used by many groups.(Citation: FireEye Poison Ivy)(Cit…
S0013PlugX
Windows
[PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Las…
S0014BS2005
Windows
[BS2005](https://attack.mitre.org/software/S0014) is malware that was used by [Ke3chang](https://attack.mitre.org/groups/G0004) in spearphishing campaigns sinc…
S0015Ixeshe
Windows
[Ixeshe](https://attack.mitre.org/software/S0015) is a malware family that has been used since at least 2009 against targets in East Asia. (Citation: Moran 201…
S0016P2P ZeuS
Windows
[P2P ZeuS](https://attack.mitre.org/software/S0016) is a closed-source fork of the leaked version of the ZeuS botnet. It presents improvements over the leaked …
S0017BISCUIT
Windows
[BISCUIT](https://attack.mitre.org/software/S0017) is a backdoor that has been used by [APT1](https://attack.mitre.org/groups/G0006) since as early as 2007. (C…
S0018Sykipot
Windows
[Sykipot](https://attack.mitre.org/software/S0018) is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily …
S0019Regin
Windows
[Regin](https://attack.mitre.org/software/S0019) is a malware platform that has targeted victims in a range of industries, including telecom, government, and f…
S0020China Chopper
Windows
[China Chopper](https://attack.mitre.org/software/S0020) is a [Web Shell](https://attack.mitre.org/techniques/T1505/003) hosted on Web servers to provide acces…
S0021Derusbi
WindowsLinux
[Derusbi](https://attack.mitre.org/software/S0021) is malware used by multiple Chinese APT groups.(Citation: Novetta-Axiom)(Citation: ThreatConnect Anthem) Bot…
S0022Uroburos
LinuxWindowsmacOS
[Uroburos](https://attack.mitre.org/software/S0022) is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Se…
S0023CHOPSTICK
WindowsLinux
[CHOPSTICK](https://attack.mitre.org/software/S0023) is a malware family of modular backdoors used by [APT28](https://attack.mitre.org/groups/G0007). It has be…
S0024Dyre
Windows
[Dyre](https://attack.mitre.org/software/S0024) is a banking Trojan that has been used for financial gain. (Citation: Symantec Dyre June 2015)(Citation: Malw…
S0025CALENDAR
Windows
[CALENDAR](https://attack.mitre.org/software/S0025) is malware used by [APT1](https://attack.mitre.org/groups/G0006) that mimics legitimate Gmail Calendar traf…
S0026GLOOXMAIL
Windows
[GLOOXMAIL](https://attack.mitre.org/software/S0026) is malware used by [APT1](https://attack.mitre.org/groups/G0006) that mimics legitimate Jabber/XMPP traffi…
S0027Zeroaccess[Zeroaccess](https://attack.mitre.org/software/S0027) is a kernel-mode [Rootkit](https://attack.mitre.org/techniques/T1014) that attempts to add victims to the…
S0028SHIPSHAPE[SHIPSHAPE](https://attack.mitre.org/software/S0028) is malware developed by [APT30](https://attack.mitre.org/groups/G0013) that allows propagation and exfiltr…
S0029PsExec
Windows
[PsExec](https://attack.mitre.org/software/S0029) is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administ…
S0030Carbanak
Windows
[Carbanak](https://attack.mitre.org/software/S0030) is a full-featured, remote backdoor used by a group of the same name ([Carbanak](https://attack.mitre.org/g…
S0031BACKSPACE
Windows
[BACKSPACE](https://attack.mitre.org/software/S0031) is a backdoor used by [APT30](https://attack.mitre.org/groups/G0013) that dates back to at least 2005. (Ci…
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.