3,719 indexed
SOFTWARESoftware & malware
3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.
Showing 2,351–2,400 of 3,719 · page 48 of 75
| ID | Title | Summary |
|---|---|---|
| RSAUTIL | RSAUtil | RSAUtil is distributed by the developer hacking into remote desktop services and uploading a package of files. This package contains a variety of tools, a conf… |
| RTM-LOCKER | rtm locker | |
| RUBELLA-MACRO-BUILDER | Rubella Macro Builder | A crimeware kit dubbed the Rubella Macro Builder has recently been gaining popularity among members of a top-tier Russian hacking forum. Despite being relative… |
| RUBY | Ruby | ransomware |
| RUCKGUV | Ruckguv | |
| RUHAPPY | RUHAPPY | RUHAPPY is a destructive wiper tool seen on systems targeted by DOGCALL. It attempts to overwrite the MBR, causing the system not to boot. When victims' system… |
| RUN-SOME-WARES | run some wares | |
| RUNEXEMEMORY | RunExeMemory | ransomware |
| RUNSOMEWERE | Runsomewere | Ransomware Based on HT/EDA2 Utilizes the Jigsaw Ransomware background |
| RURKTAR | Rurktar | Dubbed Rurktar, the tool hasn’t had all of its functionality implemented yet, but G DATA says “it is relatively safe to say [it] is intended for use in targete… |
| RUSH | Rush | ransomware |
| RUSSENGER | Russenger | ransomware |
| RUSSIAN-EDA2 | Russian EDA2 | ransomware |
| RUSSIAN-GLOBE-RANSOMWARE | Russian Globe Ransomware | This is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac… |
| RUSSIANROULETTE | RussianRoulette | Ransomware Variant of the Philadelphia ransomware |
| RUSTOCK | Rustock | |
| RUSTYLOCKER | rustylocker | |
| RWX-RAT | RWX RAT | |
| RYUK-RANSOMWARE | Ryuk ransomware | Similar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments. Code comparison between versions of Ryuk and Hermes ransomware ind… |
| S0001 | Trojan.Mebromi Windows | [Trojan.Mebromi](https://attack.mitre.org/software/S0001) is BIOS-level malware that takes control of the victim before MBR. (Citation: Ge 2011) Documented pl… |
| S0002 | Mimikatz Windows | [Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many… |
| S0003 | RIPTIDE Windows | [RIPTIDE](https://attack.mitre.org/software/S0003) is a proxy-aware backdoor used by [APT12](https://attack.mitre.org/groups/G0005). (Citation: Moran 2014) Do… |
| S0004 | TinyZBot Windows | [TinyZBot](https://attack.mitre.org/software/S0004) is a bot written in C# that was developed by [Cleaver](https://attack.mitre.org/groups/G0003). (Citation: C… |
| S0005 | Windows Credential Editor Windows | [Windows Credential Editor](https://attack.mitre.org/software/S0005) is a password dumping tool. (Citation: Amplia WCE) Documented platforms: Windows. Catalog… |
| S0006 | pwdump Windows | [pwdump](https://attack.mitre.org/software/S0006) is a credential dumper. (Citation: Wikipedia pwdump) Documented platforms: Windows. Catalogued in ATT&CK 14.… |
| S0007 | Skeleton Key Windows | [Skeleton Key](https://attack.mitre.org/software/S0007) is malware used to inject false credentials into domain controllers with the intent of creating a backd… |
| S0008 | gsecdump Windows | [gsecdump](https://attack.mitre.org/software/S0008) is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows opera… |
| S0009 | Hikit Windows | [Hikit](https://attack.mitre.org/software/S0009) is malware that has been used by [Axiom](https://attack.mitre.org/groups/G0001) for late-stage persistence and… |
| S0010 | Lurid Windows | [Lurid](https://attack.mitre.org/software/S0010) is a malware family that has been used by several groups, including [PittyTiger](https://attack.mitre.org/grou… |
| S0011 | Taidoor Windows | [Taidoor](https://attack.mitre.org/software/S0011) is a remote access trojan (RAT) that has been used by Chinese government cyber actors to maintain access on … |
| S0012 | PoisonIvy Windows | [PoisonIvy](https://attack.mitre.org/software/S0012) is a popular remote access tool (RAT) that has been used by many groups.(Citation: FireEye Poison Ivy)(Cit… |
| S0013 | PlugX Windows | [PlugX](https://attack.mitre.org/software/S0013) is a remote access tool (RAT) with modular plugins that has been used by multiple threat groups.(Citation: Las… |
| S0014 | BS2005 Windows | [BS2005](https://attack.mitre.org/software/S0014) is malware that was used by [Ke3chang](https://attack.mitre.org/groups/G0004) in spearphishing campaigns sinc… |
| S0015 | Ixeshe Windows | [Ixeshe](https://attack.mitre.org/software/S0015) is a malware family that has been used since at least 2009 against targets in East Asia. (Citation: Moran 201… |
| S0016 | P2P ZeuS Windows | [P2P ZeuS](https://attack.mitre.org/software/S0016) is a closed-source fork of the leaked version of the ZeuS botnet. It presents improvements over the leaked … |
| S0017 | BISCUIT Windows | [BISCUIT](https://attack.mitre.org/software/S0017) is a backdoor that has been used by [APT1](https://attack.mitre.org/groups/G0006) since as early as 2007. (C… |
| S0018 | Sykipot Windows | [Sykipot](https://attack.mitre.org/software/S0018) is malware that has been used in spearphishing campaigns since approximately 2007 against victims primarily … |
| S0019 | Regin Windows | [Regin](https://attack.mitre.org/software/S0019) is a malware platform that has targeted victims in a range of industries, including telecom, government, and f… |
| S0020 | China Chopper Windows | [China Chopper](https://attack.mitre.org/software/S0020) is a [Web Shell](https://attack.mitre.org/techniques/T1505/003) hosted on Web servers to provide acces… |
| S0021 | Derusbi WindowsLinux | [Derusbi](https://attack.mitre.org/software/S0021) is malware used by multiple Chinese APT groups.(Citation: Novetta-Axiom)(Citation: ThreatConnect Anthem) Bot… |
| S0022 | Uroburos LinuxWindowsmacOS | [Uroburos](https://attack.mitre.org/software/S0022) is a sophisticated cyber espionage tool written in C that has been used by units within Russia's Federal Se… |
| S0023 | CHOPSTICK WindowsLinux | [CHOPSTICK](https://attack.mitre.org/software/S0023) is a malware family of modular backdoors used by [APT28](https://attack.mitre.org/groups/G0007). It has be… |
| S0024 | Dyre Windows | [Dyre](https://attack.mitre.org/software/S0024) is a banking Trojan that has been used for financial gain. (Citation: Symantec Dyre June 2015)(Citation: Malw… |
| S0025 | CALENDAR Windows | [CALENDAR](https://attack.mitre.org/software/S0025) is malware used by [APT1](https://attack.mitre.org/groups/G0006) that mimics legitimate Gmail Calendar traf… |
| S0026 | GLOOXMAIL Windows | [GLOOXMAIL](https://attack.mitre.org/software/S0026) is malware used by [APT1](https://attack.mitre.org/groups/G0006) that mimics legitimate Jabber/XMPP traffi… |
| S0027 | Zeroaccess | [Zeroaccess](https://attack.mitre.org/software/S0027) is a kernel-mode [Rootkit](https://attack.mitre.org/techniques/T1014) that attempts to add victims to the… |
| S0028 | SHIPSHAPE | [SHIPSHAPE](https://attack.mitre.org/software/S0028) is malware developed by [APT30](https://attack.mitre.org/groups/G0013) that allows propagation and exfiltr… |
| S0029 | PsExec Windows | [PsExec](https://attack.mitre.org/software/S0029) is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administ… |
| S0030 | Carbanak Windows | [Carbanak](https://attack.mitre.org/software/S0030) is a full-featured, remote backdoor used by a group of the same name ([Carbanak](https://attack.mitre.org/g… |
| S0031 | BACKSPACE Windows | [BACKSPACE](https://attack.mitre.org/software/S0031) is a backdoor used by [APT30](https://attack.mitre.org/groups/G0013) that dates back to at least 2005. (Ci… |