3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 3,001–3,050 of 3,719 · page 61 of 75

IDTitleSummary
S1065Woody RAT
Windows
[Woody RAT](https://attack.mitre.org/software/S1065) is a remote access trojan (RAT) that has been used since at least August 2021 against Russian organization…
S1066DarkTortilla
Windows
[DarkTortilla](https://attack.mitre.org/software/S1066) is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. […
S1068BlackCat
LinuxWindows
[BlackCat](https://attack.mitre.org/software/S1068) is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First obs…
S1070Black Basta
Windows
[Black Basta](https://attack.mitre.org/software/S1070) is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since…
S1071Rubeus
Windows
[Rubeus](https://attack.mitre.org/software/S1071) is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ra…
S1072Industroyer2
Field Controller/RTU/PLC/IEDEngineering Workstation
[Industroyer2](https://attack.mitre.org/software/S1072) is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol…
S1073Royal
Windows
[Royal](https://attack.mitre.org/software/S1073) is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed …
S1074ANDROMEDA
Windows
[ANDROMEDA](https://attack.mitre.org/software/S1074) is commodity malware that was widespread in the early 2010's and continues to be observed in infections ac…
S1075KOPILUWAK
Windows
[KOPILUWAK](https://attack.mitre.org/software/S1075) is a JavaScript-based reconnaissance tool that has been used for victim profiling and C2 since at least 20…
S1076QUIETCANARY
Windows
[QUIETCANARY](https://attack.mitre.org/software/S1076) is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data …
S1078RotaJakiro
Linux
[RotaJakiro](https://attack.mitre.org/software/S1078) is a 64-bit Linux backdoor used by [APT32](https://attack.mitre.org/groups/G0050). First seen in 2018, it…
S1081BADHATCH
Windows
[BADHATCH](https://attack.mitre.org/software/S1081) is a backdoor that has been utilized by [FIN8](https://attack.mitre.org/groups/G0061) since at least 2019. …
S1084QUIETEXIT
Network
[QUIETEXIT](https://attack.mitre.org/software/S1084) is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by […
S1085Sardonic
Windows
[Sardonic](https://attack.mitre.org/software/S1085) is a backdoor written in C and C++ that is known to be used by [FIN8](https://attack.mitre.org/groups/G0061…
S1086Snip3
Windows
[Snip3](https://attack.mitre.org/software/S1086) is a sophisticated crypter-as-a-service that has been used since at least 2021 to obfuscate and load numerous …
S1087AsyncRAT
Windows
[AsyncRAT](https://attack.mitre.org/software/S1087) is an open-source remote access tool originally available through the NYANxCAT Github repository that has b…
S1088Disco
Windows
[Disco](https://attack.mitre.org/software/S1088) is a custom implant that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1019) since at …
S1089SharpDisco
Windows
[SharpDisco](https://attack.mitre.org/software/S1089) is a dropper developed in C# that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1…
S1090NightClub
Windows
[NightClub](https://attack.mitre.org/software/S1090) is a modular implant written in C++ that has been used by [MoustachedBouncer](https://attack.mitre.org/gro…
S1091Pacu
IaaS
Pacu is an open-source AWS exploitation framework. The tool is written in Python and publicly available on GitHub.(Citation: GitHub Pacu) Documented platforms…
S9000Ngrok
Windows
Documented platforms: Windows. Catalogued in ATT&CK 14.1. 1 reference curated. Documented platforms: Windows. Catalogued in ATT&CK 14.1. 1 reference curated.
SABBATHSabbath
SADSADransomware
SADCOMPUTERSadComputerransomware
SADOGOSadogoransomware
SADSTORYSADStoryRansomware Variant of CryPy
SAFEPAYsafepaySafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code. Soon after launching, the group made a bi…
SAGE-2-0-RANSOMWARESage 2.0 RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. This ransomware attacks your MS Office by offering a Micro to help with your pr…
SAGE-2-2Sage 2.2Ransomware Sage 2.2 deletes volume snapshots through vssadmin.exe, disables startup repair, uses process wscript.exe to execute a VBScript, and coordinates the…
SAGE-RANSOMWARESage RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypt…
SAKULASakulaThe RAT, which according to compile timestamps first surfaced in November 2012, has been used in targeted intrusions through 2015. Sakula enables an adversary …
SALITYSalitySality is the classification for a family of malicious software (malware), which infects files on Microsoft Windows systems. Sality was first discovered in 200…
SALSASalsaransomware
SAMAS-SAMSAMSamas-SamsamRansomware Targeted attacks -Jexboss -PSExec -Hyena
SANCTIONSanctionRansomware Based on HiddenTear, but heavily modified keygen
SANCTIONSSanctionsRansomware
SANDRO-RATSandro RAT
SANTA-ENCRYPTORSanta Encryptorransomware
SARAMATSaramatransomware
SARANSOMSARansomransomware
SARCOMAsarcomaSarcoma is a ransomware group that emerged in October 2024 and has been actively targeting various organizations. Sarcoma's attack methods include phishing cam…
SARDONINIRSardoninirRansomware
SATAN-CRYPTOR-2-0Satan Cryptor 2.0ransomware
SATAN-RANSOMWARESatan RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. Its original name is RAAS RANSOMWARE. It is spread using email spam, fake updat…
SATAN-S-DOOM-CRYPTERSatan's Doom Crypterransomware
SATAN666-RANSOMWARESatan666 RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
SATANASatanaRansomware
SATANCDsatancd
SATANCRYPTOR-GOSatanCryptor Goransomware
SATANLOCKsatanlockConnected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages).
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.