3,697 indexed
SOFTWARESoftware & malware
3,697 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.
Showing 3,001–3,050 of 3,697 · page 61 of 74
| ID | Title | Summary |
|---|---|---|
| S1086 | Snip3 Windows | [Snip3](https://attack.mitre.org/software/S1086) is a sophisticated crypter-as-a-service that has been used since at least 2021 to obfuscate and load numerous … |
| S1087 | AsyncRAT Windows | [AsyncRAT](https://attack.mitre.org/software/S1087) is an open-source remote access tool originally available through the NYANxCAT Github repository that has b… |
| S1088 | Disco Windows | [Disco](https://attack.mitre.org/software/S1088) is a custom implant that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1019) since at … |
| S1089 | SharpDisco Windows | [SharpDisco](https://attack.mitre.org/software/S1089) is a dropper developed in C# that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1… |
| S1090 | NightClub Windows | [NightClub](https://attack.mitre.org/software/S1090) is a modular implant written in C++ that has been used by [MoustachedBouncer](https://attack.mitre.org/gro… |
| S1091 | Pacu IaaS | Pacu is an open-source AWS exploitation framework. The tool is written in Python and publicly available on GitHub.(Citation: GitHub Pacu) Documented platforms… |
| S9000 | Ngrok Windows | Documented platforms: Windows. Catalogued in ATT&CK 14.1. 1 reference curated. Documented platforms: Windows. Catalogued in ATT&CK 14.1. 1 reference curated. |
| SABBATH | Sabbath | |
| SAD | SAD | ransomware |
| SADCOMPUTER | SadComputer | ransomware |
| SADOGO | Sadogo | ransomware |
| SADSTORY | SADStory | Ransomware Variant of CryPy |
| SAFEPAY | safepay | SafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code. Soon after launching, the group made a bi… |
| SAGE-2-0-RANSOMWARE | Sage 2.0 Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. This ransomware attacks your MS Office by offering a Micro to help with your pr… |
| SAGE-2-2 | Sage 2.2 | Ransomware Sage 2.2 deletes volume snapshots through vssadmin.exe, disables startup repair, uses process wscript.exe to execute a VBScript, and coordinates the… |
| SAGE-RANSOMWARE | Sage Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypt… |
| SAKULA | Sakula | The RAT, which according to compile timestamps first surfaced in November 2012, has been used in targeted intrusions through 2015. Sakula enables an adversary … |
| SALITY | Sality | Sality is the classification for a family of malicious software (malware), which infects files on Microsoft Windows systems. Sality was first discovered in 200… |
| SALSA | Salsa | ransomware |
| SAMAS-SAMSAM | Samas-Samsam | Ransomware Targeted attacks -Jexboss -PSExec -Hyena |
| SANCTION | Sanction | Ransomware Based on HiddenTear, but heavily modified keygen |
| SANCTIONS | Sanctions | Ransomware |
| SANDRO-RAT | Sandro RAT | |
| SANTA-ENCRYPTOR | Santa Encryptor | ransomware |
| SARAMAT | Saramat | ransomware |
| SARANSOM | SARansom | ransomware |
| SARCOMA | sarcoma | Sarcoma is a ransomware group that emerged in October 2024 and has been actively targeting various organizations. Sarcoma's attack methods include phishing cam… |
| SARDONINIR | Sardoninir | Ransomware |
| SATAN-CRYPTOR-2-0 | Satan Cryptor 2.0 | ransomware |
| SATAN-RANSOMWARE | Satan Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. Its original name is RAAS RANSOMWARE. It is spread using email spam, fake updat… |
| SATAN-S-DOOM-CRYPTER | Satan's Doom Crypter | ransomware |
| SATAN666-RANSOMWARE | Satan666 Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp… |
| SATANA | Satana | Ransomware |
| SATANCD | satancd | |
| SATANCRYPTOR-GO | SatanCryptor Go | ransomware |
| SATANLOCK | satanlock | Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages). |
| SATHURBOT | Sathurbot | The trojan serves as a backdoor. It can be controlled remotely. |
| SATORI | Satori | According to a report Li shared with Bleeping Computer today, the Mirai Satori variant is quite different from all previous pure Mirai variants.Previous Mirai … |
| SATURN | Saturn | ransomware |
| SATYR | Satyr | ransomware |
| SAVEFILES | SAVEfiles | |
| SAVETHEQUEEN | SaveTheQueen | ransomware |
| SCAMMERLOCKER-HT | ScammerLocker HT | ransomware |
| SCAMMERLOCKER-PH | ScammerLocker Ph | ransomware |
| SCATTERBRAIN | Scatterbrain | ransomware |
| SCATTERED-LAPSUS-HUNTERS | scattered lapsus$ hunters | |
| SCHOOLBOYS | schoolboys | |
| SCHWARZE-SONNE-RAT | Schwarze-Sonne-RAT | |
| SCHWERER | Schwerer | ransomware |
| SCIERON | Scieron |