3,719 indexed
SOFTWARESoftware & malware
3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.
Showing 3,001–3,050 of 3,719 · page 61 of 75
| ID | Title | Summary |
|---|---|---|
| S1065 | Woody RAT Windows | [Woody RAT](https://attack.mitre.org/software/S1065) is a remote access trojan (RAT) that has been used since at least August 2021 against Russian organization… |
| S1066 | DarkTortilla Windows | [DarkTortilla](https://attack.mitre.org/software/S1066) is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. [… |
| S1068 | BlackCat LinuxWindows | [BlackCat](https://attack.mitre.org/software/S1068) is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First obs… |
| S1070 | Black Basta Windows | [Black Basta](https://attack.mitre.org/software/S1070) is ransomware written in C++ that has been offered within the ransomware-as-a-service (RaaS) model since… |
| S1071 | Rubeus Windows | [Rubeus](https://attack.mitre.org/software/S1071) is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ra… |
| S1072 | Industroyer2 Field Controller/RTU/PLC/IEDEngineering Workstation | [Industroyer2](https://attack.mitre.org/software/S1072) is a compiled and static piece of malware that has the ability to communicate over the IEC-104 protocol… |
| S1073 | Royal Windows | [Royal](https://attack.mitre.org/software/S1073) is ransomware that first appeared in early 2022; a version that also targets ESXi servers was later observed … |
| S1074 | ANDROMEDA Windows | [ANDROMEDA](https://attack.mitre.org/software/S1074) is commodity malware that was widespread in the early 2010's and continues to be observed in infections ac… |
| S1075 | KOPILUWAK Windows | [KOPILUWAK](https://attack.mitre.org/software/S1075) is a JavaScript-based reconnaissance tool that has been used for victim profiling and C2 since at least 20… |
| S1076 | QUIETCANARY Windows | [QUIETCANARY](https://attack.mitre.org/software/S1076) is a backdoor tool written in .NET that has been used since at least 2022 to gather and exfiltrate data … |
| S1078 | RotaJakiro Linux | [RotaJakiro](https://attack.mitre.org/software/S1078) is a 64-bit Linux backdoor used by [APT32](https://attack.mitre.org/groups/G0050). First seen in 2018, it… |
| S1081 | BADHATCH Windows | [BADHATCH](https://attack.mitre.org/software/S1081) is a backdoor that has been utilized by [FIN8](https://attack.mitre.org/groups/G0061) since at least 2019. … |
| S1084 | QUIETEXIT Network | [QUIETEXIT](https://attack.mitre.org/software/S1084) is a novel backdoor, based on the open-source Dropbear SSH client-server software, that has been used by [… |
| S1085 | Sardonic Windows | [Sardonic](https://attack.mitre.org/software/S1085) is a backdoor written in C and C++ that is known to be used by [FIN8](https://attack.mitre.org/groups/G0061… |
| S1086 | Snip3 Windows | [Snip3](https://attack.mitre.org/software/S1086) is a sophisticated crypter-as-a-service that has been used since at least 2021 to obfuscate and load numerous … |
| S1087 | AsyncRAT Windows | [AsyncRAT](https://attack.mitre.org/software/S1087) is an open-source remote access tool originally available through the NYANxCAT Github repository that has b… |
| S1088 | Disco Windows | [Disco](https://attack.mitre.org/software/S1088) is a custom implant that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1019) since at … |
| S1089 | SharpDisco Windows | [SharpDisco](https://attack.mitre.org/software/S1089) is a dropper developed in C# that has been used by [MoustachedBouncer](https://attack.mitre.org/groups/G1… |
| S1090 | NightClub Windows | [NightClub](https://attack.mitre.org/software/S1090) is a modular implant written in C++ that has been used by [MoustachedBouncer](https://attack.mitre.org/gro… |
| S1091 | Pacu IaaS | Pacu is an open-source AWS exploitation framework. The tool is written in Python and publicly available on GitHub.(Citation: GitHub Pacu) Documented platforms… |
| S9000 | Ngrok Windows | Documented platforms: Windows. Catalogued in ATT&CK 14.1. 1 reference curated. Documented platforms: Windows. Catalogued in ATT&CK 14.1. 1 reference curated. |
| SABBATH | Sabbath | |
| SAD | SAD | ransomware |
| SADCOMPUTER | SadComputer | ransomware |
| SADOGO | Sadogo | ransomware |
| SADSTORY | SADStory | Ransomware Variant of CryPy |
| SAFEPAY | safepay | SafePay ransomware started in October 2024 as a new ransomware service, using some of the leaked LockBit source code. Soon after launching, the group made a bi… |
| SAGE-2-0-RANSOMWARE | Sage 2.0 Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. This ransomware attacks your MS Office by offering a Micro to help with your pr… |
| SAGE-2-2 | Sage 2.2 | Ransomware Sage 2.2 deletes volume snapshots through vssadmin.exe, disables startup repair, uses process wscript.exe to execute a VBScript, and coordinates the… |
| SAGE-RANSOMWARE | Sage Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypt… |
| SAKULA | Sakula | The RAT, which according to compile timestamps first surfaced in November 2012, has been used in targeted intrusions through 2015. Sakula enables an adversary … |
| SALITY | Sality | Sality is the classification for a family of malicious software (malware), which infects files on Microsoft Windows systems. Sality was first discovered in 200… |
| SALSA | Salsa | ransomware |
| SAMAS-SAMSAM | Samas-Samsam | Ransomware Targeted attacks -Jexboss -PSExec -Hyena |
| SANCTION | Sanction | Ransomware Based on HiddenTear, but heavily modified keygen |
| SANCTIONS | Sanctions | Ransomware |
| SANDRO-RAT | Sandro RAT | |
| SANTA-ENCRYPTOR | Santa Encryptor | ransomware |
| SARAMAT | Saramat | ransomware |
| SARANSOM | SARansom | ransomware |
| SARCOMA | sarcoma | Sarcoma is a ransomware group that emerged in October 2024 and has been actively targeting various organizations. Sarcoma's attack methods include phishing cam… |
| SARDONINIR | Sardoninir | Ransomware |
| SATAN-CRYPTOR-2-0 | Satan Cryptor 2.0 | ransomware |
| SATAN-RANSOMWARE | Satan Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. Its original name is RAAS RANSOMWARE. It is spread using email spam, fake updat… |
| SATAN-S-DOOM-CRYPTER | Satan's Doom Crypter | ransomware |
| SATAN666-RANSOMWARE | Satan666 Ransomware | It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp… |
| SATANA | Satana | Ransomware |
| SATANCD | satancd | |
| SATANCRYPTOR-GO | SatanCryptor Go | ransomware |
| SATANLOCK | satanlock | Connected to GD Lockersec and Babuk-Bjorka. <br/> <br/>Group is aka SalanLock (from typo on victim pages). |