3,719 indexed

SOFTWARESoftware & malware

3,719 tools and malware families — MITRE ATT&CK Software plus the wider cs-graph malware corpus. Use /search for keyword + ID lookup. Authored by Adam Lundqvist.

Showing 351–400 of 3,719 · page 8 of 75

IDTitleSummary
BOOKWORMBookwormThreat actors have delivered Bookworm as a payload in attacks on targets in Thailand. Readers who are interested in this campaign should start with our first b…
BOOMBooMRansomware
BOOOAMCRYPTBoooamCryptRansomware
BOOYAHBooyahRansomware EXE was replaced to neutralize threat
BORIS-HTBoris HTRansomware
BOUNCERBOUNCERBOUNCER will load an extracted DLL into memory, and then will call the DLL's dump export. The dump export is called with the parameters passed via the command…
BOZOKBozokBozok, like many other popular RATs, is freely available. The author of the Bozok RAT goes by the moniker “Slayer616” and has created another RAT known as Schw…
BQTLOCKbqtlockaka BaqiyatLock
BR0K3Rbr0k3rBr0k3r is not a conventional ransomware gang, but rather an Iran-linked cyber espionage and access brokerage group leveraging its foothold within victim networ…
BRAIN-CIPHERbrain cipherIn mid-June 2024, a new ransomware operation named Brain Cipher emerged, notably targeting Indonesia's National Data Center. This attack disrupted immigration …
BRAIN-FOODBrain FoodBrain Food is usually the second step in a chain of redirections, its PHP code is polymorphic and obfuscated with multiple layers of base64 encoding. Backdoor …
BRAINCRYPT-RANSOMWAREBrainCrypt RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
BRAINLAGBrainLagRansomware
BRAMBULBrambulBrambul malware is a malicious Windows 32-bit SMB worm that functions as a service dynamic link library file or a portable executable file often dropped and in…
BRANSOMWAREBRansomwareRansomware
BRATBrat
BRAVEPRINCEBRAVEPRINCEBRAVEPRINCE is a C/C++ downloader. It uses the Daum email service to upload collected system information and download files. Availability: Public
BRAVOXbravox
BRAZILIANBrazilianRansomware Based on EDA2
BRAZILIAN-GLOBEBrazilian GlobeRansomware
BREDOLABBredoLabThe Bredolab botnet, also known by its alias Oficla, was a Russian botnet mostly involved in viral e-mail spam. Before the botnet was eventually dismantled in …
BRICKBrickRansomware
BRICKRBrickRRansomware
BRLOCKBrLockRansomware
BROTHERHOODbrotherhood
BROWLOCKBrowlockRansomware no local encryption, browser only
BRUSHALOADERBrushaloaderBrushaloader also leverages a combination of VBScript and PowerShell to create a Remote Access Trojan (RAT) that allows persistent command execution on infecte…
BTCAMANT-RANSOMWAREBTCamant RansomwareIt’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encryp…
BTCKINGBtcKINGRansomware
BTCLOCKER-RANSOMWAREBTCLocker RansomwareThis is most likely to affect English speaking users, since the note is written in English. English is understood worldwide, thus anyone can be harmed. The hac…
BTCWARE-ALETABTCWare-AletaRansomware
BTCWARE-GRYPHONBTCWare-GryphonRansomware
BTCWARE-MASTERBTCWare-MasterRansomware
BTCWARE-NUCLEARBTCWare-NuclearRansomware
BTCWARE-ONYONBTCWare-OnyonRansomware
BTCWARE-PAYDAYBTCWare-PayDayRansomware
BTCWARE-RELATED-TO-NEW-VERSION-OF-CRYPTXXXBTCWare Related to / new version of CryptXXXRansomware
BTCWARE-WYVERNBTCWare-WyvernRansomware
BUCBIBucbiRansomware no file name change, no extension
BUDBudRansomware
BUDDYRANSOMEbuddyransome
BUGJUICEBUGJUICEBUGJUICE is a backdoor that is executed by launching a benign file and then hijacking the search order to load a malicious dll into it. That malicious dll then…
BUGWAREBugWareRansomware
BULBACRYPT-HTBulbaCrypt HTRansomware
BUMBLEBEEBumbleBeeBumbleBee is a modular backdoor that comprises two applications, a server and a client application (a master and slaver application, respectively in the malwar…
BUNNYBunny
BURANBuranBuran is a new version of the Vega ransomware strain (a.k.a. Jamper, Ghost, Buhtrap) that attacked accountants from February through April 2019. The new Buran …
BUSHALOADERBushaloader
BUSHWALKBUSHWALKA mitigation bypass technique was recently identified that led to the deployment of a custom webshell tracked as BUSHWALK. Successful exploitation would bypass…
BUYUNLOCKCODEBuyUnlockCodeRansomware Does not delete Shadow Copies
Sourced from MITRE ATT&CK Software and allied malware catalogues. Curated by Adam Lundqvist, Founder at SQUR.