Malware Families
BTP ships a default set of rules to detect malware samples from families listed here.Backdoors, RATs and implants
- ANEL (APT10)
- Agent.BTZ, Kazuar, Mosquito, RUAG malware (Turla)
- Ares, AresPYDoor
- Atharvan 3RAT, Agni, EasyRAT/JUPITER, Fipps (ELF), Grease2, LilithRAT, MagicRAT, SocksTroy, Validalpha (Andariel)
- BASICSTAR, NOKNOK, POWERLESS, POWERSTAR (CharmingCypress)
- Bifrose (ELF), BTSDoor, Gh0stTimes, Hipid, Kivars, PLEAD, SpiderRAT, TSCookie (BlackTech)
- BILDINGCAN, BTREE, Comebacker, Dtrack, Kaos, LCPDot, magicpoint, Torisma, ValeforBeta, VSingle (Lazarus)
- BLUELIGHT, DOLPHIN (North Korea)
- BOATBEAM
- BoomBox (APT29)
- BPFDoor and its controllers (Red Menshen)
- BRICKSTORM
- BRICKSTEAL
- CatchDNS
- CHAOS / CHAOS-RAT
- Chily / SunnyDay (Vice Society)
- COMPOOD
- DEEPDATA and its plugins
- DISGOMOJI / GOMOJI
- DOPLUGS
- Doraemon
- DevilsTongue (Candiru/SOURGUM)
- Emdivi
- Exaramel (Sandworm)
- FakeM
- FalseFont (Peach Sandstorm)
- Fysbis (Sofacy)
- FROSTRIFT
- GHOSTKNIFE, GHOSTSABER
- GIMMICK (Windows .NET and macOS)
- GobRAT
- gokcpdoor (Tick)
- GOLDBACKDOOR
- Gopuram
- GOVERSHELL
- GRIDTIDE
- GRIMBOLT
- HorseShell and sheel (Camaro Dragon router implants)
- INFINITERED
- JITTERLY (Linux ELF implant, Red Heron)
- LightSpy (Windows and macOS)
- LINE VIPER (Cisco ASA)
- LODEINFO
- MACMA
- MAYBEROBOT, YESROBOT
- Meterpreter (in-memory)
- MILDFROST
- Nimbus Manticore agent and stager (APT35/UNC1549)
- OnionDuke (APT29)
- OVERSTEP
- Pangolin8RAT
- PeerBlight
- PELdoor (Fortinet ELF backdoor)
- Plague (PAM backdoor)
- PLASMAGRID
- PLENET
- PUPYRAT
- RahadRAT, Trishul RAT (BangkokShell)
- Gh0stCringe (Indexsinas)
- SeaSpy
- SILENCELIFT
- SLAPSTICK, TinyShell (UNC2891)
- SNOWBASIN, SNOWBELT
- Speculoos (APT41)
- SpyGrace
- sqroot RAT and plugins
- StealthWorker
- STOCKSTAY: STOCKTRADER, STOCKMARKET, STOCKBROKER, configs, crypto containers
- STONEMITE
- SUNBURST
- SUPERSTOMP (JungleBamboo)
- SysrvBot
- TokyoX RAT
- TOUGHPROGRESS
- TriangleDB (Operation Triangulation)
- vboxuserRAT
- VEILEDSIGNAL
- Voldemort
- WAVESHAPER (v1 and v2 PowerShell)
- WellMess (APT29, ELF)
- WinDealer (LuoYu)
- xlogin
- ZinFoq
Rootkits, bootkits and firmware implants
- Diamorphine (Linux LKM rootkit)
- DtSftDriver and its loader
- HP iLO firmware implant
- LinaDoor (Linux rootkit)
- PSKiller_sys (Rook, Atom Silo)
- RayInitiator (GRUB bootkit on Cisco ASA)
- RegPhantom (kernel-mode rootkit)
- SIXZUT (ring-3 rootkit dropped by JITTERLY)
- Snake (Turla)
- UEFI bootkit heuristics: CR4.CET clearing, old EfiGuard variants, kernel API resolution by string hash, PEI-stage backdoor relocation
Ransomware
- AGENDA / Qilin (Golang and Rust)
- Akira
- CLOP (sample and config-hash hunting)
- ESXi ransomware (ELF locker and scripts, Feb 2023)
- FIREFLAME
- FURYSTORM
- The Gentlemen (Storm-2697)
- Grief
- INC / Lynx
- LockBit 2.x, 3.0 (dropped file), 4.0 (packer and hashing), Linux/macOS
- MedusaLocker 3
- Megazord
- NimFilecoder
- PLAYCRYPT (Windows and Linux)
- Prestige
- RANSOMHUB
- REDBIKE
- SAFEPAY
- Venus
Loaders, downloaders, droppers and launchers
- ABK, DALBOT (Tick)
- Amadey 5.34
- AtlasLoader and plugin
- BabbleLoader
- BACKORDER (Go)
- Backwash loader
- BADAUDIO
- BEATDROP, NativeZone (APT29)
- Bookworm dropper and shellcode
- CANONSTAGER
- CLEARSHORT
- COILHATCH
- CryptHunter / DangerousPassword JS and Python downloaders, HTTP bot, JokerSpy (macOS)
- DarkHotel downloaders (.NET, isyss)
- DECROK, FLIPFLOP (Cobalt Strike loader), FRESHFIRE
- DUSTPAN, POCOSTICK
- Flagpro, HeavyROT, HIPO, iam downloader, IconDown, SelfMake/SpiderPig loader (BlackTech)
- GOLDVEIN.JAVA
- GRIMPULL
- HUI Loader
- HYPERCALL
- IcedID loader
- INetGet
- JADESNOW
- Kimsuky VBS, PowerShell and .NET downloaders
- Korku loader (CharmingCypress)
- Lazarus boardid, npmLoader, OtterCookie, oprep.js, default.py, Thumbs.db loader
- NOROBOT
- PLUSBED, PLUSDROP
- PoohlyDown
- RestyLink, TRANSBOX, PLUGBOX (Dropbox API)
- ROKRAT Ruby loader
- SAGEGIFT, SAGELEAF, SAGEWAVE
- Sindoor decryptor and downloader (APT36)
- SNOWLIGHT
- SoupDealer Java loader
- SPINNER and loaders (TwistedPanda)
- STARKVEIL
- STATICPLUGIN
- STOCKSTAY.MARKETMAKER
- SUGARLOADER
- TEARDROP
- TokyoX loader
- Veletrix loader
- webrcs
- WebView2Loader
- BangkokShell DLL loaders, APT32 wwlib.dll sideloading, Russian-actor “bectrl” DLL sideloading
Infostealers, keyloggers and data miners
- CHROMEPUSH, DEEPBREATH, GHOSTBLADE
- Chrome App-Bound Encryption decryptor DLL
- ClientUploader, AppStorage (CISA AR22-277A)
- DarkCloud Stealer
- DuckTail (compromised signing certs)
- HawkEye keylogger
- ICONIC (3CX)
- JamiStealer, Lazarus keylogger
- Katz Stealer and loader
- LOSTKEYS
- SharpExt, RELOADEXT, LONGTALE (malicious Chrome extensions)
- Stealc
- Vietnamese-actor Python infostealer chain
- Water Pamola JS and PHP stealers, EC-CUBE injection
- JScript credit card skimmer
Cryptominers and botnets
- Indexsinas / Redosdru XMRig miner
- kittipongk cryptominer scripts
- SysrvBot
- SystemBC (Emotet module)
Webshells
- Adminer 4.7, b374k, FilesMan, FoxWSO, ruoji, Spider PHP shell
- Behinder, Godzilla, reGeorg, RealCMD (Java/JSP)
- China Chopper-like ASPX (Hafnium)
- FluBot download-page webshell
- H4ntu shell
- ORANGETAIL (UTA0533), SPORTSBALL (Exchange), UPSTYLE (PAN-OS)
- P.A.S. webshell artifacts (Sandworm/Centreon)
- SLAYSTYLE
- Water Pamola webshells
Wipers
- CaddyWiper
- DruidFly wiper (Iran)
- IsaacWiper
- KillDisk (BlackEnergy)
- WhisperGate
Other
- ATM malware DispenserXFS
- AVBurner (EDR killer)
- Fake document/image utility adware-malware
- Ralord v1
- Unattributed samples: APT6, Unit78020, CloudHopper, http.exe (Danti), phishing payloads (Feb 2025), VT QA sample
Offensive frameworks and hacktools
- 3proxy, frp (fast reverse proxy)
- BlueHammer / Nightmare-Eclipse (Windows LPE)
- Brute Ratel C4
- Cobalt Strike (beacon encoding, 4.5 sleep mask)
- CowTunnel, NATBypass
- CRASHPAD, DCSYNCER.SLICK, REALBREEZE
- Donut shellcode
- EDR-Freeze
- Edge saved-password dumper (.NET)
- K1.Morpher (.NET obfuscator, hunting)
- Khepri C2
- Lazarus SMB scanner, simple curl, exploit tools
- Discord C2 (bmdyy), pysoxy SOCKS5, reverse SSH (Fahrj)
- NimPackt
- PSAttack, Windows Credential Editor
- RedSun (LPE), Rotten Potato
- cmstp.exe UAC bypass (.NET)
Threat actors
- Andariel
- APT10
- APT27
- APT29 (NOBELIUM)
- APT32 (OceanLotus)
- APT35 / CharmingCypress / Nimbus Manticore
- APT36
- APT41
- BlackEnergy
- BlackTech
- Camaro Dragon
- Candiru (SOURGUM)
- DarkHotel
- DruidFly
- Equation Group
- FIN7
- Hafnium
- JungleBamboo (SUPERSTOMP)
- Kimsuky
- Lazarus / AppleJeus / LazyPine
- Lotus Blossom
- LuoYu
- Peach Sandstorm
- Red Heron
- Red Menshen
- Sandworm
- SharpTongue / SharpPine
- SteelClover (PowerHarbor)
- Storm-2697
- Tick
- Turla
- TwistedPanda
- UNC1069
- UNC2891
- UNC4736
- UNC4841
- UNC5174
- UTA0388
- UTA0533
- Vice Society
- Water Pamola