Skip to main content

Malware Families

BTP ships a default set of rules to detect malware samples from families listed here.

Backdoors, RATs and implants

  • ANEL (APT10)
  • Agent.BTZ, Kazuar, Mosquito, RUAG malware (Turla)
  • Ares, AresPYDoor
  • Atharvan 3RAT, Agni, EasyRAT/JUPITER, Fipps (ELF), Grease2, LilithRAT, MagicRAT, SocksTroy, Validalpha (Andariel)
  • BASICSTAR, NOKNOK, POWERLESS, POWERSTAR (CharmingCypress)
  • Bifrose (ELF), BTSDoor, Gh0stTimes, Hipid, Kivars, PLEAD, SpiderRAT, TSCookie (BlackTech)
  • BILDINGCAN, BTREE, Comebacker, Dtrack, Kaos, LCPDot, magicpoint, Torisma, ValeforBeta, VSingle (Lazarus)
  • BLUELIGHT, DOLPHIN (North Korea)
  • BOATBEAM
  • BoomBox (APT29)
  • BPFDoor and its controllers (Red Menshen)
  • BRICKSTORM
  • BRICKSTEAL
  • CatchDNS
  • CHAOS / CHAOS-RAT
  • Chily / SunnyDay (Vice Society)
  • COMPOOD
  • DEEPDATA and its plugins
  • DISGOMOJI / GOMOJI
  • DOPLUGS
  • Doraemon
  • DevilsTongue (Candiru/SOURGUM)
  • Emdivi
  • Exaramel (Sandworm)
  • FakeM
  • FalseFont (Peach Sandstorm)
  • Fysbis (Sofacy)
  • FROSTRIFT
  • GHOSTKNIFE, GHOSTSABER
  • GIMMICK (Windows .NET and macOS)
  • GobRAT
  • gokcpdoor (Tick)
  • GOLDBACKDOOR
  • Gopuram
  • GOVERSHELL
  • GRIDTIDE
  • GRIMBOLT
  • HorseShell and sheel (Camaro Dragon router implants)
  • INFINITERED
  • JITTERLY (Linux ELF implant, Red Heron)
  • LightSpy (Windows and macOS)
  • LINE VIPER (Cisco ASA)
  • LODEINFO
  • MACMA
  • MAYBEROBOT, YESROBOT
  • Meterpreter (in-memory)
  • MILDFROST
  • Nimbus Manticore agent and stager (APT35/UNC1549)
  • OnionDuke (APT29)
  • OVERSTEP
  • Pangolin8RAT
  • PeerBlight
  • PELdoor (Fortinet ELF backdoor)
  • Plague (PAM backdoor)
  • PLASMAGRID
  • PLENET
  • PUPYRAT
  • RahadRAT, Trishul RAT (BangkokShell)
  • Gh0stCringe (Indexsinas)
  • SeaSpy
  • SILENCELIFT
  • SLAPSTICK, TinyShell (UNC2891)
  • SNOWBASIN, SNOWBELT
  • Speculoos (APT41)
  • SpyGrace
  • sqroot RAT and plugins
  • StealthWorker
  • STOCKSTAY: STOCKTRADER, STOCKMARKET, STOCKBROKER, configs, crypto containers
  • STONEMITE
  • SUNBURST
  • SUPERSTOMP (JungleBamboo)
  • SysrvBot
  • TokyoX RAT
  • TOUGHPROGRESS
  • TriangleDB (Operation Triangulation)
  • vboxuserRAT
  • VEILEDSIGNAL
  • Voldemort
  • WAVESHAPER (v1 and v2 PowerShell)
  • WellMess (APT29, ELF)
  • WinDealer (LuoYu)
  • xlogin
  • ZinFoq

Rootkits, bootkits and firmware implants

  • Diamorphine (Linux LKM rootkit)
  • DtSftDriver and its loader
  • HP iLO firmware implant
  • LinaDoor (Linux rootkit)
  • PSKiller_sys (Rook, Atom Silo)
  • RayInitiator (GRUB bootkit on Cisco ASA)
  • RegPhantom (kernel-mode rootkit)
  • SIXZUT (ring-3 rootkit dropped by JITTERLY)
  • Snake (Turla)
  • UEFI bootkit heuristics: CR4.CET clearing, old EfiGuard variants, kernel API resolution by string hash, PEI-stage backdoor relocation

Ransomware

  • AGENDA / Qilin (Golang and Rust)
  • Akira
  • CLOP (sample and config-hash hunting)
  • ESXi ransomware (ELF locker and scripts, Feb 2023)
  • FIREFLAME
  • FURYSTORM
  • The Gentlemen (Storm-2697)
  • Grief
  • INC / Lynx
  • LockBit 2.x, 3.0 (dropped file), 4.0 (packer and hashing), Linux/macOS
  • MedusaLocker 3
  • Megazord
  • NimFilecoder
  • PLAYCRYPT (Windows and Linux)
  • Prestige
  • RANSOMHUB
  • REDBIKE
  • SAFEPAY
  • Venus

Loaders, downloaders, droppers and launchers

  • ABK, DALBOT (Tick)
  • Amadey 5.34
  • AtlasLoader and plugin
  • BabbleLoader
  • BACKORDER (Go)
  • Backwash loader
  • BADAUDIO
  • BEATDROP, NativeZone (APT29)
  • Bookworm dropper and shellcode
  • CANONSTAGER
  • CLEARSHORT
  • COILHATCH
  • CryptHunter / DangerousPassword JS and Python downloaders, HTTP bot, JokerSpy (macOS)
  • DarkHotel downloaders (.NET, isyss)
  • DECROK, FLIPFLOP (Cobalt Strike loader), FRESHFIRE
  • DUSTPAN, POCOSTICK
  • Flagpro, HeavyROT, HIPO, iam downloader, IconDown, SelfMake/SpiderPig loader (BlackTech)
  • GOLDVEIN.JAVA
  • GRIMPULL
  • HUI Loader
  • HYPERCALL
  • IcedID loader
  • INetGet
  • JADESNOW
  • Kimsuky VBS, PowerShell and .NET downloaders
  • Korku loader (CharmingCypress)
  • Lazarus boardid, npmLoader, OtterCookie, oprep.js, default.py, Thumbs.db loader
  • NOROBOT
  • PLUSBED, PLUSDROP
  • PoohlyDown
  • RestyLink, TRANSBOX, PLUGBOX (Dropbox API)
  • ROKRAT Ruby loader
  • SAGEGIFT, SAGELEAF, SAGEWAVE
  • Sindoor decryptor and downloader (APT36)
  • SNOWLIGHT
  • SoupDealer Java loader
  • SPINNER and loaders (TwistedPanda)
  • STARKVEIL
  • STATICPLUGIN
  • STOCKSTAY.MARKETMAKER
  • SUGARLOADER
  • TEARDROP
  • TokyoX loader
  • Veletrix loader
  • webrcs
  • WebView2Loader
  • BangkokShell DLL loaders, APT32 wwlib.dll sideloading, Russian-actor “bectrl” DLL sideloading

Infostealers, keyloggers and data miners

  • CHROMEPUSH, DEEPBREATH, GHOSTBLADE
  • Chrome App-Bound Encryption decryptor DLL
  • ClientUploader, AppStorage (CISA AR22-277A)
  • DarkCloud Stealer
  • DuckTail (compromised signing certs)
  • HawkEye keylogger
  • ICONIC (3CX)
  • JamiStealer, Lazarus keylogger
  • Katz Stealer and loader
  • LOSTKEYS
  • SharpExt, RELOADEXT, LONGTALE (malicious Chrome extensions)
  • Stealc
  • Vietnamese-actor Python infostealer chain
  • Water Pamola JS and PHP stealers, EC-CUBE injection
  • JScript credit card skimmer

Cryptominers and botnets

  • Indexsinas / Redosdru XMRig miner
  • kittipongk cryptominer scripts
  • SysrvBot
  • SystemBC (Emotet module)

Webshells

  • Adminer 4.7, b374k, FilesMan, FoxWSO, ruoji, Spider PHP shell
  • Behinder, Godzilla, reGeorg, RealCMD (Java/JSP)
  • China Chopper-like ASPX (Hafnium)
  • FluBot download-page webshell
  • H4ntu shell
  • ORANGETAIL (UTA0533), SPORTSBALL (Exchange), UPSTYLE (PAN-OS)
  • P.A.S. webshell artifacts (Sandworm/Centreon)
  • SLAYSTYLE
  • Water Pamola webshells

Wipers

  • CaddyWiper
  • DruidFly wiper (Iran)
  • IsaacWiper
  • KillDisk (BlackEnergy)
  • WhisperGate

Other

  • ATM malware DispenserXFS
  • AVBurner (EDR killer)
  • Fake document/image utility adware-malware
  • Ralord v1
  • Unattributed samples: APT6, Unit78020, CloudHopper, http.exe (Danti), phishing payloads (Feb 2025), VT QA sample

Offensive frameworks and hacktools

  • 3proxy, frp (fast reverse proxy)
  • BlueHammer / Nightmare-Eclipse (Windows LPE)
  • Brute Ratel C4
  • Cobalt Strike (beacon encoding, 4.5 sleep mask)
  • CowTunnel, NATBypass
  • CRASHPAD, DCSYNCER.SLICK, REALBREEZE
  • Donut shellcode
  • EDR-Freeze
  • Edge saved-password dumper (.NET)
  • K1.Morpher (.NET obfuscator, hunting)
  • Khepri C2
  • Lazarus SMB scanner, simple curl, exploit tools
  • Discord C2 (bmdyy), pysoxy SOCKS5, reverse SSH (Fahrj)
  • NimPackt
  • PSAttack, Windows Credential Editor
  • RedSun (LPE), Rotten Potato
  • cmstp.exe UAC bypass (.NET)

Threat actors

  • Andariel
  • APT10
  • APT27
  • APT29 (NOBELIUM)
  • APT32 (OceanLotus)
  • APT35 / CharmingCypress / Nimbus Manticore
  • APT36
  • APT41
  • BlackEnergy
  • BlackTech
  • Camaro Dragon
  • Candiru (SOURGUM)
  • DarkHotel
  • DruidFly
  • Equation Group
  • FIN7
  • Hafnium
  • JungleBamboo (SUPERSTOMP)
  • Kimsuky
  • Lazarus / AppleJeus / LazyPine
  • Lotus Blossom
  • LuoYu
  • Peach Sandstorm
  • Red Heron
  • Red Menshen
  • Sandworm
  • SharpTongue / SharpPine
  • SteelClover (PowerHarbor)
  • Storm-2697
  • Tick
  • Turla
  • TwistedPanda
  • UNC1069
  • UNC2891
  • UNC4736
  • UNC4841
  • UNC5174
  • UTA0388
  • UTA0533
  • Vice Society
  • Water Pamola