> ## Documentation Index
> Fetch the complete documentation index at: https://docs.binarly.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Malware Families Detection Reference

> Full reference of known malware families and threat actors covered by BTP

## Malware Families

BTP ships a default set of rules to detect malware samples from families listed here.

### Backdoors, RATs and implants

* ANEL (APT10)
* Agent.BTZ, Kazuar, Mosquito, RUAG malware (Turla)
* Ares, AresPYDoor
* Atharvan 3RAT, Agni, EasyRAT/JUPITER, Fipps (ELF), Grease2, LilithRAT, MagicRAT, SocksTroy, Validalpha (Andariel)
* BASICSTAR, NOKNOK, POWERLESS, POWERSTAR (CharmingCypress)
* Bifrose (ELF), BTSDoor, Gh0stTimes, Hipid, Kivars, PLEAD, SpiderRAT, TSCookie (BlackTech)
* BILDINGCAN, BTREE, Comebacker, Dtrack, Kaos, LCPDot, magicpoint, Torisma, ValeforBeta, VSingle (Lazarus)
* BLUELIGHT, DOLPHIN (North Korea)
* BOATBEAM
* BoomBox (APT29)
* BPFDoor and its controllers (Red Menshen)
* BRICKSTORM
* BRICKSTEAL
* CatchDNS
* CHAOS / CHAOS-RAT
* Chily / SunnyDay (Vice Society)
* COMPOOD
* DEEPDATA and its plugins
* DISGOMOJI / GOMOJI
* DOPLUGS
* Doraemon
* DevilsTongue (Candiru/SOURGUM)
* Emdivi
* Exaramel (Sandworm)
* FakeM
* FalseFont (Peach Sandstorm)
* Fysbis (Sofacy)
* FROSTRIFT
* GHOSTKNIFE, GHOSTSABER
* GIMMICK (Windows .NET and macOS)
* GobRAT
* gokcpdoor (Tick)
* GOLDBACKDOOR
* Gopuram
* GOVERSHELL
* GRIDTIDE
* GRIMBOLT
* HorseShell and sheel (Camaro Dragon router implants)
* INFINITERED
* JITTERLY (Linux ELF implant, Red Heron)
* LightSpy (Windows and macOS)
* LINE VIPER (Cisco ASA)
* LODEINFO
* MACMA
* MAYBEROBOT, YESROBOT
* Meterpreter (in-memory)
* MILDFROST
* Nimbus Manticore agent and stager (APT35/UNC1549)
* OnionDuke (APT29)
* OVERSTEP
* Pangolin8RAT
* PeerBlight
* PELdoor (Fortinet ELF backdoor)
* Plague (PAM backdoor)
* PLASMAGRID
* PLENET
* PUPYRAT
* RahadRAT, Trishul RAT (BangkokShell)
* Gh0stCringe (Indexsinas)
* SeaSpy
* SILENCELIFT
* SLAPSTICK, TinyShell (UNC2891)
* SNOWBASIN, SNOWBELT
* Speculoos (APT41)
* SpyGrace
* sqroot RAT and plugins
* StealthWorker
* STOCKSTAY: STOCKTRADER, STOCKMARKET, STOCKBROKER, configs, crypto containers
* STONEMITE
* SUNBURST
* SUPERSTOMP (JungleBamboo)
* SysrvBot
* TokyoX RAT
* TOUGHPROGRESS
* TriangleDB (Operation Triangulation)
* vboxuserRAT
* VEILEDSIGNAL
* Voldemort
* WAVESHAPER (v1 and v2 PowerShell)
* WellMess (APT29, ELF)
* WinDealer (LuoYu)
* xlogin
* ZinFoq

### Rootkits, bootkits and firmware implants

* Diamorphine (Linux LKM rootkit)
* DtSftDriver and its loader
* HP iLO firmware implant
* LinaDoor (Linux rootkit)
* PSKiller\_sys (Rook, Atom Silo)
* RayInitiator (GRUB bootkit on Cisco ASA)
* RegPhantom (kernel-mode rootkit)
* SIXZUT (ring-3 rootkit dropped by JITTERLY)
* Snake (Turla)
* UEFI bootkit heuristics: CR4.CET clearing, old EfiGuard variants, kernel API resolution by string hash, PEI-stage backdoor relocation

### Ransomware

* AGENDA / Qilin (Golang and Rust)
* Akira
* CLOP (sample and config-hash hunting)
* ESXi ransomware (ELF locker and scripts, Feb 2023)
* FIREFLAME
* FURYSTORM
* The Gentlemen (Storm-2697)
* Grief
* INC / Lynx
* LockBit 2.x, 3.0 (dropped file), 4.0 (packer and hashing), Linux/macOS
* MedusaLocker 3
* Megazord
* NimFilecoder
* PLAYCRYPT (Windows and Linux)
* Prestige
* RANSOMHUB
* REDBIKE
* SAFEPAY
* Venus

### Loaders, downloaders, droppers and launchers

* ABK, DALBOT (Tick)
* Amadey 5.34
* AtlasLoader and plugin
* BabbleLoader
* BACKORDER (Go)
* Backwash loader
* BADAUDIO
* BEATDROP, NativeZone (APT29)
* Bookworm dropper and shellcode
* CANONSTAGER
* CLEARSHORT
* COILHATCH
* CryptHunter / DangerousPassword JS and Python downloaders, HTTP bot, JokerSpy (macOS)
* DarkHotel downloaders (.NET, isyss)
* DECROK, FLIPFLOP (Cobalt Strike loader), FRESHFIRE
* DUSTPAN, POCOSTICK
* Flagpro, HeavyROT, HIPO, iam downloader, IconDown, SelfMake/SpiderPig loader (BlackTech)
* GOLDVEIN.JAVA
* GRIMPULL
* HUI Loader
* HYPERCALL
* IcedID loader
* INetGet
* JADESNOW
* Kimsuky VBS, PowerShell and .NET downloaders
* Korku loader (CharmingCypress)
* Lazarus boardid, npmLoader, OtterCookie, oprep.js, default.py, Thumbs.db loader
* NOROBOT
* PLUSBED, PLUSDROP
* PoohlyDown
* RestyLink, TRANSBOX, PLUGBOX (Dropbox API)
* ROKRAT Ruby loader
* SAGEGIFT, SAGELEAF, SAGEWAVE
* Sindoor decryptor and downloader (APT36)
* SNOWLIGHT
* SoupDealer Java loader
* SPINNER and loaders (TwistedPanda)
* STARKVEIL
* STATICPLUGIN
* STOCKSTAY.MARKETMAKER
* SUGARLOADER
* TEARDROP
* TokyoX loader
* Veletrix loader
* webrcs
* WebView2Loader
* BangkokShell DLL loaders, APT32 wwlib.dll sideloading, Russian-actor "bectrl" DLL sideloading

### Infostealers, keyloggers and data miners

* CHROMEPUSH, DEEPBREATH, GHOSTBLADE
* Chrome App-Bound Encryption decryptor DLL
* ClientUploader, AppStorage (CISA AR22-277A)
* DarkCloud Stealer
* DuckTail (compromised signing certs)
* HawkEye keylogger
* ICONIC (3CX)
* JamiStealer, Lazarus keylogger
* Katz Stealer and loader
* LOSTKEYS
* SharpExt, RELOADEXT, LONGTALE (malicious Chrome extensions)
* Stealc
* Vietnamese-actor Python infostealer chain
* Water Pamola JS and PHP stealers, EC-CUBE injection
* JScript credit card skimmer

### Cryptominers and botnets

* Indexsinas / Redosdru XMRig miner
* kittipongk cryptominer scripts
* SysrvBot
* SystemBC (Emotet module)

### Webshells

* Adminer 4.7, b374k, FilesMan, FoxWSO, ruoji, Spider PHP shell
* Behinder, Godzilla, reGeorg, RealCMD (Java/JSP)
* China Chopper-like ASPX (Hafnium)
* FluBot download-page webshell
* H4ntu shell
* ORANGETAIL (UTA0533), SPORTSBALL (Exchange), UPSTYLE (PAN-OS)
* P.A.S. webshell artifacts (Sandworm/Centreon)
* SLAYSTYLE
* Water Pamola webshells

### Wipers

* CaddyWiper
* DruidFly wiper (Iran)
* IsaacWiper
* KillDisk (BlackEnergy)
* WhisperGate

### Other

* ATM malware DispenserXFS
* AVBurner (EDR killer)
* Fake document/image utility adware-malware
* Ralord v1
* Unattributed samples: APT6, Unit78020, CloudHopper, http.exe (Danti), phishing payloads (Feb 2025), VT QA sample

### Offensive frameworks and hacktools

* 3proxy, frp (fast reverse proxy)
* BlueHammer / Nightmare-Eclipse (Windows LPE)
* Brute Ratel C4
* Cobalt Strike (beacon encoding, 4.5 sleep mask)
* CowTunnel, NATBypass
* CRASHPAD, DCSYNCER.SLICK, REALBREEZE
* Donut shellcode
* EDR-Freeze
* Edge saved-password dumper (.NET)
* K1.Morpher (.NET obfuscator, hunting)
* Khepri C2
* Lazarus SMB scanner, simple curl, exploit tools
* Discord C2 (bmdyy), pysoxy SOCKS5, reverse SSH (Fahrj)
* NimPackt
* PSAttack, Windows Credential Editor
* RedSun (LPE), Rotten Potato
* cmstp.exe UAC bypass (.NET)

## Threat actors

* Andariel
* APT10
* APT27
* APT29 (NOBELIUM)
* APT32 (OceanLotus)
* APT35 / CharmingCypress / Nimbus Manticore
* APT36
* APT41
* BlackEnergy
* BlackTech
* Camaro Dragon
* Candiru (SOURGUM)
* DarkHotel
* DruidFly
* Equation Group
* FIN7
* Hafnium
* JungleBamboo (SUPERSTOMP)
* Kimsuky
* Lazarus / AppleJeus / LazyPine
* Lotus Blossom
* LuoYu
* Peach Sandstorm
* Red Heron
* Red Menshen
* Sandworm
* SharpTongue / SharpPine
* SteelClover (PowerHarbor)
* Storm-2697
* Tick
* Turla
* TwistedPanda
* UNC1069
* UNC2891
* UNC4736
* UNC4841
* UNC5174
* UTA0388
* UTA0533
* Vice Society
* Water Pamola


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.