Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
Pegasus is a mercenary mobile spyware platform developed by NSO Group and marketed to government intelligence and law-enforcement customers. It has been repeatedly associated with surveillance of journalists, activists, dissidents, political opposition figures, diplomats, and other high-risk individuals. Pegasus has targeted both iOS and Android devices through exploit chains that can include zero-click compromise, requiring no interaction from the target. Confirmed delivery methods have included iMessage zero-click exploitation, while historical reporting also linked an Android exploit chain to CVE-2019-2215. Following successful compromise, Pegasus can provide an operator access to sensitive device-resident data, including messages, photographs, notes, files, and encrypted communications accessible on the device. It can also covertly activate microphones and cameras for surveillance. Citizen Lab and the SHARE Foundation forensically confirmed Pegasus on the iPhone of a Serbian student-protest movement member, with high-confidence infection evidence spanning December 2025 to January 2026; the infection used an iMessage zero-click exploit. The publicly available evidence confirms Pegasus infection but does not establish the responsible operator or whether Serbia was an NSO Group customer. Apple assessed the relevant iMessage flaw as addressed in iOS 18.4.1.
NoviSpy is an Android spyware family assessed with high confidence to be associated with Serbia’s Security Information Agency (BIA). It has been used against Serbian journalists, environmental activists, civil-society members, and student-movement participants. Documented infections commonly followed detention, police questioning, or other circumstances in which Serbian authorities had physical custody of a target’s phone. Cellebrite mobile-forensics tooling was reportedly used to unlock devices and enable subsequent implantation, and exploitation of CVE-2024-43047 was associated with obtaining privileged access on affected Qualcomm-based Android devices. NoviSpy collects sensitive data from compromised devices, captures screenshots, and can remotely activate the microphone and camera. Later variants were assessed as incorporating measures intended to hinder forensic detection. The malware has been linked to Serbian authorities through forensic, code-language, and infrastructure evidence.
DarkVNC is a Windows hidden-VNC (hVNC) remote-access trojan that creates a concealed virtual desktop on an infected system, allowing an operator to view and control that desktop through Virtual Network Computing technology without presenting the normal remote-control interface to the victim. It has been used to provide covert remote access and to transmit stolen data from compromised hosts to command-and-control infrastructure. DarkVNC has been delivered through phishing messages carrying malicious Microsoft Excel attachments whose enabled macros download the malware. It has also been observed as a payload associated with ICEDID infections. U.S. prosecutors have alleged its use, alongside TVRAT, in a 2016–2017 campaign targeting users of a freelance-employment platform; those allegations concern Searzhudin Tamirlanovich Aktulaev and co-conspirators and remain unproven.
TVRAT, commonly known as TeamSpy and also referred to as TVSPY, is a Windows remote-access trojan that abuses legitimate TeamViewer components to provide covert remote control of compromised systems. Observed TeamSpy implementations use DLL side-loading or search-order hijacking against signed TeamViewer binaries, conceal TeamViewer user-interface elements, and provide operators with the compromised host's TeamViewer identifier for remote access. Reported functionality includes remote control, file transfer, collection and exfiltration of victim data, and, in some variants, access to the microphone and webcam. TVRAT has been delivered through socially engineered documents, including job-application lures and malicious Excel attachments that require victims to enable macros; it has also appeared as a follow-on payload in phishing and cryptocurrency-themed lure campaigns. In a U.S. criminal case, prosecutors alleged that TVRAT and DarkVNC were distributed through fraudulent accounts on a freelance-employment platform and used to collect victim data for subsequent fraud. TVRAT has also been deployed as a secondary payload following Ursnif infections.
Sality is a long-running Windows polymorphic file-infector that evolved into a decentralized peer-to-peer botnet. First observed in 2003, it infects and modifies Windows executable files and propagates when compromised executables are transferred through network shares, removable media, and file-sharing systems. Its peer-to-peer architecture uses publicly reachable infected hosts as super peers, allowing bots to exchange commands and payload-delivery information without dependence on a conventional centralized command-and-control server. Sality has principally functioned as a malware-delivery platform. Payloads distributed through the botnet have supported credential theft, spam distribution, proxy services, network exploitation, distributed denial-of-service attacks, and cryptocurrency theft. For approximately eight years, its primary payload was EggJagger, a clipboard-hijacking cryptocurrency clipper that replaces copied cryptocurrency wallet addresses with attacker-controlled addresses. Sality has also been associated with process injection, security-tool interference, and deployment of a driver and service intended to identify and terminate security products. Two incompatible Sality peer-to-peer networks, referred to as versions 3 and 4, used a shared codebase but different protocols and cryptographic keys. CrowdStrike tracks the associated criminal activity as SALTY SPIDER and assesses that the operator likely operates from Russia's Republic of Bashkortostan; this is an intelligence assessment rather than a public legal attribution. Sality activity has been financially motivated overall, although the botnet has also been used in notable DDoS campaigns. A documented campaign delivered Sality through trojanized password-recovery software targeting an industrial engineering workstation connected to a programmable logic controller. In August 2026, an international public-private operation used peer-list manipulation and sinkholing to isolate infected hosts from Sality operators and prevent further command and payload delivery. Sinkholing does not remove Sality or secondary payloads already installed on compromised endpoints.
StreamRAT is an Android banking trojan and information stealer targeting Spanish-speaking users, primarily in Spain. It has been distributed through fraudulent social-media advertisements impersonating a free television-streaming service. Victims are directed to device-aware landing pages that expose the download flow only to Android users and provide tailored instructions for sideloading the application and granting high-risk permissions. The infection chain uses a dropper that requests default Home-app, VPN, installation-from-unknown-sources, and Accessibility permissions before installing the final payload. The dropper can temporarily disrupt connectivity for other applications through a nonfunctional VPN configuration, apparently to reduce cloud-based reputation and analysis checks during installation. It can also retain interface control by becoming the default Home application. After Accessibility access is granted, StreamRAT can monitor foreground applications, capture typed input, collect visible interface content and installed-application information, capture screenshots, and display credential-harvesting overlays matching targeted applications. It supports visible VNC-style screen viewing as well as screenshot-based hidden monitoring, and enables operators to perform taps, swipes, navigation actions, application launches, screen locking, and other remote device actions. Black-screen and fake-update overlays can obstruct victim interaction while an operator acts on the device. StreamRAT also includes anti-uninstall controls and can execute shell commands. Its administration panel includes payload and dropper building functions, role-based user management, and device-management features consistent with a malware-as-a-service design. Technical links have been observed between its delivery infrastructure and the earlier Mirax campaign, but no named threat actor has been conclusively attributed.
Cobalt Strike is a commercial adversary-simulation platform whose Beacon implant is extensively abused by criminal, ransomware, and espionage operators for post-exploitation. Beacon can operate as an in-memory implant and supports command execution, host and user discovery, file transfer, keylogging, SOCKS proxying, port scanning, process injection, privilege-escalation activity, and lateral movement. It supports command-and-control communications over HTTP, HTTPS, DNS, SMB named pipes, and TCP, and its Malleable C2 profiles allow operators to customize network traffic characteristics. Cobalt Strike has been observed in intrusions involving groups including Conti, Transparent Tribe, Warlock, and operators linked to The Gentlemen, as well as in campaigns targeting government, financial technology, technology, and other enterprise organizations. It is commonly deployed after an initial foothold; observed delivery chains include ClickFix social engineering. Beacon is frequently used on Windows systems, including through DLL sideloading and reflective process injection.
Mirai is a self-propagating IoT botnet malware created by Paras Jha, Josiah White, and Dalton Norman. It became prominent in 2016 after being used in exceptionally large distributed denial-of-service attacks against gaming infrastructure, OVH, KrebsOnSecurity, and Dyn. Its source code was later publicly released, leading to extensive reuse, modification, and the emergence of numerous derivatives and variants. Original Mirai primarily compromises Linux-based internet-connected devices, including cameras, DVRs, routers, VoIP devices, and other embedded systems. It scans pseudorandom public addresses for exposed Telnet services, attempts logins using a hard-coded set of common and factory-default credentials, and reports successful access to loader infrastructure. The loader identifies the target architecture and deploys an appropriate binary. Mirai variants have subsequently added exploitation of exposed and vulnerable services, including vulnerabilities affecting routers, networking appliances, and web applications. Compromised devices receive command-and-control instructions to conduct DDoS attacks, commonly using network traffic floods. Mirai attempts to evade competition and hinder analysis by terminating processes associated with rival malware, deleting its on-disk binary after execution, and randomizing its process name. Original infections are generally non-persistent and can often be removed by rebooting the affected device, though later variants may implement persistence. Mirai has materially shaped the IoT botnet ecosystem and remains a foundational codebase for DDoS-oriented malware families.
EggJagger is a cryptocurrency clipper that monitors an infected system’s clipboard for copied Bitcoin and Ethereum wallet addresses, then silently substitutes an address controlled by the operator. The substitution can redirect a victim’s intended cryptocurrency transfer if the altered address is not verified before the transaction is authorized. EggJagger was the primary payload distributed for approximately eight years by the Sality peer-to-peer botnet, which CrowdStrike tracks as associated with the financially motivated SALTY SPIDER criminal group. The payload is estimated to have diverted at least $150,000 in cryptocurrency. Disrupting Sality’s command and payload-delivery infrastructure prevents further delivery through that botnet but does not remove EggJagger instances already installed on compromised systems.
Tsunami, also known as Kaiten, is a long-running UNIX/Linux IRC-controlled botnet and backdoor family first observed in 2002. It primarily compromises Linux servers and Linux-based IoT devices and is commonly used for distributed denial-of-service attacks, remote shell-command execution, and downloading or updating additional payloads. Variants support multiple flooding methods, including TCP and UDP-based attacks, and commonly use IRC channels for command-and-control. Tsunami has been distributed through brute-force attacks against weak SSH or Telnet credentials and through exploitation of exposed, vulnerable internet-facing services. It has been deployed in campaigns exploiting vulnerabilities in web applications, enterprise middleware, cloud-native services, and IoT devices. Compromised hosts have also been used to scan for further targets and to deploy cryptocurrency miners or other malware. The family has been actively maintained and modified by multiple operators. Keksec-associated activity has involved customized Tsunami variants alongside Gafgyt and Necro, while TeamTNT has repeatedly deployed Tsunami in container- and cloud-focused Linux intrusions. Observed variants have used process-name masquerading, startup persistence, in-memory execution, and other concealment measures. Tsunami remains a significant threat to exposed Linux infrastructure, routers, DVRs, and other IoT systems.
Gafgyt, also known as Bashlite, is a long-running Linux-focused IoT botnet family primarily used to recruit compromised devices into distributed denial-of-service botnets. Other established aliases include Lizkebab, Qbot, Torlus, PinkSlip, and LizardStresser. First prominent in 2014, early variants exploited Shellshock against susceptible embedded systems; the family subsequently proliferated following a 2015 source-code leak. Gafgyt commonly targets internet-exposed routers, cameras, DVRs, and other embedded Linux devices. Variants propagate through Telnet or SSH scanning and brute-force attempts against weak or default credentials, as well as exploitation of publicly known remote-code-execution vulnerabilities affecting IoT devices, routers, and exposed applications. Payloads are commonly built for multiple processor architectures to support heterogeneous embedded-device populations. The botnet receives commands through lightweight IRC-like or related command-and-control mechanisms. Its attack functions include TCP, UDP, HTTP, DNS, and flag-based flooding, connection-holding, and random-data flooding. Variants may execute remote shell commands, download additional payloads, remove competing malware, obscure operational strings or process identity, and establish persistence. Some newer variants have expanded beyond conventional IoT targets to Linux servers and cloud-oriented systems, including through separate propagation scanners and cryptomining payloads. Gafgyt code has been extensively reused and modified in derivative botnets, including Hakai, vbot, and Enemybot. Multiple Gafgyt variants, including Tor-enabled versions, have been associated with or attributed to the Keksec cybercrime ecosystem, although attribution does not apply uniformly to all Gafgyt activity.
Kaiji is a Go-based Linux botnet and distributed-denial-of-service malware family targeting Linux servers and IoT devices. It has propagated through SSH brute-forcing of root accounts, abuse of exposed Docker APIs, and post-exploitation deployment following server-side remote-code-execution compromises. Kaiji supports multiple TCP-, UDP-, and spoofing-based flood attacks, executes attacker-supplied shell commands, and can use compromised systems to relay malicious traffic. It establishes persistence through Linux startup services, scheduled tasks, shell initialization, and modification of startup mechanisms. Variants have masqueraded as system utilities, removed competing processes or unnecessary binaries, altered host security settings, and used watchdog behavior to restart or reboot hosts when the payload is terminated. Kaiji can attempt further spread using locally available SSH keys and host information recovered from shell history. Chaos has been assessed as an evolutionary descendant of Kaiji based on code overlap.
Dofloo, also known as AESDDoS, is a Linux-focused DDoS botnet malware family first identified in 2014. It is used to construct large-scale botnets capable of conducting SYN, UDP, TCP, and related flood attacks. Dofloo variants collect host-system information and transmit it to command-and-control infrastructure, enabling operators to profile compromised systems and select follow-on activity. Some variants have also been associated with deployment of cryptocurrency-mining payloads. Dofloo has been deployed to improperly exposed Docker environments by enumerating running containers and executing the malware within them through the Docker API. It has also been observed among payloads delivered through exploitation of vulnerable server software, including Atlassian Confluence. A Linux Dofloo/AESDDoS variant has been linked to campaigns targeting Internet-exposed, unauthenticated Docker services.
DDoSTF is a cross-platform DDoS botnet first identified around 2016 and reported to have been developed in China. It has Windows PE and Linux ELF variants and is designed to conduct targeted distributed denial-of-service attacks, including SYN, ICMP, TCP, UDP, and HTTP request floods. The Linux variant checks for root privileges, establishes persistence, profiles compromised hosts, and communicates with command-and-control infrastructure using a distinctive protocol marker. The Windows variant persists by copying itself under a randomized name and registering a service; it collects operating-system, CPU, hostname, language, network-performance, and resource-usage information for command-and-control reporting. DDoSTF can start and stop attacks, receive DDoS commands from alternate command-and-control infrastructure, and download and execute additional payloads. It has been deployed against exposed MySQL servers after attackers obtain access through weak credentials or exploitation of unpatched services, including through malicious MySQL user-defined-function components that provide command execution and payload download capability. It has also been observed as a payload following exploitation of Apache ActiveMQ CVE-2023-46604.
Hajime is a Linux-based IoT worm and peer-to-peer botnet first identified in October 2016. It primarily targets internet-exposed embedded devices, including routers, cameras, DVRs, and GPON equipment, with MIPS systems constituting a substantial portion of observed infections. Hajime propagates through Telnet credential brute forcing, targeted use of default or weak credentials, and exploitation of device vulnerabilities, including TR-069 abuse and, in later variants, GPON router flaws CVE-2018-10561 and CVE-2018-10562. Some variants also incorporated targeting logic for MikroTik devices and Arris cable modems. The malware uses a decentralized DHT-based peer-to-peer architecture for node discovery, command distribution, and module synchronization rather than conventional centralized command-and-control infrastructure. Inter-node communications use UDP-based uTP, encrypted sessions, Curve25519 key exchange, and signed modules to authenticate synchronized content. Hajime is modular, with separate propagation and execution components, and has historically focused on self-propagation rather than overt payload actions. Researchers have not observed denial-of-service or other disruptive attack modules in Hajime, although infected devices may have ports commonly targeted by competing IoT malware blocked. The operator has embedded messages portraying Hajime as a white-hat effort, but its unauthorized compromise and control of devices remains malicious activity. No reliable public attribution to a specific threat actor is available.
OtterCookie is a modular JavaScript-based infostealer and remote-access malware family associated with the DPRK-aligned Contagious Interview operation, including activity tracked as WaterPlum, Famous Chollima, and REF9403. First observed in 2024, it has evolved from a file-grabbing tool into a multi-component toolkit that targets Windows, macOS, and Linux systems. It steals saved Chromium-browser credentials, autofill data, cryptocurrency-wallet extension data, selected macOS credential-store data, clipboard contents, and sensitive developer, cloud, key, configuration, document, and cryptocurrency-related files. OtterCookie uses a Socket.IO-based command channel to register infected hosts, maintain operator communications, and provide interactive shell execution. Later variants added Windows support, hardcoded file-collection logic, virtual-environment detection, clipboard theft, and dedicated browser and wallet-stealing modules. Contagious Interview operators distribute OtterCookie through fake recruitment outreach, trojanized coding assignments and software projects, malicious package ecosystems, and trojanized macOS installers. A 2026 campaign concealed payload fragments in SVG assets within functional developer projects; starting the local development server reconstructed and executed the malware. The activity principally targets software developers, particularly those in cryptocurrency, Web3, financial, and technology environments, where developer workstations may provide access to source code, cloud credentials, browser sessions, wallets, and downstream software supply chains.
EtherRAT is a cross-platform remote access trojan implemented in Node.js that targets Windows workstations, Linux servers, and macOS systems. It provides remote command execution, file manipulation, data theft, persistence, credential theft, lateral movement, and web-server hijacking functionality. Its command-and-control discovery uses Ethereum smart contracts: infected hosts query public Ethereum RPC services to retrieve an active controller, allowing operators to rotate infrastructure without updating the implant. The malware can execute JavaScript received from its controller and uses randomized-looking request paths to blend command traffic with ordinary web activity. On Windows, EtherRAT has established persistence through user-level Run-key execution and can acquire a Node.js runtime when one is absent. It has been deployed through malicious MSI installers, including in Windows domain compromises where remote scheduled tasks, administrative shares, WMI, and SMB were used to distribute the installer across hosts. Such activity has been linked to an affiliate of the Gentlemen ransomware operation. Other observed delivery chains use phishing followed by voice-based social engineering on Microsoft Teams, in which operators impersonate IT support staff, obtain remote control through legitimate remote-access tools, and install the malicious MSI. EtherRAT has also been delivered through ClickFix-style copy-and-paste lures on Windows, while Linux server targeting has involved exploitation of server-side vulnerabilities.
AdaptixC2 is an open-source post-exploitation command-and-control framework comprising a Go-based teamserver, a Qt-based operator client, and cross-platform agents. Its Beacon and Gopher implants support Windows, Linux, and macOS, and the framework provides HTTP/S, DNS/DoH, SMB named-pipe, and raw TCP listener transports. Observed AdaptixC2 agents support command execution, file operations, process control, Beacon Object File execution, SOCKS forwarding, and data exfiltration. The framework has been used as a follow-on remote-access capability in intrusions involving ransomware, cyberespionage, and commodity cybercrime. AdaptixC2 has been observed following phishing, ClickFix, SEO-poisoning, and DLL-sideloading infection chains. It was deployed in campaigns associated with the China-nexus JadeProx cluster through TriBack Loader, in intrusions leading to Akira ransomware, and in activity attributed with medium confidence to hacktivist clusters including 4BID. It has also been delivered through supply-chain compromise and by crypter-protected malware chains. Default deployments may expose distinctive AdaptixC2-branded HTTP response behavior, although discovery of a public-facing instance alone does not establish malicious use because the framework can be used in authorized red-team operations.
C2Looper is a Rust-based Windows backdoor identified in 2026. It executes arbitrary commands, conducts host and domain reconnaissance, enumerates directories and drives, downloads and executes additional payloads, and can inject shellcode into a legitimate Windows library’s memory. Earlier variants used frequent plaintext HTTP JSON beaconing and command-result reporting; a later version moved command-and-control, command results, and collected data to GitHub. C2Looper uses XOR-obfuscated strings, dynamic Windows API resolution, and DLL side-loading through a legitimate OneDrive component to reduce detection. It has been observed in an intrusion affecting a U.S. financial-technology organization and is assessed as likely intended to establish footholds in ransomware-related operations.
ModeloRAT is a Python-based remote access trojan targeting domain-joined Windows systems in enterprise environments. First observed in January 2026, it has been associated with the financially motivated initial-access broker Woodgnat, also known as KongTuke. The malware has been observed in CrashFix ClickFix campaigns involving a malicious browser extension that causes browser instability before persuading victims to execute attacker-controlled commands. KongTuke has also used Microsoft Teams helpdesk impersonation lures to induce victims to run malicious PowerShell commands that lead to ModeloRAT deployment. ModeloRAT is deployed with a portable Python environment and establishes user-level persistence through multiple startup triggers. It profiles hosts, including domain membership and security software, and selectively deploys to domain-joined systems. Its command-and-control protocol uses HTTP, RC4 encryption, compressed JSON, and adaptive beacon intervals. Operator tasking supports host reconnaissance, arbitrary command execution, deployment and execution of additional payloads, restoration of persistence, implant updates, and clean termination or removal. The malware incorporates anti-analysis checks, obfuscation, runtime construction of configuration values, and hidden subprocess execution to hinder detection and analysis. Its focus on enterprise domain hosts and post-compromise tasking makes it suitable for establishing durable access that may be used to support ransomware-affiliate operations.
cam-agent is a Go-based ELF reconnaissance and asset-mapping utility associated with the Gambling Goblin cybercrime cluster, which has been linked with medium-to-high confidence to Earth Berberoka. It was identified on exposed infrastructure used in operations against Brazilian government, educational, and commercial organizations. The utility bundles plugins for discovery and scanning of internet-facing systems, including web probing, port scanning, vulnerability-template scanning, subdomain enumeration, and technology fingerprinting. It communicates using gRPC with embedded certificates. cam-agent appears intended to identify exposed or trusted web properties that can be evaluated for subsequent compromise; its use does not establish the initial-access method. The broader operation primarily targets Linux web-server environments and abuses compromised sites for gambling-related phishing and search fraud.
ChUser is a Linux command-execution backdoor associated with the Chinese-speaking Gambling Goblin cybercrime cluster, which has been linked with medium-to-high confidence to Earth Berberoka. It masquerades as a legitimate system utility and executes commands supplied through a command-line option only after an activation check succeeds. The activation mechanism can validate either a remote HTTP response or a locally derived secret, limiting execution by unauthorized users and hindering analysis. Gambling Goblin deploys ChUser as a follow-on payload through the DownPro downloader after compromising Linux web servers, including systems belonging to Brazilian government and educational organizations. ChUser supports post-compromise remote command execution and uses utility-name masquerading for defense evasion.
DownPro is a custom Go-based Linux downloader used by the Chinese-speaking Gambling Goblin cybercrime cluster after it compromises web servers. It retrieves and launches additional components of the group’s toolkit, including backdoors, remote-access tools, credential-harvesting malware, and SSH credential-testing utilities. DownPro decrypts protected payload locations before downloading tooling and uses Linux-like naming to disguise deployed components. Gambling Goblin has used the associated Linux toolset on compromised Brazilian government, educational, commercial, healthcare, and media web infrastructure in gambling-focused SEO-fraud and phishing operations. The cluster has been assessed as linked to Earth Berberoka with medium-to-high confidence.