Trending Malware
Active families, ranked. Mallory tracks every named malware family across vendor reports, researcher analysis, and threat feeds, then surfaces the ones gaining velocity right now.
Ranked by Mallory's mention-velocity model across sources.
Mention map · Last day
Sized by mentionsTop 24 malware · Last day
Medusa is a ransomware family and ransomware-as-a-service operation first identified in 2021 that evolved from a closed operation into an affiliate-based model by at least early 2023. It has impacted more than 500 victims across multiple critical infrastructure and enterprise sectors, with frequent targeting of healthcare and public health organizations as well as education, legal, insurance, technology, manufacturing, government, defense, and financial services entities. The operation is distinct from MedusaLocker. Medusa uses double extortion: operators and affiliates steal data, encrypt systems, and threaten public release of exfiltrated information if ransom demands are not met. The group commonly gives victims a short negotiation window and uses leak-site pressure to coerce payment. Initial access is obtained through phishing, purchased access from initial access brokers, and rapid exploitation of newly disclosed unpatched internet-facing vulnerabilities. Medusa has been observed weaponizing public vulnerabilities within 24 hours of disclosure and, in some cases, using exploit access before public disclosure. Post-compromise activity emphasizes speed, stealth, and use of legitimate or commonly available tooling. Medusa actors use PowerShell and other living-off-the-land techniques, harvest credentials with tools such as Mimikatz, leverage remote monitoring and management software and remote access services including RDP for lateral movement, and use common utilities for staging and exfiltration. Reported tradecraft includes disabling security tools, deleting shadow copies, terminating services, archiving data for theft, and transferring the encryptor across the environment before broad encryption. The Windows encryptor has been associated with a payload that appends a Medusa-specific extension to encrypted files. Medusa’s operational model relies heavily on affiliates and access brokers, with payments scaled to the value of access. Its intrusion pattern is characterized by opportunistic targeting of exposed, unpatched systems rather than exclusive focus on a single vertical, although healthcare has been a particularly frequent victim sector. The combination of rapid exploitation, credential theft, lateral movement, data exfiltration, defense evasion, and network-wide encryption has made Medusa a significant and persistent ransomware threat.
Clop, also written Cl0p, is a ransomware and data-extortion operation known for large-scale exploitation of enterprise software vulnerabilities to steal data from victim organizations. The operation has repeatedly targeted internet-exposed business platforms, including managed file transfer products and product lifecycle management systems, and has used stolen data to pressure victims through leak-site publication and direct extortion. In 2026, activity attributed to Clop included exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM. In those intrusions, operators deployed a bespoke JavaServer Pages web shell tailored specifically to Windchill environments. The implant used native Windchill classes and application context to access the database, decrypt credentials stored in the application keystore, enumerate file-vault repositories, retrieve and delete files, and execute additional Java code in memory. Its design reflected detailed knowledge of Windchill internals, including APIs, schema, keystore handling, and vault structure, and enabled theft of engineering data, product designs, administrative secrets, and directory-management credentials. Running through the application’s own identity and traffic patterns also reduced forensic visibility and supported stealthy post-compromise activity. Clop has also been associated with earlier mass-exploitation campaigns against Accellion FTA, GoAnywhere MFT, and MOVEit Transfer. Across these campaigns, the group has emphasized rapid data theft and extortion at scale, often claiming large numbers of victims and publishing victim names on a leak site when negotiations fail. Reporting also links Clop to deployment of custom web shells in some software-exploitation operations, reinforcing its pattern of developing platform-specific tooling for high-value enterprise targets. The operation is widely characterized as extortion-focused and has at times prioritized data exfiltration over encryption. It has used victim-shaming infrastructure and pressure tactics such as contacting employees, customers, or partners of affected organizations. Targeting has included sectors that rely heavily on enterprise file transfer and PLM platforms, such as manufacturing, aerospace, defense, automotive, retail, energy, and medtech. Clop is commonly discussed alongside affiliate designations such as FIN11 and TA505, although precise organizational relationships are not always consistently resolved in public reporting.
GoginRAT is a previously undocumented Go-based remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. It is part of a broader modular malware ecosystem used for long-term access and selective capability deployment against public-sector victims. Architecturally, GoginRAT closely resembles NomadRAT despite being implemented in a different programming language, suggesting a shared design pattern across the operator’s toolset. The implant uses a separate transmitter component for command-and-control communications and exposes functionality through independent plugins rather than embedding all capabilities in a monolithic payload. Confirmed plugin-supported functions include file system operations and shell command execution, consistent with hands-on post-compromise control. GoginRAT has been observed in intrusions that begin with tailored spearphishing against government entities, including malicious Office-document lures and, in some cases, password-protected archive delivery. Within the wider SilkParasite campaign, malware deployment commonly relies on DLL sideloading using legitimately signed applications, and the overall toolset is designed to maintain a small footprint and reduce detection. Researchers also noted development artifacts in GoginRAT, including leftover Go test functions and a placeholder encryption key, assessed as signs of AI-assisted development rather than fully automated malware generation.
NomadRAT is a previously undocumented remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. It has been observed in operations against public-sector entities in countries including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. The malware is written in C++ and is designed as a modular implant with a main orchestrator component, a dedicated transmitter library for command-and-control communications, and plugins that are retrieved from the server on demand using numeric identifiers. This architecture supports a low-footprint, selectively deployed post-compromise capability set aligned with long-term espionage objectives. NomadRAT has been linked to spear-phishing-led intrusion chains using tailored Office-document lures, sometimes delivered in password-protected archives, with execution facilitated through macro-triggered DLL sideloading via legitimately signed applications. The broader SilkParasite toolset is characterized by modular engineering, defense evasion through trusted binaries and small operational footprint, and tradecraft overlaps with other Chinese-linked malware ecosystems.
DriveSilkRAT is a previously undocumented remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. The malware is part of a broader modular toolset used against public-sector entities in countries including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. It has been observed in operations that rely on tailored spearphishing lures, including malicious Office documents sometimes delivered in password-protected archives, with execution chains involving macro-triggered DLL sideloading through legitimately signed applications. DriveSilkRAT is implemented in .NET and C++ and uses Google Drive as its command-and-control channel, polling a designated folder for tasking and uploading execution results back to the same location. It supports an in-memory .NET plugin architecture that enables operators to selectively extend functionality while maintaining a relatively small footprint. Reported plugin capabilities include process listing, system and network enumeration, file management, and command execution, making the malware suitable for long-term interactive access and espionage-oriented post-compromise activity. Its use of trusted cloud infrastructure and modular execution model aligns with defense-evasion tradecraft seen across the SilkParasite ecosystem.
NodeEdgeRAT is a JavaScript-based remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set assessed to have targeted government organizations in Central Asia. It is one of several distinct RAT families used by the operators as part of a modular, low-footprint toolset intended to establish and maintain access in selected victim environments. NodeEdgeRAT packages its core functionality into a single script rather than relying on a broader plugin framework. Documented capabilities include remote command execution, file management, and file transfer, enabling operators to interact with compromised hosts, manipulate files, and move data to and from victim systems. The malware family has also been noted for development artifacts consistent with AI-assisted coding workflows, including a placeholder encryption-key configuration value. Within the broader SilkParasite intrusion chain, initial compromise activity has been linked to spear-phishing using tailored government-themed lures, including password-protected archives containing malicious Office documents. Those documents have been reported to trigger macro-based execution and DLL sideloading to deploy first-stage payloads, after which SilkParasite operators use multiple RAT families for persistence and post-compromise operations. The campaign has primarily targeted government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, with related lure material also observed for a Georgian government entity. SilkParasite has been linked by researchers to prior China-aligned activity including FamousSparrow, and its broader tooling ecosystem includes other implants such as DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, SpiceRAT, and BloodAlchemy.
CookiETagRAT is a previously undocumented remote access trojan associated with the SilkParasite cyber-espionage campaign, a China-nexus intrusion set targeting government organizations in Central Asia. It has been observed in operations against public-sector entities in countries including Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan as part of a broader modular malware ecosystem used for long-term access and selective post-compromise tasking. The malware is implemented in C++ and is notable for using HTTP Cookie and ETag response headers as its command-and-control channel to receive and execute operator commands. This design aligns with SilkParasite’s broader emphasis on low-footprint, evasive tooling intended to blend into normal traffic patterns and avoid looking like conventional malware. Across the campaign, operators relied on plugin-oriented and modular implants, legitimately signed applications abused for DLL sideloading, and tailored spearphishing lures delivered through malicious Office documents, sometimes packaged in password-protected archives. CookiETagRAT forms part of a professionally engineered espionage toolset that also includes other RAT families such as DriveSilkRAT, NomadRAT, GoginRAT, NodeEdgeRAT, SpiceRAT, and BLOODALCHEMY. The campaign has been linked directly to prior FamousSparrow activity and indirectly to the broader ShadowPad-linked Chinese threat ecosystem. Its operational use indicates a focus on covert command execution and sustained access in government environments rather than disruptive effects.
Mirai is a Linux-based IoT botnet malware family best known for compromising internet-exposed embedded devices such as routers, IP cameras, DVRs, NAS appliances, and other edge systems, then enrolling them into centrally controlled botnets for large-scale distributed denial-of-service operations. It became one of the defining malware families in the IoT threat landscape and has remained highly influential because its source code was publicly leaked, enabling extensive reuse, modification, and proliferation of variants and derivative botnets. Mirai commonly propagates by scanning for exposed services and abusing weak or default credentials, especially over Telnet and SSH, and by exploiting known vulnerabilities in internet-facing devices and servers. Once a device is compromised, Mirai typically downloads an architecture-appropriate binary, executes it on the target, and connects to command-and-control infrastructure to await instructions. Mirai-derived campaigns have targeted a wide range of Linux-based and embedded platforms and have also been observed infecting some server environments in addition to traditional IoT devices. The malware family’s core capability is botnet-enabled DDoS activity, with variants supporting multiple flood techniques across TCP, UDP, GRE, DNS, and HTTP. Many descendants preserve this attack engine while extending the framework with additional modules such as encrypted command-and-control, exploit dispatchers, SSH brute-forcing, credential sniffing, proxying, reverse relays, interactive shell access, file transfer, persistence mechanisms, anti-analysis checks, and process-killing logic. Some Mirai-related families have also incorporated monetization features beyond DDoS, including proxy abuse, extortion support, and in certain derivative strains, cryptomining. Mirai has inspired or directly contributed code to numerous later botnets and malware families, including variants and forks such as IZ1H9, Murdoc Botnet, LiquorBot, EnemyBot, and Evooo1Bot. These descendants have been used in campaigns exploiting newly disclosed vulnerabilities in routers, cameras, web applications, and edge infrastructure, demonstrating the continued operational relevance of the Mirai codebase years after its original emergence. Mirai remains a foundational malware family in Linux and IoT botnet operations and a persistent driver of opportunistic exploitation, large-scale scanning, and DDoS activity worldwide.
MacSync Stealer is a macOS-focused information stealer used in social-engineering-driven campaigns that trick users into executing attacker-supplied Terminal commands. Observed delivery commonly relies on ClickFix-style lures, including fake support or software-installation pages, malvertising, and GitHub- or chat-themed landing pages that instruct victims to paste a curl command into Terminal. The malware uses native macOS and Unix tooling, including shell scripts, curl, base64 or compression utilities, and AppleScript executed through osascript, to retrieve, unpack, and run its payload while blending into normal system activity. Once active, MacSync Stealer collects a broad range of high-value data from infected Macs. Reported targets include macOS Keychain material, browser credentials, cookies, session data, browsing history, Apple Notes, SSH keys, cloud credentials such as AWS material, Kubernetes configuration files, Telegram sessions, and files from common user directories. It also checks for cryptocurrency wallet browser extensions, desktop wallet applications, and hardware-wallet companion software, and has been observed modifying wallet applications to phish for wallet recovery phrases. Data is staged locally, compressed into archives, split into chunks, and exfiltrated through recurring HTTP PUT upload patterns. The malware also removes temporary staging artifacts after exfiltration. MacSync has also been associated with post-compromise remote access functionality. Reported variants install a persistent macOS component via LaunchAgent mechanisms, enabling interactive shell access, command execution, and file transfer for the operator. Campaigns involving MacSync have requested sensitive macOS permissions such as Full Disk Access and Screen Recording to expand collection and surveillance. The malware’s infrastructure is known to rotate rapidly, but recurring behavioral traits across payload retrieval, AppleScript-assisted execution, staging, chunked exfiltration, and cleanup have enabled defenders to cluster related activity. No named threat actor attribution is established at high confidence, though the malware shares delivery templates and tradecraft with other macOS stealers such as Atomic Stealer and CrashStealer.
Atomic macOS Stealer, commonly abbreviated AMOS, is a macOS-focused information stealer offered through a malware-as-a-service model and widely used in criminal campaigns targeting credentials, cryptocurrency assets, and authenticated browser sessions. It is commonly delivered through social-engineering lures such as counterfeit software installers, malvertising, fake document-sharing pages, and ClickFix-style workflows that trick users into executing commands or installing trojanized disk images. Observed lures have impersonated trusted brands and services including collaboration, file-sharing, and software distribution platforms. AMOS is designed to harvest browser credentials, cookies and session material, cryptocurrency wallet data, macOS keychain contents, and messaging-app data such as Telegram files. Reported variants and campaigns have also targeted Apple Notes and other sensitive user files. The malware commonly prompts victims for their macOS password to unlock protected data sources and improve collection depth. Exfiltration of staged data to attacker-controlled infrastructure is a core function. Persistence has been observed through scheduled background components on macOS, including LaunchDaemon-style mechanisms. Reporting from 2025 also indicates the family gained an embedded backdoor capability, expanding it beyond pure theft into longer-term post-compromise access. In campaign use, AMOS has appeared alongside other payloads and shared lure infrastructure with macOS stealers such as MacSync and, in comparative analysis, has been discussed alongside families including CrashStealer and AmnesiaStealer. AMOS has been distributed in broad criminal operations including malvertising and ClickFix campaigns, and has been observed in targeted social-engineering activity against conference attendees and cryptocurrency-adjacent users. It is a prominent macOS infostealer family and a recurring component of financially motivated intrusion activity focused on credential theft, session hijacking, and cryptocurrency wallet compromise.
FakeMBAM is a Windows backdoor disguised as a Malwarebytes installer and associated with a large-scale supply-chain style distribution campaign that abused the automatic update mechanisms of Download Studio and the adblocker applications NetShield Kit, My AdBlock, and Net AdBlock. Activity was observed at significant scale, with infections concentrated in Russia, Ukraine, and Kazakhstan, and the campaign appears intended to reach the full user bases of the affected applications. Code and infrastructure overlaps between the distributors and the malware suggest either a common operator or a closely connected compromise. The malware is installed through a counterfeit Malwarebytes package that silently creates a fake Malwarebytes directory populated with legitimate signed components alongside malicious DLLs. Execution relies on DLL sideloading: a trojanized Qt component causes the legitimate Malwarebytes executable to load a malicious library that implements the backdoor. Persistence is established by creating a Windows service masquerading as a Malwarebytes service, and the malware also modifies host settings to facilitate execution. Once active, FakeMBAM polls attacker-controlled infrastructure for encrypted configuration updates using custom HTTP headers and cryptographic validation. It stores encrypted configuration locally and supports retrieval and deployment of additional payloads. Observed secondary payloads included persistent XMRig-based cryptocurrency miners. The malware can execute payloads directly or via scheduled tasks, periodically reinstall removed payloads, and in some cases attempt to run payloads under a stolen active user token. Its behavior demonstrates defense evasion, persistence, post-compromise payload delivery, and monetization through cryptomining.
ShadowPad is a sophisticated modular Windows backdoor and malware platform widely associated with Chinese espionage operations. It emerged around 2015 as an evolution of PlugX and became publicly notable after its use in major software supply-chain compromises, including the NetSarang, CCleaner, and ASUS ShadowHammer incidents. ShadowPad is best characterized as a privately sold or selectively shared malware framework rather than an openly distributed toolkit, with functionality extended through plugins that enable operators to tailor capabilities to specific intrusions. The malware is designed for long-term covert access on compromised systems. Its architecture uses an obfuscated loader and shellcode-based components to decrypt and load a root plugin, which in turn loads additional embedded or remotely supplied plugins into memory. Reported functionality includes arbitrary command execution, deployment of next-stage payloads, host reconnaissance, process discovery, collection of victim username and domain information, collection of system date and time, configuration and virtual file system storage in the Windows Registry, and DLL injection into legitimate processes such as svchost.exe. ShadowPad is also noted for anti-detection and persistence features, and operators commonly pair it with DLL sideloading through legitimate signed applications. ShadowPad has been used across multiple espionage clusters and by several China-linked threat groups, which makes attribution based solely on its presence unreliable. Groups and activity clusters publicly linked to ShadowPad use include APT41-related operations, Tick, Tonto Team, SparklingGoblin, FamousSparrow-linked activity, and other China-nexus intrusion sets. It has appeared in campaigns targeting government, telecommunications, critical infrastructure, software supply chains, and other strategic sectors across Asia and beyond, including operations against entities in Pakistan, India, and Central Asia. Its broad adoption, modularity, and continued evolution have made it one of the most consequential shared backdoors in the Chinese cyber-espionage ecosystem.
BloodAlchemy is a Windows x86 backdoor and remote access trojan associated with China-aligned espionage activity. It has been assessed as an updated evolution of DeedRAT and part of the broader ShadowPad lineage, and has been observed in operations linked to the REF5961 intrusion set as well as later campaigns targeting government and strategic-sector organizations in Asia. Multiple reports note that it is favored by several China-aligned threat actors and has appeared in intrusions against government entities in Southern, Southeastern, and Central Asia. The malware is typically deployed through DLL sideloading using a legitimate signed application and a malicious loader, after which shellcode decrypts and reconstructs the BloodAlchemy payload in memory from a custom encrypted and compressed format. It is designed for stealthy post-compromise access and supports multiple execution modes, including in-process execution, separate-thread execution, service-based execution, and creation of a process followed by code injection. Documented anti-analysis and evasion features include anti-debugging, anti-sandbox checks, encrypted strings and configuration data, and use of trusted or benign host processes. BloodAlchemy supports persistence through several mechanisms, including services, scheduled tasks, registry autoruns, and COM-based task scheduling interfaces. Its configuration can contain multiple command-and-control entries along with mutexes, process names for injection, and behavioral flags. Communication capabilities include HTTP, sockets, and named pipes, with support for encrypted, compressed, and encoded data transport. Reported backdoor functions include host information collection, component replacement and self-update, proxy configuration handling, self-uninstallation, and storage or removal of additional payloads. Observed command support and development artifacts indicate an actively maintained espionage implant rather than commodity malware. Operational reporting has tied BloodAlchemy to spearphishing-led intrusion chains in which malicious Office documents and archive-based lures trigger DLL sideloading and deployment of modular implants. It has been used in campaigns targeting government ministries, foreign affairs organizations, and other high-value public-sector entities, and has also been cited in activity against Central Asian energy and policy-related targets. Its lineage, tradecraft, and victimology are consistent with long-term intelligence collection operations.
WannaCry is a Windows ransomware family that caused a major global outbreak in 2017 by combining file-encryption extortion with worm-like network propagation. It is widely known under aliases including WanaCrypt0r, WanaCrypt, WanaCry, and WCRY. The malware is strongly associated with exploitation of the SMB vulnerability addressed by MS17-010, particularly through EternalBlue, and with use of the DoublePulsar backdoor to deliver its payload in memory and spread laterally across vulnerable systems. Operationally, WannaCry separates propagation and ransomware functions across multiple components. Its worming stage scans for vulnerable hosts, checks SMB behavior consistent with MS17-010 exposure, exploits susceptible systems, and can install or leverage DoublePulsar to inject a launcher into a privileged process. Subsequent stages deploy service-based components that establish execution and launch the ransomware interface and encryption workflow. Analyses of the 2.0 generation showed a modular design in which the SMB-spreading dropper, service component, and decryptor GUI were distinct binaries, making the propagation mechanism adaptable for delivery of other payloads. Core behaviors include rapid lateral movement over SMB, in-memory payload delivery through DoublePulsar, service creation for persistence, local network discovery to identify nearby targets, and defense-evasion measures such as hiding files. WannaCry has also been observed using a kill-switch domain check in prominent variants; later modified samples disabled the practical effect of that logic while retaining worm behavior. Some altered variants lacked functional encryption yet continued to propagate, underscoring that the family’s worm capability can persist independently of its extortion component. The malware targets Windows systems, especially unpatched or exposed hosts within enterprise and organizational networks. Its impact was amplified by self-propagation rather than reliance on user interaction during the main outbreak, although earlier reporting indicates the family had also appeared through other delivery paths before the global incident. WannaCry remains a defining example of ransomware fused with worm-like exploitation and post-exploitation backdoor use.
Evooo1Bot is a modular Linux botnet derived from the leaked Mirai source code that targets internet-facing edge infrastructure, including routers, firewalls, IP cameras, NAS appliances, and other embedded or gateway devices. Active since at least July 2026, it extends Mirai’s original distributed denial-of-service functionality with a broader post-compromise feature set oriented toward proxy abuse, credential collection, remote administration, and continued propagation. Initial compromise is achieved through exploitation of multiple known vulnerabilities in exposed devices and through SSH brute-force activity. After access is obtained, the malware deploys architecture-specific Linux binaries and attempts to reduce forensic visibility by clearing shell history. It performs anti-analysis and anti-honeypot checks before fully activating, including checks for debuggers, reverse-engineering tools, sandbox artifacts, virtualization or container environments, and known SSH honeypot indicators. A defining capability of Evooo1Bot is its SOCKS5 relay module, which converts compromised devices into persistent proxy nodes. It supports both direct-listening and reverse-relay modes, allowing operators to route traffic through victim infrastructure for concealment, geographic evasion, internal-network pivoting, and criminal proxy operations. The malware also supports encrypted command-and-control communications disguised to blend with normal encrypted web traffic. Beyond proxying, Evooo1Bot includes an interactive shell, file upload and download functions, self-update, and multiple persistence mechanisms using common Linux startup and scheduling facilities. It also contains a credential-sniffing component that monitors network activity to capture HTTP Basic Authentication material and cookies, as well as an SSH scanner that uses a built-in credential dictionary and additional checks to avoid honeypots. Newer variants include an embedded exploit dispatcher targeting additional products and enterprise-facing applications, although some exploit implementations appear to be faulty. Evooo1Bot retains Mirai-style botnet behavior through an inherited DDoS engine supporting multiple flood techniques, but its modular design and reverse proxy capability make it more versatile than conventional Mirai descendants. The malware is best characterized as a Linux botnet platform for distributed denial-of-service attacks, credential interception, proxy infrastructure creation, and follow-on intrusion support against exposed edge environments.
StopAndProtect is a multi-component cybercrime malware operation centered on a ransomware family of the same name and supported by a broader toolkit for covert data theft, surveillance, lateral movement, and victim interaction. The operation relies heavily on large numbers of compromised WordPress websites, which are repurposed as distributed infrastructure for malware delivery, command-and-control, and storage of exfiltrated victim data. Infection commonly begins with a ClickFix-style fake CAPTCHA lure that tricks users into executing a PowerShell command, after which staged PowerShell and .NET downloader/loader components deploy the main payloads. Observed payloads include SilentEncryptor, the ransomware component; SilentDataCollector, a stealer focused on file inventorying and selective exfiltration; NetworkShareScanner, which propagates via SMB shares and removable media; a VBS-based spreader that also supports WMI-driven lateral movement; a lock-screen module; and a custom chat utility used for operator-victim communication. Newer stealer variants have been observed with keylogging, screenshot capture, network-share mapping, and WhatsApp-focused collection features. The operation does not always culminate in encryption; in many cases it appears to prioritize reconnaissance and theft of file listings and selected files before, or instead of, ransomware deployment. The campaign targets Windows systems and has affected victims globally, with notable concentrations observed in the United States, Russia, and India. Operational security failures exposed internal logs, screenshots, stolen-data archives, and tooling used to manage the compromised WordPress infrastructure, indicating a broad, actively managed criminal ecosystem rather than isolated ransomware incidents. The abuse of outdated and vulnerable WordPress installations, along with malicious plugins and must-use plugins for persistence and arbitrary file upload, is a defining feature of the operation’s infrastructure strategy.
Mimikatz is a widely used open-source Windows post-exploitation tool created by Benjamin Delpy that is primarily known for credential theft and abuse of Windows authentication mechanisms. It can extract credentials from memory, including material associated with the Local Security Authority Subsystem Service, and is commonly used to dump passwords, hashes, and Kerberos-related secrets from compromised systems. Its functionality has made it a staple utility in both red-team operations and real-world intrusions by ransomware operators, cybercriminal groups, and state-linked threat actors. Beyond basic credential dumping, Mimikatz includes capabilities for abusing Active Directory replication and trust relationships. Its lsadump::dcsync functionality can request directory replication data from domain controllers to obtain password hashes, including highly sensitive account material, while lsadump::dcshadow can register a rogue domain controller context and push unauthorized directory changes. These features enable privilege escalation, persistence, and broad post-compromise control in Windows enterprise environments when attackers already possess sufficient privileges. Mimikatz is frequently observed after initial compromise as part of hands-on-keyboard intrusion activity rather than as a self-propagating payload. Threat actors commonly pair it with PowerShell, remote administration tools, lateral movement frameworks, and exfiltration utilities. It has been used in ransomware intrusions such as Medusa and Maze-related activity, in campaigns involving tools like Emotet, QakBot, and TrickBot, and in long-term intrusions where operators used it to harvest credentials before moving laterally or escalating privileges. Variants, modified builds, reflective loaders, and Mimikatz-like components are also commonly embedded or repurposed inside other malware families. Mimikatz targets Windows systems and is especially impactful in Active Directory environments because stolen credentials and replication abuse can enable domain-wide compromise. Its core role is credential access, but in practice it also supports privilege escalation, lateral movement, persistence, and broader post-exploitation objectives by giving attackers access to privileged accounts and authentication artifacts.
FormBook is a Windows information-stealing malware family that has been active since at least the mid-2010s and is widely used in cybercrime campaigns. It is commonly sold or distributed through criminal ecosystems and has frequently appeared in phishing-driven intrusions, malspam operations, and exploit-based delivery chains. FormBook has also been delivered by intermediary malware such as GuLoader and Smoke Loader, and has been observed in campaigns exploiting Microsoft Office Equation Editor vulnerability CVE-2017-11882. COVID-19-themed lures and financial or invoice-themed messages have been used in some campaigns, including activity targeting educational institutions and organizations in multiple regions. The malware’s core function is credential theft and data collection from infected Windows systems. High-confidence reporting associates FormBook with theft of credentials from major web browsers including Chrome, Firefox, and Opera, as well as from FTP applications. It is broadly characterized as an infostealer and information-stealing trojan. Related reporting also links it to anti-analysis measures, runtime code decryption, and stealthy execution techniques. FormBook has been documented using process injection and section-mapping-based injection techniques to load or execute payloads in a less conspicuous manner. It has been specifically associated with mapping sections using SEC_IMAGE and with use of NtMapViewOfSection as part of stealthier payload loading. These behaviors align with defense-evasion and post-exploitation tradecraft intended to reduce visibility compared with more traditional remote-memory-write patterns. FormBook was later rebranded as XLoader, which introduced notable changes including improved command-and-control encryption and expanded platform support through separate macOS-capable variants under the XLoader name. Despite that evolution, FormBook remains the widely recognized name for the original Windows infostealer lineage. In threat reporting and malware distribution ecosystems, FormBook is consistently treated as a prominent commodity stealer used across broad criminal campaigns rather than a tool exclusive to a single threat actor or sector.
NetSupport RAT is the malicious use of NetSupport Manager, a legitimate remote administration product, as a remote access trojan on Windows systems. In intrusion activity it is commonly deployed as a post-compromise remote-control payload that gives operators broad access to an infected host, including interactive control, follow-on malware installation, reconnaissance, data theft, and potential lateral movement. Threat actors frequently repackage or configure the NetSupport client for stealthy operation and persistence, turning commercial remote-support software into commodity malware. NetSupport RAT has appeared across a wide range of cybercrime campaigns and loader ecosystems rather than being exclusive to a single actor. It has been observed in fake browser update operations associated with SocGholish and similar clusters, in phishing and social-engineering campaigns, in cracked-software and pay-per-install distribution chains such as PrivateLoader, and in multi-stage malware delivery workflows involving JavaScript, PowerShell, batch scripts, archive extraction, and scheduled tasks or Run-key persistence. It has also been used by intrusion sets targeting Ukraine, including activity attributed to UAC-0050, and by initial access brokers seeking durable footholds on victim networks. Observed delivery lures include counterfeit browser updates, malicious documents, fake software installers, trading-themed applications, and other trusted-brand impersonation schemes. In several campaigns, NetSupport RAT was delivered alongside additional malware such as information stealers, cryptocurrency-focused implants, hidden VNC modules, or traffic-interception tooling, underscoring its role as a flexible access-enablement component within broader intrusion chains. Operationally, NetSupport RAT is used to establish persistent remote administration on compromised Windows hosts. Reported behaviors include host profiling, screenshot capture in some delivery chains before payload staging, execution of downloaded components, persistence via scheduled tasks or Windows Run entries, and communications with attacker-controlled gateways using NetSupport configuration parameters. Because it derives from legitimate software, it can blend into enterprise environments more easily than bespoke malware, and its repeated use across unrelated campaigns has made it a common commodity RAT in financially motivated and opportunistic intrusion activity.
PylangGhost is a Python-based remote access trojan associated with the North Korean threat actor Famous Chollima, also tracked as Wagemole and linked by multiple vendors to the broader Contagious Interview or DeceptiveDevelopment activity cluster. It is primarily used against Windows systems, while related campaigns commonly deploy the closely aligned GolangGhost variant against macOS. The malware has been observed in financially motivated operations targeting cryptocurrency, blockchain, Web3, finance, and technology professionals, including both technical staff and business-facing roles with potential access to wallets, credentials, or company funds. PylangGhost is modular and supports remote command execution, system profiling, file upload and download, browser data theft, and persistence. Reported module sets include orchestration, configuration, archive handling, command execution, command-and-control communications, and a dedicated stealer component. Its communications use HTTP with RC4-encrypted payloads and integrity checking. On infected hosts it can maintain state, identify victims, and receive additional tasking from its operators. A core function of PylangGhost is credential and session theft from Chromium-based browsers. It has been reported stealing saved credentials, authentication cookies, session data, and data from more than 80 browser extensions, including cryptocurrency wallet and password-manager extensions. Multiple reports also state that it is engineered to bypass newer Chrome protections, including app-bound credential protection, in order to recover protected browser secrets. This makes it relevant not only for direct credential theft but also for session hijacking and cryptocurrency theft. Delivery has most prominently occurred through highly tailored fake job interview and recruiter-impersonation campaigns. Victims are lured through professional networking and messaging platforms into fraudulent assessment portals, then manipulated with ClickFix-style prompts that claim a camera, microphone, or driver issue must be fixed by pasting a supplied command into the system. On Windows, this execution chain has been reported to use native scripting and download utilities, unpack a bundled Python runtime, and launch PylangGhost through staged loaders. Some variants have been compiled with Nuitka into native Python extension modules to hinder analysis and signature-based detection. Beyond direct social-engineering delivery, PylangGhost has also been observed in software supply-chain abuse. Researchers reported malicious npm packages distributing the malware, including campaigns that used JavaScript loaders, runtime decryption, environment profiling, sandbox checks, and staged retrieval through cloud-hosted infrastructure. These supply-chain cases expand the risk from individual job seekers to developers, CI/CD environments, and organizations consuming compromised dependencies. PylangGhost is best characterized as a Windows-focused RAT used in DPRK-linked financially motivated intrusion campaigns, combining remote access, persistence, defense evasion, credential theft, session theft, and browser-extension harvesting to support theft of cryptocurrency and access to enterprise resources.
GolangGhost is a Go-based remote access trojan associated with North Korean threat activity, especially clusters tracked as Famous Chollima, Wagemole, WaterPlum, and broader Contagious Interview or ClickFake Interview operations. It is also referred to as FlexibleFerret and WeaselStore in reporting that treats the Go and Python implementations as closely related variants, with PylangGhost representing the Python counterpart. The malware has been used primarily against macOS victims in recruiter-themed social-engineering campaigns targeting cryptocurrency, Web3, blockchain, and related business roles, though some reporting also describes Windows and broader cross-platform lineage. Delivery commonly occurs through fake job interviews, skill assessments, and ClickFix-style lures in which victims are persuaded to paste attacker-supplied commands into a terminal after a fabricated camera or microphone problem. Operators have used recruiter impersonation on professional and messaging platforms and have tailored lures to both technical and non-technical personnel with access to digital assets or sensitive corporate systems. GolangGhost is modular and supports command execution, file transfer, host profiling, encrypted command-and-control communications, and theft of browser data. Documented capabilities include stealing saved browser credentials, cookies, session data, and data from numerous browser extensions, especially cryptocurrency wallets and password managers. On macOS it has been observed retrieving browser secrets from the Keychain to decrypt Chromium-derived credential stores, harvesting wallet-related extension data, and establishing persistence through Launch Agent mechanisms. Reporting also describes functionality to alter Chromium Secure Preferences to grant elevated permissions to wallet extensions such as MetaMask, enabling abuse of the victim's trusted browser context. Some analyses note Linux credential-decryption logic as part of the codebase, reinforcing its cross-platform design heritage. Operationally, GolangGhost serves both as an infostealer and as a RAT that maintains ongoing access to infected systems. Its use aligns with financially motivated DPRK operations focused on cryptocurrency theft, credential harvesting, and follow-on access into organizational environments connected to exchanges, DeFi platforms, venture firms, and other digital-asset ecosystems.
GuLoader, also known as CloudEyE, is a Windows malware loader and downloader widely used to retrieve, decrypt, and execute second-stage payloads on victim systems. It has been observed delivering a broad range of commodity malware, including information stealers and remote access trojans such as FormBook, XLoader, Remcos, NanoCore, LokiBot, Agent Tesla, NetWire, Vidar, and AZORult. GuLoader has been linked to large-scale criminal delivery operations and has been used by multiple threat actors, including campaigns associated with RATicate as well as reporting that ties its use to groups such as TA505, TA542, and Gorgon APT. GuLoader is commonly distributed through phishing and malspam campaigns using malicious links, archive attachments, and Microsoft Office documents with embedded macros. Some campaigns have also used exploit-based delivery through CVE-2017-11882. Lures have included tax invoices, shipping statements, financial documents, and COVID-19-themed messages. The malware has also been observed using cloud-hosted staging, particularly web services and cloud storage platforms, to host encrypted payloads and obscure delivery infrastructure. Functionally, GuLoader acts as an intermediary execution layer. It downloads additional binaries or shellcode over HTTP and from cloud services, decrypts the payload, and then executes it in memory. Execution methods include shellcode injection into suspended donor processes, use of section-mapping-based injection with NtCreateSection and NtMapViewOfSection, and cross-architecture injection techniques such as Heaven’s Gate to reach 64-bit targets from a 32-bit process under WoW64. GuLoader has also been described as using native APIs extensively for discovery and execution, and some variants abuse legitimate processes such as RegAsm during injection workflows. The malware incorporates substantial anti-analysis and defense-evasion features. Reported behaviors include anti-VM and anti-sandbox checks, debugger detection, time-based anti-debugging, string hashing, patching of debugging-related functions, attempts to remove user-mode hooks, and self-deletion from temporary directories after execution. Persistence has also been observed through the Windows RunOnce autostart mechanism. GuLoader is notable for its role as a malware-as-a-service-style delivery component and for the frequency with which it appears in phishing-driven intrusion chains. Its combination of cloud-hosted payload retrieval, in-memory execution, process injection, and anti-analysis tradecraft has made it a durable and widely reused loader in Windows-focused cybercrime operations.
Mirage2FA is a phishing-as-a-service adversary-in-the-middle framework used to target Microsoft 365 and Microsoft Entra ID users. It operates by placing an attacker-controlled portal between the victim and legitimate Microsoft authentication services, proxying the login flow in real time so victims complete their normal sign-in and multi-factor authentication process while the operator captures submitted credentials and authenticated session cookies. This enables session hijacking and follow-on access to cloud email, file repositories, and single sign-on-connected enterprise applications without requiring additional MFA prompts. The platform’s activity has been associated with a threat group identified as LinX Coders. Observed campaigns have targeted organizations across numerous countries, with notable concentration in the United States, and have affected sectors including technology, manufacturing, education, healthcare, consulting, and finance. Reported lure themes included corporate human-resources and benefits notifications. Mirage2FA delivery has relied on browser-based phishing content distributed through links and HTML-family attachments, including XHTML and SVG formats. The phishing chain uses obfuscated client-side scripts and persistent communications to relay authentication data to legitimate services and return responses to the victim, allowing the attack to remain transparent during login. The operation is notable for functioning entirely within the browser rather than requiring deployment of a traditional binary payload. Its core capabilities are credential theft and, more prominently, theft of authenticated session material after MFA completion. Because compromise centers on active sessions and refresh tokens, remediation requires revocation of those sessions rather than password reset alone.